ShadowPad
MITRE ATT&CK: S0596 View on attack.mitre.org
Aliases: POISONPLUG.SHADOW, XShellGhost, ShadowPad
- First seen
- 2017-07-15 00:00:00
- Malware type
- backdoor, trojan
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 575 (93 malicious)
- Last IoC activity
- 2026-09-02 00:37:41
- Profile updated
- 2026-07-07 12:51:12
Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical technology-and-telecommunications
Targeted regions: country_code:us country_code:de country_code:gb country_code:jp country_code:cn
Context
ShadowPad is a modular backdoor that was first identified in a supply chain compromise of the NetSarang software in mid-July 2017. The malware was originally thought to be exclusively used by APT41, but has since been observed to be used by various Chinese threat activity groups.
Recent IoC activity
93 malicious indicators in Maltiverse are attributed to ShadowPad (S0596). The 20 most recently updated:
Detection coverage
- 2 YARA rules
- 425 Sigma rules
Malware & tools used
- System Owner/User Discovery (attack-pattern)
- Modify Registry (attack-pattern)
- System Time Discovery (attack-pattern)
- Indicator Removal (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Fileless Storage (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Scheduled Transfer (attack-pattern)
- Process Discovery (attack-pattern)
- DNS (attack-pattern)
- Non-Standard Encoding (attack-pattern)
- File Transfer Protocols (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Web Protocols (attack-pattern)
- Process Injection (attack-pattern)
- System Information Discovery (attack-pattern)
- Local Storage Discovery (attack-pattern)
- Domain Generation Algorithms (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
Used by threat actors
- RedDelta Modified PlugX Infection Chain Operations (campaign)
- Indian Critical Infrastructure Intrusions (campaign)
- BRONZE BUTLER (threat-actor)
- Earth Lusca (threat-actor)
- Tropic Trooper (threat-actor)
- Tonto Team (threat-actor)
- Mustang Panda (threat-actor)
- Aquatic Panda (threat-actor)
- APT41 (threat-actor)
- RedEcho (threat-actor)
Detection rules
- SEKOIA_Apt_Shadowpad_First_Called_Function (yara-rule)
- MALPEDIA_Win_Shadowpad_Auto (yara-rule)
Reports & references
- Trend Micro — Supply Chain Attack Targeting Pakistani Government Delivers Shad (report)
- pwc.co.uk — Cyber Threats 2019 Retrospect (report)
- ESET — Luckymouse Ta428 Compromise Able Desktop (report)
- MITRE ATT&CK — G0096 (report)
- CrowdStrike — Report2021Gtr (report)
- recordedfuture.com — Redecho Targeting Indian Power Sector (report)
- therecord.media — Redecho Group Parks Domains After Public Exposure (report)
- community.riskiq.com — D8B749F2 (report)
- hello.global.ntt — The Operations Of Winnti Group (report)
- Trend Micro — Technical Brief Delving Deep An Analysis Of Earth Lusca Operations (report)
- recordedfuture.com — Chinese Group Tag 22 Targets Nepal Philippines Taiwan (report)
- sentinelone.com — Sentinelone Sentinellabs Shadowpad Wp V2 (report)
- pwc.co.uk — Chasing Shadows (report)
- go.recordedfuture.com — Cta 2023 0808 (report)
- youtube.com — Watch (report)
- ESET — Operation Fishmedley (report)
- Kaspersky — 97937 (report)
- i.blackhat.com — As 22 Leonsilvia Nextgenplugxshadowpad (report)
- ESET — Worok Big Picture (report)
- Broadcom/Symantec — Critical Infrastructure Attacks (report)
- Broadcom/Symantec — Lancefly Merdoor Zxshell Custom Backdoor (report)
- jsac.jpcert.or.jp — Jsac2025 1 5 Leon Chang Theo Chen En (report)
- sentinelone.com — Moshen Dragons Triad And Error Approach Abusing Security Software To Sideload Plugx And Shadowpad (report)
- Trend Micro — Earth Krahang (report)
- Trend Micro — Updated Shadowpad Malware Leads To Ransomware Deployment (report)
External references
- mitre-attack — S0596
- POISONPLUG.SHADOW
- FireEye APT41 Aug 2019
- Securelist ShadowPad Aug 2017
- Recorded Future RedEcho Feb 2021
- Kaspersky ShadowPad Aug 2017
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy