ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System Access

Threat actors have used a newly fixed security vulnerability in Microsoft Windows Server Update Services (WSUS) to spread malware called ShadowPad.

According to a report released last week by AhnLab Security Intelligence Center (ASEC), the attacker used PowerCat, an open-source PowerShell-based Netcat utility, to obtain a system shell (CMD), after which they downloaded and installed ShadowPad using certutil and curl. The attacker targeted Windows servers with WSUS enabled, exploiting CVE-2025-59287 for initial access.

Chinese state-sponsored hacking groups employ ShadowPad, a modular backdoor that originally surfaced in 2015 and was dubbed a masterpiece of privately sold malware in Chinese espionage by SentinelOne in an August 2021 analysis. ShadowPad is thought to be a successor of PlugX.

Microsoft fixed CVE-2025-59287 this month, which describes a serious deserialization vulnerability in WSUS read more about ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System Access.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *