ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System Access
Threat actors have used a newly fixed security vulnerability in Microsoft Windows Server Update Services (WSUS) to spread malware called ShadowPad.
According to a report released last week by AhnLab Security Intelligence Center (ASEC), the attacker used PowerCat, an open-source PowerShell-based Netcat utility, to obtain a system shell (CMD), after which they downloaded and installed ShadowPad using certutil and curl. The attacker targeted Windows servers with WSUS enabled, exploiting CVE-2025-59287 for initial access.
Chinese state-sponsored hacking groups employ ShadowPad, a modular backdoor that originally surfaced in 2015 and was dubbed a masterpiece of privately sold malware in Chinese espionage by SentinelOne in an August 2021 analysis. ShadowPad is thought to be a successor of...



