Tag: ShadowPad Malware

China-Linked Ink Dragon Hacks Governments Using ShadowPad and FINALDRAFT Malware
News

China-Linked Ink Dragon Hacks Governments Using ShadowPad and FINALDRAFT Malware

Since July 2025, the threat actor known as Jewelbug has been concentrating more on European government targets while still attacking organizations in South America and Southeast Asia. The cluster is being monitored by Check Point Research under the moniker Ink Dragon. The larger cybersecurity community also makes reference to it under the names Earth Alux, REF7707, and CL-STA-0049. It is estimated that the hacker gang with ties to China has been working since at least March 2023. The cybersecurity firm stated in a technical analysis released on Tuesday that the actor's efforts combine strong software engineering, rigorous operational playbooks, and a readiness to reuse platform-native tools to blend into regular enterprise telemetry. Their incursions are both successful and covert b...
ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System Access
News

ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System Access

Threat actors have used a newly fixed security vulnerability in Microsoft Windows Server Update Services (WSUS) to spread malware called ShadowPad. According to a report released last week by AhnLab Security Intelligence Center (ASEC), the attacker used PowerCat, an open-source PowerShell-based Netcat utility, to obtain a system shell (CMD), after which they downloaded and installed ShadowPad using certutil and curl. The attacker targeted Windows servers with WSUS enabled, exploiting CVE-2025-59287 for initial access. Chinese state-sponsored hacking groups employ ShadowPad, a modular backdoor that originally surfaced in 2015 and was dubbed a masterpiece of privately sold malware in Chinese espionage by SentinelOne in an August 2021 analysis. ShadowPad is thought to be a successor of...
Pakistani Entities Targeted in Sophisticated Attack Deploying ShadowPad Malware
News

Pakistani Entities Targeted in Sophisticated Attack Deploying ShadowPad Malware

ShadowPad, a replacement for the PlugX backdoor that is frequently linked to Chinese hacker groups, was delivered through the penetration of an application used by numerous companies in Pakistan by an undisclosed threat actor. According to Trend Micro, the targets included the Pakistani government, a public sector bank, and a telecommunications company. Between the middle of February 2022 and September 2022, the infections occurred. The cybersecurity firm speculated that the event might have been caused by a supply-chain assault, in which a legal piece of software used by potential targets is trojanized to spread malware that can capture private data from infected systems read more Pakistani Entities Targeted in Sophisticated Attack Deploying ShadowPad Malware. Stay informed with...