Trending

#shadowpad

Latest posts tagged with #shadowpad on Bluesky

Latest Top
Trending

Posts tagged #shadowpad

Post image

The #Shadowpad samples are signed with two certificates both issued from the signer “四川奇雨网络科技有限公司”. This is a company located in Sichuan Chengdu, China specialised in developing computer software and providing network communication devices.

1 0 1 0
Preview
Knife Cutting the Edge: Disclosing a China-nexus gateway-monitoring AitM framework Cisco Talos uncovered “DKnife,” a fully featured gateway-monitoring and adversary-in-the-middle (AitM) framework comprising seven Linux-based implants.

🔥 NEW research published: We uncover #DKnife, a China-nexus gateway-monitoring framework that intercepts network traffic, monitors user activity, and delivers malware #Shadowpad & #DarkNimbus via routers and edge devices.
blog.talosintelligence.com/knife-cuttin...

3 2 1 0
Preview
China-Linked Ink Dragon Hacks Governments Using ShadowPad and FINALDRAFT Malware campaign is still in progress read more about China-Linked Ink Dragon Hacks Governments Using ShadowPad and FINALDRAFT Malware

China-Linked Ink Dragon Hacks Governments Using ShadowPad and FINALDRAFT Malware reconbee.com/china-linked...

#china #InkDragon #government #shadowpad #FINALDRAFT #malware #malwareattack #cyberattack

0 0 0 0
Ink Dragon Builds Victim-Based C2 Relay Network

~Checkpoint~
Threat actor Ink Dragon turns compromised IIS servers into a distributed C2 relay network using a custom ShadowPad module.
-
IOCs: CVE-2025-49706, CVE-2025-53771, CVE-2025-49704
-
#InkDragon #ShadowPad #ThreatIntel

0 0 0 0
Post image

Critical WSUS flaw CVE-2025-59287 exploited to deploy ShadowPad malware, granting full system access. Immediate patching is essential. #CyberSecurity #WSUS #ShadowPad #MalwareAlert Link: thedailytechfeed.com/shadowpad-ma...

0 0 0 0
Post image

Alert: ShadowPad malware is exploiting a critical WSUS vulnerability (CVE-2025-59287) to gain full system access. Ensure your systems are patched and monitor for unusual activities. #CyberSecurity #WSUS #ShadowPad Link: thedailytechfeed.com/shadowpad-ma...

0 0 0 0
Post image

Microsoft corregge il bug su WSUS, ma gli hacker Cinesi arrivano prima

📌 Link all'articolo : www.redhotcyber.com/post/mic...

#redhotcyber #news #cybersecurity #hacking #malware #windowsserver #microsoft #shadowpad #powercat

0 0 0 0
ShadowPad Backdoor Deployed via Critical WSUS Server Vulnerability Chinese state-sponsored APTs are actively exploiting a critical RCE vulnerability (CVE-2025-59287) in Microsoft WSUS to deploy the ShadowPad backdoor for espionage. Patching is critical.

🔥 CRITICAL: Chinese APTs are actively exploiting a WSUS RCE vulnerability (CVE-2025-59287) to deploy the ShadowPad backdoor. Attackers gain SYSTEM access for espionage. Patching is urgent! #ThreatIntel #CVE #ShadowPad #CyberAttack

0 0 0 0
Preview
ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System Access deserialization vulnerability in WSUS read more about ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System Access

ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System Access reconbee.com/shadowpad-ma...

#shadowpad #malware #malwareattack #WSUS #Vulnerability #cyberattack

2 0 0 0
Post image

Analisi dell’attacco ShadowPad via CVE-2025-59287 su WSUS, con installazione tramite curl e certutil e gravi rischi per infrastrutture enterprise.

#ahnlab #apt #backdoor #cina #ShadowPad #WSUS
www.matricedigitale.it/2025/11/24/a...

0 0 0 0
Security threat visualization

Security threat visualization

ShadowPad is exploiting a HIGH-severity WSUS vulnerability—full system access at stake! Euro orgs: restrict WSUS access, watch for patches, monitor for unusual activity. Act now. radar.offseq.com/threat/shadowpad-malware... #OffSeq #WSUS #ShadowPad

0 0 0 0
Post image

Chinese hackers are exploiting a critical WSUS vulnerability to deploy ShadowPad malware. Ensure your systems are patched and secure. #CyberSecurity #WSUS #ShadowPad #InfoSec Link: thedailytechfeed.com/chinese-hack...

0 0 0 0
Post image

Jewelbug: APT cinese attivo dal 2023 con backdoor modulari, sideloading DLL, uso di Graph API e nuove intrusioni che coinvolgono provider IT russi.

#apt #cina #EarthAlux #FINALDRAFT #iis #Jewelbug #MicrosoftGraphAPI #ShadowPad #supplychain
www.matricedigitale.it/2025/10/16/j...

0 0 0 0
Preview
Chinese-Linked Hackers Targeted 70+ Global Organizations, SentinelLABS Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread

⚠️ Chinese hackers hit governments, media, and cybersecurity firms in a global cyber espionage spree. Over 70 orgs targeted using tools like ShadowPad and PurpleHaze.

Read: hackread.com/chinese-link...

#CyberSecurity #China #CyberAttack #PurpleHaze #ShadowPad #APT15

4 2 0 0
Preview
Famous Sparrow APT Group: Enhanced Cyber Arsenal and Global Threats | The DefendOps Diaries Explore the enhanced cyber arsenal of the Famous Sparrow APT group and their global threat impact.

Famous Sparrow APT Group: Enhanced Cyber Arsenal and Global Threats

#famoussparrow
#aptgroup
#cyberespionage
#shadowpad
#cybersecurity

0 0 0 0
Preview
New SparrowDoor Backdoor Variants Uncovered | FamousSparrow FamousSparrow APT group deploys new SparrowDoor backdoor variants in targeted cyberattacks on U.S. and Mexican organizations. Discover how

🚨 Cyber Alert: FamousSparrow APT Group Resurfaces!
Two new variants of the SparrowDoor

👉 technijian.com/cyber-securi...

#CyberSecurity #Malware #FamousSparrow #APTThreat #SparrowDoor #ShadowPad #Technijian #InfoSec #CyberAttack #DataBreach #ThreatIntelligence #CISO #IncidentResponse #HackingNews

0 0 0 0

This campaign is also the first documented time that FamousSparrow used #ShadowPad, a privately sold modular backdoor known to only be supplied to threat actors affiliated with China. 4/5

2 0 1 0
Preview
Cases of China-Backed Spy Groups Using Ransomware Come to Light Cyberattacks detected by Trend Micro and Orange Cyberdefense find hackers using malware linked to China-backed groups and ransomware, adding more evidence that nation-state cyberespionage groups are…

中国が支援するスパイ集団がランサムウェアを使用していた事例が明るみに

Cases of China-Backed Spy Groups Using Ransomware Come to Light #SecurityBoulevard (Feb 21)

#中国 #サイバースパイ #ランサムウェア #ShadowPad #PlugX

0 0 0 0
Preview
China-Linked Attackers Exploit Check Point Flaw to Deploy ShadowPad and Ransomware install ShadowPad and PlugX read more about China-Linked Attackers Exploit Check Point Flaw to Deploy ShadowPad and Ransomware

China-Linked Attackers Exploit Check Point Flaw to Deploy ShadowPad and Ransomware reconbee.com/china-linked...

#china #Chinese #Shadowpad #ransomware #ransomwareattack #cyberattacks

1 0 0 0
Original post on securityweek.com

Chinese APT Tools Found in Ransomware Schemes, Blurring Attribution Lines China-linked cyberespio...

www.securityweek.com/chinese-apt-tools-found-...

#Cybercrime #Malware #& #Threats #Nation-State […]

[Original post on securityweek.com]

0 0 0 0
Post image Post image

For incident responders, remember to retrieve the volume serial number where #Shadowpad was deployed, since it is used to encrypt the payload in the registry. Those serial numbers can also be found in LNK and Prefetch files in case you don't have live access to the host anymore

0 0 1 0
Post image Post image Post image

We released a report on an updated version of #Shadowpad including anti-debugging features and new configuration structure, that in some cases deploy a custom ransomware family. We have mainly seen the manufacturing industry being targeted in Europe and Asia www.trendmicro.com/fr_fr/resear...
#APT

6 3 1 0

🆕We publish today the result of a deep-dive investigation into a malicious campaign leveraging #ShadowPad and #PlugX to distribute a previously-undocumented ransomware, dubbed #NailaoLocker.
This campaign targeted 🇪🇺 organizations during S2 2024 and is tied to Chinese TA 🇨🇳.

1 0 1 0
Preview
APT41 Hackers Attacking Research Institute with ShadowPad and Cobalt Strike Cisco Talos has unearthed a sophisticated cyber-espionage campaign targeting a Taiwanese government-affiliated research institute.

APT41 Hackers Attacking Research Institute with ShadowPad and Cobalt Strike
cybersecuritynews.com/apt41-hacker...
#Infosec #Security #Cybersecurity #CeptBiro #APT41Hackers #ResearchInstitute #ShadowPad #CobaltStrike

1 0 0 0
Preview
APT41 likely compromised Taiwanese government-affiliated research institute with ShadowPad and Cobalt Strike ShadowPad, widely considered the successor of PlugX, is a modular remote access trojan (RAT) only seen sold to Chinese hacking groups.

#APT41 rumored to have compromised a Taiwanese government-affiliated research institute.

The malicious campaign was run using #Cobalt Strike and RAT #ShadowPad (namely the successor of PlugX).

blog.talosintelligence.com/chinese-hack...

0 0 0 0
Preview
Stealthy BLOODALCHEMY Malware Targeting ASEAN Government Networks BLOODALCHEMY malware, an updated version of Deed RAT and successor to ShadowPad, targets government organizations in Southern and Southeastern Asia.


🚨 ALERT: BLOODALCHEMY #malware, an updated version of Deed RAT and successor to #ShadowPad, targets government organizations in Southern and Southeastern Asia.

thehackernews.com/2024/05/japa...
#cybersecurity #infosec #hacking

0 1 0 0