ShadowPad

S0596

Malware.View on attack.mitre.org

About this malware

ShadowPad is a modular backdoor that was first identified in a supply chain compromise of the NetSarang software in mid-July 2017. The malware was originally thought to be exclusively used by APT41, but has since been observed to be used by various Chinese threat activity groups.

Techniques used21

Procedure examples21

TechniqueProcedure example
T1016
System Network Configuration Discovery

ShadowPad has collected the domain name of the victim system.

T1027
Obfuscated Files or Information

ShadowPad has encrypted its payload, a virtual file system, and various files.

T1027.011
Fileless Storage

ShadowPad maintains a configuration block and virtual file system in the Registry.

T1029
Scheduled Transfer

ShadowPad has sent data back to C2 every 8 hours.

T1033
System Owner/User Discovery

ShadowPad has collected the username of the victim system.

T1055
Process Injection

ShadowPad has injected an install module into a newly created process.

T1055.001
Dynamic-link Library Injection

ShadowPad has injected a DLL into svchost.exe.

T1057
Process Discovery

ShadowPad has collected the PID of a malicious process.

T1070
Indicator Removal

ShadowPad has deleted arbitrary Registry values.

T1071.001
Web Protocols

ShadowPad communicates over HTTP to retrieve a string that is decoded into a C2 server URL.

T1071.002
File Transfer Protocols

ShadowPad has used FTP for C2 communications.

T1071.004
DNS

ShadowPad has used DNS tunneling for C2 communications.

T1082
System Information Discovery

ShadowPad has discovered system information including memory status, CPU frequency, and OS versions.

T1095
Non-Application Layer Protocol

ShadowPad has used UDP for C2 communications.

T1105
Ingress Tool Transfer

ShadowPad has downloaded code from a C2 server.

View all 21 procedure examples

Groups that use it8

Campaigns2

References3

  1. Kaspersky ShadowPad Aug 2017 Open source
    Kaspersky Lab. (2017, August). ShadowPad: popular server management software hit in supply chain attack. Retrieved March 22, 2021.
  2. Recorded Future RedEcho Feb 2021 Open source
    Insikt Group. (2021, February 28). China-Linked Group RedEcho Targets the Indian Power Sector Amid Heightened Border Tensions. Retrieved March 22, 2021.
  3. Securelist ShadowPad Aug 2017 Open source
    GReAT. (2017, August 15). ShadowPad in corporate networks. Retrieved March 22, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.