AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
Æ / PUBLIC MALWARE INTELLIGENCE

Follow the evidence.

Published file metadata, source observations and research history in one connected catalog.

131,398Catalog records
62,804File records
147,419Source observations
123Family labels
Clear filters
1 MATCHING RECORDS
Export metadata JSON · CSV
REFERENCE1 SOURCE

ShadowPad - S0596

ShadowPad - S0596

Name of ATT&CK software | [ShadowPad](https://attack.mitre.org/software/S0596) is a modular backdoor that was first identified in a supply chain compromise of the NetSarang software in mid-July 2017. The malware was originally thought to be exclusively used by [APT41](https://attack.mitre.org/groups/G0096), but has since been observed to be used by various Chinese threat activity groups. (Citation

misp:galaxy-name="Malware"misp:galaxy-type="mitre-malware"misp-galaxy:mitre-malware="ShadowPad - S0596"
First reported 2024-07-30 15:56 UTCOpen evidence record

Source labels and confidence are preserved. A filename or report mention alone does not establish that a file is malicious. Indicator observation dates describe the cited source; collection dates describe this catalog.