{"schema":"aeternae-malware-metadata/v1","generated_at":"2026-10-08T09:16:20+00:00","total_matching":1,"page":1,"page_size":200,"records":[{"id":"9e2f5328dfb0498e0520b65b94c654414a5acc70dd04270614c910cdd8474985","kind":"reference","title":"ShadowPad - S0596","family":"ShadowPad - S0596","category":"Malware intelligence","summary":"Name of ATT&CK software | [ShadowPad](https://attack.mitre.org/software/S0596) is a modular backdoor that was first identified in a supply chain compromise of the NetSarang software in mid-July 2017. The malware was originally thought to be exclusively used by [APT41](https://attack.mitre.org/groups/G0096), but has since been observed to be used by various Chinese threat activity groups. (Citation","first_seen":1722355016,"last_seen":1770672334,"created_at":1791439684,"updated_at":1791440466,"source_count":1,"data":{"context":"2026/02/knife-cutting-the-edge.json","tags":["misp:galaxy-name=\"Malware\"","misp:galaxy-type=\"mitre-malware\"","misp-galaxy:mitre-malware=\"ShadowPad - S0596\""],"aliases":[],"references":["https://github.com/Cisco-Talos/IOCs/blob/main/2024/08/chinese-hacking-group-apt41-compromised-taiwanese-government-affiliated-research-institute.json","https://github.com/Cisco-Talos/IOCs/blob/main/2026/02/knife-cutting-the-edge.json"],"filenames":[],"features":[],"related_cves":[],"labels":["ShadowPad - S0596"]},"observations":[{"source_id":"talos_ioc","source_url":"https://github.com/Cisco-Talos/IOCs/blob/main/2024/08/chinese-hacking-group-apt41-compromised-taiwanese-government-affiliated-research-institute.json","source_label":"ShadowPad - S0596","evidence_class":"provider_reported","confidence":null,"observed_at":1722355016,"fetched_at":1791439684,"data":{"context":"2024/08/chinese-hacking-group-apt41-compromised-taiwanese-government-affiliated-research-institute.json","tags":["misp:galaxy-name=\"Malware\"","misp:galaxy-type=\"mitre-malware\"","misp-galaxy:mitre-malware=\"ShadowPad - S0596\""],"aliases":[],"references":["https://github.com/Cisco-Talos/IOCs/blob/main/2024/08/chinese-hacking-group-apt41-compromised-taiwanese-government-affiliated-research-institute.json"],"family":"ShadowPad - S0596"}},{"source_id":"talos_ioc","source_url":"https://github.com/Cisco-Talos/IOCs/blob/main/2026/02/knife-cutting-the-edge.json","source_label":"ShadowPad - S0596","evidence_class":"provider_reported","confidence":null,"observed_at":1770672334,"fetched_at":1791440466,"data":{"context":"2026/02/knife-cutting-the-edge.json","tags":["misp:galaxy-name=\"Malware\"","misp:galaxy-type=\"mitre-malware\"","misp-galaxy:mitre-malware=\"ShadowPad - S0596\""],"aliases":[],"references":["https://github.com/Cisco-Talos/IOCs/blob/main/2026/02/knife-cutting-the-edge.json"],"family":"ShadowPad - S0596"}}],"indicators":[]}]}