Cisco Talos published IOCs ↗
- Evidence class
- provider reported
- Source family label
- ShadowPad - S0596
- Source confidence
- Not reported
- Observed
- 2026-02-09 21:25 UTC
- Retrieved
- 2026-10-08 06:21 UTC
Name of ATT&CK software | [ShadowPad](https://attack.mitre.org/software/S0596) is a modular backdoor that was first identified in a supply chain compromise of the NetSarang software in mid-July 2017. The malware was originally thought to be exclusively used by [APT41](https://attack.mitre.org/groups/G0096), but has since been observed to be used by various Chinese threat activity groups. (Citation
2026/02/knife-cutting-the-edge.jsonNetwork addresses are displayed in defanged form.
No file hashes or network indicators were published in this record.