AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← Catalog
REFERENCEPUBLIC INTELLIGENCE

ShadowPad - S0596

Name of ATT&CK software | [ShadowPad](https://attack.mitre.org/software/S0596) is a modular backdoor that was first identified in a supply chain compromise of the NetSarang software in mid-July 2017. The malware was originally thought to be exclusively used by [APT41](https://attack.mitre.org/groups/G0096), but has since been observed to be used by various Chinese threat activity groups. (Citation

Reference details

Primary displayed family label
ShadowPad - S0596
Source context
2026/02/knife-cutting-the-edge.json
First reported
2024-07-30 15:56 UTC
Last reported
2026-02-09 21:25 UTC
Catalog updated
2026-10-08 06:21 UTC

Source family labels

ShadowPad - S0596

Tags

misp:galaxy-name="Malware"misp:galaxy-type="mitre-malware"misp-galaxy:mitre-malware="ShadowPad - S0596"

Published indicators

Network addresses are displayed in defanged form.

No file hashes or network indicators were published in this record.

Source observations

Cisco Talos published IOCs ↗

Evidence class
provider reported
Source family label
ShadowPad - S0596
Source confidence
Not reported
Observed
2026-02-09 21:25 UTC
Retrieved
2026-10-08 06:21 UTC

Cisco Talos published IOCs ↗

Evidence class
provider reported
Source family label
ShadowPad - S0596
Source confidence
Not reported
Observed
2024-07-30 15:56 UTC
Retrieved
2026-10-08 06:08 UTC

Research references