Netskope Threat Labs

ShadowPad

ATP Sandbox Adv. HeuristicsAVNetskope IPS

ShadowPad is a modular backdoor used by Chinese state sponsored groups, and researchers regard it as one of the most significant espionage platforms of the modern era. It reached victims through a supply chain compromise of server software in 2015 and 2017, and its plugin architecture lets operators extend it with remote control, credential theft, and module downloads on demand. Multiple APT crews have deployed it in campaigns against governments and industries across Asia and beyond.

First seen
February 2022
Last seen
October 2026
Shadowpad

21 techniques across 5 tactics.

TA0005 Stealth

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1033System Owner/User Discovery
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1124System Time Discovery
  • T1680Local Storage Discovery

TA0011 Command and Control

TA0010 Exfiltration

TA0112 Defense Impairment

Alert Name
Gen:Variant.ShadowPad.14
Gen:Variant.ShadowPad.15
Gen:Variant.Shadowpad.20
Trojan.ShadowPad.1
Trojan.ShadowPad.2
Trojan.ShadowPad.3
Trojan.ShadowPad.4
Trojan.ShadowPad.A
Trojan.ShadowPad.B
Trojan.ShadowPad.F