APT41 likely compromised Taiwanese government-affiliated research institute with ShadowPad and Cobalt StrikeCisco Talos·Aug 1, 12:00 UTC · Aug 1, 2024Threat actorCVE-2018-082460
Researchers Link ShadowPad Malware Attacks to Chinese Ministry and PLAThe Hacker News·Feb 17, 05:17 UTC · Feb 17, 2022Malware42
Attackers deliver ShadowPad via newly patched WSUS RCE bugSecurity Affairs·Nov 24, 12:35 UTC · Nov 24, 2025Vulnerability in the wildCVE-2025-5928760
ShadowPad backdoor was spread in corporate networks through software update mechanismSecurity Affairs·May 7, 12:30 UTC · May 7, 2018Malware55
China-Linked Attackers Exploit Check Point Flaw to Deploy ShadowPad and RansomwareThe Hacker News·Feb 22, 06:56 UTC · Feb 22, 2025RansomwareCVE-2024-2491960
ShadowPad Malware is Becoming a Favorite Choice of Chinese Espionage GroupsThe Hacker News·Aug 22, 09:34 UTC · Aug 22, 2021Malware55
Knife Cutting the Edge: Disclosing a China-nexus gatewayCisco Talos·Feb 5, 11:00 UTC · Feb 5, 2026Malware42
ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System AccessThe Hacker News·Nov 30, 09:05 UTC · Nov 30, 2025VulnerabilityCVE-2025-59287160
China-linked APT41 breached Taiwanese research instituteSecurity Affairs·Aug 5, 06:19 UTC · Aug 5, 2024Data breachCVE-2018-0824160
Kaspersky speculates the involvement of ShadowPad attackers in Operation ShadowHammerSecurity Affairs·Apr 24, 06:00 UTC · Apr 24, 2019Data breach57
Chinese Hackers Targeting South American Diplomatic Entities with ShadowPadThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2023VulnerabilityCVE-2022-2946460
Researchers Expose Over 80 ShadowPad Malware C2 ServersThe Hacker News·Oct 28, 13:10 UTC · Oct 28, 2022Malware42
APT Hackers Targeting Industrial Control Systems with ShadowPad BackdoorThe Hacker News·Jun 29, 03:13 UTC · Jun 29, 2022MalwareCVE-2021-2685547
Winnti APT Group targeted Hong Kong UniversitiesSecurity Affairs·Feb 1, 10:04 UTC · Feb 1, 2020Threat actor57
China-Linked Ink Dragon Hacks Governments Using ShadowPad and FINALDRAFT MalwareThe Hacker News·Dec 19, 04:48 UTC · Dec 19, 2025Malware42
APT41 Hackers Use ShadowPad, Cobalt Strike in Taiwanese Institute Cyber AttackThe Hacker News·Aug 2, 16:32 UTC · Aug 2, 2024Threat actorCVE-2018-082460
Chinese State-Sponsored Activity Group TAG-22 Targets Nepal, the Philippines, and TaiwanRecorded Future·Jul 15, 00:00 UTC · Jul 15, 2025Threat actor57
Hackers target Pakistani government, bank and telecom provider with ChinaThe Record·Jul 14, 16:39 UTC · Jul 14, 2023Vulnerability42
Pakistani Entities Targeted in Sophisticated Attack Deploying ShadowPad MalwareThe Hacker News·Jul 18, 12:58 UTC · Jul 18, 2023Malware42
Redfly group infiltrated an Asian national grid as long as six monthsSecurity Affairs·Sep 13, 11:51 UTC · Sep 13, 2023Malware55
Chinese APT Favorite Backdoor Found in Pakistani Government AppInfosecurity Magazine·Jul 14, 14:00 UTC · Jul 14, 2023Malware42
Hackers Deploy Shadowpad Backdoor and Target Industrial Control Systems in AsiaInfosecurity Magazine·Jun 28, 17:30 UTC · Jun 28, 2022MalwareCVE-2021-2685547
APT trends report Q2 2020Kaspersky Securelist·Jul 29, 10:00 UTC · Jul 29, 2020VulnerabilityCVE-2019-1014947
Continued Targeting of Indian Power Grid Assets by Chinese StateRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Vulnerability55
Power grid of Asian nation shows signs of intrusion by espionage groupThe Record·Sep 12, 13:12 UTC · Sep 12, 2023Threat actor60
Chinese Hackers Infiltrate South American Diplomatic NetworksInfosecurity Magazine·Feb 14, 17:00 UTC · Feb 14, 2023Vulnerability30
ShadowPad-Associated Hackers Targeted Asian GovernmentsInfosecurity Magazine·Sep 13, 17:00 UTC · Sep 13, 2022Vulnerability42
Chinese Hackers Caught Exploiting Popular Antivirus Products to Target Telecom SectorThe Hacker News·May 4, 07:40 UTC · May 4, 2022Malware42
Hackers Weaponize Balochistan Police Portal in MultiThe Hacker News·Jul 11, 17:49 UTC · Jul 11, 2026Malware42
SentinelOne Uncovers Chinese Espionage Campaign Targeting Its Infrastructure and ClientsThe Hacker News·Apr 29, 17:10 UTC · Apr 29, 2025Threat actor57
China-linked hackers target European healthcare orgs in suspected espionage campaignThe Record·Feb 21, 01:12 UTC · Feb 21, 2025Threat actorCVE-2024-2491960
NailaoLocker ransomware targets EU healthcareSecurity Affairs·Feb 20, 15:48 UTC · Feb 20, 2025RansomwareCVE-2024-2491960
Stealthy BLOODALCHEMY Malware Targeting ASEAN Government NetworksThe Hacker News·May 29, 04:43 UTC · May 29, 2024Malware42
Chinese Redfly Group Compromised a Nation's Critical Grid in 6The Hacker News·Sep 12, 11:22 UTC · Sep 12, 2023Data breach60
Chinene Moshen Dragon abuses security software to sideload malwareSecurity Affairs·May 3, 10:56 UTC · May 3, 2022Malware42
Bad backdoor found in server software used by financial institutionsCyberScoop·Aug 16, 14:29 UTC · Aug 16, 2017Malware in the wild60
DKnife toolkit abuses routers to spy and deliver malware since 2019Security Affairs·Feb 8, 10:06 UTC · Feb 8, 2026Malware55