Study of the ShadowPad APT backdoor and its relation to PlugX
ID: 5a9237c5-e7a0-48a9-9c5b-f6272bb69602
STIX ID: report--5a9237c5-e7a0-48a9-9c5b-f6272bb69602
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2020-10-26
Last Modified Date: 2020-10-26
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Doctor Web technical report analyzes multiple ShadowPad backdoor variants found on a compromised Kyrgyzstan state institution, compares code and operational similarities with PlugX (suggesting shared authorship or code reuse likely tied to Chinese APT activity such as Winnti), documents multi-module loaders, plugin formats, persistence and network behaviors (TCP/HTTP/DNS/UDP), provides implementation-level pseudocode and decryption routines, and lists IOCs (hashes, domains, IPs) for detection and response.
