logo

Study of the ShadowPad APT backdoor and its relation to PlugX

ID: 5a9237c5-e7a0-48a9-9c5b-f6272bb69602

STIX ID: report--5a9237c5-e7a0-48a9-9c5b-f6272bb69602

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2020-10-26

Last Modified Date: 2020-10-26

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Doctor Web technical report analyzes multiple ShadowPad backdoor variants found on a compromised Kyrgyzstan state institution, compares code and operational similarities with PlugX (suggesting shared authorship or code reuse likely tied to Chinese APT activity such as Winnti), documents multi-module loaders, plugin formats, persistence and network behaviors (TCP/HTTP/DNS/UDP), provides implementation-level pseudocode and decryption routines, and lists IOCs (hashes, domains, IPs) for detection and response.