⤷ Title: China-Nexus Espionage: ScatterBrain Obfuscation Tactics Revealed
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 31 Jan 2025 01:46:04 +0000
════════════════════════
⌗ Tags: #Malware #APT41 #Complete Headerless Mode #Complete Mode #Control Flow Graph #POISONPLUG #POISONPLUG.SHADOW #ScatterBrain #Selective Mode #ShadowPad
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 31 Jan 2025 01:46:04 +0000
════════════════════════
⌗ Tags: #Malware #APT41 #Complete Headerless Mode #Complete Mode #Control Flow Graph #POISONPLUG #POISONPLUG.SHADOW #ScatterBrain #Selective Mode #ShadowPad
Cybersecurity News
China-Nexus Espionage: ScatterBrain Obfuscation Tactics Revealed
Discover ScatterBrain, a powerful obfuscating compiler employed by APT41. Understand its role in protecting the advanced modular backdoor POISONPLUG.SHADOW.
⤷ Title: Updated ShadowPad Malware Facilitates Ransomware Deployment in Global Attacks
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 21 Feb 2025 01:43:35 +0000
════════════════════════
⌗ Tags: #Malware #APT41 #Earth Baku #Earth Freybug #Earth Longzhi #ransomware #ShadowPad #ShadowPad malware
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 21 Feb 2025 01:43:35 +0000
════════════════════════
⌗ Tags: #Malware #APT41 #Earth Baku #Earth Freybug #Earth Longzhi #ransomware #ShadowPad #ShadowPad malware
Cybersecurity News
Updated ShadowPad Malware Facilitates Ransomware Deployment in Global Attacks
Explore the evolving threat of ShadowPad malware, now facilitating ransomware attacks linked to Chinese threat actors.
⤷ Title: Chinese Cyberespionage Groups Probe SentinelOne in Sophisticated ShadowPad and PurpleHaze Campaigns
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Jun 2025 00:45:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT15 #China_nexus #cyber_espionage #cybersecurity #PurpleHaze #SentinelLABS #SentinelOne #ShadowPad #supply chain attack #UNC5174
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Jun 2025 00:45:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT15 #China_nexus #cyber_espionage #cybersecurity #PurpleHaze #SentinelLABS #SentinelOne #ShadowPad #supply chain attack #UNC5174
Daily CyberSecurity
Chinese Cyberespionage Groups Probe SentinelOne in Sophisticated ShadowPad and PurpleHaze Campaigns
SentinelLABS exposes China-nexus APTs (ShadowPad, PurpleHaze) targeting SentinelOne and over 70 organizations in extensive cyber-espionage.
⤷ Title: Symantec Exposes Chinese APT Overlap: Zingdoor, ShadowPad, and KrustyLoader Used in Global Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:43:11 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Chinese APT #DLL Sideloading #Espionage #KrustyLoader #ShadowPad #Supply Chain #Zingdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:43:11 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Chinese APT #DLL Sideloading #Espionage #KrustyLoader #ShadowPad #Supply Chain #Zingdoor
Daily CyberSecurity
Symantec Exposes Chinese APT Overlap: Zingdoor, ShadowPad, and KrustyLoader Used in Global Espionage
Symantec exposed a complex Chinese APT network (Glowworm/UNC5221) deploying Zingdoor and ShadowPad across US/South American targets. The groups abuse DLL sideloading and PetitPotam for credential theft.
⤷ Title: China-Aligned APTs Launch “Premier Pass-as-a-Service,” Sharing Access in Coordinated Global Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:10:55 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT Collaboration #China APT #cyber_espionage #Earth Estries #Earth Naga #Premier Pass_as_a_Service #ShadowPad
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:10:55 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT Collaboration #China APT #cyber_espionage #Earth Estries #Earth Naga #Premier Pass_as_a_Service #ShadowPad
Daily CyberSecurity
China-Aligned APTs Launch "Premier Pass-as-a-Service," Sharing Access in Coordinated Global Espionage
Trend exposed "Premier Pass-as-a-Service," a model where Earth Estries (access broker) and Earth Naga (APT36) share compromised network access to deploy ShadowPad in a coordinated espionage campaign.
⤷ Title: Critical WSUS RCE (CVE-2025-59287) Actively Exploited to Deploy ShadowPad Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 00:06:54 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #AhnLab #APT #backdoor #CVE_2025_59287 #cyber attack #rce #security advisory #ShadowPad #Windows Server #WSUS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 00:06:54 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #AhnLab #APT #backdoor #CVE_2025_59287 #cyber attack #rce #security advisory #ShadowPad #Windows Server #WSUS
Daily CyberSecurity
Critical WSUS RCE (CVE-2025-59287) Actively Exploited to Deploy ShadowPad Backdoor
Threat actors are actively exploiting a new WSUS RCE flaw (CVE-2025-59287) to gain SYSTEM shells and deploy the dangerous ShadowPad backdoor. Patch immediately!
⤷ Title: Critical WSUS RCE (CVE-2025-59287) Actively Exploited to Deploy ShadowPad Espionage Tool
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 03:30:12 +0000
════════════════════════
⌗ Tags: #Vulnerability #AhnLab #China APT #CVE_2025_59287 #Cyber Espionage #Patch Now #RCE #ShadowPad #Windows Server #WSUS
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 03:30:12 +0000
════════════════════════
⌗ Tags: #Vulnerability #AhnLab #China APT #CVE_2025_59287 #Cyber Espionage #Patch Now #RCE #ShadowPad #Windows Server #WSUS
Penetration Testing Tools
Critical WSUS RCE (CVE-2025-59287) Actively Exploited to Deploy ShadowPad Espionage Tool
Threat actors are actively exploiting the critical WSUS RCE flaw (CVE-2025-59287) to gain SYSTEM access and deploy the powerful, Chinese-linked ShadowPad espionage backdoor.
⤷ Title: The Living Mesh: Ink Dragon Turns European Government Servers into a Global ShadowPad Relay Network
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:52:47 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #Check Point Research #Cyber Espionage #Earth Alux #European Security #FINALDRAFT #IIS Malware #Ink Dragon #ShadowPad #SharePoint Exploit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:52:47 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #Check Point Research #Cyber Espionage #Earth Alux #European Security #FINALDRAFT #IIS Malware #Ink Dragon #ShadowPad #SharePoint Exploit
Penetration Testing Tools
The Living Mesh: Ink Dragon Turns European Government Servers into a Global ShadowPad Relay Network
Researchers at Check Point Research have uncovered a large-scale espionage operation conducted by the Chinese APT group Ink
⤷ Title: The Silent Listener: New DRBControl Backdoor Variant Uses Network Sniffing to Evade Detection
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:48:07 +0000
════════════════════════
⌗ Tags: #Malware #APT27 #APT41 #Cyber Espionage #DLL Sideloading #DRBControl #IIJ #malware analysis #Mofu Loader #Promiscuous Mode #ShadowPad #Type 1 Backdoor
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:48:07 +0000
════════════════════════
⌗ Tags: #Malware #APT27 #APT41 #Cyber Espionage #DLL Sideloading #DRBControl #IIJ #malware analysis #Mofu Loader #Promiscuous Mode #ShadowPad #Type 1 Backdoor
Penetration Testing Tools
The Silent Listener: New DRBControl Backdoor Variant Uses Network Sniffing to Evade Detection
Japanese company Internet Initiative Japan (IIJ) has reported observing a new variant of the malware known as Type
⤷ Title: Ink Dragon’s Global Mesh: How Chinese Spies Turn Compromised Government Servers into C2 Relay Nodes
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:27:49 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT41 #ASP.NET #Check Point Research #cyber_espionage #Earth Alux #IIS Listener #Ink Dragon #Microsoft Graph API #Relay Network #ShadowPad
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:27:49 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT41 #ASP.NET #Check Point Research #cyber_espionage #Earth Alux #IIS Listener #Ink Dragon #Microsoft Graph API #Relay Network #ShadowPad
Daily CyberSecurity
Ink Dragon’s Global Mesh: How Chinese Spies Turn Compromised Government Servers into C2 Relay Nodes
Ink Dragon is weaponizing government servers in Europe using a relay-centric mesh. By hijacking IIS servers, they mask C2 traffic across global networks.
⤷ Title: The “All-in-One” Spy: DKnife Malware Hijacks Routers to Swap Downloads
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 00:38:42 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #AiTM #Chinese Threat Actors #Cisco Talos #DarkNimbus #DKnife #Edge Devices #Malware Analysis #router security #ShadowPad #Traffic Manipulation #yitiji
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 00:38:42 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #AiTM #Chinese Threat Actors #Cisco Talos #DarkNimbus #DKnife #Edge Devices #Malware Analysis #router security #ShadowPad #Traffic Manipulation #yitiji
Daily CyberSecurity
The "All-in-One" Spy: DKnife Malware Hijacks Routers to Swap Downloads
Cisco Talos exposes DKnife, a router malware that inspects traffic and swaps legitimate downloads for ShadowPad backdoors. Active since 2019.
⤷ Title: Shattering the Edge: Cisco Talos Unmasks “DKnife,” the 7-Module Framework Hijacking Your Router
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 04:19:48 +0000
════════════════════════
⌗ Tags: #Malware #AitM attack #China_nexus APT #Cisco Talos #DarkNimbus #DKnife #edge device security #Linux malware #network infrastructure #router malware #ShadowPad #Tech News 2026 #WizardNet
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 04:19:48 +0000
════════════════════════
⌗ Tags: #Malware #AitM attack #China_nexus APT #Cisco Talos #DarkNimbus #DKnife #edge device security #Linux malware #network infrastructure #router malware #ShadowPad #Tech News 2026 #WizardNet
Penetration Testing Tools
Shattering the Edge: Cisco Talos Unmasks "DKnife," the 7-Module Framework Hijacking Your Router
Security analysts at Cisco Talos have unmasked a clandestine offensive platform that has operated surreptitiously within network infrastructure
⤷ Title: The N-Day Nightmare: How SHADOW-EARTH-053 Breaches Governments Using “Old” Exploits
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 05 May 2026 07:02:51 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #Asia Cybersecurity #China_Aligned APT #Cyberespionage #DLL Sideloading #Godzilla #GodZilla Web Shell #NATO Security #ProxyLogon #SHADOW_EARTH_053 #ShadowPad #TrendAI Research #Web Shell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 05 May 2026 07:02:51 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #Asia Cybersecurity #China_Aligned APT #Cyberespionage #DLL Sideloading #Godzilla #GodZilla Web Shell #NATO Security #ProxyLogon #SHADOW_EARTH_053 #ShadowPad #TrendAI Research #Web Shell
Daily CyberSecurity
The N-Day Nightmare: How SHADOW-EARTH-053 Breaches Governments Using "Old" Exploits
SHADOW-EARTH-053 is breaching governments and NATO using old ProxyLogon flaws and ShadowPad. Learn how this China-aligned group stays hidden via registry loading.