SHADOWPAD

SHADOWPADShadowPad

Description

ShadowPad is a modular cyber-attack platform that attackers deploy in victim networks to gain flexible remote control capabilities. The platform is designed to run in two stages. The first stage is a shellcode that was embedded in a legitimate nssock2.dll used by Xshell, Xmanager and other software packages produced by NetSarang. This stage is responsible for connecting to “validation” command and control (C&C) servers and getting configuration information including the location of the real C&C server, which may be unique per victim. The second stage acts as an orchestrator for five main modules responsible for C&C communication, working with the DNS protocol, loading and injecting additional plugins into the memory of other processes.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
shadowtech
Software
ShadowHammer
Software
CryptoShadow
Software
STARSYPOUND
Software
PlugX
Software
DeathOfShadow
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.