home.social

#shadowpad — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #shadowpad, aggregated by home.social.

fetched live
  1. Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

    Between July 9-13, 2026, three exposed directories on a Hong Kong server revealed an ongoing cyber espionage operation targeting Thailand's Ministry of Finance. The attack leveraged Hermes, an autonomous AI agent operating in unattended YOLO mode, alongside a custom Go-based implant called Hades. Recovered files included exploit code for multiple vulnerabilities, webshells, stolen credentials, and purpose-built scripts targeting MOF Hadoop infrastructure, mail systems, and GlassFish consoles. The AI agent autonomously enumerated ministry networks using LinPEAS, traversed files, and assessed privilege escalation paths. Infrastructure analysis linked multiple Hong Kong and Malaysian servers through TLS certificates and hardcoded C2 addresses. Chinese-language indicators and historical ShadowPad/VShell presence suggest probable Chinese-speaking attribution, though initial access methods remain undetermined.

    Pulse ID: 6a6280a6b0f220d5330af106
    Pulse Link: otx.alienvault.com/pulse/6a628
    Pulse Author: AlienVault
    Created: 2026-07-23 20:59:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #CyberSecurity #Espionage #Hadoop #HongKong #InfoSec #OTX #OpenThreatExchange #RAT #ShadowPad #TLS #Thailand #bot #AlienVault

  2. Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

    Between July 9-13, 2026, three exposed directories on a Hong Kong server revealed an ongoing cyber espionage operation targeting Thailand's Ministry of Finance. The attack leveraged Hermes, an autonomous AI agent operating in unattended YOLO mode, alongside a custom Go-based implant called Hades. Recovered files included exploit code for multiple vulnerabilities, webshells, stolen credentials, and purpose-built scripts targeting MOF Hadoop infrastructure, mail systems, and GlassFish consoles. The AI agent autonomously enumerated ministry networks using LinPEAS, traversed files, and assessed privilege escalation paths. Infrastructure analysis linked multiple Hong Kong and Malaysian servers through TLS certificates and hardcoded C2 addresses. Chinese-language indicators and historical ShadowPad/VShell presence suggest probable Chinese-speaking attribution, though initial access methods remain undetermined.

    Pulse ID: 6a6280a6b0f220d5330af106
    Pulse Link: otx.alienvault.com/pulse/6a628
    Pulse Author: AlienVault
    Created: 2026-07-23 20:59:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #CyberSecurity #Espionage #Hadoop #HongKong #InfoSec #OTX #OpenThreatExchange #RAT #ShadowPad #TLS #Thailand #bot #AlienVault

  3. Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

    Between July 9-13, 2026, three exposed directories on a Hong Kong server revealed an ongoing cyber espionage operation targeting Thailand's Ministry of Finance. The attack leveraged Hermes, an autonomous AI agent operating in unattended YOLO mode, alongside a custom Go-based implant called Hades. Recovered files included exploit code for multiple vulnerabilities, webshells, stolen credentials, and purpose-built scripts targeting MOF Hadoop infrastructure, mail systems, and GlassFish consoles. The AI agent autonomously enumerated ministry networks using LinPEAS, traversed files, and assessed privilege escalation paths. Infrastructure analysis linked multiple Hong Kong and Malaysian servers through TLS certificates and hardcoded C2 addresses. Chinese-language indicators and historical ShadowPad/VShell presence suggest probable Chinese-speaking attribution, though initial access methods remain undetermined.

    Pulse ID: 6a6280a6b0f220d5330af106
    Pulse Link: otx.alienvault.com/pulse/6a628
    Pulse Author: AlienVault
    Created: 2026-07-23 20:59:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #CyberSecurity #Espionage #Hadoop #HongKong #InfoSec #OTX #OpenThreatExchange #RAT #ShadowPad #TLS #Thailand #bot #AlienVault

  4. Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

    Between July 9-13, 2026, three exposed directories on a Hong Kong server revealed an ongoing cyber espionage operation targeting Thailand's Ministry of Finance. The attack leveraged Hermes, an autonomous AI agent operating in unattended YOLO mode, alongside a custom Go-based implant called Hades. Recovered files included exploit code for multiple vulnerabilities, webshells, stolen credentials, and purpose-built scripts targeting MOF Hadoop infrastructure, mail systems, and GlassFish consoles. The AI agent autonomously enumerated ministry networks using LinPEAS, traversed files, and assessed privilege escalation paths. Infrastructure analysis linked multiple Hong Kong and Malaysian servers through TLS certificates and hardcoded C2 addresses. Chinese-language indicators and historical ShadowPad/VShell presence suggest probable Chinese-speaking attribution, though initial access methods remain undetermined.

    Pulse ID: 6a6280a6b0f220d5330af106
    Pulse Link: otx.alienvault.com/pulse/6a628
    Pulse Author: AlienVault
    Created: 2026-07-23 20:59:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #CyberSecurity #Espionage #Hadoop #HongKong #InfoSec #OTX #OpenThreatExchange #RAT #ShadowPad #TLS #Thailand #bot #AlienVault

  5. Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

    Between July 9-13, 2026, three exposed directories on a Hong Kong server revealed an ongoing cyber espionage operation targeting Thailand's Ministry of Finance. The attack leveraged Hermes, an autonomous AI agent operating in unattended YOLO mode, alongside a custom Go-based implant called Hades. Recovered files included exploit code for multiple vulnerabilities, webshells, stolen credentials, and purpose-built scripts targeting MOF Hadoop infrastructure, mail systems, and GlassFish consoles. The AI agent autonomously enumerated ministry networks using LinPEAS, traversed files, and assessed privilege escalation paths. Infrastructure analysis linked multiple Hong Kong and Malaysian servers through TLS certificates and hardcoded C2 addresses. Chinese-language indicators and historical ShadowPad/VShell presence suggest probable Chinese-speaking attribution, though initial access methods remain undetermined.

    Pulse ID: 6a6280a6b0f220d5330af106
    Pulse Link: otx.alienvault.com/pulse/6a628
    Pulse Author: AlienVault
    Created: 2026-07-23 20:59:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #CyberSecurity #Espionage #Hadoop #HongKong #InfoSec #OTX #OpenThreatExchange #RAT #ShadowPad #TLS #Thailand #bot #AlienVault

  6. SHADOW-EARTH-053: la campagna APT cinese che spia governi asiatici, la NATO e i diplomatici cubani

    Trend Micro ha smascherato SHADOW-EARTH-053, un gruppo APT allineato alla Cina attivo dal dicembre 2024 che ha colpito governi e contractor difesa in Pakistan, India, Malaysia, Taiwan e Polonia. In parallelo, un'operazione correlata ha violato le email di 68 diplomatici cubani a Washington sfruttando Exchange non patchati. Analisi tecnica di ShadowPad, Godzilla webshell, CVE-2025-55182 e delle implicazioni per i difensori.

    insicurezzadigitale.com/shadow

  7. SHADOW-EARTH-053: la campagna APT cinese che spia governi asiatici, la NATO e i diplomatici cubani

    Trend Micro ha smascherato SHADOW-EARTH-053, un gruppo APT allineato alla Cina attivo dal dicembre 2024 che ha colpito governi e contractor difesa in Pakistan, India, Malaysia, Taiwan e Polonia. In parallelo, un'operazione correlata ha violato le email di 68 diplomatici cubani a Washington sfruttando Exchange non patchati. Analisi tecnica di ShadowPad, Godzilla webshell, CVE-2025-55182 e delle implicazioni per i difensori.

    insicurezzadigitale.com/shadow

  8. SHADOW-EARTH-053: la campagna APT cinese che spia governi asiatici, la NATO e i diplomatici cubani

    Trend Micro ha smascherato SHADOW-EARTH-053, un gruppo APT allineato alla Cina attivo dal dicembre 2024 che ha colpito governi e contractor difesa in Pakistan, India, Malaysia, Taiwan e Polonia. In parallelo, un'operazione correlata ha violato le email di 68 diplomatici cubani a Washington sfruttando Exchange non patchati. Analisi tecnica di ShadowPad, Godzilla webshell, CVE-2025-55182 e delle implicazioni per i difensori.

    insicurezzadigitale.com/shadow

  9. SHADOW-EARTH-053: la campagna APT cinese che spia governi asiatici, la NATO e i diplomatici cubani

    Trend Micro ha smascherato SHADOW-EARTH-053, un gruppo APT allineato alla Cina attivo dal dicembre 2024 che ha colpito governi e contractor difesa in Pakistan, India, Malaysia, Taiwan e Polonia. In parallelo, un'operazione correlata ha violato le email di 68 diplomatici cubani a Washington sfruttando Exchange non patchati. Analisi tecnica di ShadowPad, Godzilla webshell, CVE-2025-55182 e delle implicazioni per i difensori.

    insicurezzadigitale.com/shadow

  10. SHADOW-EARTH-053: la campagna APT cinese che spia governi asiatici, la NATO e i diplomatici cubani

    Trend Micro ha smascherato SHADOW-EARTH-053, un gruppo APT allineato alla Cina attivo dal dicembre 2024 che ha colpito governi e contractor difesa in Pakistan, India, Malaysia, Taiwan e Polonia. In parallelo, un'operazione correlata ha violato le email di 68 diplomatici cubani a Washington sfruttando Exchange non patchati. Analisi tecnica di ShadowPad, Godzilla webshell, CVE-2025-55182 e delle implicazioni per i difensori.

    insicurezzadigitale.com/shadow

  11. China-Linked Hackers Expose Wide-Ranging Espionage Campaign

    Meet SHADOW-EARTH-053, a China-aligned espionage group that's been secretly lurking in the shadows since December 2024, using clever tactics like exploiting vulnerabilities and deploying web shells to gain persistent access to sensitive targets. Their sophisticated attacks have been linked to other notorious intrusion sets, revealing a…

    osintsights.com/china-linked-h

    #ChinalinkedHackers #EspionageCampaign #Proxylogon #Godzilla #Shadowpad

  12. DKnife – nowy cyberzagrożenie w routerach zmienia zasady bezpieczeństwa sieci

    Czy Twój router to tylko nudne pudełko do Wi-Fi? DKnife pokazuje, że to może być idealna budka podsłuchowa – tuż przy drzwiach Twojej sieci.

    Czytaj dalej:
    pressmind.org/dknife-nowy-cybe

    #PressMindLabs #aitm #darknimbus #dknife #routery #shadowpad

  13. 🔥 NEW research published: We uncover #DKnife, a China-nexus gateway-monitoring framework that intercepts network traffic, monitors user activity, and delivers malware #Shadowpad & #DarkNimbus via routers and edge devices. blog.talosintelligence.com/knife-cuttin...

    Knife Cutting the Edge: Disclo...

  14. #CheckPoint Research revealed a sophisticated wave of attacks attributed to the Chinese #threat actor #InkDragon, which targets European governments while continuing campaigns in Southeast Asia and South America. The threat actor converts compromised #IIS servers into relay nodes with #ShadowPad, exploits predictable configuration keys for access, and deploys a new #FinalDraft #backdoor for exfiltration and lateral movement.

    research.checkpoint.com/2025/i

  15. #CheckPoint Research revealed a sophisticated wave of attacks attributed to the Chinese #threat actor #InkDragon, which targets European governments while continuing campaigns in Southeast Asia and South America. The threat actor converts compromised #IIS servers into relay nodes with #ShadowPad, exploits predictable configuration keys for access, and deploys a new #FinalDraft #backdoor for exfiltration and lateral movement.

    research.checkpoint.com/2025/i

  16. #CheckPoint Research revealed a sophisticated wave of attacks attributed to the Chinese #threat actor #InkDragon, which targets European governments while continuing campaigns in Southeast Asia and South America. The threat actor converts compromised #IIS servers into relay nodes with #ShadowPad, exploits predictable configuration keys for access, and deploys a new #FinalDraft #backdoor for exfiltration and lateral movement.

    research.checkpoint.com/2025/i

  17. #CheckPoint Research revealed a sophisticated wave of attacks attributed to the Chinese #threat actor #InkDragon, which targets European governments while continuing campaigns in Southeast Asia and South America. The threat actor converts compromised #IIS servers into relay nodes with #ShadowPad, exploits predictable configuration keys for access, and deploys a new #FinalDraft #backdoor for exfiltration and lateral movement.

    research.checkpoint.com/2025/i

  18. Analysis of ShadowPad Attack Exploiting WSUS Remote Code Execution Vulnerability (CVE-2025-59287)
    #CVE_2025_59287 #ShadowPad
    asec.ahnlab.com/en/91166/

  19. Analysis of ShadowPad Attack Exploiting WSUS Remote Code Execution Vulnerability (CVE-2025-59287)
    #CVE_2025_59287 #ShadowPad
    asec.ahnlab.com/en/91166/

  20. Analysis of ShadowPad Attack Exploiting WSUS Remote Code Execution Vulnerability (CVE-2025-59287)
    #CVE_2025_59287 #ShadowPad
    asec.ahnlab.com/en/91166/

  21. Analysis of ShadowPad Attack Exploiting WSUS Remote Code Execution Vulnerability (CVE-2025-59287)
    #CVE_2025_59287 #ShadowPad
    asec.ahnlab.com/en/91166/

  22. Analysis of ShadowPad Attack Exploiting WSUS Remote Code Execution Vulnerability (CVE-2025-59287)
    #CVE_2025_59287 #ShadowPad
    asec.ahnlab.com/en/91166/

  23. Threat actors are actively exploiting CVE-2025-59287 in WSUS to deploy ShadowPad.

    ASEC notes the attackers used PowerCat for shell access, then fetched and installed ShadowPad with certutil/curl, executing it through DLL side-loading.

    How are you securing WSUS or other update infrastructure in your environment?
    💬 Share your insights
    ⭐ Follow TechNadu for timely threat intel

    #infosec #WSUS #ShadowPad #CVE2025 #malware #threatintel #sysadmin #DFIR #TechNadu

  24. Threat actors are actively exploiting CVE-2025-59287 in WSUS to deploy ShadowPad.

    ASEC notes the attackers used PowerCat for shell access, then fetched and installed ShadowPad with certutil/curl, executing it through DLL side-loading.

    How are you securing WSUS or other update infrastructure in your environment?
    💬 Share your insights
    ⭐ Follow TechNadu for timely threat intel

    #infosec #WSUS #ShadowPad #CVE2025 #malware #threatintel #sysadmin #DFIR #TechNadu

  25. Threat actors are actively exploiting CVE-2025-59287 in WSUS to deploy ShadowPad.

    ASEC notes the attackers used PowerCat for shell access, then fetched and installed ShadowPad with certutil/curl, executing it through DLL side-loading.

    How are you securing WSUS or other update infrastructure in your environment?
    💬 Share your insights
    ⭐ Follow TechNadu for timely threat intel

    #infosec #WSUS #ShadowPad #CVE2025 #malware #threatintel #sysadmin #DFIR #TechNadu

  26. Threat actors are actively exploiting CVE-2025-59287 in WSUS to deploy ShadowPad.

    ASEC notes the attackers used PowerCat for shell access, then fetched and installed ShadowPad with certutil/curl, executing it through DLL side-loading.

    How are you securing WSUS or other update infrastructure in your environment?
    💬 Share your insights
    ⭐ Follow TechNadu for timely threat intel

    #infosec #WSUS #ShadowPad #CVE2025 #malware #threatintel #sysadmin #DFIR #TechNadu

  27. Threat actors are actively exploiting CVE-2025-59287 in WSUS to deploy ShadowPad.

    ASEC notes the attackers used PowerCat for shell access, then fetched and installed ShadowPad with certutil/curl, executing it through DLL side-loading.

    How are you securing WSUS or other update infrastructure in your environment?
    💬 Share your insights
    ⭐ Follow TechNadu for timely threat intel

    #infosec #WSUS #ShadowPad #CVE2025 #malware #threatintel #sysadmin #DFIR #TechNadu

  28. Good day everyone!

    This is a really interesting read from SentinelOne Labs . Back in October 2024 they dealt with a reconnaissance operation that was related to the activity cluster tracked as #PurpleHaze and then in 2025 "they helped disrupt an intrusion linked to a wider #ShadowPad operation". The activity was attributed to China-nexus threat actors.

    The article gives an in-depth view of what it looks like when an organization that is responsible for "IT services and logistics" gets compromised, which we could call a supply-chain attack. The article also provides a TON of technical details about tools and infrastructure that was used, indicators of compromise to scan for in your environment, and behaviors and commands that were observed throughout. This one may take a while to read but its worth it! Thanks to the researchers Dr Aleksandar Milenkoski and Tom Hegel for this report! I hope you all enjoy it as much as I did. Happy Hunting!

    Follow the Smoke | China-nexus Threat Actors Hammer At the Doors of Top Tier Targets
    sentinelone.com/labs/follow-th

    Intel 471 Cyborg Security, Now Part of Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday

  29. Good day everyone!

    This is a really interesting read from SentinelOne Labs . Back in October 2024 they dealt with a reconnaissance operation that was related to the activity cluster tracked as #PurpleHaze and then in 2025 "they helped disrupt an intrusion linked to a wider #ShadowPad operation". The activity was attributed to China-nexus threat actors.

    The article gives an in-depth view of what it looks like when an organization that is responsible for "IT services and logistics" gets compromised, which we could call a supply-chain attack. The article also provides a TON of technical details about tools and infrastructure that was used, indicators of compromise to scan for in your environment, and behaviors and commands that were observed throughout. This one may take a while to read but its worth it! Thanks to the researchers Dr Aleksandar Milenkoski and Tom Hegel for this report! I hope you all enjoy it as much as I did. Happy Hunting!

    Follow the Smoke | China-nexus Threat Actors Hammer At the Doors of Top Tier Targets
    sentinelone.com/labs/follow-th

    Intel 471 Cyborg Security, Now Part of Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday

  30. Good day everyone!

    This is a really interesting read from SentinelOne Labs . Back in October 2024 they dealt with a reconnaissance operation that was related to the activity cluster tracked as #PurpleHaze and then in 2025 "they helped disrupt an intrusion linked to a wider #ShadowPad operation". The activity was attributed to China-nexus threat actors.

    The article gives an in-depth view of what it looks like when an organization that is responsible for "IT services and logistics" gets compromised, which we could call a supply-chain attack. The article also provides a TON of technical details about tools and infrastructure that was used, indicators of compromise to scan for in your environment, and behaviors and commands that were observed throughout. This one may take a while to read but its worth it! Thanks to the researchers Dr Aleksandar Milenkoski and Tom Hegel for this report! I hope you all enjoy it as much as I did. Happy Hunting!

    Follow the Smoke | China-nexus Threat Actors Hammer At the Doors of Top Tier Targets
    sentinelone.com/labs/follow-th

    Intel 471 Cyborg Security, Now Part of Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday

  31. Good day everyone!

    This is a really interesting read from SentinelOne Labs . Back in October 2024 they dealt with a reconnaissance operation that was related to the activity cluster tracked as #PurpleHaze and then in 2025 "they helped disrupt an intrusion linked to a wider #ShadowPad operation". The activity was attributed to China-nexus threat actors.

    The article gives an in-depth view of what it looks like when an organization that is responsible for "IT services and logistics" gets compromised, which we could call a supply-chain attack. The article also provides a TON of technical details about tools and infrastructure that was used, indicators of compromise to scan for in your environment, and behaviors and commands that were observed throughout. This one may take a while to read but its worth it! Thanks to the researchers Dr Aleksandar Milenkoski and Tom Hegel for this report! I hope you all enjoy it as much as I did. Happy Hunting!

    Follow the Smoke | China-nexus Threat Actors Hammer At the Doors of Top Tier Targets
    sentinelone.com/labs/follow-th

    Intel 471 Cyborg Security, Now Part of Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday

  32. Chinese spy crew appears to be preparing for conflict by backdooring 75+ critical orgs
    #SentinelOne discovered the campaign when they tried to hit the #security vendor's own servers
    In their report, they describe a series of intrusions between July 2024 and March 2025 involving #ShadowPad #malware and post-exploitation espionage activity that SentinelOne has dubbed "#PurpleHaze", publicly reported as #APT15 and #UNC5174, And they're blaming #China.
    theregister.com/2025/06/09/chi

  33. Chinese spy crew appears to be preparing for conflict by backdooring 75+ critical orgs
    #SentinelOne discovered the campaign when they tried to hit the #security vendor's own servers
    In their report, they describe a series of intrusions between July 2024 and March 2025 involving #ShadowPad #malware and post-exploitation espionage activity that SentinelOne has dubbed "#PurpleHaze", publicly reported as #APT15 and #UNC5174, And they're blaming #China.
    theregister.com/2025/06/09/chi

  34. Chinese spy crew appears to be preparing for conflict by backdooring 75+ critical orgs
    discovered the campaign when they tried to hit the vendor's own servers
    In their report, they describe a series of intrusions between July 2024 and March 2025 involving and post-exploitation espionage activity that SentinelOne has dubbed "#PurpleHaze", publicly reported as and , And they're blaming .
    theregister.com/2025/06/09/chi

  35. Chinese spy crew appears to be preparing for conflict by backdooring 75+ critical orgs
    #SentinelOne discovered the campaign when they tried to hit the #security vendor's own servers
    In their report, they describe a series of intrusions between July 2024 and March 2025 involving #ShadowPad #malware and post-exploitation espionage activity that SentinelOne has dubbed "#PurpleHaze", publicly reported as #APT15 and #UNC5174, And they're blaming #China.
    theregister.com/2025/06/09/chi

  36. Chinese spy crew appears to be preparing for conflict by backdooring 75+ critical orgs
    #SentinelOne discovered the campaign when they tried to hit the #security vendor's own servers
    In their report, they describe a series of intrusions between July 2024 and March 2025 involving #ShadowPad #malware and post-exploitation espionage activity that SentinelOne has dubbed "#PurpleHaze", publicly reported as #APT15 and #UNC5174, And they're blaming #China.
    theregister.com/2025/06/09/chi

  37. ⚠️ Chinese hackers hit governments, media, and cybersecurity firms in a global cyber espionage spree. Over 70 orgs targeted using tools like ShadowPad and PurpleHaze.

    Read: hackread.com/chinese-linked-ha

  38. ⚠️ Chinese hackers hit governments, media, and cybersecurity firms in a global cyber espionage spree. Over 70 orgs targeted using tools like ShadowPad and PurpleHaze.

    Read: hackread.com/chinese-linked-ha

    #CyberSecurity #China #CyberAttack #PurpleHaze #ShadowPad #APT15

  39. ⚠️ Chinese hackers hit governments, media, and cybersecurity firms in a global cyber espionage spree. Over 70 orgs targeted using tools like ShadowPad and PurpleHaze.

    Read: hackread.com/chinese-linked-ha

    #CyberSecurity #China #CyberAttack #PurpleHaze #ShadowPad #APT15

  40. ⚠️ Chinese hackers hit governments, media, and cybersecurity firms in a global cyber espionage spree. Over 70 orgs targeted using tools like ShadowPad and PurpleHaze.

    Read: hackread.com/chinese-linked-ha

    #CyberSecurity #China #CyberAttack #PurpleHaze #ShadowPad #APT15