A group of unknown hackers breached a Pakistani government application and used it to infect victims with the malicious software Shadowpad, which is linked to China, researchers say.
See also: JumpCloud: Hacking attack led to breach

Cybersecurity firm Trend Micro identified three entities in Pakistan that were targeted by Shadowpad last year: an anonymous government agency, a state bank, and a telecommunications provider.
Researchers believe it may have been a supply chain attack, in which hackers compromise third-party software to gain access to their desired targets.
In this incident, the hackers modified a Microsoft installer that was built by a Pakistani government entity for the E‑Office application, which helps the country's public services avoid using paper.
See also: Hackers are actively exploiting two ColdFusion vulnerabilities
This application is intended solely for government agencies and is not available to the public.
Hackers added three files to the legitimate Microsoft installer in order to load a malicious payload.
Shadowpad, an advanced malware family first discovered in 2017after a supply chain attack on the popular computer cleaning tool CCleaner, is believed to have been developed by the Chinese espionage actor known as APT41 or Barium.
The researchers said they did not find enough evidence to attribute this attack to any known threat actor. However, the fact that the hackers had access to a recent version of Shadowpad possibly links it to the network of Chinese threat groups, according to Trend Micro.
Shadowpad is a common malware family and since 2019 has been distributed by many Chinese espionage threat actors, including Earth Akhlut and Earth Lusca, a fact that makes attribution complex.

In one of the victims' environments, researchers found multiple malware families that they could attribute “with high confidence” to the Chinese hacking group Calypso.
See also: Red Menshen team rapidly evolves BPFDoor malware
In June, a previously unknown Chinese-speaking threat actor exploited a vulnerability in Microsoft Exchange Server to target the telecommunications, manufacturing, and transportation sectors in Afghanistan, Malaysia , and Pakistan with the Shadowpad malware.
During these attacks, the Shadowpad backdoor was uploaded to the victim computers under the guise of legitimate software.
Source of information: therecord.media
