HomeSecurityShadowPad malware: Distribution via WSUS vulnerability

ShadowPad malware: Distribution via WSUS vulnerability

A recently patched security vulnerability in Microsoft Windows Server Update Services (WSUS) has been exploited by malicious actors to distribute the ShadowPad.

ShadowPad malware WSUS

“ The attacker targeted Windows Servers with WSUS enabled, exploiting CVE-2025-59287 for initial access ,” AhnLab Security Intelligence Center (ASEC) said in a report published last week.

“Next, he used PowerCat , an open source PowerShell-based tool, to obtain a system shell (CMD). He then downloaded and installed ShadowPad using the certutil and curl tools “.

See also: New threat landscape: Weaponized quantum computers

ShadowPad malware

ShadowPad, considered a successor to PlugX, is a modular backdoor widely used by Chinese state-. It first appeared in 2015. In an analysis published in August 2021, SentinelOne described it as “a masterpiece of malware privately sold for Chinese espionage.”

CVE -2025-59287, which was patched by Microsoft last month, refers to a critical deserialization vulnerability in WSUS, which could be exploited to achieve remote code execution with system privileges.

ShadowPad malware: Distribution via WSUS vulnerability

This vulnerability has since been heavily exploited, with malicious actors using it to gain initial access to publicly exposed WSUS instances, conduct reconnaissance , and even install legitimate tools like Velociraptor.

See also: Simulated phishing attacks and employee training

In the attack observed by the South Korean cybersecurity firm, the attackers used the vulnerability to enable Windows utilities such as “curl.exe” and “certutil.exe” to communicate with an external server (“149.28.78[.]189:42306”). From there, they downloaded and installed ShadowPad.

ShadowPad is launched via DLL side-loading, using a legitimate binary (“ETDCtrlHelper.exe”) to execute a DLL payload (“ETDApix.dll”). This acts as a loader in memory to execute the backdoor.

Once installed, the malware launches a core module that is responsible for loading other plugins embedded in the shellcode into memory. It is also equipped with various detection and persistence techniques.

See also: Grafana: Critical vulnerability allows privilege escalation

ShadowPad malware: Distribution via WSUS vulnerability

“After the public release of the proof-of-concept (PoC) exploit for the vulnerability, attackers quickly exploited it to distribute the ShadowPad malware via WSUS servers,” AhnLab said. “This vulnerability is critical because it allows remote code execution with system-level privileges, significantly increasing the potential impact.”

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS