Threat Advisory

ShadowPad and GOREshell Malware Campaign target Government and IT Sectors

Threat: Malware
Threat Actor Name: APT15
Threat Actor Type: State-Sponsored
Targeted Region: Global
Alias: G0004, Vixen Panda, Ke3chang, Playful Dragon, Nickel, Nylon Typhoon, Flea, Hive0044, Gref, Bronze Palace, Red Vulture, ATK103, Bronze Davenport, Bronze Idlewood, CTG-9246, Royal APT, BackdoorDiplomacy, Playful Taurus, Metushy, Lurid, Social Network Team
Threat Actor Region: China
Targeted Sector: Government & Defense, Technology & IT, Telecommunications, Critical Infrastructure
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The threat involves a sophisticated cyberespionage campaign attributed to China-nexus actors, targeting a diverse range of sectors including government, technology, telecommunications, and media. The attackers employed a combination of custom malware and publicly available tools to infiltrate systems, conduct reconnaissance, and maintain persistence. Initial access vectors included exploitation of vulnerabilities in IT infrastructure and supply chain compromises via third-party logistics providers. The campaign’s primary objectives appear to be intelligence gathering, lateral movement, and long-term access to high-value networks, posing significant risks to organizational data integrity and operational security.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The threat involves a sophisticated cyberespionage campaign attributed to China-nexus actors, targeting a diverse range of sectors including government, technology, telecommunications, and media. The attackers employed a combination of custom malware and publicly available tools to infiltrate systems, conduct reconnaissance, and maintain persistence. Initial access vectors included exploitation of vulnerabilities in IT infrastructure and supply chain compromises via third-party logistics providers. The campaign’s primary objectives appear to be intelligence gathering, lateral movement, and long-term access to high-value networks, posing significant risks to organizational data integrity and operational security.[emaillocker id="1283"]

The attack methodology involved multiple stages, beginning with reconnaissance and initial access through exploited vulnerabilities (CVE-2024-8963, CVE-2024-8190) or compromised IT service providers. ShadowPad, obfuscated using ScatterBrain, was deployed via PowerShell scripts, while GOREshell (a modified reverse_ssh backdoor) facilitated persistent remote access. The threat actors leveraged operational relay box (ORB) networks to obscure C2 infrastructure, dynamically rotating IPs, and domains. Post-exploitation activities included credential theft, lateral movement via DLL hijacking, and log manipulation using THC’s clear13 tool. Notably, the attackers reused SSH keys across different intrusions, indicating operational overlaps or shared infrastructure management.

This campaign underscores the persistent and evolving threat posed by China-nexus cyberespionage actors, particularly their focus on cybersecurity vendors and critical infrastructure. The reuse of tools, infrastructure, and TTPs across multiple intrusions suggests a coordinated, long-term operation with potential links to known threat clusters.The attacks highlight the increasing use of ORB networks and open-source tooling to evade detection, positioning this activity within the broader trend of Chinese cyberespionage operations targeting global enterprises and government entities.

THREAT PROFILE:

THREAT PROFILE:

Tactic Technique ID Technique Sub-Technique
Reconnaissance T1595 Active Scanning -
Resource Development T1583 Acquire Infrastructure -
Initial Access T1190 Exploit Public-Facing Application -
Execution T1047 Windows Management Instrumentation -
Persistence T1543.003 Create or Modify System Process Windows Service
Defense Evasion T1070 Indicator Removal -
Credential Access T1539 Steal Web Session Cookie -
Discovery T1082 System Information Discovery -
Collection T1560 Archive Collected Data -
Command and Control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu