Malware
ShadowPad
- First Reported
- Jul 23, 2026
- Latest Reported
- Sep 9, 2026
Reported Context (2)
- China-aligned UNK_LateNight targets US aerospace to deliver ShadowPad backdoor using BlueMoon Multiple State-Aligned Threat Actors Rapidly Adopt BlueMoon Chrome and Windows Exploit Chain
- on ports 80, 8443, and 8080. The IP is identified as high risk due to the historical presence of a ShadowPad controller, and currently hosting a VShell C2 server on port 21083. A single domain, Unattended Hermes AI Agent Used in Targeting of Thailand Finance Ministry, Researchers Find
CVE (10)
Malware (2)
People (2)
Threat Actors (5)
MITRE ATT&CK (36)
Vendors (3)
Products (20)
Tools (9)
Industries (9)
Countries (8)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.