Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System Access

ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System Access

Posted on November 24, 2025November 24, 2025 By CWS

Nov 24, 2025Ravie LakshmananMalware / Vulnerability
A just lately patched safety flaw in Microsoft Home windows Server Replace Providers (WSUS) has been exploited by menace actors to distribute malware referred to as ShadowPad.
“The attacker focused Home windows Servers with WSUS enabled, exploiting CVE-2025-59287 for preliminary entry,” AhnLab Safety Intelligence Middle (ASEC) mentioned in a report printed final week. “They then used PowerCat, an open-source PowerShell-based Netcat utility, to acquire a system shell (CMD). Subsequently, they downloaded and put in ShadowPad utilizing certutil and curl.”
ShadowPad, assessed to be a successor to PlugX, is a modular backdoor broadly utilized by Chinese language state-sponsored hacking teams. It first emerged in 2015. In an evaluation printed in August 2021, SentinelOne known as it a “masterpiece of privately offered malware in Chinese language espionage.”

CVE-2025-59287, addressed by Microsoft final month, refers to a important deserialization flaw in WSUS that could possibly be exploited to attain distant code execution with system privileges. The vulnerability has since come beneath heavy exploitation, with menace actors utilizing it to acquire preliminary entry to publicly uncovered WSUS situations, conduct reconnaissance, and even drop reputable instruments like Velociraptor.
ShadowPad put in through CVE-2025-59287 exploit
Within the assault documented by the South Korean cybersecurity firm, the attackers have been discovered to weaponize the vulnerability to launch Home windows utilities like “curl.exe” and “certutil.exe,” to contact an exterior server (“149.28.78[.]189:42306”) to obtain and set up ShadowPad.
ShadowPad, much like PlugX, is launched by the use of DLL side-loading, leveraging a reputable binary (“ETDCtrlHelper.exe”) to execute a DLL payload (“ETDApix.dll”), which serves as a memory-resident loader to execute the backdoor.

As soon as put in, the malware is designed to launch a core module that is accountable for loading different plugins embedded within the shellcode into reminiscence. It additionally comes fitted with quite a lot of anti-detection and persistence strategies.
“After the proof-of-concept (PoC) exploit code for the vulnerability was publicly launched, attackers rapidly weaponized it to distribute ShadowPad malware through WSUS servers,” AhnLab mentioned. “This vulnerability is important as a result of it permits distant code execution with system-level permission, considerably growing the potential affect.”

The Hacker News Tags:Access, Actively, Exploits, Full, Malware, ShadowPad, System, Vulnerability, WSUS

Post navigation

Previous Post: Wireshark Vulnerabilities Let Attackers Crash by Injecting a Malformed Packet
Next Post: DeepSeek-R1 Makes Code for Prompts With Severe Security Vulnerabilities

Related Posts

FIRESTARTER Backdoor Threatens Cisco Devices Despite Patches FIRESTARTER Backdoor Threatens Cisco Devices Despite Patches The Hacker News
Critical 18-Year NGINX Vulnerability Enables Remote Code Execution Critical 18-Year NGINX Vulnerability Enables Remote Code Execution The Hacker News
Pentests once a year? Nope. It’s time to build an offensive SOC Pentests once a year? Nope. It’s time to build an offensive SOC The Hacker News
Cisco Warns of New Firewall Attack Exploiting CVE-2025-20333 and CVE-2025-20362 Cisco Warns of New Firewall Attack Exploiting CVE-2025-20333 and CVE-2025-20362 The Hacker News
Unpatchable usbliter8 Exploit Affects Apple Devices Unpatchable usbliter8 Exploit Affects Apple Devices The Hacker News
Chaos RaaS Emerges After BlackSuit Takedown, Demanding 0K from U.S. Victims Chaos RaaS Emerges After BlackSuit Takedown, Demanding $300K from U.S. Victims The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AmnesiaStealer Malware Targets macOS Through Fake Sites
  • Beacon CRM Data Breach: Full Database Stolen After AWS Key Leak
  • Fortinet Addresses Critical Security Flaws in Key Products
  • Armored Likho Tool Compromises Telegram & Records Conversations
  • Jewelbug Exploits Browsers to Infiltrate Government Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AmnesiaStealer Malware Targets macOS Through Fake Sites
  • Beacon CRM Data Breach: Full Database Stolen After AWS Key Leak
  • Fortinet Addresses Critical Security Flaws in Key Products
  • Armored Likho Tool Compromises Telegram & Records Conversations
  • Jewelbug Exploits Browsers to Infiltrate Government Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark