logo

Chinese Hackers Using Custom ShadowPad IIS Listener Module to Turn Compromised Servers into Active Nodes

ID: bea41f29-c08d-5000-85f1-9ca37109053d

STIX ID: report--bea41f29-c08d-5000-85f1-9ca37109053d

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-12-17

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Ink Dragon (Earth Alux / REF7707) operates a sophisticated campaign using a custom ShadowPad IIS Listener to hijack IIS/SharePoint servers via ASP.NET ViewState deserialization and SharePoint ToolShell flaws; the implant registers dynamic URL listeners, decrypts operator payloads, forwards non‑malicious traffic to avoid detection, and pairs server/client nodes to create a resilient, stealthy relay network that enables persistent C2 and lateral pivoting across victim infrastructures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.