Chinese Hackers Using Custom ShadowPad IIS Listener Module to Turn Compromised Servers into Active Nodes
ID: bea41f29-c08d-5000-85f1-9ca37109053d
STIX ID: report--bea41f29-c08d-5000-85f1-9ca37109053d
Feed Name: cybersecurityNews.com
Ink Dragon (Earth Alux / REF7707) operates a sophisticated campaign using a custom ShadowPad IIS Listener to hijack IIS/SharePoint servers via ASP.NET ViewState deserialization and SharePoint ToolShell flaws; the implant registers dynamic URL listeners, decrypts operator payloads, forwards non‑malicious traffic to avoid detection, and pairs server/client nodes to create a resilient, stealthy relay network that enables persistent C2 and lateral pivoting across victim infrastructures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
