Building Casper’s Shadow
ID: 797018a3-d608-5bf6-ac5b-c435895756de
STIX ID: report--797018a3-d608-5bf6-ac5b-c435895756de
Feed Name: Nao_Sec
Researchers report discovering a ShadowPad builder (“CasperVMakerHTTPx86”) that outputs an AppLaunch.exe and mscoree.dll pair using Casper Loader for DLL sideloading to run ShadowPad shellcode, with configurable modules (Install/Inject/Online/Proxy/DNS). They link the builder’s loader algorithm (custom XOR decoding) to prior RoyalRoad RTF-based campaigns in Kyrgyzstan and Kazakhstan and to an FBI-reported intrusion exploiting CVE-2021-44515, noting overlaps with APT usage by Tick and APT41. The report provides sample hashes and highlights shared TTPs across these operations, underscoring ShadowPad’s commercial ecosystem and widespread adoption.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
