logo

Building Casper’s Shadow

ID: 797018a3-d608-5bf6-ac5b-c435895756de

STIX ID: report--797018a3-d608-5bf6-ac5b-c435895756de

Feed Name: Nao_Sec

Threat Score

Date Published: 2024-06-30

Date Updated: 2026-03-24

Author: nao_sec

...
...

Researchers report discovering a ShadowPad builder (“CasperVMakerHTTPx86”) that outputs an AppLaunch.exe and mscoree.dll pair using Casper Loader for DLL sideloading to run ShadowPad shellcode, with configurable modules (Install/Inject/Online/Proxy/DNS). They link the builder’s loader algorithm (custom XOR decoding) to prior RoyalRoad RTF-based campaigns in Kyrgyzstan and Kazakhstan and to an FBI-reported intrusion exploiting CVE-2021-44515, noting overlaps with APT usage by Tick and APT41. The report provides sample hashes and highlights shared TTPs across these operations, underscoring ShadowPad’s commercial ecosystem and widespread adoption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.