Analysis of ShadowPad Attack Exploiting WSUS Remote Code Execution Vulnerability (CVE-2025-59287)
ID: 973c4498-000b-5fa1-a1e0-8a773448826a
STIX ID: report--973c4498-000b-5fa1-a1e0-8a773448826a
Feed Name: ASEC
Threat Score
AhnLab ASEC observed active exploitation of WSUS RCE (CVE-2025-59287) after public PoC release, where attackers used PowerCat to gain a CMD shell and then leveraged curl/certutil to download and install the ShadowPad backdoor. The report includes ShadowPad DLL sideloading details, configuration values, file and MD5 indicators, C2 addresses, and recommended mitigations (apply Microsoft update, restrict WSUS access, audit PowerShell/certutil/curl activity).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
