logo

RST TI Report Digest: 24 Feb 2025

ID: 36739c71-9507-5eb6-a424-cd766e755627

STIX ID: report--36739c71-9507-5eb6-a424-cd766e755627

Feed Name: RST Cloud Blog

Threat Score
80/100

Date Published: 2025-02-24

Date Updated: 2026-04-29

Author: RST Cloud

...
...

Shadowpad—historically used for espionage by APT41—has been updated to deliver a previously unseen ransomware strain; attackers gained remote access to 21 companies by exploiting weak administrative credentials and bypassing multi-factor authentication, then installed Shadowpad to enable theft, keylogging, and encrypted ransomware deployment using AES/RSA and evasive techniques such as DNS over HTTPS. The report includes extensive indicators of compromise (IP address, multiple malicious domains, and numerous SHA-256 hashes) and links the activity to intelligence-gathering objectives, particularly targeting manufacturing intellectual property.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.