ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Malware

APT41 Targets Taiwanese Government Research Institute with ShadowPad and Cobalt Strike

Chinese Hackers Exploit Vulnerabilities in Sophisticated Cyber Attack

Paul by Paul
August 5, 2024
in Malware, Security
Reading Time: 2 mins read
Photo of the Taiwanese Government Research Institute being targeted by China's APT41.
Share on FacebookShare on Twitter

Cisco Talos researchers have reported a significant cyber attack on a Taiwanese government-affiliated research institute, attributing the breach to the China-linked group APT41 with medium confidence. The campaign began as early as July 2023 and involved deploying advanced malware tools including ShadowPad and Cobalt Strike.

You might also like

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

How Hackers Still Manage to Compromise MFA

Anthropic Unveils Claude Code Security to Detect and Fix Critical Vulnerabilities

Attack Overview and Attribution

The researchers identified several key aspects of the attack:

  • The campaign targeted a Taiwanese government-affiliated research institute
  • APT41, a group allegedly comprised of Chinese nationals, is believed to be responsible
  • Attribution is based on overlaps in tactics, techniques, and procedures (TTPs), infrastructure, and malware families exclusive to Chinese APT groups

ShadowPad Malware Deployment

A central component of the attack was the use of ShadowPad, a sophisticated modular remote access trojan (RAT):

  • ShadowPad is known to be sold exclusively to Chinese hacking groups
  • The malware exploited an outdated vulnerable version of Microsoft Office IME binary as a loader
  • A customized second-stage loader was used to launch the payload
  • Two distinct iterations of ShadowPad were encountered during the investigation

Cobalt Strike and Custom Loaders

The attackers also leveraged Cobalt Strike and developed custom loaders to evade detection:

  • A unique Cobalt Strike loader written in GoLang was used to bypass Windows Defender
  • The loader was derived from an anti-AV tool called CS-Avoid-Killing, found on GitHub
  • Simplified Chinese file and directory paths suggest the attackers’ proficiency in the language
  • PowerShell commands were used to execute scripts for running ShadowPad directly in memory and fetching Cobalt Strike from command and control (C2) servers
A screenshot of the Github repository for the Cobalt Strike loader.
The Github repository of Cobalt Strike loader.

Exploitation of CVE-2018-0824

APT41 demonstrated advanced capabilities by exploiting a known vulnerability:

  • The group created a custom loader to inject a proof-of-concept for CVE-2018-0824 directly into memory
  • This remote code execution vulnerability was used to achieve local privilege escalation
  • A tool called UnmarshalPwn was employed in the exploitation process

Attack Methodology and Persistence

The attackers employed various techniques to maintain access and avoid detection:

  • Three hosts in the targeted environment were compromised
  • Documents were exfiltrated from the network
  • A web shell was used to maintain persistence and drop additional payloads
  • The “quser” command was executed to monitor for other logged-on users, allowing the attackers to pause activities if detected
  • After deploying backdoors, the web shell and guest account used for initial access were deleted

Broader Implications and Ongoing Investigations

Cisco Talos researchers emphasized the potential for further discoveries:

  • Analysis of artifacts from this campaign led to the identification of samples and infrastructure potentially used in different campaigns
  • Sharing these findings could help the cybersecurity community make connections and enhance ongoing investigations
  • Indicators of Compromise (IoCs) for this campaign have been released on Cisco Talos’ GitHub repository

This sophisticated cyber attack on a Taiwanese government research institute highlights the ongoing threat posed by advanced persistent threat (APT) groups like APT41. Complex malware such as ShadowPad, combined with custom loaders and exploitation of known vulnerabilities, demonstrates the evolving tactics employed by state-sponsored threat actors.

Tags: APT41china
Previous Post

Russian International Prisoner Swap includes Carder.su Member Roman Seleznev

Next Post

LianSpy: New Android Spyware Targeting Russian Users

Paul

Paul

Editor and chief at ZeroSecurity. Expertise includes programming, malware analysis, and penetration testing. If you would like to write for ZeroSecurity, please click "Contact us" at the bottom of the page.

Recommended For You

Photo of the CISCO logo and text saying "You have been hacked!"

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

March 6, 2026
How Hackers Still Manage to Compromise MFA

How Hackers Still Manage to Compromise MFA

March 6, 2026

Anthropic Unveils Claude Code Security to Detect and Fix Critical Vulnerabilities

February 22, 2026

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

Phishing 2.0: How AI is Turning Cyber Attacks into a Science

January 7, 2025 - Updated on January 9, 2025

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.