Skip to content
ThreatCluster

Chinese Hackers Target WSUS Vulnerability to Distribute ShadowPad Malware

First seen 23 Nov 2025, 03:35 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

Chinese hackers are exploiting a remote code execution vulnerability in Windows Server Update Services (WSUS) to deploy ShadowPad malware. This attack affects organizations using WSUS for patch management, potentially compromising sensitive data and systems. The exploitation of this vulnerability highlights the ongoing threat posed by advanced persistent threat (APT) groups.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 194d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track ShadowPad in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed