Chinese Hackers Target WSUS Vulnerability to Distribute ShadowPad Malware
Article Content
Browse articles
Chinese hackers are exploiting a remote code execution vulnerability in Windows Server Update Services (WSUS) to deploy ShadowPad malware. This attack affects organizations using WSUS for patch management, potentially compromising sensitive data and systems. The exploitation of this vulnerability highlights the ongoing threat posed by advanced persistent threat (APT) groups.
Ask AI about this cluster
Answers cite the sources they use
Updated 194d ago How this analysis works
More articles in this cluster (2)
Following this threat?
Track ShadowPad in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…
China-Linked Hackers Target NGOs with Chrome and Windows Exploits On September 1, 2026, Chinese threat actors UTA0560 and JungleBamboo executed phishing campaigns targeting NGOs, exploiting zero-day vulnerabilities in Google Chrome and Microsoft Windows. The attack utilized a spear-phishing email that redirected victims to a compromised U.S.-based university website, leveraging a…