The NetSarang Xshell ShadowPad Supply Chain Attack

Updated 5 Oct 2026 · Incident date 18 Jul 2017 · vendor binary

PackageXshell 5 Build 1322, Xmanager Enterprise 5 Build 1232, Xmanager 5 Build 1045, Xftp 5 Build 1218, Xlpd 5 Build 1220
Filenssock2.dll

On 18 July 2017, NetSarang software went live on its website with a backdoor named ShadowPad inside the library nssock2.dll. The builds were Xshell 5 Build 1322, Xmanager Enterprise 5 Build 1232, Xmanager 5 Build 1045, Xftp 5 Build 1218 and Xlpd 5 Build 1220.

The library carried NetSarang's own certificate. Kaspersky found it and told NetSarang privately on 4 August 2017.

What happened

A malicious library was built into five server management tools and signed by the vendor. Kaspersky reports that nssock2.dll was compiled on 13 July 2017 and that it carried a legitimate NetSarang certificate. The compromised software went live on 18 July. NetSarang pulled the affected versions after Kaspersky reported the issue on 4 August, so the exposure ran at least 17 days.

The backdoor had layers. The business logic stayed dormant until activation. The first layer sent basic data (computer name, domain, user name) to a command server every eight hours. It used a domain generation algorithm that changed each month. An attacker turned it on with a specially built DNS TXT record. After that, the backdoor was able to download and run any code and keep a virtual file system in encrypted registry locations, unique to each victim.

Kaspersky confirmed a financial firm in Hong Kong as a victim and suggests Chinese-speaking actors, because of similarities with the PlugX and Winnti malware.

Vigilance compares the version you trust with the new one. A vendor installer that carries a changed library with new network behavior is the kind of change it reports. See the scan block below.

Affected versions

The Hacker News reports that kits from April 2017 or earlier are not affected. Tenable lists Xshell 5 builds before 1326 as vulnerable, and Build 1326 as the fix. Treat any build from the July 2017 release as bad.

Indicators of compromise

How to check

Hash the library in each NetSarang install folder and compare it with the MD5 above. In PowerShell:

Get-ChildItem "C:\Program Files*\NetSarang" -Recurse -Filter nssock2.dll | Get-FileHash -Algorithm MD5

A match with 97363d50a279492fda14cbab53429e75 means the backdoored library is present. Also search DNS logs for the domains above.

What to do now

  1. Update every NetSarang product to the current release. Xshell 5 Build 1326 or later is the fix that Tenable names.
  2. If you ran a bad build, check DNS logs for the domains above and hunt on the hosts that ran it. The attacker was able to run any code.
  3. Rotate the passwords and keys that were used from those machines. These tools hold access to servers.
  4. Block the domains.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old Xshell-prev --new Xshell-current
files scanned: 13

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    nssock2.dll
           It now downloads from the internet, reads saved passwords and access keys and runs a hidden, encoded command. It did not before.

Frequently asked questions

Which NetSarang builds contained ShadowPad?

Xshell 5 Build 1322, Xmanager Enterprise 5 Build 1232, Xmanager 5 Build 1045, Xftp 5 Build 1218 and Xlpd 5 Build 1220 contained ShadowPad.

How did ShadowPad activate?

It activated when the attacker sent a specially built DNS TXT record. Until then the backdoor only sent basic host data every eight hours.

Sources

  1. securelist.com/shadowpad-in-corporate-networks/81432/
  2. thehackernews.com/2017/08/netsarang-server-management.html
  3. tenable.com/plugins/nessus/102713

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free