The NetSarang Xshell ShadowPad Supply Chain Attack
Updated 5 Oct 2026 · Incident date 18 Jul 2017 · vendor binary
Xshell 5 Build 1322, Xmanager Enterprise 5 Build 1232, Xmanager 5 Build 1045, Xftp 5 Build 1218, Xlpd 5 Build 1220nssock2.dllOn 18 July 2017, NetSarang software went live on its website with a backdoor named ShadowPad inside the library nssock2.dll. The builds were Xshell 5 Build 1322, Xmanager Enterprise 5 Build 1232, Xmanager 5 Build 1045, Xftp 5 Build 1218 and Xlpd 5 Build 1220.
The library carried NetSarang's own certificate. Kaspersky found it and told NetSarang privately on 4 August 2017.
What happened
A malicious library was built into five server management tools and signed by the vendor. Kaspersky reports that nssock2.dll was compiled on 13 July 2017 and that it carried a legitimate NetSarang certificate. The compromised software went live on 18 July. NetSarang pulled the affected versions after Kaspersky reported the issue on 4 August, so the exposure ran at least 17 days.
The backdoor had layers. The business logic stayed dormant until activation. The first layer sent basic data (computer name, domain, user name) to a command server every eight hours. It used a domain generation algorithm that changed each month. An attacker turned it on with a specially built DNS TXT record. After that, the backdoor was able to download and run any code and keep a virtual file system in encrypted registry locations, unique to each victim.
Kaspersky confirmed a financial firm in Hong Kong as a victim and suggests Chinese-speaking actors, because of similarities with the PlugX and Winnti malware.
Vigilance compares the version you trust with the new one. A vendor installer that carries a changed library with new network behavior is the kind of change it reports. See the scan block below.
Affected versions
- Xshell 5 Build 1322.
- Xmanager Enterprise 5 Build 1232.
- Xmanager 5 Build 1045.
- Xftp 5 Build 1218.
- Xlpd 5 Build 1220.
The Hacker News reports that kits from April 2017 or earlier are not affected. Tenable lists Xshell 5 builds before 1326 as vulnerable, and Build 1326 as the fix. Treat any build from the July 2017 release as bad.
Indicators of compromise
- File:
nssock2.dll, MD597363d50a279492fda14cbab53429e75, signed by NetSarang. - MD5 of Xshell 5 Build 1322:
b2c302537ce8fbbcff0d45968cc0a826. - MD5 of Xmanager Enterprise 5 Build 1232:
0009f4b9972660eeb23ff3a9dccd8d86. - MD5 of Xmanager 5 Build 1045:
b69ab19614ef15aa75baf26c869c9cdd. - MD5 of Xftp 5 Build 1218:
78321ad1deefce193c8172ec982ddad1. - MD5 of Xlpd 5 Build 1220:
28228f337fdbe3ab34316a7132123c49. - Domains:
ribotqtonut[.]com,nylalobghyhirgh[.]com,jkvmdmjyfcvkf[.]com,bafyvoruzgjitwr[.]com,xmponmzmxkxkh[.]com,tczafklirkl[.]com,notped[.]com,dnsgogle[.]com,operatingbox[.]com,paniesx[.]com,techniciantext[.]com. - Kaspersky detection name: Backdoor.Win32.ShadowPad.a.
How to check
Hash the library in each NetSarang install folder and compare it with the MD5 above. In PowerShell:
Get-ChildItem "C:\Program Files*\NetSarang" -Recurse -Filter nssock2.dll | Get-FileHash -Algorithm MD5
A match with 97363d50a279492fda14cbab53429e75 means the backdoored library is present. Also search DNS logs for the domains above.
What to do now
- Update every NetSarang product to the current release. Xshell 5 Build 1326 or later is the fix that Tenable names.
- If you ran a bad build, check DNS logs for the domains above and hunt on the hosts that ran it. The attacker was able to run any code.
- Rotate the passwords and keys that were used from those machines. These tools hold access to servers.
- Block the domains.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 13 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED nssock2.dll It now downloads from the internet, reads saved passwords and access keys and runs a hidden, encoded command. It did not before.
Frequently asked questions
Which NetSarang builds contained ShadowPad?
Xshell 5 Build 1322, Xmanager Enterprise 5 Build 1232, Xmanager 5 Build 1045, Xftp 5 Build 1218 and Xlpd 5 Build 1220 contained ShadowPad.
How did ShadowPad activate?
It activated when the attacker sent a specially built DNS TXT record. Until then the backdoor only sent basic host data every eight hours.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.