Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors SHADOW-VOID-042

Also known as: Storm-0978, Tropical Scorpius, APT28, Smoke Sandstorm, tracked as, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, VOLTZITE, for follow-on operations, Tech Sectors, Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, APT44, Seashell Blizzard, BlackEnergy, PHANTOM, September 2025, Void Rabisu, operated by TA569, RomCom, the Bulldog backdoor, defense-industry organizations, TA455, Yellow Liderc, Tortoiseshell, aviation, IMPERIAL KITTEN, Imperial Kitten, TA456, DUSTYCAVE, Crimson Sandstorm, Cuboid Sandstorm, CURIUM, Agrius, APT34, Royal Ransomware, Blue Echidna, UNC2596, GOFFEE, Fluffy Wolf, LuoYu, CASCADE PANDA, Qilin, file transfer tools, UNC1549, APT33, Fancy Bear, Samurai Panda, PLA Navy, APT4, Wisp Team, APT35, Quedagh, VOODOO BEAR, TEMP.Noble, IRON VIKING, G0034, ELECTRUM, TeleBots, IRIDIUM, FROZENBARENTS, UAC-0113, UAC-0082, SANDWORM RELIC, Newscaster Team, Magic Hound, G0059, Phosphorus, Mint Sandstorm, TunnelVision, COBALT MIRAGE, Agent Serpens, RICH ION, BOHRIUM, DEV-0228

Description

SHADOW-VOID-042 is an emergent intrusion set that surfaced in late‑2025 and has been linked to a series of sophisticated spear‑phishing operations. The group targets a broad spectrum of industries—including energy, defense, pharmaceuticals, financial services, telecommunications, manufacturing, and aerospace—across numerous countries such as the United States, Russia, Ukraine, China, Iran, India, and Saudi Arabia. Campaign emails frequently mimic official Trend Micro communications or present themselves as HR complaints or research surveys to lure recipients into executing malicious attachments or visiting compromised web pages. The attacker employs an intricate multi‑stage loader architecture. Initially a shellcode stub embedded in JavaScript is delivered via phishing or compromised vendor updates; the code contacts the adversary’s command‑and‑control (C2) on TCP port 1026 with an opaque four‑byte magic header (0x36694201). After establishing contact, it downloads an encrypted Stage 2 binary—SystemProcessHost.exe—writes it to disk, and schedules a scheduled task named "DavaniGulyashaSdeshka" for persistence. Subsequent stages retrieve further payloads through an API hashing scheme with retries on hardcoded C2 endpoints. In addition to stealthy delivery, SHADOW-VOID-042 demonstrates destructive intent by deploying data‑wiping tools ZeroLot and Sting via Group Policy manipulation and scheduled tasks against Ukrainian entities. The adversary also leverages the Chrome vulnerability CVE‑2018‑6065 through injected JavaScript that redirects victims through a Cloudflare‑impersonating chain, exemplifying its ability to integrate web‑based exploitation with desktop payloads. Operationally, the group shares infrastructure and TTP similarities with the Void Rabisu (ROMCOM) operatives but remains distinct, focusing on non‑Ukraine sectors and lacking confirmed ROMCOM-specific attacks. Their tools feature Netlink kernel sockets for stealth, payload polymorphism, credential theft from "/etc/passwd"/"/etc/shadow", and UDP‑based distributed denial‑of‑service capabilities. Overall, SHADOW-VOID-042 presents a versatile threat that blends social engineering, web exploitation, lateral movement techniques, and destructive malware to achieve both financial gains and infrastructure sabotage.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Manufacturing
Healthcare
Energy
Education
Critical infrastructure
Transportation
Media
Non profit
Aerospace
Pharmaceutical
Aviation
Hospitality
Retail
Information technology
Chemical
Maritime
Gaming
Think tank
Construction
Food agriculture
Mining
Entertainment
Legal services
Nuclear
Utilities
Oil gas

Targeted Countries / Regions

CN
US
RU
UA
IR
GB
IN
BY
JP
TW
IL
AE
KP
VN
AU
PK
DE
SA
MX
CA
SG
KR
PL
TR
FR
ES
RO
NG
IT
LB
AZ
KZ
EG
BR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 12 hours ago

Executive Summary

SHADOW-VOID-042 is a financially motivated intrusion set active from October to November 2025 that conducts highly tailored spear‑phishing using Trend Micro brand lures, exploiting a Chrome CVE and Windows Group Policy for deployment. The campaign uses multi‑stage loaders with custom C2 over TCP ports 1026/6969, and includes destructive wiper malware ZeroLot/Sting targeting critical infrastructure in Ukraine and beyond.

Goals & Targeting

The strategic objective of SHADOW‑VOID‑042 appears to be dual‑pronged: short‑term financial gain through credential theft and phishing, coupled with long‑term reputational damage or disruption via targeted wipers against critical infrastructure. By focusing on high‑value sectors such as energy, defense, and pharmaceuticals, the actor seeks to leverage the economic impact of downtime while simultaneously signaling capability and intent. The targeting profile reveals a methodical selection of victims based on perceived value and susceptibility rather than geographical bias, although the majority of recent activity points towards Ukrainian infrastructure. The attacker’s use of brand‑spoofed malware and zero‑day browser exploits indicates an emphasis on maximizing compromise likelihood while minimizing user awareness.

Enhanced Description

Key Capabilities

  • Spear‑phishing with brand spoofing
  • Deceptive software update lures
  • Exploitation of Windows Group Policy for deployment
  • Scheduled task creation for persistence (DavaniGulyashaSdeshka)
  • Deployment of wiper malware ZeroLot / Sting
  • Chrome CVE‑2018‑6065 exploitation via injected JavaScript and redirect chain
  • Hardcoded 64‑bit shellcode contacting C2 on TCP 1026/6969 with magic header 0x36694201
  • Custom command‑and‑control protocol over TCP ports 1026 and 6969
  • Netlink kernel socket usage for stealth and payload polymorphism
  • Credential theft from /etc/passwd and /etc/shadow
  • UDP “bandwidth” DDoS launch

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Impact
Credential Access
Discovery
Command and Control

ATT&CK Techniques

T1566.001
T1204.0
T1484.001
T1053.006
T1485
T1190
T1203
T1059
T1105
T1041
T1140
T1499
T1003.004
T1068
T1133
T1204.002
T1657

Software / Tooling

ZeroLot
Sting
Broadside
Mirai

Campaigns & Victims

SHADOW‑VOID‑042’s campaigns have a clear operational tempo: rapid deployment of spear‑phishing emails in late‑2025, followed by immediate exploitation of known browser vulnerabilities (Chrome CVE‑2018‑6065) and Windows Group Policy weaknesses. Victims are often industrial, governmental, or commercial organizations with critical infrastructure holdings. The actor routinely establishes persistence via scheduled tasks, deploys destructive wipers against Ukrainian facilities, and exfiltrates credential material for lateral movement. The group’s overlap with Void Rabisu (ROMCOM) suggests shared infrastructure, though the two maintain separate operational foci. This dual presence hints at a broader, modular threat network capable of evolving tactics, techniques, and procedures across multiple campaigns.

IOC Patterns

  • Malicious email lures claiming Trend Micro updates
  • Scheduled task creation named "DavaniGulyashaSdeshka"
  • Software update impersonation mimicking legitimate vendors
  • Injected JavaScript with hard‑coded 64‑bit shellcode
  • Custom C2 traffic containing magic header 0x36694201 on TCP ports 1026/6969
  • Redirect chains through Cloudflare‑impersonating HTML pages

Recommended Actions

  • Implement advanced phishing detection and conduct regular user training focused on brand spoofing attacks.
  • Harden Group Policy Objects and closely monitor for unauthorized modifications or policy injections.
  • Set up monitoring for suspicious scheduled task creation, particularly tasks named after known malware artefacts. Deploy EDR solutions with signatures for zero‑day wiper families such as ZeroLot and Sting to detect payloads promptly. Segment critical infrastructure segments from general corporate networks and apply firewall rules limiting internal movement of malicious binaries. Enforce URL filtering and sandboxing for outbound web traffic, especially for redirect chains leading to spoofed sites. Apply timely patches for CVE‑2018‑6065 as well as other known client‑side vulnerabilities. Deploy network IDS that flag unusual Netlink kernel socket activity or traffic on bespoke C2 ports (1026, 6969). Protect credential files (/etc/passwd and /etc/shadow) via integrity monitoring and enforce least privilege for all user accounts.

Suggested Tags

Sandworm Team
APT activity
Spear Phishing
Brand Spoofing
Data Wiper
Group Policy Exploitation
Scheduled Task Abuse
Critical Infrastructure Targeting
Web‑based Exploitation
Chrome Vulnerability
Shellcode Download
Custom C2 Protocol
Magic Header Identification
Botnet Activity
DDoS Launch
Credential Theft
Privilege Escalation

ATT&CK Techniques

Software / Tooling

Observed Data

No observed data linked yet.

References

  1. ics-cert.kaspersky.com — Cited by web research for: Storm-0978
  2. attack.mitre.org — Cited by web research for: APT28
  3. attack.mitre.org — Cited by web research for: Tech Sectors
  4. unit42.paloaltonetworks.com — Cited by web research for: BlackCat
  5. www.paloaltonetworks.com — Cited by web research for: T1219
  6. www.trendmicro.com — Cited by web research for: SystemProcessHost.exe

Intel Summary

25

Techniques

53

Tools

2

Campaigns

40

IOCs

0

Observed Data

12

Tactics

Tags

Healthcare Targeting
Phishing
Backdoor / C2
Spear-phishing
Multi-nation
Critical Infrastructure
Sandworm Team
APT activity
Spear Phishing
Brand Spoofing
Data Wiper
Group Policy Exploitation
Scheduled Task Abuse
Critical Infrastructure Targeting
Web‑based Exploitation
Chrome Vulnerability
Shellcode Download
Custom C2 Protocol
Magic Header Identification
Botnet Activity
DDoS Launch
Credential Theft
Privilege Escalation

Details

MITRE ID
APT4
Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.