AhnLab

  • Privacy & Security
  • EULA
  • Contact Us
  • Terms of Use
  • Sitemap

Subscribe to Our Newsletter

Stay informed with AhnLab’s latest threat intelligence
and security insights delivered monthly to your inbox.

Country
AhnLab V3 Engine VersionOES :
Update Engine Now →
  • Visit our LinkedIn Profile
  • Visit our Twitter page
  • Visit our YouTube channel
  • © AhnLab, Inc. All rights reserved.
  • ASEC
  • MyCompany(ELS)
  • AhnLab Document Center
    • Contact Us
    • My Company
    • Security Map
Article
Threat Analysis07-01-2025

TA-ShadowCricket: The 13-Year Shadow Campaign Exposed


▶ Download Full Report


Background

TA-ShadowCricket is a threat group formerly known as Shadow Force and is suspected to have ties to China. This group has been active for over ten years in countries across the Asia-Pacific region, including South Korea. The group primarily infiltrates systems by using Windows MS SQL and RDP, and installs IRC bots or backdoors for control. Since December 2021, installations of virtual asset miners have also been identified on some compromised systems.

 

This report is based on joint tracking of TA-ShadowCricket's activities since 2023, conducted by the National Cyber Security Center (hereinafter referred to as NCSC) and AhnLab.

 

TA-ShadowCricket

Threat Group Naming

AhnLab manages threat activity using its Threat Actor Classification System and Naming Convention, which categorizes threats into four levels. Threat actors are classified as either unidentified (Larva) or identified (Arthropod).



Since November 2024, AhnLab has been analyzing the threat group's IRC server and related malware in collaboration with the NCSC. At that time, the threat group was being tracked as the unidentified threat actor Larva-24013. It was later confirmed that they were connected to the previously known Shadow Force group. Accordingly, in line with AhnLab's classification system and naming convention, the group was newly designated as the identified threat actor TA-ShadowCricket.

 

Conclusion

The TA-ShadowCricket group has been operating out of Korea for over a decade, targeting regions across Asia. The threat actors have maintained their legacy attack habits as they have consistently used the same malware and tool file names. Despite this, there has been limited coverage of this threat group by security firms or institutions, resulting in a continued lack of information.

 

TA-ShadowCricket does not demand ransom post-breach, nor does it release stolen data on the dark web. Instead, the group has quietly operated for over 13 years, persistently managing affected systems and their corresponding C2 servers across thousands of IPs. This infrastructure could potentially be leveraged for future attacks such as DDoS.

 

Various indicators—including the tools and developers used, primary target regions, and connections to C&C servers via Chinese IPs—suggest potential links to China. However, the use of personal nicknames within the malware and recent behaviors like installing miners raise doubts about whether this is a state-sponsored APT group.

 

This joint analysis has confirmed that TA-ShadowCricket still manages compromised systems using IRC bots. Analysis of the IRC servers indicates that more than 2,000 bots are currently in operation. To prevent further, potentially widespread damage, it is critical to block these IRC servers and to detect, neutralize, and remove the associated malware.


▶ Download Full Report
List

Related Content

White Paper

How Agentic AI Is Reshaping the Role of Security Admins

How Agentic AI Is Reshaping the Role of Security Admins

Article

AhnLab Partners with the Korean National Police Agency to Combat Phishing Crimes

AhnLab Partners with the Korean National Police Agency to Combat Phishing Crimes

Article

The Evolution of AI-Powered Hacking Tools

The Evolution of AI-Powered Hacking Tools

Article

The Hidden Threat Behind Fake CAPTCHAs and Installation Guides: Why ClickFix Is Dangerous

The Hidden Threat Behind Fake CAPTCHAs and Installation Guides: Why ClickFix Is Dangerous

skip navigation
  • 메뉴
  • 본문
  • 하단 정보(링크)
  • Products
    • AhnLab PLUS Platform
    • AhnLab Endpoint PLUS
      • Anti-Malware
      • EPP
      • Sandbox (ATD)
      • EDR
      • SMB Security
      • Mobile Security
    • AhnLab Network PLUS
      • NGFW
      • IPS
      • DDoS Mitigation
      • Sandbox (ATD)
      • Threat Management
    • AhnLab Cloud PLUS
      • CWPP
      • Cloud NGFW
      • Cloud IPS
      • Cloud Threat Management
    • AhnLab Connect PLUS
      • XDR
      • Threat Intelligence
      • SOAR
    • AhnLab CPS PLUS
      • CPS Protection Management
      • OT Endpoint Protection
      • OT IDS
      • OT Portable AV
      • OT Firewall
      • OT Data Diode
      • OT Network Sandbox
      • IT Endpoint Protection
      • IT Anti-Malware
      • CPS Threat Intelligence
    • AhnLab AI PLUS
    • All Products and Services
  • Services
    • AhnLab Service PLUS
      • MDR
      • MSS
      • Professional Service
      • Security Consulting
      • Digital Forensics
      • Cloud Managed Service
      • Global Partners
    • All Products and Services
  • Solution
    • Ransomware Protection
    • Hybrid Cloud Security
    • Zero Trust
    • CPS Protection
    • SOC Modernization
    • TDR
    • DDoS Mitigation
  • Support
    • Technical Support
    • Threat Inquiry
    • Online Support
      • Q&A
    • Notice
    • Download
    • AhnLab Document Center
  • Content Center
    • Content Center
    • ASEC
      • Threat Descriptions
      • Threat Actor Naming
      • ASEC Security Advisory
      • ASEC Blog
    • Highlights
      • MITRE ATT&CK Eval Round 7
      • AhnLab 30th Anniversary
      • Frost Radar CPS Security Leader
  • Partners
  • Company
    • About Us
    • Strategic Materials
my page
Sign InSign Up
언어 선택

No recent searches