Threat actor
Shadow Network
Last fetched
Shadow Network is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.
Description
Shadows in the Cloud documents a complex ecosystem of cyber espionage that systematically compromised government, business, academic, and other computer network systems in India, the Offices of the Dalai Lama, the United Nations, and several other countries. The report also contains an analysis of data which were stolen from politically sensitive targets and recovered during the course of the investigation. These include documents from the Offices of the Dalai Lama and agencies of the Indian national security establishment. Data containing sensitive information on citizens of numerous third-party countries, as well as personal, financial, and business information, were also exfiltrated and recovered during the course of the investigation. The report analyzes the malware ecosystem employed by the Shadows’ attackers, which leveraged multiple redundant cloud computing systems, social networking platforms, and free web hosting services in order to maintain persistent control while operating core servers located in the People’s Republic of China (PRC). Although the identity and motivation of the attackers remain unknown, the report is able to determine the location (Chengdu, PRC) as well as some of the associations of the attackers through circumstantial evidence. The investigation is the product of an eight month, collaborative activity between the Information Warfare Monitor (Citizen Lab and SecDev) and the Shadowserver Foundation. The investigation employed a fusion methodology, combining technical interrogation techniques, data analysis, and field research, to track and uncover the Shadow cyber espionage network.
Techniques by tactic
No ATT&CK techniques are recorded for Shadow Network in WhisperGraph.
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to Shadow Network today — this states the absence of a published link, not that Shadow Network has no infrastructure.
References
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from Shadow Network into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.