/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Symantec: Chinese cyberespionage group Redfly used the ShadowPad trojan to hack a national electricity grid company in Asia from February 28 to August 3, 2023

An espionage threat group tracked as ‘Redfly’ hacked a national electricity grid organization in Asia and quietly maintained access to the breached network for six months.

BleepingComputer Bill Toulas

Context & Ripple Effects

This report extends a related pattern of espionage activity against Asian organizations: Symantec had earlier described Lancefly targeting Asian governments and telecoms with custom malware.

Its focus on a grid operator also echoes the earlier penetration of energy companies' operational networks, making long-lived access—not merely initial compromise—the central risk.

First-order effects

  • The affected grid organization must identify and remove any remaining ShadowPad-related persistence, then determine whether the intrusion reached systems connected to electricity operations.
  • Symantec's disclosure gives grid-sector defenders a concrete malware and intrusion pattern to hunt for across their own environments.

Second-order effects

  • Other electricity operators and their managed-service providers are likely to prioritize searches for ShadowPad and review monitoring coverage across corporate and operational-network boundaries.
  • Security vendors and incident-response teams gain a clearer basis for tuning detections around a campaign that maintained access over an extended period.

Third-order effects

  • If similar intrusions continue, critical-infrastructure defense will increasingly depend on ecosystem-wide detection and response, rather than treating each utility's enterprise network as an isolated security perimeter.
  • The case reinforces a durable shift toward measuring resilience by attackers' ability to persist undetected in critical environments, not just by whether an initial intrusion is blocked.

The trend: Cyberespionage campaigns are putting greater strategic value on durable, covert access to critical-infrastructure networks, raising the importance of coordinated ecosystem cyber defense.

Discussion

  • @campuscodi@mastodon.social Catalin Cimpanu on mastodon
    “Symantec's Threat Hunter Team has found evidence that a threat actor group Symantec calls Redfly used the ShadowPad Trojan to compromise a national grid in an Asian country for as long as six months earlier this year.  The attackers managed to steal credentials and compromise mu…
  • @lindseyod123 Lindsey O'Donnell Welch on x
    “The frequency at which CNI organizations are being attacked appears to have increased over the past year and is now a source of concern.” A national grid in Asia was compromised by attackers using the ShadowPad malware - here's Symantec's threat intel: https://symantec-enterpris…