AhnLab and South Korea’s National Cyber Security Center (NCSC) have jointly disclosed comprehensive findings on TA-ShadowCricket a persistent, highly sophisticated threat group linked to China and formerly known as Shadow Force.
According to the detailed technical report, TA-ShadowCricket has managed to operate mostly undetected for more than thirteen years, targeting government and enterprise networks across the Asia-Pacific region.
A Decade-Long Intrusion Campaign
The report confirms that the group has been active since at least 2012, steadily building an expansive network of compromised systems through stealthy and multi-staged operations.
Originally identified by AhnLab as Larva-24013 under its Threat Actor Naming and Taxonomy guidelines, TA-ShadowCricket’s ultimate classification as an “Arthropod”-level actor was based on in-depth forensics, which tied the group’s code lineage to previously documented Shadow Force malware.

Collaboration between AhnLab and the NCSC was instrumental in correlating malware samples, network infrastructure, and operational patterns, confirming the association and revealing the scale of the threat.
Central to TA-ShadowCricket’s operations is an Internet Relay Chat (IRC) server, discovered to be functioning as the command-and-control (C2) nucleus.
This server, hosted on a Korean IP, was found to manage over 2,000 compromised systems spread across 72 countries.
Forensic analysis indicates concentrated targeting in China (895 infected IPs), South Korea (457), and India (98), suggesting both regional focus and broad operational reach.
Attackers primarily gained initial access through exploitation of Remote Desktop Protocol (RDP) and maintained persistent control through regular command sessions.
Log data traced some C2 activity directly to Chinese IP addresses, lending further weight to the speculation of geopolitical motives behind the campaign.
Multi-Stage Malware Ecosystem
TA-ShadowCricket’s attack methodology is characterized by a structured three-stage model.
The initial “Reconnaissance & Access” phase uses custom tools such as Upm and SqlShell for privilege escalation and system profiling, with additional downloaders and command executors facilitating primary infection.
In the subsequent “Remote Control” stage, the group leverages sophisticated backdoors like Maggie and Sqldoor to dispatch commands and extract data, while continuing to use legacy IRC bots like Wgdrop for botnet management.
The “Persistence & Monetization” phase introduces advanced malware components such as CredentialStealer, Detofin for API hooking, and a cryptocurrency miner, indicating a focus on maintaining long-term access and extracting economic value from compromised assets.
One of the most notable elements in TA-ShadowCricket’s arsenal is the continued use of Pemodifier a tool for injecting malicious DLLs into system processes and the strategic deployment of the Maggie malware.
Maggie, implemented as an Extended Stored Procedure (ESP) compatible with Microsoft SQL Server, allows the attackers to execute arbitrary commands via crafted SQL queries, blending seamlessly into legitimate database traffic and evading conventional detection mechanisms.
Unlike many contemporary Advanced Persistent Threat (APT) groups, TA-ShadowCricket is not driven by quick financial gain through ransomware or extortion.
Instead, the group exhibits remarkable discipline and patience, focused exclusively on espionage and infrastructure development.
The absence of public data leaks or ransom demands suggests state-level intelligence collection or a highly organized cybercrime enterprise laying groundwork for possible disruptive operations such as distributed denial-of-service (DDoS) attacks.
While analysis of server access and control points to a Chinese nexus, the group’s inclusion of coin miners and embedded nicknames in the malware complicates clear attribution.
As the report summarizes, while there is strong evidence linking TA-ShadowCricket to Chinese interests, the operational complexity and mix of espionage and monetization strategies leave open the possibility that the group represents either a clandestine state-sponsored actor or a disciplined cybercrime syndicate with evolving objectives.
Experts warn that the group’s continued presence poses a severe risk to government and enterprise networks, demanding increased vigilance and international cooperation.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates