Shadow-Earth-053
SHADOW-EARTH-053 is a China-aligned intrusion cluster and cyberespionage campaign tracked by Trend Micro/TrendAI. It has been active since at least December 2024 and has targeted government agencies, ministries, defense-adjacent contractors, defense contractors, critical infrastructure organizations, technology firms, transportation entities, and IT consulting firms. Reported victim countries include Pakistan, Thailand, Malaysia, India, Myanmar, Sri Lanka, Taiwan, and Poland, with the campaign primarily focused on South, East, and Southeast Asia and at least one victim in a European NATO member state. The group gains initial access by exploiting unpatched internet-facing Microsoft Exchange Server and IIS systems, including the ProxyLogon chain (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065). After exploitation it deploys GODZILLA web shells, including ASPX and ASHX variants, for persistence, command execution, and reconnaissance. SHADOW-EARTH-053 then deploys ShadowPad using DLL sideloading chains built around legitimate signed executables, including GameHook.exe, imecmnt.exe, xReport.exe, LUManager.EXE, and a renamed Toshiba Bluetooth Stack executable, CIATosBtKbd.exe, which sideloads TosBtKbd.dll. In observed cases, the loader retrieved encrypted payloads from Windows Registry keys under HKEY_CURRENT_USER\Software[ComputerName], allocated executable memory, and executed shellcode via EnumDesktopsA callback injection. Persistence included a scheduled task named M1onltor configured to run every five minutes with elevated privileges. Post-compromise activity included reconnaissance through compromised IIS worker processes; domain controller and domain admin discovery; LDAP enumeration; csvde.exe exports; PowerView-based user enumeration; internal Exchange discovery; mailbox enumeration and export via a custom ExchangeExport tool using Exchange Web Services; credential theft with Mimikatz, Evil-CreateDump, and newdcsync; and lateral movement using WMIC, Sharp-SMBExec, custom RDP tooling, and propagation of web shells to internal Exchange servers over administrative SMB shares. The group also used multiple tunneling and proxy tools, including IOX Proxy, GOST, Wstunnel, and tunnel-core.exe variants, and used RingQ to pack binaries and evade detection. Researchers also observed renamed legitimate Windows binaries to evade process-based detection. In some intrusions, AnyDesk was used to deploy ShadowPad. Separate reporting also noted Linux NoodleRat deployment following exploitation of React2Shell (CVE-2025-55182), though attribution of those samples to SHADOW-EARTH-053 was stated with low confidence in one report. Trend Micro reported significant overlap with the related cluster SHADOW-EARTH-054, including shared victims, identical tool hashes, overlapping TTPs, and exploitation of the same vulnerabilities, but stated there was no evidence of direct operational coordination and assessed the overlap as likely reflecting parallel exploitation of the same exposed environments. Related overlaps were also noted with activity tracked elsewhere as CL-STA-0049, REF7707, and Earth Alux. Separate reporting linked parallel phishing activity targeting journalists and diaspora activists from Uyghur, Tibetan, Taiwanese, and Hong Kong communities to clusters named Glitter Carp and Sequin Carp as part of the broader campaign context. Those operations used impersonation emails, fake security alerts, 1x1 tracking pixels, and credential-harvesting pages. The overall activity is described as aligned with Chinese intelligence priorities and focused on espionage and, in some reporting, intellectual property theft.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
- Military
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
Associated vulnerabilities
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
The campaign primarily leveraged the ProxyLogon exploit chain affecting Microsoft Exchange Server, including CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065. | The campaign primarily leveraged the ProxyLogon exploit chain affecting Microsoft Exchange Server, including CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065. Following successful exploitation, operators deployed GODZILLA web shells into Exchange and IIS directories to establish persistent remote access.
The campaign primarily leveraged the ProxyLogon exploit chain affecting Microsoft Exchange Server, including CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065.
The campaign primarily leveraged the ProxyLogon exploit chain affecting Microsoft Exchange Server, including CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065.
The campaign primarily leveraged the ProxyLogon exploit chain affecting Microsoft Exchange Server, including CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065.
In a separate instance, the incident responders found Linux NoodleRat backdoors deployed after Shadow-Earth-053 exploited another widely-abused Microsoft security hole: React2Shell (CVE-2025-55182), a critical flaw in React Server Components that can allow attackers to run arbitrary code on vulnerable servers.
Observables
17 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-aligned espionage cluster targeting IIS servers in campaigns against government and defense sectors across parts of Asia.
Cyberespionage campaign targeting government, defense-adjacent, transportation, critical infrastructure, and technology organizations across Asia by exploiting legacy Microsoft Exchange/IIS vulnerabilities, deploying web shells and ShadowPad, stealing credentials, tunneling traffic, moving laterally, and exporting executive mailboxes.
Conducting cyberespionage and likely intellectual property theft by exploiting unpatched Microsoft Exchange and IIS servers, compromising government, defense-linked, IT consulting, and transportation targets across Asia and Poland, and deploying ShadowPad for persistence and post-compromise operations.
China-aligned espionage cluster targeting government and defense sectors across South, East, and Southeast Asia, plus Poland, by exploiting internet-facing Microsoft Exchange and IIS vulnerabilities, deploying Godzilla web shells, and staging ShadowPad and Noodle RAT for persistence and post-compromise operations.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.