A China-aligned threat group designated SHADOW-EARTH-053 has been conducting cyberespionage operations against government entities and critical infrastructure across at least eight countries in South, East, and Southeast Asia, plus one NATO member state, since December 2024. The group exploits unpatched Microsoft Exchange vulnerabilities, particularly the ProxyLogon chain, to gain initial access and deploys GODZILLA web shells for persistence. ShadowPad implants are staged via DLL sideloading of legitimate signed executables. Nearly half of the compromised environments showed overlap with another intrusion set, SHADOW-EARTH-054, sharing identical tooling including Evil-CreateDump and IOX proxy. The attackers conduct extensive Active Directory reconnaissance, credential harvesting, and mailbox exfiltration targeting high-profile government officials and defense contractors. Multiple tunneling tools including GOST and Wstunnel establish covert command-and-control channels, while lateral movement leverages WM...
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Shadow-Earth-053 is a China-aligned threat group conducting cyberespionage across multiple countries since December 2024. Targeting government, defense, and transportation sectors, they exploit Microsoft Exchange vulnerabilities and use web shells for persistence.
Goals & Targeting
Targeting government entities suggests a focus on espionage and geopolitical interests. The choice of sectors and countries aligns with China's strategic interests in regional influence and military intelligence, possibly linked to its Belt and Road Initiative.
Enhanced Description
Shadow-Earth-053, as a China-aligned cyberespionage group, has been active since December 2024. They primarily target government entities, critical infrastructure in South, East, and Southeast Asia, and Poland. Their tactics include exploiting unpatched Microsoft Exchange vulnerabilities, deploying GODZILLA web shells, using ShadowPad via DLL sideloading, and employing tools like Evil-CreateDump for lateral movement. They share tooling with another group, SHADOW-EARTH-054, indicating potential collaboration.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Campaigns involve extensive Active Directory reconnaissance, credential harvesting, and mailbox exfiltration. Notable for overlapping activities with SHADOW-EARTH-054, indicating toolkits are reused.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in their cyberespionage activities, but limited info on initial access vectors and exact motives.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
23
IOCs
0
Observed Data
0
Tactics