Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors shadow-earth-053

Description

A China-aligned threat group designated SHADOW-EARTH-053 has been conducting cyberespionage operations against government entities and critical infrastructure across at least eight countries in South, East, and Southeast Asia, plus one NATO member state, since December 2024. The group exploits unpatched Microsoft Exchange vulnerabilities, particularly the ProxyLogon chain, to gain initial access and deploys GODZILLA web shells for persistence. ShadowPad implants are staged via DLL sideloading of legitimate signed executables. Nearly half of the compromised environments showed overlap with another intrusion set, SHADOW-EARTH-054, sharing identical tooling including Evil-CreateDump and IOX proxy. The attackers conduct extensive Active Directory reconnaissance, credential harvesting, and mailbox exfiltration targeting high-profile government officials and defense contractors. Multiple tunneling tools including GOST and Wstunnel establish covert command-and-control channels, while lateral movement leverages WM...

Goals & Targeting

Targeted Sectors

Government
Defense
Transportation

Targeted Countries / Regions

British Indian Ocean Territory
India
Malaysia
Myanmar
Pakistan
Poland
Sri Lanka
Taiwan
Thailand

AI Analysis

· 1 week ago

Executive Summary

Shadow-Earth-053 is a China-aligned threat group conducting cyberespionage across multiple countries since December 2024. Targeting government, defense, and transportation sectors, they exploit Microsoft Exchange vulnerabilities and use web shells for persistence.

Goals & Targeting

Targeting government entities suggests a focus on espionage and geopolitical interests. The choice of sectors and countries aligns with China's strategic interests in regional influence and military intelligence, possibly linked to its Belt and Road Initiative.

Enhanced Description

Shadow-Earth-053, as a China-aligned cyberespionage group, has been active since December 2024. They primarily target government entities, critical infrastructure in South, East, and Southeast Asia, and Poland. Their tactics include exploiting unpatched Microsoft Exchange vulnerabilities, deploying GODZILLA web shells, using ShadowPad via DLL sideloading, and employing tools like Evil-CreateDump for lateral movement. They share tooling with another group, SHADOW-EARTH-054, indicating potential collaboration.

Key Capabilities

  • Exploitation via ProxyLogon chain
  • Deployment of GODZILLA web shells for persistence
  • ShadowPad deployment through DLL sideloading
  • Evil-CreateDump for lateral movement
  • IOX proxy tool usage

MITRE ATT&CK Tactics

Credential Access
Discovery
Exfiltration

ATT&CK Techniques

T1078.001
T1566
T1214.003

Software / Tooling

Evil-CreateDump
IOX proxy
GOST
Wstunnel

Campaigns & Victims

Campaigns involve extensive Active Directory reconnaissance, credential harvesting, and mailbox exfiltration. Notable for overlapping activities with SHADOW-EARTH-054, indicating toolkits are reused.

IOC Patterns

  • Exploitation ofCVE-2021-268XX ProxyLogon
  • GODZILLA web shell activity
  • Spear-phishing emails
  • Use of GOST and Wstunnel C2 channels

Recommended Actions

  • Patch MS Exchange vulnerabilities immediately.
  • Implement multi-factor authentication on critical accounts.
  • Monitor network traffic for C2 toolkits like Gost and Wstunnel.
  • Conduct regular backups to mitigate potential data breaches.

Suggested Tags

APT
cyber espionage
government targeting
defense

Confidence Assessment

High confidence in their cyberespionage activities, but limited info on initial access vectors and exact motives.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

23

IOCs

0

Observed Data

0

Tactics

Tags

APT
Critical Infrastructure
Phishing
Backdoor / C2
Government Targeting
cyber espionage
government targeting
defense

Details

Type
Unknown
Country of Origin
C
Confidence
55%
Added
May 6, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.