Shadow-Earth-053
SHADOW-EARTH-053 is a China-aligned cyberespionage threat cluster temporarily designated by Trend Micro/TrendAI. The activity has been observed since at least December 2024 and has targeted government agencies, ministries, defense-adjacent contractors, defense-sector organizations, critical infrastructure, transportation entities, technology firms, and IT consulting firms. Reported victim countries include Pakistan, Thailand, Malaysia, India, Myanmar, Sri Lanka, Taiwan, and Poland. Additional targeting included journalists and diaspora activists, with parallel phishing activity linked in reporting to Glitter Carp and Sequin Carp. The group primarily gains initial access by exploiting unpatched internet-facing Microsoft Exchange Server and IIS systems, including the ProxyLogon chain (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065). After compromise, it deploys GODZILLA web shells and other ASPX/ASHX web shells for persistence and command execution, conducts reconnaissance through IIS worker processes, and performs mailbox discovery and export via Exchange Web Services using a custom ExchangeExport tool. SHADOW-EARTH-053 deploys ShadowPad as its primary malware, commonly via DLL sideloading chains using legitimate signed executables, including renamed Toshiba Bluetooth Stack components such as CIATosBtKbd.exe loading TosBtKbd.dll. Reporting also describes use of executables associated with Samsung Electronics, Mainline Net Holdings, GameHook.exe, imecmnt.exe, xReport.exe, and LUManager.EXE. In observed cases, the malicious DLL retrieves encrypted payloads from the Windows Registry, executes shellcode via EnumDesktopsA callback injection, and persistence is maintained through a scheduled task named "M1onltor" running every five minutes with elevated privileges. Post-compromise tradecraft includes Active Directory and Exchange reconnaissance, domain controller and domain admin enumeration, LDAP and csvde.exe-based discovery, PowerView-based user enumeration, credential theft with Mimikatz, Evil-CreateDump, and newdcsync, and lateral movement using WMIC, Sharp-SMBExec, custom RDP tooling, and propagation of web shells across internal Exchange servers via administrative SMB shares. The operators also use multiple tunneling and proxy tools, including IOX Proxy, GOST, Wstunnel, and tunnel-core.exe variants, and have used RingQ to pack binaries and evade detection. Reporting also notes use of AnyDesk in at least one intrusion and low-confidence attribution of Linux NOODLERAT deployment in exploitation associated with React2Shell. Trend Micro reported overlaps with the related cluster SHADOW-EARTH-054, including shared victims, identical tool hashes, overlapping TTPs, and infrastructure overlap; however, the reporting states there was no evidence of direct operational coordination and that the overlap may reflect parallel exploitation of the same exposed environments. Other reported overlaps involve activity tracked as CL-STA-0049, REF7707, and Earth Alux.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
- Military
- Transportation
- Software & Services
- Commercial & Professional Services
Where they target
Geographies tied to known operations.
- 🇵🇰 Pakistan
- 🇹🇭 Thailand
- 🇲🇾 Malaysia
- 🇮🇳 India
- 🇲🇲 Myanmar (Burma)
- 🇱🇰 Sri Lanka
- 🇹🇼 Taiwan
- 🇵🇱 Poland
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
Associated vulnerabilities
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
The campaign primarily leveraged the ProxyLogon exploit chain affecting Microsoft Exchange Server, including CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065. | The campaign primarily leveraged the ProxyLogon exploit chain affecting Microsoft Exchange Server, including CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065. Following successful exploitation, operators deployed GODZILLA web shells into Exchange and IIS directories to establish persistent remote access.
The campaign primarily leveraged the ProxyLogon exploit chain affecting Microsoft Exchange Server, including CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065.
The campaign primarily leveraged the ProxyLogon exploit chain affecting Microsoft Exchange Server, including CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065.
The campaign primarily leveraged the ProxyLogon exploit chain affecting Microsoft Exchange Server, including CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065.
In a separate instance, the incident responders found Linux NoodleRat backdoors deployed after Shadow-Earth-053 exploited another widely-abused Microsoft security hole: React2Shell (CVE-2025-55182), a critical flaw in React Server Components that can allow attackers to run arbitrary code on vulnerable servers.
Observables
17 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cyberespionage campaign targeting government, defense-adjacent, transportation, critical infrastructure, and technology organizations across Asia by exploiting legacy Microsoft Exchange/IIS vulnerabilities, deploying web shells and ShadowPad, stealing credentials, tunneling traffic, moving laterally, and exporting executive mailboxes.
Conducting cyberespionage and likely intellectual property theft by exploiting unpatched Microsoft Exchange and IIS servers, compromising government, defense-linked, IT consulting, and transportation targets across Asia and Poland, and deploying ShadowPad for persistence and post-compromise operations.
China-aligned espionage cluster targeting government and defense sectors across South, East, and Southeast Asia, plus Poland, by exploiting internet-facing Microsoft Exchange and IIS vulnerabilities, deploying Godzilla web shells, and staging ShadowPad and Noodle RAT for persistence and post-compromise operations.
China-aligned espionage cluster conducting cyberespionage and likely intellectual property theft against government agencies and critical infrastructure, using ProxyLogon exploitation, web shells, ShadowPad, lateral movement, and credential harvesting.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.