SHADOW-EARTH-053: China-Linked Hackers Hit Asian Governments, a NATO State, and ICIJ Journalists via Exchange Exploits
Trend Micro and Citizen Lab jointly disclosed a China-aligned threat cluster exploiting ProxyLogon-era Microsoft Exchange flaws to deploy ShadowPad implants against governments across Asia, a NATO member in Europe, and journalists from the International Consortium of Investigative Journalists.
Trend Micro and Citizen Lab released coordinated findings May 1–2 exposing a China-aligned espionage cluster they track as SHADOW-EARTH-053, active since at least December 2024 and still operational at time of disclosure.
The campaign has compromised government and defense organizations across South, East, and Southeast Asia, a NATO member state in Europe, and journalists affiliated with the International Consortium of Investigative Journalists (ICIJ) — including reporter Scilla Alecci and diaspora activist communities in the Uyghur, Tibetan, Taiwanese, and Hong Kong communities.
Attack Chain
The initial intrusion vector is ProxyLogon-chain exploitation against internet-facing Microsoft Exchange and IIS servers. Despite these vulnerabilities being patched in 2021, a significant population of on-premises Exchange deployments — particularly in government ministries with long patch cycles — remains exposed.
From the foothold, attackers deploy Godzilla webshells for persistent command access, then install ShadowPad as the primary implant via DLL sideloading. ShadowPad is a modular backdoor framework widely associated with contractors working for China’s Ministry of State Security; it supports keylogging, screen capture, credential harvesting, and lateral movement plugins loaded at runtime.
Citizen Lab documented a parallel phishing campaign using OAuth token harvesting against civil society targets — individuals who wouldn’t have on-premises Exchange servers to exploit. The phishing messages impersonated conference invitations and document-sharing notifications from legitimate organizations.
Linked Clusters
Trend Micro identified two satellite clusters under the same umbrella:
- GLITTER CARP — focused on Taiwanese semiconductor firms and ICIJ journalists
- SEQUIN CARP — targeted diaspora civil society groups and individual activist journalists
The infrastructure overlaps — shared C2 IP ranges and certificate fingerprints — link all three clusters to the same sponsoring entity, though Trend Micro stops short of a direct MSS attribution.
What to Do if You Run On-Premises Exchange
If your organization still runs on-premises Exchange, the immediate actions are:
- Verify all applicable ProxyLogon, ProxyShell, and ProxyNotShell patches are installed. Running unpatched Exchange in 2026 is not defensible.
- Audit IIS application pools and virtual directories for unexpected handlers or modules — Godzilla webshells frequently masquerade as legitimate ASP.NET modules.
- Check for unsigned DLLs in Exchange server directories that may indicate ShadowPad sideloading.
- Review OAuth application registrations in your Microsoft 365 tenant for any apps your security team didn’t authorize.
Threat intelligence indicators of compromise (IoCs) — including C2 IPs, ShadowPad hash variants, and Godzilla webshell signatures — are available in Trend Micro’s full technical report.
Wider Context
The targeting profile — governments, semiconductor supply chain, investigative journalists, and diaspora activists — is consistent with Chinese state intelligence priorities documented repeatedly over the past decade. What’s notable here is the persistence: December 2024 through May 2026 is an 18-month campaign window, suggesting either high-value targets or exceptionally low detection rates in the affected environments.
Organizations in the named sectors should treat unpatched Exchange infrastructure as compromised until proven otherwise.
Related reading
- Cybersecurity Microsoft Exchange Zero-Day CVE-2026-42897 Actively Exploited — No Full Patch, Automatic Mitigation Only
- Cybersecurity China Weaponizes the Tata Electronics Breach to Undercut India's iPhone Buildout
- Cybersecurity Nvidia Forms 60-Member Open Secure AI Alliance to Fight Back Against AI-Powered Attacks