Back to Blog
Cybersecurity May 4, 2026 5 min read

SHADOW-EARTH-053: China-Linked Hackers Hit Asian Governments, a NATO State, and ICIJ Journalists via Exchange Exploits

Trend Micro and Citizen Lab jointly disclosed a China-aligned threat cluster exploiting ProxyLogon-era Microsoft Exchange flaws to deploy ShadowPad implants against governments across Asia, a NATO member in Europe, and journalists from the International Consortium of Investigative Journalists.

SHADOW-EARTH-053: China-Linked Hackers Hit Asian Governments, a NATO State, and ICIJ Journalists via Exchange Exploits

Trend Micro and Citizen Lab released coordinated findings May 1–2 exposing a China-aligned espionage cluster they track as SHADOW-EARTH-053, active since at least December 2024 and still operational at time of disclosure.

The campaign has compromised government and defense organizations across South, East, and Southeast Asia, a NATO member state in Europe, and journalists affiliated with the International Consortium of Investigative Journalists (ICIJ) — including reporter Scilla Alecci and diaspora activist communities in the Uyghur, Tibetan, Taiwanese, and Hong Kong communities.

Attack Chain

The initial intrusion vector is ProxyLogon-chain exploitation against internet-facing Microsoft Exchange and IIS servers. Despite these vulnerabilities being patched in 2021, a significant population of on-premises Exchange deployments — particularly in government ministries with long patch cycles — remains exposed.

From the foothold, attackers deploy Godzilla webshells for persistent command access, then install ShadowPad as the primary implant via DLL sideloading. ShadowPad is a modular backdoor framework widely associated with contractors working for China’s Ministry of State Security; it supports keylogging, screen capture, credential harvesting, and lateral movement plugins loaded at runtime.

Citizen Lab documented a parallel phishing campaign using OAuth token harvesting against civil society targets — individuals who wouldn’t have on-premises Exchange servers to exploit. The phishing messages impersonated conference invitations and document-sharing notifications from legitimate organizations.

Linked Clusters

Trend Micro identified two satellite clusters under the same umbrella:

  • GLITTER CARP — focused on Taiwanese semiconductor firms and ICIJ journalists
  • SEQUIN CARP — targeted diaspora civil society groups and individual activist journalists

The infrastructure overlaps — shared C2 IP ranges and certificate fingerprints — link all three clusters to the same sponsoring entity, though Trend Micro stops short of a direct MSS attribution.

What to Do if You Run On-Premises Exchange

If your organization still runs on-premises Exchange, the immediate actions are:

  1. Verify all applicable ProxyLogon, ProxyShell, and ProxyNotShell patches are installed. Running unpatched Exchange in 2026 is not defensible.
  2. Audit IIS application pools and virtual directories for unexpected handlers or modules — Godzilla webshells frequently masquerade as legitimate ASP.NET modules.
  3. Check for unsigned DLLs in Exchange server directories that may indicate ShadowPad sideloading.
  4. Review OAuth application registrations in your Microsoft 365 tenant for any apps your security team didn’t authorize.

Threat intelligence indicators of compromise (IoCs) — including C2 IPs, ShadowPad hash variants, and Godzilla webshell signatures — are available in Trend Micro’s full technical report.

Wider Context

The targeting profile — governments, semiconductor supply chain, investigative journalists, and diaspora activists — is consistent with Chinese state intelligence priorities documented repeatedly over the past decade. What’s notable here is the persistence: December 2024 through May 2026 is an 18-month campaign window, suggesting either high-value targets or exceptionally low detection rates in the affected environments.

Organizations in the named sectors should treat unpatched Exchange infrastructure as compromised until proven otherwise.

cybersecurity china-apt exchange shadowpad espionage proxylogon