Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign

SHADOW-EARTH-053 Exchange/IIS espionage against government and defense networks

Updated 01.05.2026 17:02
Case score 55
Members 1 First seen 01.05.2026 17:02 Latest activity 01.05.2026 17:02

Overview

**SHADOW-EARTH-053** is exploiting internet-facing **Microsoft Exchange** and **IIS** systems to reach government and defense networks across South, East, and Southeast Asia and Poland. After access, the operators deploy **Godzilla** web shells, stage **ShadowPad** through **AnyDesk** and DLL sideloading, and in at least one chain use **CVE-2025-55182** to deliver **Linux Noodle RAT**. The activity has been active since at least December 2024 and uses tunneling, privilege-escalation, and lateral-movement tooling to sustain access. Available evidence indicates overlap with a related intrusion set for some victims, while the full scope of compromise remains unquantified.
Latest development

SHADOW-EARTH-053 espionage campaign disclosed against Asian government and defense targets

Trend Micro attributed a China-aligned espionage campaign to SHADOW-EARTH-053, saying the cluster targets government and defense sectors across South, East, and Southeast Asia and Poland, has been active since at least December 2024, and uses internet-facing Microsoft Exchange and IIS exploitation to drop Godzilla web shells, stage ShadowPad via DLL sideloading and AnyDesk, and in one case deliver Linux Noodle RAT through CVE-2025-55182.

Signals

CVEs/products
Geographic context
Status
Threat context

Threat actor context

1 listed

Malware & tooling context

3 families · 3 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Campaign SHADOW-EARTH-053 China-aligned espionage campaign against Asian government and defense targets
Updated 01.05.2026 17:02 Lead Contribution 55
Objective Espionage Campaign Active

**SHADOW-EARTH-053** is running an active **China-aligned espionage campaign** against **government and defense** targets across **South, East, and Southeast Asia** and **Poland**, creating persistent access for intelligence collection. The operation has been active since **at least December 2024** and uses **internet-facing Microsoft Exchange and IIS vulnerabilities** to gain entry, then deploys **Godzilla** web shells and **ShadowPad** implants. The intrusion chain also includes **CVE-2025-55182** in one case, plus tunneling, privilege-escalation, and lateral-movement tooling to extend reach inside victim networks.