Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Adobe Campaign Classic Critical Flaws Let Attackers Run Code
August 27, 2026
Critical WatchGuard Agent for Windows Bug Lets Attackers Run Code
August 27, 2026
Critical Apache Tomcat Flaws Let Attackers Bypass Security, Crash Servers
August 27, 2026
Home/Threats/China-Aligned Hackers Use ShadowPad, IOX Proxy, WMIC in Espionage Campaign
Threats

China-Aligned Hackers Use ShadowPad, IOX Proxy, WMIC in Espionage Campaign

Key Takeaways A sophisticated, multi-stage cyberespionage campaign, dubbed SHADOW-EARTH-053, is targeting government entities and critical infrastructure across at least eight Asian nations, along...

David kimber
David kimber
May 1, 2026 4 Min Read
75 0

Key Takeaways

  • A sophisticated, multi-stage cyberespionage campaign, dubbed SHADOW-EARTH-053, is targeting government entities and critical infrastructure across at least eight Asian nations, along with Poland.
  • The threat group leverages well-known vulnerabilities in Microsoft Exchange and IIS servers, specifically the ProxyLogon chain (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065), as initial access vectors.
  • Attackers deploy advanced malware like ShadowPad and IOX Proxy, combined with living-off-the-land techniques using WMIC and web shells, to maintain persistence and exfiltrate data.
  • Patches for the exploited vulnerabilities have been available since 2021; immediate application is critical for defense.

A China-aligned advanced persistent threat (APT) group is executing a complex, multi-stage espionage campaign, primarily targeting government agencies and critical infrastructure in Asia. This operation, meticulously designed for intelligence gathering, exploits known vulnerabilities and utilizes a blend of custom malware and legitimate system tools, according to a recent analysis.

Table Of Content

  • Key Takeaways
  • Initial Infiltration and Persistence
  • Research Uncovers Broader Campaign
  • Malware and Tooling Arsenal
  • How the Attack Unfolds: ShadowPad’s Infection Mechanism
  • What You Should Do

The group, identified by researchers under the provisional designation SHADOW-EARTH-053, has been active since at least December 2024. Its operations have quietly compromised organizations across at least eight countries, indicating a broad strategic focus.

The campaign’s success hinges on its ability to combine bespoke malware with “living-off-the-land” techniques, allowing the attackers to remain undetected within victim networks for extended periods. Further details on the campaign’s mechanics are outlined in a comprehensive report.

Initial Infiltration and Persistence

Initial access is primarily achieved by exploiting unpatched vulnerabilities within Microsoft Exchange and Internet Information Services (IIS) servers. The threat actors specifically target the ProxyLogon vulnerability chain, which includes CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065. Despite patches for these critical flaws being available for years, many organizations continue to operate vulnerable Exchange servers, making them prime targets.

Once inside a network, the attackers deploy web shells, such as GODZILLA, to establish persistent backdoor access. These web shells enable remote command execution, providing the threat actors with continuous control over compromised systems.

Research Uncovers Broader Campaign

Researchers Daniel Lunghi and Lucas Silva at Trend Micro were instrumental in uncovering this extensive campaign. Their investigation began with an analysis of ShadowPad implants targeting South and Southeast Asia, which subsequently revealed a related cluster, SHADOW-EARTH-054. Both clusters exhibited identical tool hashes and overlapping attack methodologies, suggesting a coordinated effort.

Notably, nearly half of the compromised environments saw both SHADOW-EARTH-053 and SHADOW-EARTH-054 active within the same organizations. Victims have been confirmed in Pakistan, Thailand, Malaysia, India, Myanmar, Sri Lanka, Taiwan, and Poland. The research team assesses that these operations are consistent with China’s strategic interests, primarily focused on cyberespionage and intellectual property theft.

Malware and Tooling Arsenal

The primary malware employed in this campaign is ShadowPad, a modular backdoor first identified in 2017 in attacks attributed to APT41. Since 2019, ShadowPad has been shared among various China-aligned groups, indicating its widespread adoption within these circles.

Beyond ShadowPad, the attackers utilize IOX Proxy to establish covert communication channels, and Windows Management Instrumentation Command-line (WMIC) for lateral movement within compromised networks. They also incorporate open-source tunneling tools like GOST and Wstunnel to funnel traffic over SOCKS5 and HTTPS connections to external command-and-control infrastructure.

How the Attack Unfolds: ShadowPad’s Infection Mechanism

A particularly sophisticated aspect of this campaign is the method used to load ShadowPad onto victim machines. The attackers employ a DLL sideloading technique, where a malicious DLL is placed alongside a legitimate, digitally signed executable. When the legitimate program is executed, it inadvertently loads the malicious DLL.

The group has been observed abusing executables from reputable vendors, including Toshiba, Samsung, and Microsoft, often renaming them to mimic legitimate system processes and evade detection. This technique further enhances the stealth of the operation.

What makes this loader especially insidious is that the ShadowPad payload itself is not embedded within the malicious DLL. Instead, the loader retrieves an encrypted payload from a machine-specific registry key located at HKEY_CURRENT_USERSoftware.

Persistence is maintained through a scheduled task named “M1onltor,” configured to execute the sideloaded binary every five minutes with the highest available privileges. WMIC is then leveraged to deploy backdoors onto additional hosts, and credential-harvesting tools such as Mimikatz and Evil-CreateDump are executed via IIS worker processes to extract sensitive account data and passwords.

What You Should Do

  • Patch Immediately: Apply the latest security patches for all internet-facing Microsoft Exchange and IIS servers, especially those addressing the ProxyLogon vulnerability chain (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065).
  • Implement Virtual Patching: If immediate patching is not feasible, deploy Intrusion Prevention Systems (IPS) or Web Application Firewalls (WAF) with virtual patching rules to mitigate known vulnerabilities.
  • Monitor Web Directories: Implement File Integrity Monitoring (FIM) on critical web directories and configure alerts for any new or modified .aspx, .ashx, or .jsp files.
  • Review EDR Telemetry: Regularly review Endpoint Detection and Response (EDR) telemetry for suspicious activity, particularly IIS worker processes spawning command shells or reconnaissance tools.
  • Monitor Staging Areas: Pay close attention to directories like C:UsersPublic and C:ProgramData, as these have been consistently used by the group as staging areas for their operations.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitMalwarePatchSecurityThreatVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Fake CAPTCHA Campaign Uses SMS Pumping Fraud to Increase Victims’ Phone Bills

Next Post

Deep#Door Stealer Harvests Browser Passwords, Cloud Tokens, SSH Keys, Wi-Fi Credentials

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Ubiquiti UniFi Critical Flaws Let Attackers Bypass Auth, Inject Commands
August 26, 2026
OpenAI Bans Russia-Linked ChatGPT Accounts for Covert Influence Operations
August 26, 2026
Attackers Abuse RMM Tools in 46-Country Phishing Campaign for Remote Access
August 26, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us