China-Aligned Hackers Use ShadowPad, IOX Proxy, WMIC in Espionage Campaign
Key Takeaways A sophisticated, multi-stage cyberespionage campaign, dubbed SHADOW-EARTH-053, is targeting government entities and critical infrastructure across at least eight Asian nations, along...
Key Takeaways
- A sophisticated, multi-stage cyberespionage campaign, dubbed SHADOW-EARTH-053, is targeting government entities and critical infrastructure across at least eight Asian nations, along with Poland.
- The threat group leverages well-known vulnerabilities in Microsoft Exchange and IIS servers, specifically the ProxyLogon chain (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065), as initial access vectors.
- Attackers deploy advanced malware like ShadowPad and IOX Proxy, combined with living-off-the-land techniques using WMIC and web shells, to maintain persistence and exfiltrate data.
- Patches for the exploited vulnerabilities have been available since 2021; immediate application is critical for defense.
A China-aligned advanced persistent threat (APT) group is executing a complex, multi-stage espionage campaign, primarily targeting government agencies and critical infrastructure in Asia. This operation, meticulously designed for intelligence gathering, exploits known vulnerabilities and utilizes a blend of custom malware and legitimate system tools, according to a recent analysis.
Table Of Content
The group, identified by researchers under the provisional designation SHADOW-EARTH-053, has been active since at least December 2024. Its operations have quietly compromised organizations across at least eight countries, indicating a broad strategic focus.
The campaign’s success hinges on its ability to combine bespoke malware with “living-off-the-land” techniques, allowing the attackers to remain undetected within victim networks for extended periods. Further details on the campaign’s mechanics are outlined in a comprehensive report.
Initial Infiltration and Persistence
Initial access is primarily achieved by exploiting unpatched vulnerabilities within Microsoft Exchange and Internet Information Services (IIS) servers. The threat actors specifically target the ProxyLogon vulnerability chain, which includes CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065. Despite patches for these critical flaws being available for years, many organizations continue to operate vulnerable Exchange servers, making them prime targets.
Once inside a network, the attackers deploy web shells, such as GODZILLA, to establish persistent backdoor access. These web shells enable remote command execution, providing the threat actors with continuous control over compromised systems.
Research Uncovers Broader Campaign
Researchers Daniel Lunghi and Lucas Silva at Trend Micro were instrumental in uncovering this extensive campaign. Their investigation began with an analysis of ShadowPad implants targeting South and Southeast Asia, which subsequently revealed a related cluster, SHADOW-EARTH-054. Both clusters exhibited identical tool hashes and overlapping attack methodologies, suggesting a coordinated effort.
Notably, nearly half of the compromised environments saw both SHADOW-EARTH-053 and SHADOW-EARTH-054 active within the same organizations. Victims have been confirmed in Pakistan, Thailand, Malaysia, India, Myanmar, Sri Lanka, Taiwan, and Poland. The research team assesses that these operations are consistent with China’s strategic interests, primarily focused on cyberespionage and intellectual property theft.
Malware and Tooling Arsenal
The primary malware employed in this campaign is ShadowPad, a modular backdoor first identified in 2017 in attacks attributed to APT41. Since 2019, ShadowPad has been shared among various China-aligned groups, indicating its widespread adoption within these circles.
Beyond ShadowPad, the attackers utilize IOX Proxy to establish covert communication channels, and Windows Management Instrumentation Command-line (WMIC) for lateral movement within compromised networks. They also incorporate open-source tunneling tools like GOST and Wstunnel to funnel traffic over SOCKS5 and HTTPS connections to external command-and-control infrastructure.
How the Attack Unfolds: ShadowPad’s Infection Mechanism
A particularly sophisticated aspect of this campaign is the method used to load ShadowPad onto victim machines. The attackers employ a DLL sideloading technique, where a malicious DLL is placed alongside a legitimate, digitally signed executable. When the legitimate program is executed, it inadvertently loads the malicious DLL.
The group has been observed abusing executables from reputable vendors, including Toshiba, Samsung, and Microsoft, often renaming them to mimic legitimate system processes and evade detection. This technique further enhances the stealth of the operation.
What makes this loader especially insidious is that the ShadowPad payload itself is not embedded within the malicious DLL. Instead, the loader retrieves an encrypted payload from a machine-specific registry key located at HKEY_CURRENT_USERSoftware.
Persistence is maintained through a scheduled task named “M1onltor,” configured to execute the sideloaded binary every five minutes with the highest available privileges. WMIC is then leveraged to deploy backdoors onto additional hosts, and credential-harvesting tools such as Mimikatz and Evil-CreateDump are executed via IIS worker processes to extract sensitive account data and passwords.
What You Should Do
- Patch Immediately: Apply the latest security patches for all internet-facing Microsoft Exchange and IIS servers, especially those addressing the ProxyLogon vulnerability chain (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065).
- Implement Virtual Patching: If immediate patching is not feasible, deploy Intrusion Prevention Systems (IPS) or Web Application Firewalls (WAF) with virtual patching rules to mitigate known vulnerabilities.
- Monitor Web Directories: Implement File Integrity Monitoring (FIM) on critical web directories and configure alerts for any new or modified .aspx, .ashx, or .jsp files.
- Review EDR Telemetry: Regularly review Endpoint Detection and Response (EDR) telemetry for suspicious activity, particularly IIS worker processes spawning command shells or reconnaissance tools.
- Monitor Staging Areas: Pay close attention to directories like C:UsersPublic and C:ProgramData, as these have been consistently used by the group as staging areas for their operations.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.