Shadow-Earth-053 is a suspected China-aligned group conducting cyberespionage against government entities via ShadowPad.
Analyst brief
Shadow-Earth-053 is a suspected China-aligned threat group engaged in cyberespionage, primarily targeting government and defense-related entities across Asia and Europe. The group exploits CVE-2021-26855 in unpatched Microsoft Exchange Servers for initial access and deploys the ShadowPad malware. Their TTPs include lateral movement via WMIC, credential dumping, use of tunneling tools, web shell deployment for persistence, and a custom ExchangeExport tool for mailbox extraction. Defenders should prioritize patching Exchange Server vulnerabilities, monitoring for anomalous WMIC usage and web shells, and deploying detection for ShadowPad and credential dumping activities.
Shadow-Earth-053
unknown
SHADOW-EARTH-053 is a China-aligned threat group exploiting unpatched Microsoft Exchange Server vulnerabilities, specifically CVE-2021-26855, to conduct cyberespionage against government and defense-linked targets across Asia and Europe. The group primarily deploys ShadowPad malware, utilizing techniques such as credential dumping, tunneling tools, and lateral movement via WMIC. They have also been observed installing web shells for persistence and leveraging a custom ExchangeExport tool to extract high-value mailbox contents. Additionally, low-confidence associations with Noodle RAT and CVE-2025-55182 have been noted in their operations.