Threadlinqs IntelligenceStart free

Threat actorChinaTracked since 2026-05

SHADOW-EARTH-053

Also known as:Earth Shadow 053TrendAI SHADOW-EARTH-053 cluster

As of 2026-09-03, SHADOW-EARTH-053 is a China-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning threat intel, apt. Also known as Earth Shadow 053, TrendAI SHADOW-EARTH-053 cluster. ATT&CK coverage spans 35 techniques across 13 tactics in 2 of 2 tracked threats. Most-observed techniques: T1059.001 (PowerShell), T1059.003 (Windows Command Shell), T1071.001 (Web Protocols).

Tracked threats
22 high
First seen
2026-05-11
Last seen
2026-09-03
ATT&CK techniques
35across 2 of 2 threats
Related CVEs
9Referenced by its activity
Attribution
ChinaNation or origin
Nation: China · 2 tracked threat(s) · Categories: THREAT_INTEL, APT

Activity timeline

SHADOW-EARTH-053 appears in 2 tracked threats between and ; the busiest month was 2026-05 with 1 report.

ATT&CK techniques observed

35 techniques observed across 2 of 2 tracked threats · Stealth (formerly Defense Evasion) (6), Discovery (4), Execution (4), Collection (3), Command and Control (3), Credential Access (3)
  • T1059.001 PowerShell — Executionobserved in 2 of 2 tracked threats
  • T1059.003 Windows Command Shell — Executionobserved in 2 of 2 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 2 of 2 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 2 of 2 tracked threats
  • T1505.003 Web Shell — Persistenceobserved in 2 of 2 tracked threats
  • T1003.001 LSASS Memory — Credential Accessobserved in 1 of 2 tracked threats
  • T1003.002 Security Account Manager — Credential Accessobserved in 1 of 2 tracked threats
  • T1003.006 OS Credential Dumping: DCSync — Credential Accessobserved in 1 of 2 tracked threats
  • T1005 Data from Local System — Collectionobserved in 1 of 2 tracked threats
  • T1018 Remote System Discovery — Discoveryobserved in 1 of 2 tracked threats
  • T1021.001 Remote Desktop Protocol — Lateral Movementobserved in 1 of 2 tracked threats
  • T1021.002 SMB/Windows Admin Shares — Lateral Movementobserved in 1 of 2 tracked threats
  • T1027.002 Software Packing — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
  • T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 1 of 2 tracked threats

Tracked threats

Related CVEs

9 CVEs referenced by tracked SHADOW-EARTH-053 activity