SHADOW-EARTH-053 — China-Aligned Cyberespionage Campaign Exploiting Microsoft Exchange (ProxyLogon CVE-2021-26855/26857/26858/27065) and IIS to Deploy GODZILLA Web Shells and ShadowPad — Threadlinqs Intelligence
As of 2026-05-30, SHADOW-EARTH-053 — China-Aligned Cyberespionage Campaign Exploiting Microsoft Exchange (ProxyLogon CVE-2021-26855/26857/26858/27065) and IIS to Deploy GODZILLA Web Shells and ShadowPad is a high-severity apt threat attributed to SHADOW-EARTH-053 (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 33 indicators of compromise.
Threat ID: TL-2026-0493 · Severity: HIGH · CVSS: 9.8 · Status: ACTIVE · Category: APT
Attribution: SHADOW-EARTH-053 · China · ESPIONAGE
SHADOW-EARTH-053 is a China-aligned cyberespionage intrusion set tracked by Trend Micro (TrendAI Research) that has, since at least December 2024, exploited N-day vulnerabilities in internet-facing
SHADOW-EARTH-053 (designation assigned by Trend Micro's TrendAI Research, disclosed 2026-04-30) is a China-aligned cyberespionage intrusion set whose campaign has been active since at least December 2024 against government ministries, defense agencies, defense-contractor IT consultancies, and transportation entities in South and Southeast Asia, with confirmed targeting extending to NATO member Poland. The campaign is notable for its aggressive exploitation of long-known but still-unpatched N-day flaws in internet-facing Microsoft Exchange Server (the ProxyLogon chain: CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065) and IIS, demonstrating that mature CVEs continue to deliver real-world initial access against under-resourced government and defense-adjacent environments more than five years after disclosure.
Initial access is overwhelmingly achieved by chaining the ProxyLogon Server-Side Request Forgery (CVE-2021-26855), Insecure Deserialization in Exchange Unified Messaging (CVE-2021-26857), and post-authentication arbitrary file-write primitives (CVE-2021-26858, CVE-2021-27065) to drop GODZILLA ASP.NET web shells under Exchange front-end paths (C:\Program Files\Microsoft\Exchange Server\V15\FrontEnd\HttpProxy\owa\auth) and IIS publishing roots (C:\inetpub\wwwroot\aspnet_client\system_web). Operators repeatedly stage shells under inconspicuous filenames designed to blend with Exchange and OWA assets — error.aspx, errorFE.aspx, signout.aspx, warn.aspx, data.aspx, page.aspx, TimeinLogout.aspx, timeout.aspx, charcode.aspx, tunnel.ashx, i.aspx, 2.aspx — and use the shells both for immediate command execution and as long-lived footholds. A subset of intrusions delivered ShadowPad via abused AnyDesk remote access, and a low-confidence cluster of Linux NOODLERAT samples was reportedly dropped via the React2Shell vulnerability (CVE-2025-55182).
Post-exploitation, SHADOW-EARTH-053 stages a multi-stage Windows implant chain built on DLL sideloading of legitimately signed executables. Trend documented at least four sideload pairs: GameHook.exe (signer ORANGE VIEW LIMITED) loading graphics-hook-filter32.dll; imecmnt.exe (Microsoft Corporation signer) loading imjp14k.dll; xReport.exe (Mainline Net Holdings Limited signer) loading Uxtheme.dll; and Samsung Electronics' LUManager.EXE loading MPS.dll. Sideloaded payloads decrypt and execute a 32-bit older-builder ShadowPad variant — distinguished from current campaigns by the absence of advanced obfuscation and anti-debugging primitives — whose encrypted body is persisted in the registry under HKEY_CURRENT_USER\Software\[ComputerName] in a binary value named 'scode'. Execution is achieved through callback injection via EnumDesktopsA, and persistence is established with a scheduled task named 'M1onltor' configured to run the sideloaded binary every five minutes at highest privileges. Secondary implants observed in the campaign include a TosBtKbd.dll registry-loaded payload sideloaded via the Toshiba Bluetooth Stack binary (renamed from CIATosBtKbd.exe), and a custom beaconing backdoor mdync.exe.
For egress and pivoting, SHADOW-EARTH-053 deploys multiple open-source tunneling and proxy utilities, frequently renamed to masquerade as legitimate Windows components: IOX proxy (renamed explorer.exe), GOST (Go Simple Tunnel — SOCKS5 plus WebSocket transport), Wstunnel (wt.exe — SOCKS5 over HTTPS), and tunnel-core.exe renamed to code.exe. Lateral movement uses WMIC, Sharp-SMBExec (a C# implementation of SMBExec), a custom RDP launcher delivered as smss.exe, and web-shell propagation across administrative shares. Credential access combines Evil-CreateDump (a modified create-dump.exe used against the LSASS process), Mimikatz invoked via rundll32 (sekurlsa::logonpasswords and lsadump::sam), and a 'newdcsync' tool consistent with DCSync against domain controllers. Discovery activity includes PowerView's Get-DomainUser, AD export via csvde.exe, domain-controller enumeration with nltest /dcl
Weaknesses (CWE)
CWE-918, CWE-502, CWE-22, CWE-78, CWE-94
Target sectors: government, defense, it-consulting, transportation
Target regions: South Asia, Southeast Asia, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 33 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065, CVE-2025-55182, T1190, T1133, T1059.001, T1059.003, T1047, T1053.005, T1505.003, T1053.005, T1574.002, T1053.005