Trend Micro links SHADOW‑EARTH‑053 to Asian, Polish targets

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Trend Micro identified a China‑aligned espionage campaign designated SHADOW‑EARTH‑053, active since at least December 2024.
- Microsoft Exchange and IIS servers were compromised via N‑day ProxyLogon vulnerabilities, after which the group deployed Godzilla web shells for persistent access.
- ShadowPad implants were staged via DLL sideloading of legitimate signed executables after the group gained foothold.
- Poland is the only NATO European victim, while governments and defense entities in Pakistan, Thailand, Malaysia, India, Myanmar, Sri Lanka, and Taiwan were also targeted.
- SHADOW‑EARTH‑053 victims—particularly in Malaysia, Sri Lanka, and Myanmar—were also previously compromised by the related SHADOW‑EARTH‑054 intrusion set, though no direct operational coordination was observed.
Why it matters: Governments in Pakistan, Thailand, Malaysia, India, Myanmar, Sri Lanka, Taiwan and Poland now face compromised defense networks after the SHADOW‑EARTH‑053 group exploited N‑day Microsoft Exchange and IIS flaws, while half of those victims had earlier been hit by the related SHADOW‑EARTH‑054 intrusion, underscoring a persistent, multi‑regional espionage threat that can erode national security and diplomatic trust.
Ask SkimNews



