SHADOW-EARTH-053 Deploys ShadowPad Through Exchange Server Exploits

A China-aligned threat cluster known as SHADOW-EARTH-053 is targeting government bodies, critical infrastructure, and technology firms by exploiting vulnerable Microsoft Exchange and IIS servers.

The campaign mainly focuses on South, East, and Southeast Asia, but researchers also observed activity against one NATO member state.

The attackers are exploiting older, already-patched Microsoft Exchange flaws, including the ProxyLogon vulnerability chain, to compromise internet-facing servers.

These weaknesses are not new, but they remain dangerous when organizations delay patching or continue running legacy systems. Once inside, the group deploys web shells, such as GODZILLA, to maintain access and remotely run commands on compromised systems.

After gaining a foothold, SHADOW-EARTH-053 installs ShadowPad, a modular malware platform often linked to China-aligned espionage groups.

ShadowPad gives attackers long-term control, supports covert communication, and allows them to load additional tools as needed.

In this campaign, malware is delivered via DLL sideloading, where legitimate, signed programs are abused to load malicious DLL files.

Timeline of SHADOW-EARTH-053 and SHADOW-EARTH-054 activities (Source: trendmicro)
Timeline of SHADOW-EARTH-053 and SHADOW-EARTH-054 activities (Source: trendmicro)

Attack Chain and Tools

The campaign demonstrates a careful, layered attack flow. First, the attackers exploit Exchange or IIS vulnerabilities.

Next, they place web shells in web-accessible directories. From there, they perform internal discovery, search Active Directory, enumerate domain controllers, and identify Exchange servers and high-value accounts.

SHADOW-EARTH-053 and SHADOW-EARTH-054 targets (Source: trendmicro)
SHADOW-EARTH-053 and SHADOW-EARTH-054 targets (Source: trendmicro)

Researchers also observed the use of tools such as IOX proxy, GOST, Wstunnel, Mimikatz, and credential-dumping utilities.

These tools help attackers move laterally, steal credentials, build hidden tunnels, and maintain access even if one method is detected.

In some cases, attackers copied web shells to other internal Exchange servers, enabling them to spread rapidly across the victim’s network.

Attribution overlap diagram showing connections between SHADOW-EARTH-054, CL-STA-0049, Earth Alux, and REF7707 (Source: trendmicro)
Attribution overlap diagram showing connections between SHADOW-EARTH-054, CL-STA-0049, Earth Alux, and REF7707 (Source: trendmicro)

The group also used evasion methods. Legitimate binaries were renamed, PowerShell and Windows tools were disguised, and malicious payloads were stored in the Windows Registry to reduce detection.

A scheduled task was also used to run a sideloaded malware component repeatedly.

This campaign highlights a major security lesson: old vulnerabilities still create serious risk.

Even though Exchange flaws such as ProxyLogon have been known for years, attackers continue to exploit organizations that have not fully patched or hardened exposed systems.

According to Trend Micro research, the likely goal appears to be cyberespionage and intellectual property theft. Targets included government entities, defense-linked contractors, transportation organizations, and technology firms.

Security teams should patch Exchange and IIS servers, monitor web directories for suspicious files, restrict IIS process permissions, and watch for unusual child processes such as cmd.exe or powershell.exe launched by w3wp.exe.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories