Home APT China-Backed Hackers Deploy ShadowPad Malware In Sophisticated Multi-Stage Spy Ops

China-Backed Hackers Deploy ShadowPad Malware In Sophisticated Multi-Stage Spy Ops

0
ShadowPad Spy Campaign
ShadowPad Spy Campaign

A newly tracked China-aligned intrusion set is hitting government and critical infrastructure networks across Asia, with one NATO member also in scope.

Researchers say the group, tracked as SHADOW-EARTH-053, has been active since at least December 2024 and has focused on cyberespionage and possible intellectual property theft.

The attackers are exploiting older but still exposed Microsoft Exchange and IIS servers, including the ProxyLogon chain, to get inside target networks.

After gaining access, they drop web shells such as GODZILLA to maintain persistence and then stage ShadowPad through DLL sideloading of legitimate signed executables. This makes the intrusion blend in with normal system activity while giving the operators long-term access.

The campaign is dangerous because it relies on N-day vulnerabilities that many organizations have already patched in theory, but not always in practice.

Trend Micro says unpatched or legacy Exchange servers remain a serious risk for mailbox compromise, credential theft, and prolonged attacker presence.

Timeline of SHADOW-EARTH-053 and SHADOW-EARTH-054 activities (Source: trendmicro)
Timeline of SHADOW-EARTH-053 and SHADOW-EARTH-054 activities (Source: trendmicro)

Stealth and Lateral Movement

Once inside, the group uses a layered toolkit that includes IOX proxy, GOST, Wstunnel, WMIC, and custom loaders. Trend Micro also observed credential theft tools, Active Directory reconnaissance, and mailbox collection activity aimed at high-value users.

In some cases, the attackers copied web shells to other internal Exchange servers over administrative shares to spread quietly across the environment.

SHADOW-EARTH-053 and SHADOW-EARTH-054 targets (Source: trendmicro)
SHADOW-EARTH-053 and SHADOW-EARTH-054 targets (Source: trendmicro)

ShadowPad remains the main backdoor in the campaign and is widely associated with China-aligned espionage activity. It has been used by multiple state-linked groups over the years, which makes it a familiar but still effective choice for covert operations.

Attribution overlap diagram showing connections between SHADOW-EARTH-054, CL-STA-0049, Earth Alux, and REF7707 (Source: trendmicro)
Attribution overlap diagram showing connections between SHADOW-EARTH-054, CL-STA-0049, Earth Alux, and REF7707 (Source: trendmicro)

Defense Guidance

Organizations should treat exposed Exchange and IIS servers as urgent patching priorities. If immediate patching is not possible, Trend Micro recommends virtual patching with IPS or WAF rules, plus file integrity monitoring on critical web directories.

Security teams should also watch for IIS spawning command shells, reconnaissance tools, or unusual outbound traffic from web servers.

Administrators should restrict IIS privileges, remove unused modules, and block unauthorized child processes.

The campaign shows how China-aligned attackers continue to turn old Exchange and IIS weaknesses into long-running espionage access.

The use of ShadowPad, web shells, IOX proxy, and WMIC highlights a careful, layered approach built for stealth, persistence, and lateral movement.

Organizations should prioritize patching, monitor web servers closely, and treat exposed internet-facing systems as high-risk entry points.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here