PULSE NAME
Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia
WHITE SHADOW-EARTH-053 AlienVault 2026-04-30 Modified: 2026-05-29
94
IOCs
HIGH VOLUME
A China-aligned threat group designated SHADOW-EARTH-053 has been conducting cyberespionage operations against government entities and critical infrastructure across at least eight countries in South, East, and Southeast Asia, plus one NATO member state, since December 2024. The group exploits unpatched Microsoft Exchange vulnerabilities, particularly the ProxyLogon chain, to gain initial access and deploys GODZILLA web shells for persistence. ShadowPad implants are staged via DLL sideloading of legitimate signed executables. Nearly half of the compromised environments showed overlap with another intrusion set, SHADOW-EARTH-054, sharing identical tooling including Evil-CreateDump and IOX proxy. The attackers conduct extensive Active Directory reconnaissance, credential harvesting, and mailbox exfiltration targeting high-profile government officials and defense contractors. Multiple tunneling tools including GOST and Wstunnel establish covert command-and-control channels, while lateral movement leverages WM...
Indicators of Compromise (6 / 94 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 domain hostname CVE
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 0933fbd16c7a8b70199f5612e147a22c 2026-04-30
FileHash-MD5 2616e7ec2d6c4b86a7fa1f4a762ae918 2026-04-30
FileHash-MD5 531da3715b1e4fc9baeaa034888ac419 2026-04-30
FileHash-MD5 a85459a1ec90a52b5c1f2f5a12bb2d10 2026-04-30
FileHash-MD5 7c698dd4090564b179309c2a64266424 2026-04-30
FileHash-MD5 e5e0e0c0fadacee1105bd340fa1b2e6d 2026-04-30