PULSE NAME
China Aligned Cyberespionage Campaign Targets Governments
WHITE CODERED_VTA 2026-05-06 Modified: 2026-05-06
23
IOCs
MEDIUM VOLUME
Cybersecurity researchers have identified a China-aligned espionage campaign targeting government and defense organizations across South, East, and Southeast Asia, as well as a European NATO member. The activity cluster, tracked as SHADOW-EARTH-053, has been active since at least late 2024 and shows overlaps with previously known threat groups. Researchers said the attackers primarily exploit known vulnerabilities in internet-facing Microsoft Exchange and IIS servers, including flaws similar to...
Indicators of Compromise (23)
All CVE FileHash-MD5 FileHash-SHA1 IPv4 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2021-26855 2026-05-06
CVE CVE-2021-26857 2026-05-06
CVE CVE-2021-26858 2026-05-06
CVE CVE-2021-27065 2026-05-06
CVE CVE-2025-55182 2026-05-06
FileHash-MD5 7c698dd4090564b179309c2a64266424 2026-05-06
FileHash-MD5 8918a891b4f8517af671bea58f0bae25 2026-05-06
FileHash-MD5 8ff586d02536d460bb020d4b400dba61 2026-05-06
FileHash-MD5 e5e0e0c0fadacee1105bd340fa1b2e6d 2026-05-06
FileHash-SHA1 82eb4b752c60b99b451f7a53b8ac856afe9deb88 2026-05-06
FileHash-SHA1 c2870caa5f016822fdaf16e3c470f96eefd4b93f 2026-05-06
FileHash-SHA1 e7d4d5cac3e0f2adc24d9074997233ce21dc9805 2026-05-06
FileHash-SHA1 ffff45b776de1bc904a31db27882002d0aafc574 2026-05-06
IPv4 141.164.46.77 2026-05-06
FileHash-SHA256 4264cfb3980a068ab36d842c7ee0942f40aaf308f31ed48b41e140e59885f5c8 2026-05-06
FileHash-SHA256 2e8f9fd8213d9f69044101cd029fd1797ec7afbcad40bb1f04eb93d881c04cd2 2026-05-06
FileHash-SHA256 8d9433e9734dd629d74abe41ff7024c84b3a28c45671df8f4baed344de733c78 2026-05-06
FileHash-SHA256 d67197bf407e74ecd77be89d0da107d5f7d37c21bdf55456c6b57df65cf429b3 2026-05-06
IPv4 194.38.11.3 2026-05-06
IPv4 209.141.40.254 2026-05-06
IPv4 96.9.125.227 2026-05-06
domain zimbra-beta.info 2026-05-06
hostname check.office365-update.com 2026-05-06