logo

China-Aligned Attackers Use ShadowPad, IOX Proxy, and WMIC in Multi-Stage Espionage Campaign

ID: 9248f4cc-2ce9-5cbb-bc11-d5a12cebcc67

STIX ID: report--9248f4cc-2ce9-5cbb-bc11-d5a12cebcc67

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: Tushar Subhra Dutta

...
...

A China-aligned APT campaign (SHADOW-EARTH-053/054) has been conducting targeted cyberespionage across at least eight countries since December 2024 by exploiting unpatched Microsoft Exchange and IIS (ProxyLogon CVE-2021-26855/26857/26858/27065) to deploy ShadowPad via DLL sideloading, web shells (e.g., GODZILLA), credential-harvesting tools, and tunneling utilities, maintaining long-term persistence and lateral movement in government and critical infrastructure networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.