logo

China-Aligned SHADOW-EARTH-053 Exploits Exchange Servers to Deploy ShadowPad Malware

ID: cd241d60-34ac-5728-a588-801aa14015ba

STIX ID: report--cd241d60-34ac-5728-a588-801aa14015ba

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

A China-aligned intrusion set tracked as SHADOW-EARTH-053 has been exploiting known but unpatched Microsoft Exchange (ProxyLogon CVEs CVE-2021-26855/26857/26858/27065) and IIS vulnerabilities since at least December 2024 to deploy ShadowPad via a three-file DLL sideloading chain, enumerate and export high-value mailboxes using EWS, and conduct cyberespionage against government, defense-related, and transportation targets across at least eight countries (including Poland); the report describes TTPs, shared tooling with SHADOW-EARTH-054, sample IoCs, and recommended mitigations such as patching, WAF/IPS, file integrity monitoring, privilege hardening, and process restrictions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.