SHADOW-EARTH-053 Deploys ShadowPad Through Exchange Server Exploits
ID: 26494bbe-3327-5535-b0ff-693e051556d5
STIX ID: report--26494bbe-3327-5535-b0ff-693e051556d5
Feed Name: Cyber Press
SHADOW-EARTH-053, a China-aligned threat group, is actively exploiting known Microsoft Exchange and IIS vulnerabilities (including ProxyLogon) across South, East, and Southeast Asia and at least one NATO member to deploy web shells (e.g., GODZILLA) and install ShadowPad via DLL sideloading; attackers perform AD discovery, credential dumping (Mimikatz), lateral movement, and use tunneling tools and scheduled tasks for persistence. Recommended mitigations include patching Exchange/IIS, monitoring web-accessible directories and w3wp.exe child processes, restricting IIS permissions, and checking for suspicious Registry-stored payloads and renamed legitimate binaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
