China-Backed Hackers Deploy ShadowPad Malware In Sophisticated Multi-Stage Spy Ops
ID: b173e515-85e8-54b1-92b7-88fa37280817
STIX ID: report--b173e515-85e8-54b1-92b7-88fa37280817
Feed Name: Cyber Press
**Executive summary:** Trend Micro identifies SHADOW-EARTH-053, a China-aligned intrusion set active since December 2024, exploiting unpatched Microsoft Exchange and IIS servers (including the ProxyLogon chain) to deploy web shells such as GODZILLA and sideload ShadowPad via legitimate signed executables; the campaign targets government and critical infrastructure across Asia (and one NATO member), focuses on mailbox compromise, credential theft, and intellectual property espionage, and uses a layered toolkit (IOX proxy, GOST, wstunnel, WMIC, custom loaders) for stealthy persistence and lateral movement, while advising urgent patching, virtual patching, and close monitoring of internet-facing web servers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
