logo

China-Backed Hackers Deploy ShadowPad Malware In Sophisticated Multi-Stage Spy Ops

ID: b173e515-85e8-54b1-92b7-88fa37280817

STIX ID: report--b173e515-85e8-54b1-92b7-88fa37280817

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: Varshini

...
...

**Executive summary:** Trend Micro identifies SHADOW-EARTH-053, a China-aligned intrusion set active since December 2024, exploiting unpatched Microsoft Exchange and IIS servers (including the ProxyLogon chain) to deploy web shells such as GODZILLA and sideload ShadowPad via legitimate signed executables; the campaign targets government and critical infrastructure across Asia (and one NATO member), focuses on mailbox compromise, credential theft, and intellectual property espionage, and uses a layered toolkit (IOX proxy, GOST, wstunnel, WMIC, custom loaders) for stealthy persistence and lateral movement, while advising urgent patching, virtual patching, and close monitoring of internet-facing web servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.