logo

What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia

ID: 61b494a8-2851-577f-ba42-3a9a58a47a6e

STIX ID: report--61b494a8-2851-577f-ba42-3a9a58a47a6e

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Jessica Lyons

...
...

TrendAI reports a China-linked threat group tracked as Shadow-Earth-053 (and an associated Shadow-Earth-054) that has infiltrated more than a dozen critical networks across Pakistan, Thailand, Malaysia, India, Myanmar, Sri Lanka, Taiwan and at least one target in Poland beginning December 2024; intrusions leveraged Microsoft Exchange vulnerabilities (ProxyLogon and chains), web shells (e.g., Godzilla), ShadowPad and other backdoors, lateral movement via WMIC and credential harvesting, and show indicators of long-term prepositioning with potential for destructive capabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.