What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia
ID: 61b494a8-2851-577f-ba42-3a9a58a47a6e
STIX ID: report--61b494a8-2851-577f-ba42-3a9a58a47a6e
Feed Name: The Register (Security)
TrendAI reports a China-linked threat group tracked as Shadow-Earth-053 (and an associated Shadow-Earth-054) that has infiltrated more than a dozen critical networks across Pakistan, Thailand, Malaysia, India, Myanmar, Sri Lanka, Taiwan and at least one target in Poland beginning December 2024; intrusions leveraged Microsoft Exchange vulnerabilities (ProxyLogon and chains), web shells (e.g., Godzilla), ShadowPad and other backdoors, lateral movement via WMIC and credential harvesting, and show indicators of long-term prepositioning with potential for destructive capabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
