What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia
ID: c9d4fa69-c5f5-5de2-8438-62ca27f6defa
STIX ID: report--c9d4fa69-c5f5-5de2-8438-62ca27f6defa
Feed Name: The Register (Security)
TrendAI reports a China-linked threat group (Shadow-Earth-053, with overlap from Shadow-Earth-054) that since December 2024 has exploited Microsoft Exchange and other vulnerabilities to infiltrate government, defense, technology and transportation networks across at least eight countries; attackers deployed web shells, ShadowPad and other backdoors, used legitimate tools for evasion and lateral movement, and appear to be prepositioning for long-term espionage and potential destructive operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
