China-Aligned Hackers Deploy ShadowPad in Multi-Stage Espionage Campaign
ID: 98481be1-8950-57ef-a983-b87f96539867
STIX ID: report--98481be1-8950-57ef-a983-b87f96539867
Feed Name: GBHackers
SHADOW-EARTH-053 is a China-aligned intrusion set (active since at least December 2024) exploiting legacy, unpatched Microsoft Exchange and IIS vulnerabilities—including the ProxyLogon chain—to install ASP.NET web shells (commonly GODZILLA) and deploy ShadowPad via DLL sideloading and registry-resident payloads; post-compromise activity includes Active Directory and Exchange reconnaissance, credential dumping (Mimikatz, Evil-CreateDump), DCSync-style theft, WMIC-based lateral movement, and covert tunneling (IOX, GOST, wstunnel). Targets include government entities, critical infrastructure, defense-adjacent IT consultancies, and at least one NATO state across South, East, and Southeast Asia and Europe; defenders should prioritize patching exposed Exchange/IIS servers, web-shell and registry-resident loader detection, WMIC activity monitoring, and hunting for tunneling/proxy tooling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
