The N-Day Nightmare: How SHADOW-EARTH-053 Breaches Governments Using “Old” Exploits
ID: c21cc114-ea08-59e4-a045-b12c310e838d
STIX ID: report--c21cc114-ea08-59e4-a045-b12c310e838d
Feed Name: securityonline.info
TrendAI Research attributes a China-aligned APT cluster named SHADOW-EARTH-053 (active since at least Dec 2024) targeting government ministries and IT contractors across multiple Asian countries and a NATO member state. The group exploits long-patched Microsoft Exchange ProxyLogon CVEs to install GODZILLA web shells and stage ShadowPad via DLL sideloading, uses registry-based loaders and EnumDesktopsA callback execution for stealth, and employs tunneling tools (GOST, Wstunnel); the report warns organizations to audit internet-facing Exchange/IIS servers and review web-shell detection and outbound traffic for signs of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
