logo

China-Linked Hackers Target Asian Governments, NATO State, Journalists, and Activists

ID: f9a1ffff-2068-519f-bec7-f6d5496b094b

STIX ID: report--f9a1ffff-2068-519f-bec7-f6d5496b094b

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: [email protected] (The Hacker News)

...
...

Trend Micro and Citizen Lab reporting describes coordinated China-aligned espionage activity: SHADOW-EARTH-053 has exploited unpatched Microsoft Exchange/IIS vulnerabilities to deploy Godzilla web shells and ShadowPad (via DLL sideloading) across government and defense targets in South, East and Southeast Asia (and Poland), while GLITTER CARP and SEQUIN CARP run credential-harvesting and AiTM phishing campaigns against journalists and diaspora activists; tactics include AnyDesk distribution, Mimikatz, custom RDP/SMB tools, tunneling utilities, and reuse of phishing infrastructure, with recommendations to patch systems and deploy IPS/WAF virtual patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.