Shadow-Earth-053

Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:27:06

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:cn country_code:in country_code:jp country_code:kr country_code:de country_code:fr country_code:it

Context

SHADOW-EARTH-053 is a China-aligned threat group exploiting unpatched Microsoft Exchange Server vulnerabilities, specifically CVE-2021-26855, to conduct cyberespionage against government and defense-linked targets across Asia and Europe. The group primarily deploys ShadowPad malware, utilizing techniques such as credential dumping, tunneling tools, and lateral movement via WMIC. They have also been observed installing web shells for persistence and leveraging a custom ExchangeExport tool to extract high-value mailbox contents. Additionally, low-confidence associations with Noodle RAT and CVE-2025-55182 have been noted in their operations.

Exploited vulnerabilities

  • CVE-2021-26855 (vulnerability)
  • CVE-2025-55182 (vulnerability)

Reports & references

  • Trend Micro — Inside Shadow Earth 053 (report)

External references