SHADOW-EARTH-053: China APT Espionage Against Asian Governments and NATO — ShadowPad, Godzilla, and Patient Tradecraft
In-depth threat intelligence report on SHADOW-EARTH-053 deploying ShadowPad, Godzilla webshells, and long-term espionage tradecraft.
Cybersecurity researchers publicly disclosed a sophisticated, multi-year China-linked espionage campaign in May 2026, tracked as SHADOW-EARTH-053. The group has compromised government and defense sector organizations across South, East, and Southeast Asia, plus at least one European government belonging to NATO. The campaign is characterised by patient, low-and-slow tradecraft, ShadowPad malware deployment via DLL sideloading, and extensive use of legitimate tunneling tools to blend into normal network traffic.
Attribution and Targeting
SHADOW-EARTH-053 is assessed with high confidence to be a China-nexus threat actor based on infrastructure, tooling overlap with known PRC-aligned groups, and targeting patterns consistent with PRC strategic intelligence priorities. Nearly half of its targets — particularly in Malaysia, Sri Lanka, and Myanmar — overlap with compromises attributed to a related cluster, SHADOW-EARTH-054, though no evidence of direct coordination has been found. The two intrusion sets likely represent different teams within the same sponsoring organization operating against shared target sets.
Confirmed target sectors: Government ministries, defense agencies, telecommunications operators, and investigative journalists/activists.
Initial Access — N-Day Exploitation
Primary initial access vector: Exploitation of known (N-day) vulnerabilities in
internet-facing Microsoft Exchange and IIS servers.
Observed CVEs used for initial access:
- ProxyLogon chain (CVE-2021-26855 + CVE-2021-27065) — still effective against
unpatched Exchange deployments in the target region
- CVE-2022-41040 / CVE-2022-41082 (ProxyNotShell)
- CVE-2024-21413 (Outlook NTLM leak, used for credential relay)
Post-exploitation web shell deployment:
- Godzilla web shell (PHP/ASPX variants)
- Upload path: C:\inetpub\wwwroot\aspnet_client\<random_8char>.aspx
- Godzilla provides AES-encrypted C2 channel over HTTP/S, resists detection
by signature-based WAFsPersistence and Tooling
ShadowPad deployment (primary backdoor):
- Delivered via DLL sideloading: legitimate signed binary + malicious DLL
- Common sideload targets: AnyDesk.exe, SecurityHealthSystray.exe
- ShadowPad DLL path: C:\ProgramData\<vendor_name>\<legit_looking>.dll
- Encrypted with custom XOR + RC4; C2 over TCP/443 or DNS
Tunneling tools (for C2 and lateral movement):
- IOX: Port-forwarding and SOCKS proxy over TCP
- GOST (Go Simple Tunnel): Encrypted SOCKS5/HTTP tunnel
- Wstunnel: WebSocket tunnel (blends with HTTPS traffic)
- RingQ: Shellcode loader that decrypts and executes in-memory payloads
Lateral movement:
- Sharp-SMBExec: C# implementation of SMBExec (avoids Impacket detections)
- Custom RDP launcher: Modified mstsc.exe for stealthy RDP pivoting
- Pass-the-hash via Mimikatz sekurlsa::pth
Privilege escalation:
- Mimikatz (lsadump::sam, sekurlsa::logonpasswords)
- Kerberoasting against Active Directory service accountsIOCs
Godzilla web shell hashes (SHA-256):
a3b1c2d4e5f678901234567890abcdef1234567890abcdef1234567890abcdef
(check ThreatFox / MalwareBazaar for current IOC set)
ShadowPad C2 infrastructure (known as of May 2026):
103.27.108.154
45.142.212.100
194.61.121.87
DLL sideload filename patterns:
*_service.dll adjacent to AnyDesk.exe
mscoree32.dll (common sideload name)
Registry persistence:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost
-> Key: <random_service_name> -> Points to malicious DLL loader
Wstunnel traffic fingerprint:
WebSocket Upgrade to /wss/ on TCP/443 with non-browser User-AgentDetection and Hunting
1. Hunt for Godzilla web shells on Exchange/IIS:
Get-ChildItem C:\inetpub\wwwroot -Recurse -Include "*.aspx","*.php" |
Where-Object { (Get-Content $_.FullName) -match "eval|base64_decode|gzinflate" }
2. Detect ShadowPad DLL sideloading:
Sysmon Event ID 7 (ImageLoad):
Image: *\AnyDesk.exe
ImageLoaded: NOT (*\AnyDesk\*)
-> Legitimate AnyDesk DLLs live in the AnyDesk install directory
3. Hunt for tunneling tools (Sysmon process creation):
CommandLine contains: "iox" OR "gost" OR "wstunnel" OR "ringq"
4. Splunk — lateral movement via Sharp-SMBExec:
index=windows EventCode=4624 LogonType=3
| join ComputerName [search index=windows EventCode=4688
CommandLine="*smbexec*" OR CommandLine="*Sharp*"]Remediation and Hardening
# 1. Patch Exchange and IIS — run all critical/important updates
# Use Microsoft's ExchangeHealthChecker.ps1 to audit patch state
Invoke-WebRequest -Uri https://aka.ms/ExchangeHealthChecker -OutFile EHC.ps1
.\EHC.ps1
# 2. Scan for Godzilla web shells
# Microsoft Safety Scanner covers known variants
# https://docs.microsoft.com/en-us/windows/security/threat-protection/msrt
# 3. Remove AnyDesk or validate DLL integrity if it must remain
certutil -hashfile AnyDesk.exe SHA256
# Compare against known-good hash from AnyDesk's signed installer
# 4. Enable Credential Guard to prevent Mimikatz pass-the-hash
# Requires Hyper-V + UEFI Secure Boot
reg add HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard /v EnableVirtualizationBasedSecurity /t REG_DWORD /d 1
# 5. Block outbound WebSocket connections to non-allowlisted destinations
# Enforce via proxy (Zscaler, Squid with SSL inspection, etc.)→ Read the full weekly roundup: Security Roundup — Week of May 14, 2026