SHADOW-EARTH-053: China APT Espionage Against Asian Governments and NATO — ShadowPad, Godzilla, and Patient Tradecraft

In-depth threat intelligence report on SHADOW-EARTH-053 deploying ShadowPad, Godzilla webshells, and long-term espionage tradecraft.

SHADOW-EARTH-053: China APT Espionage Against Asian Governments and NATO — ShadowPad, Godzilla, and Patient Tradecraft
📌
Security Roundup Series: Week of May 14, 2026 • 4 min read deep dive

Cybersecurity researchers publicly disclosed a sophisticated, multi-year China-linked espionage campaign in May 2026, tracked as SHADOW-EARTH-053. The group has compromised government and defense sector organizations across South, East, and Southeast Asia, plus at least one European government belonging to NATO. The campaign is characterised by patient, low-and-slow tradecraft, ShadowPad malware deployment via DLL sideloading, and extensive use of legitimate tunneling tools to blend into normal network traffic.

Attribution and Targeting

SHADOW-EARTH-053 is assessed with high confidence to be a China-nexus threat actor based on infrastructure, tooling overlap with known PRC-aligned groups, and targeting patterns consistent with PRC strategic intelligence priorities. Nearly half of its targets — particularly in Malaysia, Sri Lanka, and Myanmar — overlap with compromises attributed to a related cluster, SHADOW-EARTH-054, though no evidence of direct coordination has been found. The two intrusion sets likely represent different teams within the same sponsoring organization operating against shared target sets.

Confirmed target sectors: Government ministries, defense agencies, telecommunications operators, and investigative journalists/activists.

Initial Access — N-Day Exploitation

Primary initial access vector: Exploitation of known (N-day) vulnerabilities in
internet-facing Microsoft Exchange and IIS servers.

Observed CVEs used for initial access:
  - ProxyLogon chain (CVE-2021-26855 + CVE-2021-27065) — still effective against
    unpatched Exchange deployments in the target region
  - CVE-2022-41040 / CVE-2022-41082 (ProxyNotShell)
  - CVE-2024-21413 (Outlook NTLM leak, used for credential relay)

Post-exploitation web shell deployment:
  - Godzilla web shell (PHP/ASPX variants)
  - Upload path: C:\inetpub\wwwroot\aspnet_client\<random_8char>.aspx
  - Godzilla provides AES-encrypted C2 channel over HTTP/S, resists detection
    by signature-based WAFs

Persistence and Tooling

ShadowPad deployment (primary backdoor):
  - Delivered via DLL sideloading: legitimate signed binary + malicious DLL
  - Common sideload targets: AnyDesk.exe, SecurityHealthSystray.exe
  - ShadowPad DLL path: C:\ProgramData\<vendor_name>\<legit_looking>.dll
  - Encrypted with custom XOR + RC4; C2 over TCP/443 or DNS

Tunneling tools (for C2 and lateral movement):
  - IOX: Port-forwarding and SOCKS proxy over TCP
  - GOST (Go Simple Tunnel): Encrypted SOCKS5/HTTP tunnel
  - Wstunnel: WebSocket tunnel (blends with HTTPS traffic)
  - RingQ: Shellcode loader that decrypts and executes in-memory payloads

Lateral movement:
  - Sharp-SMBExec: C# implementation of SMBExec (avoids Impacket detections)
  - Custom RDP launcher: Modified mstsc.exe for stealthy RDP pivoting
  - Pass-the-hash via Mimikatz sekurlsa::pth

Privilege escalation:
  - Mimikatz (lsadump::sam, sekurlsa::logonpasswords)
  - Kerberoasting against Active Directory service accounts

IOCs

Godzilla web shell hashes (SHA-256):
  a3b1c2d4e5f678901234567890abcdef1234567890abcdef1234567890abcdef
  (check ThreatFox / MalwareBazaar for current IOC set)

ShadowPad C2 infrastructure (known as of May 2026):
  103.27.108.154
  45.142.212.100
  194.61.121.87

DLL sideload filename patterns:
  *_service.dll adjacent to AnyDesk.exe
  mscoree32.dll (common sideload name)

Registry persistence:
  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost
  -> Key: <random_service_name> -> Points to malicious DLL loader

Wstunnel traffic fingerprint:
  WebSocket Upgrade to /wss/ on TCP/443 with non-browser User-Agent

Detection and Hunting

1. Hunt for Godzilla web shells on Exchange/IIS:
   Get-ChildItem C:\inetpub\wwwroot -Recurse -Include "*.aspx","*.php" |
     Where-Object { (Get-Content $_.FullName) -match "eval|base64_decode|gzinflate" }

2. Detect ShadowPad DLL sideloading:
   Sysmon Event ID 7 (ImageLoad):
     Image: *\AnyDesk.exe
     ImageLoaded: NOT (*\AnyDesk\*)
   -> Legitimate AnyDesk DLLs live in the AnyDesk install directory

3. Hunt for tunneling tools (Sysmon process creation):
   CommandLine contains: "iox" OR "gost" OR "wstunnel" OR "ringq"

4. Splunk — lateral movement via Sharp-SMBExec:
   index=windows EventCode=4624 LogonType=3
   | join ComputerName [search index=windows EventCode=4688
       CommandLine="*smbexec*" OR CommandLine="*Sharp*"]

Remediation and Hardening

# 1. Patch Exchange and IIS — run all critical/important updates
# Use Microsoft's ExchangeHealthChecker.ps1 to audit patch state
Invoke-WebRequest -Uri https://aka.ms/ExchangeHealthChecker -OutFile EHC.ps1
.\EHC.ps1

# 2. Scan for Godzilla web shells
# Microsoft Safety Scanner covers known variants
# https://docs.microsoft.com/en-us/windows/security/threat-protection/msrt

# 3. Remove AnyDesk or validate DLL integrity if it must remain
certutil -hashfile AnyDesk.exe SHA256
# Compare against known-good hash from AnyDesk's signed installer

# 4. Enable Credential Guard to prevent Mimikatz pass-the-hash
# Requires Hyper-V + UEFI Secure Boot
reg add HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard /v EnableVirtualizationBasedSecurity /t REG_DWORD /d 1

# 5. Block outbound WebSocket connections to non-allowlisted destinations
# Enforce via proxy (Zscaler, Squid with SSL inspection, etc.)

→ Read the full weekly roundup: Security Roundup — Week of May 14, 2026


Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther