Skip to content

China-Aligned Hackers Deploy ShadowPad in Multi

Gbhackers •Mayura Kathir • May 1, 2026

China-aligned threat actors tracked as SHADOW-EARTH-053 are exploiting old but unpatched Microsoft Exchange and IIS vulnerabilities to run a stealthy, multi-stage espionage campaign across Asian governments, critical infrastructure, and one NATO member state. The group primarily targets government entities and critical infrastructure in South, East, and Southeast Asia, with additional activity against at least one […]

Extracted Entities

APT Groups (1)

Attack Types (1)

Industries (1)

Malware (1)

Platforms (2)