China-Aligned SHADOW-EARTH
A China-aligned threat group tracked as SHADOW-EARTH-053 has been exploiting unpatched Microsoft Exchange Server vulnerabilities to conduct cyberespionage against government and defense-linked targets across Asia and beyond. The group’s activity dates back to at least December 2024, with campaigns targeting at least eight countries, including government ministries, defense contractors, IT consulting firms, and transportation organizations […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
