Adversary Intelligence — 2026-05-09

China-Aligned Shadow-Earth-053 Cyberespionage Campaign Targets Eight Asian Nations and Poland

On May 1, Trend Micro disclosed Shadow-Earth-053, a China-aligned campaign active since at least December 2024 that has targeted government and defense networks in Pakistan, Thailand, Malaysia, India, Myanmar, Sri Lanka, Taiwan, and Poland. The Diplomat's reporting described attackers exploiting unpatched Microsoft Exchange and IIS servers via ProxyLogon vulnerabilities, installing custom backdoors and espionage malware, and in one instance leveraging a previously unknown Linux vulnerability for initial access. Two linked phishing clusters, Glitter Carp and Sequin Carp, targeted Uyghur, Tibetan, Taiwanese, and Hong Kong diaspora activists and journalists using tracking-pixel emails and credential-harvesting pages. Trend Micro assessed China-aligned actors, possibly including commercial contractors, as responsible and noted that nearly half of targets were also hit by the related Shadow-Earth-054 campaign.

Analysis
Shadow-Earth-053's dual-track architecture, ProxyLogon exploitation of government and defense networks paired with precision phishing of diaspora critics, operated as a unified framework, not parallel programs, reinforced by near-complete infrastructure overlap with Shadow-Earth-054. Confidence is moderate: a single Trend Micro disclosure, no independent corroboration. Warsaw's role as the principal military-aid corridor into Ukraine makes sustained Polish access a window into NATO logistics; sustained penetration of India's defense ministry could expose joint Quad naval planning. A previously unknown Linux vulnerability deployed alongside ProxyLogon signals a more mature, modular Chinese offensive enterprise. Public identification of additional Western victims by November 2026 carries roughly even odds, and the contractor overlap may instead reflect competitive redundancy among tasked vendors rather than central direction from Beijing.
2 sources
  1. Chinas Cyber Operations Hit Asian Governments and Dissidents Abroad - The Diplomat
  2. Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign - Trend Micro vinfo

View in full brief →

UNCLASSIFIED // OPEN SOURCE