Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
China-Linked Cyber Attacks Target Asian Nations and Journalists

China-Linked Cyber Attacks Target Asian Nations and Journalists

Posted on May 1, 2026 By CWS

Recent investigations by cybersecurity experts have unearthed a China-linked cyber espionage campaign aimed at government and defense sectors across South, East, and Southeast Asia, as well as a NATO member in Europe. The cybersecurity firm Trend Micro attributes these activities to a group they have temporarily named SHADOW-EARTH-053. This group has been active since at least December 2024 and shares some network characteristics with other known threat actors.

Details of the Cyber Espionage Campaign

The group exploits existing vulnerabilities in Microsoft Exchange and Internet Information Services (IIS) servers to gain unauthorized access. These vulnerabilities, such as the ProxyLogon chain, are used to deploy web shells like Godzilla, maintaining persistent access. The attackers then implement ShadowPad implants via DLL sideloading of legitimate signed executables.

The campaign’s targets include nations such as Pakistan, Thailand, Malaysia, India, Myanmar, Sri Lanka, and Taiwan, with Poland being the sole European target. Trend Micro observed that nearly half of SHADOW-EARTH-053’s targets, particularly in Malaysia, Sri Lanka, and Myanmar, were previously compromised by a related group known as SHADOW-EARTH-054.

Techniques Employed in the Attacks

The attackers start by exploiting known security flaws, dropping web shells to enable persistent remote access. These shells serve as conduits for command execution, reconnaissance, and deploying the ShadowPad backdoor through AnyDesk. In some instances, vulnerabilities like React2Shell are used to distribute Linux versions of malicious software such as Noodle RAT.

The attackers also use various open-source tunneling tools and techniques to evade detection and escalate privileges. Mimikatz is employed for privilege escalation, while lateral movement is facilitated using custom tools. Trend Micro emphasizes the importance of applying the latest security updates to mitigate these threats.

Impact on Journalists and Activists

In a related development, Citizen Lab has identified phishing campaigns by China-affiliated groups targeting journalists and civil society. These campaigns, identified as GLITTER CARP and SEQUIN CARP, impersonate journalists and activists, particularly those focused on sensitive issues related to the Chinese government.

The phishing tactics are sophisticated, involving digital impersonations and the reuse of infrastructure across various targets. The campaigns aim to harvest credentials and gain unauthorized access to email accounts, using techniques such as phishing pages and OAuth token manipulation.

Citizen Lab’s analysis highlights the growing trend of digital transnational repression conducted by distributed networks of actors. The targets align with the intelligence priorities of the Chinese government, suggesting possible involvement of commercial entities hired by the state.

As these cyber threats continue to evolve, nations and organizations must remain vigilant and proactive in enhancing their cybersecurity measures to protect against such espionage activities.

The Hacker News Tags:Activists, Asian governments, China, Cybersecurity, Espionage, Journalists, NATO, Phishing, ShadowPad, Trend Micro

Post navigation

Previous Post: Cybercriminals Exploit CAPTCHA for New Phishing Tactics
Next Post: Malware Campaign Exploits SEO to Target IT Professionals

Related Posts

AI-Driven Exploitation Challenges Vulnerability Management AI-Driven Exploitation Challenges Vulnerability Management The Hacker News
Addressing the Hidden Costs of Credential Incidents Addressing the Hidden Costs of Credential Incidents The Hacker News
XDigo Malware Exploits Windows LNK Flaw in Eastern European Government Attacks XDigo Malware Exploits Windows LNK Flaw in Eastern European Government Attacks The Hacker News
Researchers Capture Lazarus APT’s Remote-Worker Scheme Live on Camera Researchers Capture Lazarus APT’s Remote-Worker Scheme Live on Camera The Hacker News
Masjesu Botnet: Global Threat to IoT Devices Masjesu Botnet: Global Threat to IoT Devices The Hacker News
Iran-Linked Cyber Attacks Target Israeli Microsoft 365 Iran-Linked Cyber Attacks Target Israeli Microsoft 365 The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaw Exposes 14,000 SimpleHelp Servers
  • NarwhalRAT Malware Targets Korean Users via LNK Files
  • Chinese Cyber Group Exploits Google Workspace to Steal Emails
  • Microsoft 365 Copilot Flaw Allows Data Theft in One Click
  • North Korean Hackers Exploit Developer Tools for Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaw Exposes 14,000 SimpleHelp Servers
  • NarwhalRAT Malware Targets Korean Users via LNK Files
  • Chinese Cyber Group Exploits Google Workspace to Steal Emails
  • Microsoft 365 Copilot Flaw Allows Data Theft in One Click
  • North Korean Hackers Exploit Developer Tools for Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark