Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
China-Linked Cyber Attacks Target Asian Nations and Journalists

China-Linked Cyber Attacks Target Asian Nations and Journalists

Posted on May 1, 2026 By CWS

Recent investigations by cybersecurity experts have unearthed a China-linked cyber espionage campaign aimed at government and defense sectors across South, East, and Southeast Asia, as well as a NATO member in Europe. The cybersecurity firm Trend Micro attributes these activities to a group they have temporarily named SHADOW-EARTH-053. This group has been active since at least December 2024 and shares some network characteristics with other known threat actors.

Details of the Cyber Espionage Campaign

The group exploits existing vulnerabilities in Microsoft Exchange and Internet Information Services (IIS) servers to gain unauthorized access. These vulnerabilities, such as the ProxyLogon chain, are used to deploy web shells like Godzilla, maintaining persistent access. The attackers then implement ShadowPad implants via DLL sideloading of legitimate signed executables.

The campaign’s targets include nations such as Pakistan, Thailand, Malaysia, India, Myanmar, Sri Lanka, and Taiwan, with Poland being the sole European target. Trend Micro observed that nearly half of SHADOW-EARTH-053’s targets, particularly in Malaysia, Sri Lanka, and Myanmar, were previously compromised by a related group known as SHADOW-EARTH-054.

Techniques Employed in the Attacks

The attackers start by exploiting known security flaws, dropping web shells to enable persistent remote access. These shells serve as conduits for command execution, reconnaissance, and deploying the ShadowPad backdoor through AnyDesk. In some instances, vulnerabilities like React2Shell are used to distribute Linux versions of malicious software such as Noodle RAT.

The attackers also use various open-source tunneling tools and techniques to evade detection and escalate privileges. Mimikatz is employed for privilege escalation, while lateral movement is facilitated using custom tools. Trend Micro emphasizes the importance of applying the latest security updates to mitigate these threats.

Impact on Journalists and Activists

In a related development, Citizen Lab has identified phishing campaigns by China-affiliated groups targeting journalists and civil society. These campaigns, identified as GLITTER CARP and SEQUIN CARP, impersonate journalists and activists, particularly those focused on sensitive issues related to the Chinese government.

The phishing tactics are sophisticated, involving digital impersonations and the reuse of infrastructure across various targets. The campaigns aim to harvest credentials and gain unauthorized access to email accounts, using techniques such as phishing pages and OAuth token manipulation.

Citizen Lab’s analysis highlights the growing trend of digital transnational repression conducted by distributed networks of actors. The targets align with the intelligence priorities of the Chinese government, suggesting possible involvement of commercial entities hired by the state.

As these cyber threats continue to evolve, nations and organizations must remain vigilant and proactive in enhancing their cybersecurity measures to protect against such espionage activities.

The Hacker News Tags:Activists, Asian governments, China, Cybersecurity, Espionage, Journalists, NATO, Phishing, ShadowPad, Trend Micro

Post navigation

Previous Post: Cybercriminals Exploit CAPTCHA for New Phishing Tactics
Next Post: Malware Campaign Exploits SEO to Target IT Professionals

Related Posts

AI-Driven Cyber Attacks Surge in 2025 AI-Driven Cyber Attacks Surge in 2025 The Hacker News
Mitigating Risks of Exposed Endpoints in LLM Infrastructure Mitigating Risks of Exposed Endpoints in LLM Infrastructure The Hacker News
Evolving Enterprise Defense to Secure the Modern AI Supply Chain Evolving Enterprise Defense to Secure the Modern AI Supply Chain The Hacker News
Researchers Detail Bitter APT’s Evolving Tactics as Its Geographic Scope Expands Researchers Detail Bitter APT’s Evolving Tactics as Its Geographic Scope Expands The Hacker News
Mirax Android RAT Exploits Devices as Proxies via Meta Ads Mirax Android RAT Exploits Devices as Proxies via Meta Ads The Hacker News
Single 8-Byte Write Shatters AMD’s SEV-SNP Confidential Computing Single 8-Byte Write Shatters AMD’s SEV-SNP Confidential Computing The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Stealthy Vidar Stealer Campaign Evades EDR, Steals Data
  • Zoom Software Vulnerabilities Pose Security Risks
  • Enhancing MSSP Security with Real-Time Threat Visibility
  • SAP Addresses Critical Vulnerabilities in S/4HANA
  • Ivanti Releases Security Patches for Multiple Products

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Stealthy Vidar Stealer Campaign Evades EDR, Steals Data
  • Zoom Software Vulnerabilities Pose Security Risks
  • Enhancing MSSP Security with Real-Time Threat Visibility
  • SAP Addresses Critical Vulnerabilities in S/4HANA
  • Ivanti Releases Security Patches for Multiple Products

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark