Shadow-Earth-053Shadow-Earth-053

Also known as: Shadow-Earth-053

Known aliases
1

Profile

SHADOW-EARTH-053 is a China-aligned threat group exploiting unpatched Microsoft Exchange Server vulnerabilities, specifically CVE-2021-26855, to conduct cyberespionage against government and defense-linked targets across Asia and Europe. The group primarily deploys ShadowPad malware, utilizing techniques such as credential dumping, tunneling tools, and lateral movement via WMIC. They have also been observed installing web shells for persistence and leveraging a custom ExchangeExport tool to extract high-value mailbox contents. Additionally, low-confidence associations with Noodle RAT and CVE-2025-55182 have been noted in their operations.

Aliases· 1

Shadow-Earth-053

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
Earth Lamia
Actor
Storm-0558
Actor
Earth Naga
Actor
BRONZE EDGEWOOD
Actor
SHADOW-AETHER-015
Actor
UNC5330
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.