Shadow-Earth-053: Trend Micro Details China-Aligned Spy Group Targeting Journalists and Activists Alongside Governments and Defense
Trend Micro publishes full technical analysis of Shadow-Earth-053 — a China-aligned cluster targeting journalists and civil society activists alongside governments and defense across Asia and Poland, with no strong overlap to any publicly reported group.
Trend Micro has published full technical analysis of Shadow-Earth-053, a China-aligned espionage cluster targeting governments, defense sectors, journalists, and activists across South, East, and Southeast Asia and Poland — revealing new tooling and new targets, while finding no strong overlap with any publicly reported group.
WASHINGTON, D.C. / SINGAPORE — Trend Micro has released comprehensive technical analysis of SHADOW-EARTH-053, the China-aligned threat cluster first disclosed by Trend Research (Trend Micro) in an exclusive to The Register last week. The full research confirms active intrusions since at least December 2024 across government and defense sectors in South, East, and Southeast Asia, and in Poland — and reveals that the group's targeting extends beyond government and defense to include journalists and civil society activists. Trend Micro describes SHADOW-EARTH-053 as a temporary intrusion set pending formal attribution, and states plainly: "Regarding SHADOW-EARTH-053, we found no strong overlap with any known publicly reported group."
Updated Threat Profile
New technical depth: the full attack chain
Trend Micro's research reveals a significantly more detailed attack chain than the initial disclosure. Initial access comes via N-day vulnerabilities in internet-facing IIS and Exchange servers. Once inside, the group uses open-source tunneling tools — IOX, GO Simple Tunnel (GOST), and Wstunnel — to establish covert communication channels. Privilege escalation uses Mimikatz, the well-known credential dumping tool. Lateral movement employs a custom RDP launcher and Sharp-SMBExec, a C# implementation of SMBExec that allows pass-the-hash and pass-the-ticket attacks without dropping traditional tooling. ShadowPad is the primary final-stage backdoor, deployed via AnyDesk using DLL side-loading after an extended dwell period. In at least one case, exploitation of CVE-2025-55182 (React2Shell) facilitated deployment of Linux Noodle RAT — though Trend Micro attributes those Linux Noodle RAT samples to SHADOW-EARTH-053 only with low confidence, the single confidence rating stated anywhere in the report.
Journalists and activists as targets
The most strategically significant new disclosure in the Trend Micro report is that SHADOW-EARTH-053's targeting extends to journalists and civil society activists alongside government and defense sectors. This is a defining characteristic of Chinese state intelligence collection — the simultaneous targeting of official government targets and civil society surveillance targets. Trend Micro describes the victims generically as journalists and diaspora activists. In The CyberSignal's own assessment — not a Trend Micro finding — the sharpest exposure is likely to sit with journalists covering China, Taiwan, Hong Kong, or Xinjiang, and with activists associated with Uyghur, Tibetan, or pro-democracy causes in the target countries. Either way, this elevates the human rights dimension of the campaign significantly beyond a typical government espionage operation.
Where the overlaps actually sit: SHADOW-EARTH-054, not 053
The infrastructure and tooling overlaps commonly associated with this research belong to SHADOW-EARTH-054, not SHADOW-EARTH-053. Trend Micro is explicit: "Regarding SHADOW-EARTH-053, we found no strong overlap with any known publicly reported group." It is SHADOW-EARTH-054 that Trend Micro compares against CL-STA-0049 (Palo Alto Networks Unit 42), Earth Alux (Trend Micro), and REF7707 (Elastic Security Labs) — and even there the comparison is heavily caveated: "The infection vector used by CL-STA-0049 matches what we observed, however none of the other TTPs match, and we found no traces of VARGEIT." Unit 42 tracks that backdoor as SQUIDOOR; Trend Micro calls it VARGEIT. The report makes no contractor or commercial-proxy attribution at any confidence level, and Trend Micro does not describe SHADOW-EARTH-053 as state-confirmed — only as China-aligned. For broader context on how advanced persistent threats operate and the full nation-state cyber threat coverage on The CyberSignal. Our original Shadow-Earth-053 disclosure is covered here.
What to do now
Organizations in South, East, and Southeast Asia in government, defense, technology, and transportation sectors should treat IIS and Exchange server patching as an emergency priority — all known N-days are documented by Trend Micro and CISA. Hunt for IOX, GOST, and Wstunnel tunneling activity in network logs. Audit AnyDesk deployments — the legitimate remote access tool is being abused for DLL side-loading. Detect Mimikatz activity via memory signatures and LSASS access alerts. Journalists and activists covering China-sensitive topics should operate on the assumption that their devices and communications may be targeted and seek support from organizations like Access Now's Digital Security Helpline.
The CyberSignal Analysis
Signal 01 — Journalist and activist targeting changes the threat calculus
When a China-linked espionage campaign targets government networks, the defensive response is clearly scoped to government and enterprise security teams. When the same campaign also targets journalists and civil society activists, the defensive population expands to include individuals who typically have far fewer security resources and far less awareness of being targeted. Trend Micro's finding that SHADOW-EARTH-053 reaches civil society alongside government is not a footnote — it is a primary finding that changes who needs to be warned and protected.
Signal 02 — Trend Micro's restraint on attribution is the story
Trend Micro did not name a state sponsor, a contractor, or a known group. It called SHADOW-EARTH-053 China-aligned, labelled it a temporary intrusion set pending formal attribution, and stated that it found no strong overlap with any known publicly reported group. The one confidence rating in the entire report is low confidence, attached to the Linux Noodle RAT samples. That restraint is worth reading carefully: coverage that folds SHADOW-EARTH-053 together with CL-STA-0049, Earth Alux, or REF7707 is importing overlaps that Trend Micro assigned to a different cluster, SHADOW-EARTH-054, and even there qualified as mostly non-matching TTPs.
Signal 03 — The IIS attack surface is chronically underdefended
SHADOW-EARTH-053's primary entry vector — N-day vulnerabilities in internet-facing IIS servers — reflects a persistent gap in enterprise security posture across Asia. IIS is widely deployed in government environments across the region, often running outdated versions without consistent patch management. This is not a zero-day problem. Every vulnerability SHADOW-EARTH-053 exploited was known and patchable. The problem is the implementation gap between known vulnerability and applied patch.