Shadow-Earth-053: Trend Micro Details China-Aligned Spy Group Targeting Journalists and Activists Alongside Governments and Defense

Trend Micro publishes full technical analysis of Shadow-Earth-053 — a China-aligned cluster targeting journalists and civil society activists alongside governments and defense across Asia and Poland, with no strong overlap to any publicly reported group.

Share
Globe with circuit traces connecting a government building, microphone, and protest sign, overlaid by a shadowed figure.

Trend Micro has published full technical analysis of Shadow-Earth-053, a China-aligned espionage cluster targeting governments, defense sectors, journalists, and activists across South, East, and Southeast Asia and Poland — revealing new tooling and new targets, while finding no strong overlap with any publicly reported group.

WASHINGTON, D.C. / SINGAPORE — Trend Micro has released comprehensive technical analysis of SHADOW-EARTH-053, the China-aligned threat cluster first disclosed by Trend Research (Trend Micro) in an exclusive to The Register last week. The full research confirms active intrusions since at least December 2024 across government and defense sectors in South, East, and Southeast Asia, and in Poland — and reveals that the group's targeting extends beyond government and defense to include journalists and civil society activists. Trend Micro describes SHADOW-EARTH-053 as a temporary intrusion set pending formal attribution, and states plainly: "Regarding SHADOW-EARTH-053, we found no strong overlap with any known publicly reported group."


Updated Threat Profile

Updated Threat Intelligence: SHADOW-EARTH-053 — Full Trend Micro Analysis
DetailInformation
Group DesignationSHADOW-EARTH-053 — a temporary intrusion set tracked by Trend Micro pending formal attribution; Trend Micro found no strong overlap with any known publicly reported group
Active SinceAt least December 2024 — ongoing through April/May 2026
Confirmed Target RegionsSouth Asia, East Asia, Southeast Asia — government, defense, tech, transport; and Poland
New Target CategoriesJournalists and civil society activists — disclosed in full Trend Micro report
Primary Entry VectorN-day vulnerabilities in internet-facing Microsoft Exchange and IIS servers
Primary BackdoorShadowPad — deployed via AnyDesk using DLL side-loading after extended dwell time
Linux BackdoorNoodle RAT (ANGRYREBEL/Nood RAT) — deployed via React2Shell CVE-2025-55182 exploitation; attributed to SHADOW-EARTH-053 with low confidence, the only confidence rating stated in the report
Evasion ToolsRingQ packer; IOX, GOST, and Wstunnel tunneling tools; Mimikatz for privilege escalation
Lateral MovementCustom RDP launcher; Sharp-SMBExec (C# implementation of SMBExec)

New technical depth: the full attack chain

Trend Micro's research reveals a significantly more detailed attack chain than the initial disclosure. Initial access comes via N-day vulnerabilities in internet-facing IIS and Exchange servers. Once inside, the group uses open-source tunneling tools — IOX, GO Simple Tunnel (GOST), and Wstunnel — to establish covert communication channels. Privilege escalation uses Mimikatz, the well-known credential dumping tool. Lateral movement employs a custom RDP launcher and Sharp-SMBExec, a C# implementation of SMBExec that allows pass-the-hash and pass-the-ticket attacks without dropping traditional tooling. ShadowPad is the primary final-stage backdoor, deployed via AnyDesk using DLL side-loading after an extended dwell period. In at least one case, exploitation of CVE-2025-55182 (React2Shell) facilitated deployment of Linux Noodle RAT — though Trend Micro attributes those Linux Noodle RAT samples to SHADOW-EARTH-053 only with low confidence, the single confidence rating stated anywhere in the report.

Journalists and activists as targets

The most strategically significant new disclosure in the Trend Micro report is that SHADOW-EARTH-053's targeting extends to journalists and civil society activists alongside government and defense sectors. This is a defining characteristic of Chinese state intelligence collection — the simultaneous targeting of official government targets and civil society surveillance targets. Trend Micro describes the victims generically as journalists and diaspora activists. In The CyberSignal's own assessment — not a Trend Micro finding — the sharpest exposure is likely to sit with journalists covering China, Taiwan, Hong Kong, or Xinjiang, and with activists associated with Uyghur, Tibetan, or pro-democracy causes in the target countries. Either way, this elevates the human rights dimension of the campaign significantly beyond a typical government espionage operation.

Where the overlaps actually sit: SHADOW-EARTH-054, not 053

The infrastructure and tooling overlaps commonly associated with this research belong to SHADOW-EARTH-054, not SHADOW-EARTH-053. Trend Micro is explicit: "Regarding SHADOW-EARTH-053, we found no strong overlap with any known publicly reported group." It is SHADOW-EARTH-054 that Trend Micro compares against CL-STA-0049 (Palo Alto Networks Unit 42), Earth Alux (Trend Micro), and REF7707 (Elastic Security Labs) — and even there the comparison is heavily caveated: "The infection vector used by CL-STA-0049 matches what we observed, however none of the other TTPs match, and we found no traces of VARGEIT." Unit 42 tracks that backdoor as SQUIDOOR; Trend Micro calls it VARGEIT. The report makes no contractor or commercial-proxy attribution at any confidence level, and Trend Micro does not describe SHADOW-EARTH-053 as state-confirmed — only as China-aligned. For broader context on how advanced persistent threats operate and the full nation-state cyber threat coverage on The CyberSignal. Our original Shadow-Earth-053 disclosure is covered here.

What to do now

Organizations in South, East, and Southeast Asia in government, defense, technology, and transportation sectors should treat IIS and Exchange server patching as an emergency priority — all known N-days are documented by Trend Micro and CISA. Hunt for IOX, GOST, and Wstunnel tunneling activity in network logs. Audit AnyDesk deployments — the legitimate remote access tool is being abused for DLL side-loading. Detect Mimikatz activity via memory signatures and LSASS access alerts. Journalists and activists covering China-sensitive topics should operate on the assumption that their devices and communications may be targeted and seek support from organizations like Access Now's Digital Security Helpline.


The CyberSignal Analysis

Signal 01 — Journalist and activist targeting changes the threat calculus

When a China-linked espionage campaign targets government networks, the defensive response is clearly scoped to government and enterprise security teams. When the same campaign also targets journalists and civil society activists, the defensive population expands to include individuals who typically have far fewer security resources and far less awareness of being targeted. Trend Micro's finding that SHADOW-EARTH-053 reaches civil society alongside government is not a footnote — it is a primary finding that changes who needs to be warned and protected.

Signal 02 — Trend Micro's restraint on attribution is the story

Trend Micro did not name a state sponsor, a contractor, or a known group. It called SHADOW-EARTH-053 China-aligned, labelled it a temporary intrusion set pending formal attribution, and stated that it found no strong overlap with any known publicly reported group. The one confidence rating in the entire report is low confidence, attached to the Linux Noodle RAT samples. That restraint is worth reading carefully: coverage that folds SHADOW-EARTH-053 together with CL-STA-0049, Earth Alux, or REF7707 is importing overlaps that Trend Micro assigned to a different cluster, SHADOW-EARTH-054, and even there qualified as mostly non-matching TTPs.

Signal 03 — The IIS attack surface is chronically underdefended

SHADOW-EARTH-053's primary entry vector — N-day vulnerabilities in internet-facing IIS servers — reflects a persistent gap in enterprise security posture across Asia. IIS is widely deployed in government environments across the region, often running outdated versions without consistent patch management. This is not a zero-day problem. Every vulnerability SHADOW-EARTH-053 exploited was known and patchable. The problem is the implementation gap between known vulnerability and applied patch.


Sources

TypeSource
Primary ResearchTrend Micro (Daniel Lunghi, Lucas Silva): Inside SHADOW-EARTH-053 — April 30, 2026
Vendor ResearchElastic Security Labs: REF7707 — Fragile Web
Vendor ResearchPalo Alto Networks Unit 42: CL-STA-0049 and the SQUIDOOR Backdoor
ReportingThe Hacker News: China-Linked Hackers Target Asian Governments, NATO State, Journalists, and Activists
Prior CoverageThe Register: Novel China-Linked Group Infiltrates Critical Networks in Poland and Asia
RelatedThe CyberSignal: Shadow-Earth-053 Original Disclosure — Poland and Asia