SHADOW-EARTH-054 is a related China-aligned intrusion cluster observed in connection with SHADOW-EARTH-053. Reporting describes substantial overlap in victimology, tooling, infrastructure, and tradecraft between the two clusters. SHADOW-EARTH-054 exploited the same vulnerable internet-facing Microsoft Exchange and IIS entry points, including the ProxyLogon chain, and in multiple cases compromised organizations months before ShadowPad deployment associated with SHADOW-EARTH-053. The cluster shared identical tool hashes and overlapping TTPs with SHADOW-EARTH-053, including web-shell-based persistence on vulnerable IIS or Exchange servers; identical hashes were specifically noted for tools such as Evil-CreateDump and IOX Proxy. In three recent cases, a malicious loader family was attributed to SHADOW-EARTH-054. Nearly half of the observed SHADOW-EARTH-053 victims were also compromised by SHADOW-EARTH-054, particularly in Malaysia, Sri Lanka, and Myanmar. Content also notes network overlaps between SHADOW-EARTH-054 and activity tracked by other vendors as CL-STA-0049, REF7707, and Earth Alux. Although the overlap suggests aligned Chinese intelligence priorities and a shared operational ecosystem among China-aligned espionage actors, the reporting explicitly states that no evidence of direct operational coordination between SHADOW-EARTH-054 and SHADOW-EARTH-053 was observed. No aliases beyond SHADOW-EARTH-054 / Shadow-Earth-054 are directly provided in the content.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
The years-old ProxyLogon (CVE-2021-26855), which can be chained with other Microsoft Exchange Server bugs (CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) to achieve remote code execution, is a favorite. Salt Typhoon and other Chinese government snoops also abused ProxyLogon to breach critical US networks back in 2021, when it was first disclosed, and it's remained a top-exploited vulnerability ever since.
The years-old ProxyLogon (CVE-2021-26855), which can be chained with other Microsoft Exchange Server bugs (CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) to achieve remote code execution, is a favorite.
The years-old ProxyLogon (CVE-2021-26855), which can be chained with other Microsoft Exchange Server bugs (CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) to achieve remote code execution, is a favorite.
The years-old ProxyLogon (CVE-2021-26855), which can be chained with other Microsoft Exchange Server bugs (CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) to achieve remote code execution, is a favorite.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Related China-aligned intrusion cluster overlapping with SHADOW-EARTH-053 in victimology, initial access, web shell deployment, IOX Proxy usage, Evil-CreateDump hashes, geography, and infrastructure; assessed as independently exploiting similar exposed environments rather than directly coordinating.
A related intrusion set overlapping with SHADOW-EARTH-053, with activity often preceding ShadowPad deployment and sharing identical tool hashes and overlapping TTPs.
Related intrusion set observed compromising some of the same targets as SHADOW-EARTH-053, especially in Malaysia, Sri Lanka, and Myanmar.
Related China-aligned activity cluster overlapping with SHADOW-EARTH-053, sharing identical tool hashes and attack methods in intrusions against the same victim organizations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.