CODERED VTA

China Aligned Cyberespionage Campaign Targets Governments

Medium
Fingerprint security scan
Photo by Lewis Kang'ethe Ngugi on Unsplash

Cybersecurity researchers have identified a China-aligned espionage campaign targeting government and defense organizations across South, East, and Southeast Asia, as well as a European NATO member. The activity cluster, tracked as SHADOW-EARTH-053, has been active since at least late 2024 and shows overlaps with previously known threat groups.

Researchers said the attackers primarily exploit known vulnerabilities in internet-facing Microsoft Exchange and IIS servers, including flaws similar to the ProxyLogon chain. Once access is gained, they deploy web shells such as Godzilla to maintain persistence and execute commands remotely.

The intrusion progresses with the delivery of ShadowPad malware through DLL sideloading using legitimate signed executables. In some cases, remote access tools like AnyDesk are leveraged to assist in payload deployment. Additional tooling includes tunneling utilities such as GOST and Wstunnel for stealthy communication, and RingQ to obfuscate malicious binaries.

Privilege escalation is achieved using credential dumping tools like Mimikatz, while lateral movement is conducted through custom RDP launchers and SMB-based tools such as Sharp-SMBExec. Researchers also observed exploitation of newer vulnerabilities to deliver Linux variants of remote access trojans.

Parallel campaigns attributed to related actors focus on phishing operations targeting journalists and civil society groups. These attacks rely on impersonation, credential harvesting pages, and OAuth token abuse. Tracking pixels are also embedded in emails to confirm victim interaction and collect device information.

Overall, the campaigns emphasize the exploitation of unpatched systems, stealthy persistence mechanisms, and credential-focused intrusion techniques to achieve long-term access.

Attack Surface

Endpoint, Server OS, Web Application

Tactics

Initial Access, Persistence, Privilege Escalation, Exfiltration

Techniques

  • T1190 – Exploit Public-Facing Application
  • T1204 – User Execution
  • T1215 – Credentials from Password Stores

SuperPRO's Threat Countermeasures Procedures

  1. Prioritize the immediate installation of security updates for Microsoft Exchange and IIS
  2. Implement Virtual Patching through Web Application Firewalls to block known CVE exploits
  3. Enforce phishing resistant Multi Factor Authentication such as hardware security keys
  4. Disable or strictly monitor the execution of signed executables that are prone to DLL side loading
  5. Audit and restrict the use of unauthorized network tunneling and RDP tools
  6. Use advanced email filtering solutions to detect tracking pixels and unauthorized OAuth requests
  7. Implement a robust incident response plan to quickly respond to security incidents

References

  1. https://www.trendmicro.com/en_us/research/26/d/inside-shadow-earth-053.html