← Back to Feed
Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia
April 30, 2026 · Trend Micro · Severity: CRITICAL
A China-aligned threat group is exploiting unpatched Microsoft Exchange vulnerabilities to conduct cyberespionage against government and critical infrastructure targets across Asia and beyond.
Key Takeaways
- Shadow-Earth-053, a China-aligned threat group, is exploiting unpatched Microsoft Exchange vulnerabilities to conduct cyberespionage against government and critical infrastructure targets in Asia.
- The campaign demonstrates how unpatched Exchange servers remain a reliable initial access vector for espionage groups.
- Organizations should patch Microsoft Exchange immediately, as Shadow-Earth-053 campaigns continue to target unpatched government systems.