← Back to Feed

Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia

April 30, 2026 · Trend Micro · Severity: CRITICAL

A China-aligned threat group is exploiting unpatched Microsoft Exchange vulnerabilities to conduct cyberespionage against government and critical infrastructure targets across Asia and beyond.

Key Takeaways

  • Shadow-Earth-053, a China-aligned threat group, is exploiting unpatched Microsoft Exchange vulnerabilities to conduct cyberespionage against government and critical infrastructure targets in Asia.
  • The campaign demonstrates how unpatched Exchange servers remain a reliable initial access vector for espionage groups.
  • Organizations should patch Microsoft Exchange immediately, as Shadow-Earth-053 campaigns continue to target unpatched government systems.
☕ Buy a Coffee