INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Exploiting Sleep Cycle Rats for Network Infiltration
| 2026-04-30 11:00 CRITICAL HIGH MALWARE & BOTNETS
Executive Summary
AI-generated
The discovery of a novel Chinese spy group infiltrating critical networks in Poland, Asia and potentially beyond has sent shockwaves through the cybersecurity community. The threat actors, described as APT41, have been linked to several high-profile intrusions dating back to 2019, including the compromise of victim organizations up to eight months prior deployment of ShadowPad a custom backdoor used by China's notorious Advanced Persistent Threat group APT41 for nearly a decade. This latest intrusion has highlighted how cyber espionage and warfare are burgeoning, with NATO countries like Poland being targeted. The researchers at TrendAI have identified the new group as Shadow-Earth-053 which is believed to be linked to this threat, further emphasizing the need for increased vigilance in protecting against these sophisticated attacks.
Technical Mitigations AI-generated
• Use secure protocols such as HTTPS and SFTP to encrypt data in transit.
• Regularly update and patch Microsoft Exchange Server vulnerabilities, including ProxyLogon (CVE-2021-26855).
• Implement a web application firewall (WAF) to detect and block suspicious traffic patterns.
• Monitor network activity for signs of unusual or unauthorized access attempts.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Volt TyphoonVolt TyphoonAPT41APT41Salt TyphoonSalt Typhoon
ShadowPadShadowPad
CVE-2021-26857CVE-2021-26857
CVE-2025-55182CVE-2025-55182
CVE-2021-26855CVE-2021-26855
CVE-2021-26858CVE-2021-26858
CVE-2021-27065CVE-2021-27065
Target & Sectors
SOUTH_ASIA
SOUTH_ASIA
NORTH_AMERICA
NORTH_AMERICA
ASEAN
ASEAN
defensedefense
energyenergy
governmentgovernment
technologytechnology
transportationtransportation
Incident Timeline
mid-2021
Chinese hackers followed in the footsteps of mid-2021 incident And Volt, burrowing deep into critical US networks to prepare for future destructive attacks.
Click on any entity below to view its context and source!
target_region
United States
And Volt followed in mid-2021, burrowing deep into
critical US networks
to preposition for
future destructive attacks
.
late 2023
Chinese hackers gained access to governments, state and journalists' computer systems in late 2023.
December 2024
China-linked threat group infiltrated critical networks in Poland and other countries.
Click on any entity below to view its context and source!
source_region
China
EXCLUSIVE
A novel China-linked threat group infiltrated more than a dozen critical networks in Poland, Asian countries, and possibly beyond, beginning in December 2024 and with activity uncovered as recently as this month.
Exclusive
A novel China-linked threat group infiltrated more than a dozen critical networks in Poland, Asian countries, and possibly beyond, beginning in December 2024 and with activity uncovered as recently as this month.
source_region
Poland
EXCLUSIVE
A novel China-linked threat group infiltrated more than a dozen critical networks in Poland, Asian countries, and possibly beyond, beginning in December 2024 and with activity uncovered as recently as this month.
Exclusive
A novel China-linked threat group infiltrated more than a dozen critical networks in Poland, Asian countries, and possibly beyond, beginning in December 2024 and with activity uncovered as recently as this month.
at least December 2024
Chinese hackers are suspected of targeting governments, state and journalists since at least December 2024.
July 2025
Chinese hackers used UNK_SparkyCarp to target governments and state entities in July 2025.
Click on any entity below to view its context and source!
organisation
UNK_SparkyCarp
Some aspects of these efforts were
previously documented
by Proofpoint in July 2025 under the name UNK_SparkyCarp.
April and June 2025
Chinese hackers launched targeted cyberattacks on governments, state institutions and journalists in April and June 2025.
2026/04/30
Shadow-Earth-053 used Mimikatz to gain initial access and Sharp-SMBExec for lateral movement.
Click on any entity below to view its context and source!
organisation
NATO
Targeting Poland, a NATO country, "highlights how cyber espionage and a cyber warfare is burgeoning," Kellermann said.
infrastructure
Windows
Shadow-y malware and legit Windows tools
In a separate instance, the incident responders found
Linux NoodleRat backdoors
- also widely used by Chinese espionage and cybercrime groups - deployed after Shadow-Earth-053 exploited another widely-abused Microsoft security hole:
In some instances, the group renamed legitimate Windows system binaries to evade process-based detection.
To move laterally through victim environments, Shadow-Earth-053 uses Windows Management Instrumentation Command-line (WMIC) and installs backdoors onto additional hosts.
infrastructure
Linux
Shadow-y malware and legit Windows tools
In a separate instance, the incident responders found
Linux NoodleRat backdoors
- also widely used by Chinese espionage and cybercrime groups - deployed after Shadow-Earth-053 exploited another widely-abused Microsoft security hole:
In at least one case, the weaponization of the
React2Shell
(CVE-2025-55182) is said to have facilitated the distribution of a Linux version of
Noodle RAT
(aka ANGRYREBEL and Nood RAT).
organisation
Microsoft
Shadow-y malware and legit Windows tools
In a separate instance, the incident responders found
Linux NoodleRat backdoors
- also widely used by Chinese espionage and cybercrime groups - deployed after Shadow-Earth-053 exploited another widely-abused Microsoft security hole:
organisation
Palo Alto Networks'
The 054 group has some network overlaps with Chinese crews tracked as
CL-STA-0049
by Palo Alto Networks' Unit 42,
REF7707
by Elastic Security Labs, and
Earth Alux
.
organisation
Elastic Security Labs
The 054 group has some network overlaps with Chinese crews tracked as
CL-STA-0049
by Palo Alto Networks' Unit 42,
REF7707
by Elastic Security Labs, and
Earth Alux
.
threat_actor
Salt Typhoon
Tom Kellermann, TrendAI VP of AI security and threat research, likened the new Chinese groups to
Salt Typhoon
and
Volt Typhoon
.
Salt Typhoon and other Chinese government snoops also abused ProxyLogon to breach critical US networks back in 2021, when it was first disclosed, and it's remained a
top-exploited vulnerability ever since
.
threat_actor
Volt Typhoon
Tom Kellermann, TrendAI VP of AI security and threat research, likened the new Chinese groups to
Salt Typhoon
and
Volt Typhoon
.
organisation
NATO State
China-Linked Hackers Target Asian Governments, NATO State, Journalists, and Activists.
threat_actor
APT41
In "multiple" of these intrusions, they compromised victim organizations up to 8 months before deploying
ShadowPad
, a custom backdoor used by
China's APT41
for almost a decade, and shared among multiple China-aligned groups since 2019.
organisation
GitHub
In one victim's environment, TrendAI detected RingQ, an open-source tool developed in China and available on GitHub that can be used to pack malicious binaries to evade detection by security solutions.
organisation
Microsoft Exchange Servers
The Chinese spies typically gain initial access to victim environments via vulnerable Microsoft Exchange Servers.
organisation
Uyghur
"
GLITTER CARP and SEQUIN CARP Go After Activists and Journalists
The disclosure comes as the Citizen Lab flagged a new phishing campaign undertaken by two distinct China-affiliated threat actors targeting and impersonating journalists and civil society, including Uyghur, Tibetan, Taiwanese, and Hong Kong diaspora activists.
organisation
AnyDesk
In one instance, the snoops delivered ShadowPad malware via legitimate, and popular, remote desktop tool AnyDesk.
The web shells function as a delivery vehicle for command execution, enabling reconnaissance and ultimately resulting in the deployment of the ShadowPad backdoor via AnyDesk.
organisation
ProxyLogon
"The group exploits N-day vulnerabilities in internet-facing Microsoft Exchange and Internet Information Services (IIS) servers (e.g.,
ProxyLogon
chain), then deploys web shells (
Godzilla
) for persistent access and stages
ShadowPad
implants via DLL sideloading of legitimate signed executables," security researchers Daniel Lunghi and Lucas Silva
said
in an analysis.
The years-old
ProxyLogon
(CVE-2021-26855), which can be chained with other Microsoft Exchange Server bugs (CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) to achieve remote code execution, is a favorite.
organisation
Microsoft Exchange
"The group exploits N-day vulnerabilities in internet-facing Microsoft Exchange and Internet Information Services (IIS) servers (e.g.,
ProxyLogon
chain), then deploys web shells (
Godzilla
) for persistent access and stages
ShadowPad
implants via DLL sideloading of legitimate signed executables," security researchers Daniel Lunghi and Lucas Silva
said
in an analysis.
The years-old
ProxyLogon
(CVE-2021-26855), which can be chained with other Microsoft Exchange Server bugs (CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) to achieve remote code execution, is a favorite.
organisation
Internet Information Services
"The group exploits N-day vulnerabilities in internet-facing Microsoft Exchange and Internet Information Services (IIS) servers (e.g.,
ProxyLogon
chain), then deploys web shells (
Godzilla
) for persistent access and stages
ShadowPad
implants via DLL sideloading of legitimate signed executables," security researchers Daniel Lunghi and Lucas Silva
said
in an analysis.
organisation
DLL
"The group exploits N-day vulnerabilities in internet-facing Microsoft Exchange and Internet Information Services (IIS) servers (e.g.,
ProxyLogon
chain), then deploys web shells (
Godzilla
) for persistent access and stages
ShadowPad
implants via DLL sideloading of legitimate signed executables," security researchers Daniel Lunghi and Lucas Silva
said
in an analysis.
organisation
Shadow-Earth-053's
"They're following in the footsteps of the Typhoon campaigns, they look like the younger brother and sister of the Typhoon campaigns, and they're island-hopping through the defense sectors and ministries of those nations for a reason."
Shadow-Earth-053's victims spanned at least eight countries, according to TrendAI's investigation.
organisation
SHADOW
The cybersecurity vendor said it observed nearly half the SHADOW-EARTH-053 targets, particularly those in Malaysia, Sri Lanka, and Myanmar, also compromised earlier by a related intrusion set dubbed SHADOW-EARTH-054, although no evidence of direct operational coordination has been observed.
organisation
ANGRYREBEL
In at least one case, the weaponization of the
React2Shell
(CVE-2025-55182) is said to have facilitated the distribution of a Linux version of
Noodle RAT
(aka ANGRYREBEL and Nood RAT).
organisation
DNS
The intruders also use domain names that impersonate products, security companies, or are related to the DNS protocol.
organisation
Shadow-Earth-054
About half of the victims were also compromised by a related group, Shadow-Earth-054, which exploited the same vulnerabilities and shared identical tool hashes and overlapping techniques with Shadow-Earth-053.
organisation
Shadow-Earth-053
About half of the victims were also compromised by a related group, Shadow-Earth-054, which exploited the same vulnerabilities and shared identical tool hashes and overlapping techniques with Shadow-Earth-053.
organisation
Exchange
So if you haven't already: patch these Exchange server bugs.
organisation
The Citizen Lab
The Citizen Lab said it "observed concurrent targeting of specific organizations using both the AiTM phishing kit (GLITTER CARP, UNK_SparkyCarp) and the delivery of HealthKick using different phishing tactics by a separate group (UNK_DropPitch)."
organisation
HealthKick
The Citizen Lab said it "observed concurrent targeting of specific organizations using both the AiTM phishing kit (GLITTER CARP, UNK_SparkyCarp) and the delivery of HealthKick using different phishing tactics by a separate group (UNK_DropPitch)."
organisation
Trend Micro
Trend Micro has attributed the activity to a threat activity cluster it tracks under the temporary designation
SHADOW-EARTH-053
.
organisation
Intrusion Prevention Systems
"Organizations should prioritize applying the latest security updates and cumulative patches to Microsoft Exchange and any web applications hosted on IIS."
"In scenarios where immediate patching is not feasible, we strongly recommend deploying Intrusion Prevention Systems (IPS) or Web Application Firewalls (WAF) with rulesets specifically tuned to block exploit attempts against these known CVEs (Virtual Patching).
organisation
Virtual Patching
"Organizations should prioritize applying the latest security updates and cumulative patches to Microsoft Exchange and any web applications hosted on IIS."
"In scenarios where immediate patching is not feasible, we strongly recommend deploying Intrusion Prevention Systems (IPS) or Web Application Firewalls (WAF) with rulesets specifically tuned to block exploit attempts against these known CVEs (Virtual Patching).
organisation
SEQUIN
SEQUIN CARP, on the other hand, shares similarities with a group tracked by Volexity as
UTA0388
and an intrusion set detailed by Trend Micro as
TAOTH
.
May 14
Chinese hackers accessed government and state computer systems on May 14.
Click on any entity below to view its context and source!
general_metric
15 May
"Here we are, leading up to the May 14 and 15 meeting between President Trump and President Xi and, God forbid, the 15th goes sideways.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
Shadow-y malware and legit Windows tools
In a separate instance, the incident responders found
Linux NoodleRat backdoors
- also widely used by Chinese espionage and cybercrime groups - deployed after Shadow-Earth-053 exploited another widely-ab…
In some instances, the group renamed legitimate Windows system binaries to evade process-based detection.
To move laterally through victim environments, Shadow-Earth-053 uses Windows Management Instrumentation Command-line (WMIC) and installs backdoors onto additional hosts.
Metrics
infrastructure
Linux
Affected Product
Shadow-y malware and legit Windows tools
In a separate instance, the incident responders found
Linux NoodleRat backdoors
- also widely used by Chinese espionage and cybercrime groups - deployed after Shadow-Earth-053 exploited another widely-ab…
In at least one case, the weaponization of the
React2Shell
(CVE-2025-55182) is said to have facilitated the distribution of a Linux version of
Noodle RAT
(aka ANGRYREBEL and Nood RAT).
Intelligence Sources
The Register - Cybercrime
2026-04-30
The Hacker News
2026-05-01
The Register - Cybercrime
2026-04-30
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-29T07:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
27x
organisation
Identified Entity
GitHub
entity
11x
target region
Target Country
Poland
country
10x
timeline
Temporal Reference
December 2024
date
9x
tactic
Cyber Operation Type
Reconnaissance
tactic
9x
attribution
Attributing Entity
Shadow-Earth-053
authority
6x
industry
Targeted Sector
Defense
sector
5x
vulnerability
Exploited CVE
CVE-2021-26855
cve
3x
source region
Origin Country
China
country
3x
threat actor
APT Group
APT41
actor
2x
infrastructure
Affected Product
Windows
software
2x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
Contextual Telemetry
Context Block
5 METRICS
malware
Malware Payload
ShadowPad
tool
general metric
Group
54
group
general metric
May
15
may
target region
Target Region
APAC
region
malware
Offensive Tool
Mimikatz
tool
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.