INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Exploiting Sleep Cycle Rats for Network Infiltration

| 2026-04-30 11:00 CRITICAL HIGH MALWARE & BOTNETS
Executive Summary
AI-generated
The discovery of a novel Chinese spy group infiltrating critical networks in Poland, Asia and potentially beyond has sent shockwaves through the cybersecurity community. The threat actors, described as APT41, have been linked to several high-profile intrusions dating back to 2019, including the compromise of victim organizations up to eight months prior deployment of ShadowPad a custom backdoor used by China's notorious Advanced Persistent Threat group APT41 for nearly a decade. This latest intrusion has highlighted how cyber espionage and warfare are burgeoning, with NATO countries like Poland being targeted. The researchers at TrendAI have identified the new group as Shadow-Earth-053 which is believed to be linked to this threat, further emphasizing the need for increased vigilance in protecting against these sophisticated attacks.
Technical Mitigations AI-generated
• Use secure protocols such as HTTPS and SFTP to encrypt data in transit. • Regularly update and patch Microsoft Exchange Server vulnerabilities, including ProxyLogon (CVE-2021-26855). • Implement a web application firewall (WAF) to detect and block suspicious traffic patterns. • Monitor network activity for signs of unusual or unauthorized access attempts.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Volt TyphoonVolt TyphoonAPT41APT41Salt TyphoonSalt Typhoon ShadowPadShadowPad CVE-2021-26857CVE-2021-26857 CVE-2025-55182CVE-2025-55182 CVE-2021-26855CVE-2021-26855 CVE-2021-26858CVE-2021-26858 CVE-2021-27065CVE-2021-27065
Target & Sectors
SOUTH_ASIA SOUTH_ASIA NORTH_AMERICA NORTH_AMERICA ASEAN ASEAN defensedefense energyenergy governmentgovernment technologytechnology transportationtransportation
Incident Timeline
‎mid-2021
Chinese hackers followed in the footsteps of mid-2021 incident And Volt, burrowing deep into critical US networks to prepare for future destructive attacks.
target_region United States
‎late 2023
Chinese hackers gained access to governments, state and journalists' computer systems in late 2023.
‎December 2024
China-linked threat group infiltrated critical networks in Poland and other countries.
source_region China
source_region Poland
‎at least December 2024
Chinese hackers are suspected of targeting governments, state and journalists since at least December 2024.
‎July 2025
Chinese hackers used UNK_SparkyCarp to target governments and state entities in July 2025.
organisation UNK_SparkyCarp
‎April and June 2025
Chinese hackers launched targeted cyberattacks on governments, state institutions and journalists in April and June 2025.
‎2026/04/30
Shadow-Earth-053 used Mimikatz to gain initial access and Sharp-SMBExec for lateral movement.
organisation NATO
infrastructure Windows
infrastructure Linux
organisation Microsoft
organisation Palo Alto Networks'
organisation Elastic Security Labs
threat_actor Salt Typhoon
threat_actor Volt Typhoon
organisation NATO State
threat_actor APT41
organisation GitHub
organisation Microsoft Exchange Servers
organisation Uyghur
organisation AnyDesk
organisation ProxyLogon
organisation Microsoft Exchange
organisation Internet Information Services
organisation DLL
organisation Shadow-Earth-053's
organisation SHADOW
organisation ANGRYREBEL
organisation DNS
organisation Shadow-Earth-054
organisation Shadow-Earth-053
organisation Exchange
organisation The Citizen Lab
organisation HealthKick
organisation Trend Micro
organisation Intrusion Prevention Systems
organisation Virtual Patching
organisation SEQUIN
‎May 14
Chinese hackers accessed government and state computer systems on May 14.
general_metric 15 May
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Linux
Affected Product