May 6, 2026
SHADOW-EARTH-053 is exploiting known Microsoft Exchange and IIS vulnerabilities, including the ProxyLogon chain, to target government, defense, technology, and critical infrastructure organizations. This analysis explains how the China-aligned campaign uses GODZILLA web shells, ShadowPad malware, DLL sideloading, credential tools, WMIC, and proxy utilities, and what organizations should do to improve detection, incident response, penetration testing, and Exchange Server protection.






