INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ATTENTION: This report is based on previous data. New intelligence sources have been linked and the Executive Summary and Mitigations need to be re-synthesized.

Chinese Hackers Target Governments, State and Journalists

| 2026-04-30 11:00 CRITICAL HIGH
Executive Summary AI-generated
China-linked hackers have launched a new espionage campaign targeting governments, defense sectors and civil society organizations across South, East, and Southeast Asia. The campaigns include phishing attacks, command execution via web shells, and the deployment of ShadowPad backdoors through AnyDesk. Targets include Pakistan, Thailand, Malaysia, India, Myanmar, Sri Lanka, and Taiwan. A cybersecurity vendor has observed nearly half of these targets being compromised earlier by a related intrusion set dubbed SHADOW-EARTH-054. The campaigns also involve digital impersonation schemes in phishing emails and the use of Mimikatz malware to facilitate privilege escalation.
Technical Mitigations AI-generated
* Apply the latest security updates and cumulative patches to Microsoft Exchange: Trend Micro recommends prioritizing applying the latest security updates and cumulative patches to Microsoft Exchange, as vulnerabilities in internet-facing IIS applications can be exploited by China-linked hackers. * Use Intrusion Prevention Systems (IPS) or Web Application Firewalls (WAF): Organizations should strongly recommend deploying IPS or WAFs with rulesets specifically tuned to block exploit attempts against known CVEs (Virtual Patching). * Implement a web application firewall: A web application firewall can help prevent attacks by blocking malicious traffic and protecting against vulnerabilities in internet-facing applications. * Use secure protocols for remote access: Implement secure remote desktop protocol (RDP) launchers, such as RingQ, to pack malicious binaries and evade detection. Use alternative protocols like SSH or VPNs instead of RDP. * Monitor network activity for suspicious behavior: Regularly monitor network activity for suspicious behavior, including phishing campaigns, malware infections, and unauthorized access attempts.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Volt TyphoonVolt TyphoonAPT41APT41Salt TyphoonSalt Typhoon ShadowPadShadowPad CVE-2021-26857CVE-2021-26857 CVE-2025-55182CVE-2025-55182 CVE-2021-26855CVE-2021-26855 CVE-2021-26858CVE-2021-26858 CVE-2021-27065CVE-2021-27065
Target & Sectors
SOUTH_ASIA SOUTH_ASIA NORTH_AMERICA NORTH_AMERICA ASEAN ASEAN governmentgovernment energyenergy technologytechnology defensedefense telecommunicationstelecommunications transportationtransportation
Incident Timeline
‎mid-2021
China-linked hackers exploited vulnerabilities in US critical infrastructure to target governments, journalists, and activists.
target_region United States
‎late 2023
China-linked hackers were first discovered targeting Asian governments and NATO state in late 2023.
‎at least December 2024
Threat actors used a China-linked hacking collective to target Asian governments, NATO state journalists and activists.
‎December 2024
Threat actors used the React2Shell exploit to target Asian governments, NATO state, journalists, and activists.
source_region China
source_region Poland
organisation Uyghur
organisation SHADOW
organisation AnyDesk
organisation Microsoft Exchange
organisation Internet Information Services
organisation ProxyLogon
organisation DLL
infrastructure Linux
organisation ANGRYREBEL
organisation Intrusion Prevention Systems
organisation Virtual Patching
‎July 2025
China-linked hackers targeted Asian governments, NATO states, journalists, and activists using phishing emails with 1x1 tracking pixels.
organisation UNK_SparkyCarp
organisation The Citizen Lab
organisation HealthKick
organisation SEQUIN
‎April and June 2025
Threat actors used phishing campaigns to target Asian governments, NATO state journalists and activists in April 2025.
‎2026/05/01
China-Linked Hackers Target Asian Governments, NATO State, Journalists, and Activists.
organisation NATO State
infrastructure Linux
infrastructure Windows
organisation Microsoft
organisation Palo Alto Networks'
organisation Elastic Security Labs
threat_actor Salt Typhoon
threat_actor Volt Typhoon
threat_actor APT41
organisation GitHub
organisation Microsoft Exchange Servers
organisation NATO
organisation AnyDesk
organisation Trend Micro
organisation Microsoft Exchange
organisation ProxyLogon
organisation DNS
organisation Shadow-Earth-054
organisation Shadow-Earth-053
organisation Shadow-Earth-053's
organisation Exchange
‎May 14
China-linked hackers targeted Asian governments, NATO state, journalists, and activists on May 14.
general_metric 15 May
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Linux
Affected Product