China-backed hackers hit Asian govts, defence sectors, NATO countries: Report

New Delhi: China-aligned hackers have targeted government and defence sectors across South, East and Southeast Asia, along with a NATO member in Europe, in a fresh cyber espionage campaign, a report has claimed.

A report by The Hacker News highlighted that the activity has been attributed to a threat cluster tracked as ‘SHADOW-EARTH-053’, which researchers assess has been active since at least December 2024, and shares overlaps with previously identified groups such as Earth Alux and REF7707.

The campaign primarily exploits known vulnerabilities in internet-facing Microsoft Exchange Server and Internet Information Services (IIS) systems to breach unpatched networks, it said

It further highlighted that security researchers stated that the group exploits N-day vulnerabilities in internet-facing Microsoft Exchange and IIS servers, then deploys web shells for persistent access and stages ShadowPad implants.

Countries targeted include India, Thailand, Malaysia, Myanmar, Sri Lanka, Taiwan and Pakistan, while Poland was identified as the only European nation affected.

The attackers deploy web shells such as ‘Godzilla’ to maintain remote access and later install the ShadowPad malware using DLL side-loading techniques, often leveraging legitimate signed executables to evade detection.

The report noted that the intrusions begin with the exploitation of security flaws to gain initial access, followed by reconnaissance and lateral movement using tools such as Mimikatz and custom remote desktop protocol launchers.

In some cases, the campaign also involved the exploitation of a vulnerability dubbed ‘React2Shell’ to distribute a Linux variant of Noodle RAT, a remote access trojan.

The attack chain has been linked by other researchers to a group known as ‘UNC6595’.

The report noted overlaps with another intrusion set, ‘SHADOW-EARTH-054’, with nearly half of the observed targets, particularly in Malaysia, Sri Lanka and Myanmar — previously compromised, though no direct operational coordination has been confirmed.

To evade detection and maintain persistence, the attackers also used open-source tunnelling tools such as IOX, GOST and Wstunnel, along with packing utilities to conceal malicious binaries, according to the report.

Trend Micro advised organisations to prioritise patching of Microsoft Exchange and IIS systems and deploy intrusion prevention or web application firewall solutions where immediate updates are not feasible.

Meanwhile, researchers flagged phishing campaigns by two other China-linked groups, dubbed ‘GLITTER CARP’ and ‘SEQUIN CARP’, targeting journalists and civil society groups.

However, the campaigns, first detected in April and June 2025, impersonated journalists, organisations and technology firms in phishing emails aimed at stealing credentials or gaining access to accounts.

IANS

 

Slow-moving crisis unfolding in China’s factories: Report

New Delhi: A slow-moving crisis is unfolding in China’s factories and manufacturing hubs which is not a cyclical correction; it is the convergence of multiple structural failures arriving simultaneously, and...

US Navy’s blockade of Iran hits China’s cheap oil deals: Report

New Delhi: The US Navy's blockade of Iran has built economic pressure on Tehran that continues even though the ceasefire has led to a temporary pause in fighting, according to...

China threat dominates US defence debate

Washington: China’s growing military assertiveness and its alignment with Russia, Iran and North Korea emerged as a central theme during a high-stakes US Senate hearing on defence spending, with potential...

National plot to shrink Maratha history, says Shiv Sena(UBT) in ‘Saamana’

Mumbai: The Shiv Sena Uddhav Balasaheb Thackeray (UBT) on the 67th Foundation Day of Maharashtra on Friday claimed that the Marathi people were being cornered by "Maharashtra-haters" and "subservient" local...

Europe faces intensifying climate extremes as reports warn of accelerating warming

Geneva: Multiple reports have painted a stark picture of accelerating climate extremes, with Europe warming faster than any other continent. The findings underscore that climate change has become an urgent...

Pentagon official says Iran war has cost $25 billion so far

Washington: A senior Pentagon official has said that the cost of the ongoing US war against Iran is estimated to be 25 billion US dollars so far, as the conflict...

92 pc monsoon forecast, 35 pc deficit risk cloud FY27 farm outlook

New Delhi: India’s agricultural outlook for FY27 likely to remain uneven despite underlying stability, with a 92 per cent monsoon forecast and a 35 per cent probability of deficient rainfall...

‘This is not development but destruction’: Rahul Gandhi after visiting Great Nicobar Island

New Delhi: Congress leader Rahul Gandhi on Wednesday launched a sharp attack on the Centre’s Great Nicobar Island development project after visiting the region, describing it as “one of the...

Uma Bharti backs reservation, calls for ‘third freedom struggle’ to achieve social equality

Bhopal: Veteran BJP leader and former Madhya Pradesh Chief Minister Uma Bharti on Tuesday strongly endorsed the reservation policy, describing it as an essential instrument for achieving social justice, and...

China threat drives US missile defence rethink

Washington: China’s expanding missile arsenal and evolving military capabilities are reshaping US defence planning, with senior Pentagon officials telling lawmakers that Beijing remains the central strategic challenge driving a new...

US lawmakers push Golden Dome plan amid rising missile threats

Washington: The United States faces an “unprecedented” missile threat environment, with senior defence officials warning lawmakers that the country’s current homeland defences are limited and increasingly vulnerable to advanced weapons,...

Concerns of Matua community may influence phase two of West Bengal Assembly polls

New Delhi: When West Bengal goes to poll in the second and last phase of Assembly election on Wednesday, the Matua community will hold an important position in determining the...

Read Previous

Slow-moving crisis unfolding in China’s factories: Report

WP2Social Auto Publish Powered By : XYZScripts.com