ShadowPad Espionage Campaign Targets Exchange and IIS Servers
Unpatched Exchange and IIS servers are being used as long-term footholds, not just entry points. The standard response of fixing the server misses the bigger problem: once ShadowPad lands, the actor can stay inside for surveillance across government, defense, media, and critical infrastructure networks.
Trend Micro attributes the activity to Shadow-Earth-053, a China-aligned cluster active since at least December 2024. The campaign uses known Microsoft Exchange and IIS flaws — CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 — and has reached organizations across South, East, and Southeast Asia, with spillover into at least one NATO member state.
The targeting of journalists and civil society activists points to collection and influence goals, not simple theft. Persistent ShadowPad implants mean the risk continues after initial access is closed, because the operator is built for staying power and monitoring.