Threats · 136 days ago

Exchange N-day Abuse Expands Espionage Reach Across Governments

Unpatched Exchange and IIS servers are still a live espionage entry point. The standard response is to treat this as a one-off intrusion, but the pattern here is sustained access: once the flaws are used, web shells and follow-on implants keep the target open for later collection and movement.

Trend Micro attributes the activity to SHADOW-EARTH-053, a China-linked cluster active since at least December 2024. The campaign has hit government and defense targets across South, East, and Southeast Asia, plus Poland, and it uses known flaws such as CVE-2025-55182 to gain access before deploying Godzilla web shells and ShadowPad.

The broader risk is scale and deniability. The overlap with other tracked clusters and the use of commercial tooling and signed binaries suggest this kind of espionage can be handed off, reused, and repeated across regional government targets without needing a fresh exploit each time.

CVE-2025-55182

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: a pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0… Known ransomware campaign use. EPSS 100% (100th percentile).

CISA federal remediation date Dec 12 · date passed

Timeline

Sources

1 source covering this story

Entities

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-05-03

Editions