Exchange N-day Abuse Expands Espionage Reach Across Governments

Unpatched Exchange and IIS servers are still a live espionage entry point. The standard response is to treat this as a one-off intrusion, but the pattern here is sustained access: once the flaws are used, web shells and follow-on implants keep the target open for later collection and movement. Trend Micro attributes the activity to SHADOW-EARTH-053, a China-linked cluster active since at least December 2024. The campaign has hit government and defense targets across South, East, and Southeast Asia, plus Poland, and it uses known flaws such as CVE-2025-55182 to gain access before deploying Godzilla web shells and ShadowPad. The broader risk is scale and deniability. The overlap with other tracked clusters and the use of commercial tooling and signed binaries suggest this kind of espionage can be handed off, reused, and repeated across regional government targets without needing a fresh exploit each time.

Part of the PlainSec briefing for 2026-05-03

Sources