Chinese Hackers Target Governments and Journalists in Asia and Europe
Researchers uncover a China-linked cyber espionage campaign affecting governments, journalists, and activists in Asia and a NATO nation.

Chinese Hackers Target Governments and Journalists in Asia and Europe
Recent findings in the field of cybersecurity reveal a sophisticated espionage campaign orchestrated by a hacking group with links to China. The operation has targeted government entities and defense sectors in South, East, and Southeast Asia, as well as a European NATO member state. Detailed information comes from the cybersecurity firm Trend Micro, which has identified this activity under the temporary designation SHADOW-EARTH-053.
Scope and Objectives of the Espionage Campaign
The SHADOW-EARTH-053 campaign stands out for its broad geographic scope and the diversity of its targets. Beyond government and military agencies, the research indicates that journalists and activists have also been targeted, suggesting a multifaceted strategy to obtain sensitive information and exert influence.
The nature of the attacks points to a prolonged cyber espionage effort designed to infiltrate networks, exfiltrate data, and potentially maintain persistent access. While specific details regarding exploiting tactics and the type of information sought are still being declassified, the attribution to a China-aligned actor raises concerns within the international security community.
Implications and Cybersecurity Risks
These types of operations underscore the growing threat posed by state-sponsored actors in cyberspace. The ability of these groups to launch complex and targeted attacks highlights the need to strengthen digital defenses globally. The possibility that previously unknown or neglected vulnerabilities are used to achieve intrusion is a constant concern. In fact, we have seen how security flaws, such as a critical vulnerability in cPanel, can open the door to hacking risks and active attacks.
Furthermore, although the Trend Micro report does not explicitly mention the use of ransomware, the sophistication of these groups implies they could employ various malicious tools. CISA's warning about new critical vulnerabilities and the associated risk of ransomware serves as a constant reminder of evolving threats.
Conclusion: Strengthening Digital Defense
The SHADOW-EARTH-053 campaign is a clear indicator of the persistent threat of cyber espionage and information warfare. Protecting critical infrastructure, government data, and freedom of the press requires constant vigilance and continuous investment in cybersecurity. International collaboration and intelligence sharing are fundamental to effectively countering these malicious actors and mitigating the risk of future attacks.
Source: The Hacker News (https://thehackernews.com/2026/05/china-linked-hackers-target-asian.html)
Related articles
7 de septiembre de 2026
Cybersecurity: New ScreenConnect vulnerability facilitates attacks
Researchers have detected a four-stage infection chain that uses ScreenConnect to compromise systems through malicious scripts.
30 de agosto de 2026
Breach at Manchester Airports Group: The hack exposing 86 GB of data
The group FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group, revealing sensitive passenger and booking information.
23 de agosto de 2026
Hackers infect Android car systems: the new vulnerability
A supply chain attack is turning Android-based automotive multimedia systems into part of a botnet, putting driver security at risk.
16 de agosto de 2026
AmnesiaStealer: The new hack compromising macOS security
We analyze AmnesiaStealer, a macOS malware that enables remote browser control and puts user privacy at risk.
Loading comments...