<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Shadowpad on karmine&#39;s notes</title>
    <link>https://karmine05.github.io/dirtyfrag-blog/tags/shadowpad/</link>
    <description>Recent content in Shadowpad on karmine&#39;s notes</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <managingEditor>dhruv@fleetdm.com (Dhruv Majumdar)</managingEditor>
    <webMaster>dhruv@fleetdm.com (Dhruv Majumdar)</webMaster>
    <copyright>© 2026 karmine&#39;s notes</copyright>
    <lastBuildDate>Tue, 26 May 2026 11:00:00 -0400</lastBuildDate><atom:link href="https://karmine05.github.io/dirtyfrag-blog/tags/shadowpad/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title>SHADOW-EARTH-053 — Threat Brief, Kill Chain, and Validated Fleet Queries</title>
      <link>https://karmine05.github.io/dirtyfrag-blog/posts/shadow-earth-053-fleet-detections/</link>
      <pubDate>Tue, 26 May 2026 11:00:00 -0400</pubDate>
      <author>dhruv@fleetdm.com (Dhruv Majumdar)</author>
      <guid>https://karmine05.github.io/dirtyfrag-blog/posts/shadow-earth-053-fleet-detections/</guid>
      <description>Trend Micro disclosed SHADOW-EARTH-053 on 30 April 2026 — a China-aligned cyberespionage campaign exploiting ProxyLogon against unpatched Microsoft Exchange and IIS to deploy GODZILLA web shells and ShadowPad across South, East, and Southeast Asia plus one NATO target. This brief documents the campaign through Lockheed&amp;rsquo;s seven kill-chain stages with a Diamond Model rendered for each stage, consolidates the atomic indicators, and ships a vetted Fleet/osquery detection pack. Every query in the pack has been audited against fleetdm.com/tables before publication — schema bugs in the publicly circulating versions are called out and corrected inline.</description>
      
    </item>
    
  </channel>
</rss>
