Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
government-diplomatic-threatstate-sponsored-espionagecritical-infrastructure-threattelecommunications-sector-threat

Unit 42 Reports Asia-Based State-Aligned Espionage Campaign Compromising 37 Governments

Updated 3mo agoFirst seen Feb 5, 20268 sources

Palo Alto Networks Unit 42 reported a large-scale cyberespionage operation, tracked as TGR-STA-1030 and dubbed the Shadow Campaigns, assessing with high confidence the actor is state-aligned and operating out of Asia. Unit 42 documented compromises of government and critical infrastructure organizations across 37 countries over roughly the past year, and observed active reconnaissance against government infrastructure associated with 155 countries (notably during November–December 2025). The activity was characterized as unusually broad in scope, with Unit 42 describing it as among the most widespread compromises of global government infrastructure in years.

The operation primarily targeted government ministries and departments, with confirmed compromises including national-level law enforcement/border control entities and ministries aligned to finance, trade, natural resources, and diplomatic functions; reporting also cited intrusions affecting national telecommunications companies, police agencies, counterterrorism departments, and multiple interior/foreign affairs-related bodies. Unit 42 stated it notified impacted entities via responsible disclosure and published technical details on the actor’s phishing and exploitation techniques, tooling, and infrastructure, along with defensive indicators intended to support detection and response; public reporting noted Unit 42 did not attribute the campaign to a specific country, while comparing its scale to other recent China-linked activity such as Volt Typhoon and Salt Typhoon in terms of strategic risk and potential long-term national security impact.

Share:
Unit 42 Reports Asia-Based State-Aligned Espionage Campaign Compromising 37 Governments
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Feb 5, 20265mo ago

CISA confirms tracking and coordination on TGR-STA-1030

Following the report's release, CISA confirmed it was tracking TGR-STA-1030 and coordinating with partners to detect and mitigate exploitation of the vulnerabilities described by researchers. This marked an official government response to the disclosed campaign.

ShadowGuard rootkit and IOCs are disclosed

In the same public reporting, Unit 42 revealed a previously undocumented Linux eBPF kernel rootkit called ShadowGuard, assessed as unique to the actor. The publication also included indicators of compromise such as IPs, domains, and file hashes.

Unit 42 publicly exposes the 'Shadow Campaigns' operation

On February 5, 2026, Palo Alto Networks Unit 42 published its report on the 'Shadow Campaigns,' attributing the activity with high confidence to an Asia-based state-aligned actor tracked as TGR-STA-1030/UNC6619. The report detailed the group's phishing and N-day exploitation tradecraft, victimology, infrastructure, and broad global scope.

Unit 42 disrupts some intrusions and notifies victims

Before public disclosure, Palo Alto Networks Unit 42 said it pushed the actors out of some affected government networks, notified impacted entities, and shared indicators with industry peers and Cyber Threat Alliance members. The researchers also monitored for attempted re-entry.

Dec 31, 20256mo ago

Campaign compromises organizations across 37 countries

Over the following year, TGR-STA-1030 compromised at least 70 government and critical-infrastructure organizations in 37 countries. Some intrusions persisted for months and included exfiltration of sensitive data from victim email servers and file shares.

Nov 1, 20258mo ago

Actor conducts global government reconnaissance surge

Between November and December 2025, the group carried out targeted reconnaissance against government infrastructure associated with 155 countries. Researchers said the activity was timed in part around geopolitical events and shifts in international affairs.

Jan 1, 20242y ago

TGR-STA-1030 begins cyberespionage activity

Unit 42 assessed the Asia-based, state-aligned cluster TGR-STA-1030/UNC6619 has been active since at least January 2024. The group began targeting government and critical-infrastructure organizations using phishing and exploitation of known vulnerabilities.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

62 LINKEDOpen in app
Threat actors
1 linked
Affected products
10 linked
CommcellExchange ServerKaspersky Anti-VirusVirustotalGithubNorton SecurityTorWordpressGithubNorton Security
Organizations
36 linked
Palo Alto NetworksSAPMicrosoft CorporationMegaBroadcomGitHubCommvaultD-LinkRescanaBridgePay Network SolutionsKasperskySentinelOneBitdefenderAviraAtlassianRuijie NetworksEyouAlibaba CloudTencentThe RegisterEnvatoAmazon Web ServicesNVISOVirustotalRecorded FutureAvastZhejiang Huayou CobaltSolarWindsTinesAvira Operations GmbH & Co. KGVenezolana de Industria TecnológicaSerra VerdeSino-Metals Leach ZambiaAnquankeYunfeng CapitalDataImpulse
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Unit 42 Reports Asia-Based State-Aligned Espionage Campaign Compromising 37 Governments | Mallory