logo

Asia-based government spies quietly broke into critical networks across 37 countries

ID: 724cc159-62c2-5b34-9cf8-845896c80fd3

STIX ID: report--724cc159-62c2-5b34-9cf8-845896c80fd3

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2026-02-05

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Palo Alto Networks Unit 42 details a large-scale, state-aligned espionage campaign by a group tracked as TGR-STA-1030 that compromised at least 70 government and critical infrastructure organizations across 37 countries. The actor used phishing lures and exploited known vulnerabilities in Microsoft Exchange, SAP, and Atlassian to deploy a malware loader ('DiaoYu.exe') and a novel Linux eBPF rootkit ('ShadowGuard'), conducting widespread reconnaissance and exfiltrating sensitive email and operational data with potential national-security impacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.