Asia-based government spies quietly broke into critical networks across 37 countries
ID: 724cc159-62c2-5b34-9cf8-845896c80fd3
STIX ID: report--724cc159-62c2-5b34-9cf8-845896c80fd3
Feed Name: The Register (Security)
Palo Alto Networks Unit 42 details a large-scale, state-aligned espionage campaign by a group tracked as TGR-STA-1030 that compromised at least 70 government and critical infrastructure organizations across 37 countries. The actor used phishing lures and exploited known vulnerabilities in Microsoft Exchange, SAP, and Atlassian to deploy a malware loader ('DiaoYu.exe') and a novel Linux eBPF rootkit ('ShadowGuard'), conducting widespread reconnaissance and exfiltrating sensitive email and operational data with potential national-security impacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
