logo

Asian Cyber Espionage Campaign Breached 37 Countries

ID: f3b6c39e-f1f8-5f45-8f2d-4a4d3a8cb057

STIX ID: report--f3b6c39e-f1f8-5f45-8f2d-4a4d3a8cb057

Feed Name: TechRepublic Security

Threat Score
90/100

Date Published: 2026-02-06

Date Updated: 2026-04-23

Author: Kezia Jungco

...
...

Palo Alto Networks observed a widespread state-aligned cyberespionage campaign (TGR-STA-1030) that compromised government agencies and critical infrastructure across 37 countries and at least 70 organizations; attackers used phishing and exploits of known products (e.g., Microsoft Exchange, SAP Solution Manager) and deployed a novel Linux kernel rootkit, ShadowGuard, to maintain stealth while collecting economic and diplomatic intelligence related to trade, rare earths, and geopolitics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.