logo

“JackMa” & ShadowGuard: TGR-STA-1030 Spies on 37 Nations via Linux Rootkit

ID: a78b7646-5400-5a79-89aa-b0182e8cb376

STIX ID: report--a78b7646-5400-5a79-89aa-b0182e8cb376

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-02-09

Date Updated: 2026-04-23

Author: Ddos

...
...

Unit 42 details a large, state-aligned cyber-espionage campaign by TGR-STA-1030 (UNC6619) that has compromised at least 70 organizations across 37 countries using phishing-lured Diaoyu Loader and a novel eBPF-based Linux rootkit called ShadowGuard; targets include ministries of finance, law enforcement, and critical infrastructure, with operations timed to geopolitical events.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.