“JackMa” & ShadowGuard: TGR-STA-1030 Spies on 37 Nations via Linux Rootkit
ID: a78b7646-5400-5a79-89aa-b0182e8cb376
STIX ID: report--a78b7646-5400-5a79-89aa-b0182e8cb376
Feed Name: securityonline.info
Threat Score
Unit 42 details a large, state-aligned cyber-espionage campaign by TGR-STA-1030 (UNC6619) that has compromised at least 70 organizations across 37 countries using phishing-lured Diaoyu Loader and a novel eBPF-based Linux rootkit called ShadowGuard; targets include ministries of finance, law enforcement, and critical infrastructure, with operations timed to geopolitical events.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
