logo

State actor targets 155 countries in 'Shadow Campaigns' espionage op

ID: 64e0ec13-f6e4-5416-acfc-98d0fff948a6

STIX ID: report--64e0ec13-f6e4-5416-acfc-98d0fff948a6

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-02-07

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Unit 42 attributes a global, state-sponsored espionage operation called "Shadow Campaigns" to an actor tracked as TGR-STA-1030/UNC6619, reporting at least 70 confirmed compromises across 37 countries and reconnaissance targeting entities connected to 155 countries; victims include government ministries, critical infrastructure and diplomatic bodies. The actor used tailored phishing (malicious archives on Mega.nz with a Diaoyu loader that fetches Cobalt Strike and VShell), exploitation of ~15 known vulnerabilities, webshells and tunneling tools, and a custom Linux eBPF rootkit (“ShadowGuard”) to maintain stealthy persistence; IoCs and TTPs are provided for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.