logo

The Shadow Campaigns: Uncovering Global Espionage

ID: 5c476c95-cb2c-5c7a-aa4e-6ed678fa7d2d

STIX ID: report--5c476c95-cb2c-5c7a-aa4e-6ed678fa7d2d

Feed Name: Palo Alto Networks Unit 42

Threat Score
90/100

Date Published: 2026-02-05

Date Updated: 2026-04-28

Author: Unit 42

...
...

Unit 42 attributes a large-scale, state-aligned cyberespionage campaign (TGR-STA-1030 / “Shadow Campaigns”) active since at least 2024 that has compromised government and critical-infrastructure organizations in 37 countries; the report documents phishing and exploitation tradecraft, payloads (Diaoyu loader, Cobalt Strike), a novel Linux eBPF rootkit (ShadowGuard), C2 tooling and infrastructure, targeted victimology, and provides IoCs and defensive guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.