The Shadow Campaigns: Uncovering Global Espionage
ID: 5c476c95-cb2c-5c7a-aa4e-6ed678fa7d2d
STIX ID: report--5c476c95-cb2c-5c7a-aa4e-6ed678fa7d2d
Feed Name: Palo Alto Networks Unit 42
Threat Score
Unit 42 attributes a large-scale, state-aligned cyberespionage campaign (TGR-STA-1030 / “Shadow Campaigns”) active since at least 2024 that has compromised government and critical-infrastructure organizations in 37 countries; the report documents phishing and exploitation tradecraft, payloads (Diaoyu loader, Cobalt Strike), a novel Linux eBPF rootkit (ShadowGuard), C2 tooling and infrastructure, targeted victimology, and provides IoCs and defensive guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
