logo

Threat Group Running Espionage Operations Against Dozens of Governments

ID: 6935330d-ed35-58fb-baa9-0519f1cd9f8d

STIX ID: report--6935330d-ed35-58fb-baa9-0519f1cd9f8d

Feed Name: Security Boulevard

Threat Score
92/100

Date Published: 2026-02-05

Date Updated: 2026-04-22

Author: Jeffrey Burt

...
...

Unit 42 attributes a sustained, Asia-aligned nation-state espionage campaign (tracked as TGR-STA-1030 / "Shadow Campaigns") active since at least January 2024 that has compromised ministries, law enforcement, telcos, parliaments and other government and critical infrastructure across 37 countries and conducted reconnaissance on many more; the group uses targeted phishing and exploitation of multiple N-day vulnerabilities to deliver loaders (Daioyu) and Cobalt Strike, maintains diverse C2 and tunneling infrastructure, and deploys a novel Linux eBPF kernel rootkit called ShadowGuard to hide activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.