Threat Group Running Espionage Operations Against Dozens of Governments
ID: 6935330d-ed35-58fb-baa9-0519f1cd9f8d
STIX ID: report--6935330d-ed35-58fb-baa9-0519f1cd9f8d
Feed Name: Security Boulevard
Unit 42 attributes a sustained, Asia-aligned nation-state espionage campaign (tracked as TGR-STA-1030 / "Shadow Campaigns") active since at least January 2024 that has compromised ministries, law enforcement, telcos, parliaments and other government and critical infrastructure across 37 countries and conducted reconnaissance on many more; the group uses targeted phishing and exploitation of multiple N-day vulnerabilities to deliver loaders (Daioyu) and Cobalt Strike, maintains diverse C2 and tunneling infrastructure, and deploys a novel Linux eBPF kernel rootkit called ShadowGuard to hide activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
