Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure Entities
ID: 43bfd5fc-bc66-54fd-a834-eee57454c599
STIX ID: report--43bfd5fc-bc66-54fd-a834-eee57454c599
Feed Name: The Hacker News
**Executive summary:** Palo Alto Networks Unit 42 has identified a previously undocumented, state-motivated espionage group dubbed TGR-STA-1030 (assessed Asian origin) that since January 2024 has compromised at least 70 government and critical-infrastructure organizations across 37 countries, using phishing-delivered Diaoyu Loader, Cobalt Strike, web shells, N-day exploits, and an eBPF-based Linux rootkit (ShadowGuard) to maintain long-term access and exfiltrate sensitive email, financial, and military-related data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
