logo

Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure Entities

ID: 43bfd5fc-bc66-54fd-a834-eee57454c599

STIX ID: report--43bfd5fc-bc66-54fd-a834-eee57454c599

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-02-06

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** Palo Alto Networks Unit 42 has identified a previously undocumented, state-motivated espionage group dubbed TGR-STA-1030 (assessed Asian origin) that since January 2024 has compromised at least 70 government and critical-infrastructure organizations across 37 countries, using phishing-delivered Diaoyu Loader, Cobalt Strike, web shells, N-day exploits, and an eBPF-based Linux rootkit (ShadowGuard) to maintain long-term access and exfiltrate sensitive email, financial, and military-related data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.