TGR-STA-0051 is a temporary state-backed threat actor designation used by Palo Alto Networks Unit 42 for activity assessed with sufficient correlation to represent a single actor or closely related operational grouping, but not yet mature enough for a formal named actor attribution. The designation emerged from the convergence of multiple previously tracked activity clusters, including CL-STA-0042 and CL-STA-0073, after analysts identified overlaps in adversary infrastructure, phishing operations, tooling, malware, and custom-developed components. Activity associated with TGR-STA-0051 includes repeated targeting of medical organizations in the United States. Reported tradecraft includes exploitation of the same vulnerabilities for initial access across separate victim environments, followed by similar lateral movement and data exfiltration patterns. The actor or associated operators also reused command-and-control infrastructure across incidents. The grouping reflects a state-backed assessment and demonstrates coordinated operational behavior across multiple intrusions rather than a single isolated campaign. TGR-STA-0051 is not a formally named intrusion set or public alias-rich actor cluster; it is an intermediate analytic construct used to consolidate related state-backed activity while attribution confidence is still developing. No additional high-confidence aliases, sub-groups, or broader victimology are currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.