TGR-STA-1030, also tracked as UNC6619 and associated with the activity cluster known as the Shadow Campaigns, is a state-aligned cyber espionage actor assessed with high confidence to operate from Asia. Reporting consistently characterizes the group as an operationally mature espionage actor active since at least January 2024, with compromises of at least 70 government and critical infrastructure organizations across 37 countries and reconnaissance activity against government infrastructure associated with 155 countries. Multiple reports describe the activity as China-affiliated or aligned with Chinese regional interests, although some public reporting stops short of definitive state attribution. The actor primarily targets government ministries, law enforcement and border-control entities, finance ministries, diplomatic organizations, parliaments, telecommunications providers, energy-related organizations, mining interests, and other critical infrastructure. Victimology and timing indicate a strong focus on strategic, economic, political, military, and diplomatic intelligence collection, including interest in trade policy, natural resources, rare earth minerals, elections, and regional geopolitical developments. Recent activity has been observed across multiple countries, with a notable concentration in Central and South America. Initial access has been achieved through tailored phishing and exploitation of known public-facing vulnerabilities rather than zero-days. Phishing operations have used ministry-themed lures and staged malware delivery through hosted archives. The group has also attempted exploitation of vulnerabilities affecting enterprise platforms including Microsoft Exchange, SAP, Atlassian, Commvault, and other internet-facing systems. Post-compromise tradecraft includes deployment of multiple command-and-control frameworks, web shells, tunneling utilities, and long-term persistence mechanisms. Observed tooling includes Cobalt Strike, VShell, Havoc, Sliver, SparkRAT, Behinder, Godzilla, Neo-reGeorg, GOST, FRPS, and IOX. A notable capability attributed to the actor is ShadowGuard, a Linux eBPF kernel rootkit assessed as unique to this cluster in public reporting. ShadowGuard provides kernel-level stealth by hiding processes and artifacts and intercepting system calls, supporting prolonged covert access. The group has maintained access to some victim environments for months and exfiltrated sensitive data from email servers and file shares, including financial negotiations, contracts, banking information, and military-related operational updates. TGR-STA-1030 demonstrates broad reconnaissance, disciplined operational security, and sustained intelligence collection against state and critical-infrastructure targets worldwide. Its scale, geographic breadth, and focus on government and strategic sectors make it one of the more significant contemporary espionage clusters publicly documented under a temporary tracking designation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 malware families attributed to this actor across reporting.
9 additional families tracked in Mallory.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Targeted numerous government and critical infrastructure organizations in Mexico.
Threat group documented as breaching at least 70 government and critical infrastructure organizations across 37 countries; overlaps with NegativeGlimmer.
Active threat group conducting widespread operations across multiple countries, with recent activity heavily focused on Central and South America.
State-aligned cyberespionage activity cluster conducting broad reconnaissance and compromises of government and critical infrastructure across dozens of countries, with interest in economic partnerships and natural resources.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.