NegativeGlimmer
NegativeGlimmer is a China-aligned threat actor involved in cyber espionage activity. ESET reported the group compromising governmental entities in Cambodia and Panama, as well as an AI and robotics company in South Korea. Reporting linked the South Korean targeting to Beijing’s interest in strategic technologies under the Made in China 2025 policy. ESET also reported that in December 2025 the group targeted a governmental organization in Panama using a spear-phishing and DLL side-loading infection chain to deploy a downloader that installed AdaptixC2 and displayed a decoy document. Later iterations observed in January 2026 in Cambodia and South Korea replaced AdaptixC2 with Cobalt Strike. The group is believed to share some level of overlap with TGR-STA-1030, which Palo Alto Networks Unit 42 documented as having breached at least 70 government and critical infrastructure organizations across 37 countries over the past year. Known alias in the provided content: negativeglimmer.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
- Utilities
Where they target
Geographies tied to known operations.
- 🇵🇦 Panama
- 🇰🇭 Cambodia
- 🇰🇷 South Korea
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-affiliated threat group overlapping with TGR-STA-1030; observed using spear-phishing and DLL side-loading to deliver AdaptixC2 and later Cobalt Strike against government targets.
Compromised government entities in Cambodia and Panama and an AI and robotics company in South Korea, consistent with espionage and strategic technology collection.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.