NegativeGlimmer is a China-aligned threat actor involved in cyber espionage activity. ESET reported the group compromising governmental entities in Cambodia and Panama, as well as an AI and robotics company in South Korea. Reporting linked the South Korean targeting to Beijing’s interest in strategic technologies under the Made in China 2025 policy. ESET also reported that in December 2025 the group targeted a governmental organization in Panama using a spear-phishing and DLL side-loading infection chain to deploy a downloader that installed AdaptixC2 and displayed a decoy document. Later iterations observed in January 2026 in Cambodia and South Korea replaced AdaptixC2 with Cobalt Strike. The group is believed to share some level of overlap with TGR-STA-1030, which Palo Alto Networks Unit 42 documented as having breached at least 70 government and critical infrastructure organizations across 37 countries over the past year. Known alias in the provided content: negativeglimmer.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-affiliated threat group overlapping with TGR-STA-1030; observed using spear-phishing and DLL side-loading to deliver AdaptixC2 and later Cobalt Strike against government targets.
Compromised government entities in Cambodia and Panama and an AI and robotics company in South Korea, consistent with espionage and strategic technology collection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.