Palo Alto Networks Unit 42 reported a large-scale cyberespionage operation, tracked as TGR-STA-1030 and dubbed the Shadow Campaigns, assessing with high confidence the actor is state-aligned and operating out of Asia. Unit 42 documented compromises of government and critical infrastructure organizations across 37 countries over roughly the past year, and observed active reconnaissance against government infrastructure associated with 155 countries (notably during November–December 2025). The activity was characterized as unusually broad in scope, with Unit 42 describing it as among the most widespread compromises of global government infrastructure in years.
The operation primarily targeted government ministries and departments, with confirmed compromises including national-level law enforcement/border control entities and ministries aligned to finance, trade, natural resources, and diplomatic functions; reporting also cited intrusions affecting national telecommunications companies, police agencies, counterterrorism departments, and multiple interior/foreign affairs-related bodies. Unit 42 stated it notified impacted entities via responsible disclosure and published technical details on the actor’s phishing and exploitation techniques, tooling, and infrastructure, along with defensive indicators intended to support detection and response; public reporting noted Unit 42 did not attribute the campaign to a specific country, while comparing its scale to other recent China-linked activity such as Volt Typhoon and Salt Typhoon in terms of strategic risk and potential long-term national security impact.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Following the report's release, CISA confirmed it was tracking TGR-STA-1030 and coordinating with partners to detect and mitigate exploitation of the vulnerabilities described by researchers. This marked an official government response to the disclosed campaign.
In the same public reporting, Unit 42 revealed a previously undocumented Linux eBPF kernel rootkit called ShadowGuard, assessed as unique to the actor. The publication also included indicators of compromise such as IPs, domains, and file hashes.
On February 5, 2026, Palo Alto Networks Unit 42 published its report on the 'Shadow Campaigns,' attributing the activity with high confidence to an Asia-based state-aligned actor tracked as TGR-STA-1030/UNC6619. The report detailed the group's phishing and N-day exploitation tradecraft, victimology, infrastructure, and broad global scope.
Before public disclosure, Palo Alto Networks Unit 42 said it pushed the actors out of some affected government networks, notified impacted entities, and shared indicators with industry peers and Cyber Threat Alliance members. The researchers also monitored for attempted re-entry.
Over the following year, TGR-STA-1030 compromised at least 70 government and critical-infrastructure organizations in 37 countries. Some intrusions persisted for months and included exfiltration of sensitive data from victim email servers and file shares.
Between November and December 2025, the group carried out targeted reconnaissance against government infrastructure associated with 155 countries. Researchers said the activity was timed in part around geopolitical events and shifts in international affairs.
Unit 42 assessed the Asia-based, state-aligned cluster TGR-STA-1030/UNC6619 has been active since at least January 2024. The group began targeting government and critical-infrastructure organizations using phishing and exploitation of known vulnerabilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
rescana.com
Open sourcebleepingcomputer.com
Open sourcescworld.com
Open sourcetechrepublic.com
Open sourcethehackernews.com
Open sourcego.theregister.com
Open sourcetherecord.media
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.