TGR-STA-1030 / UNC6619 Shadow Campaigns — China-Nexus APT Breaches 70+ Government Organizations Across 37 Countries, Recons 155 Nations, Novel ShadowGuard eBPF Rootkit, Diaoyu Loader, Event-Driven Geopolitical Targeting — Threadlinqs Intelligence
As of 2026-05-30, TGR-STA-1030 / UNC6619 Shadow Campaigns — China-Nexus APT Breaches 70+ Government Organizations Across 37 Countries, Recons 155 Nations, Novel ShadowGuard eBPF Rootkit, Diaoyu Loader, Event-Driven Geopolitical Targeting is a critical-severity apt threat attributed to TGR-STA-1030 (China (assessed with high confidence — Asian state-aligned, GMT+8, AS 9808, regional tooling, JackMa handle)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 29 indicators of compromise.
Threat ID: TL-2026-0109 · Severity: CRITICAL · Status: ACTIVE · Category: APT
Attribution: TGR-STA-1030 · China (assessed with high confidence — Asian state-aligned, GMT+8, AS 9808, regional tooling, JackMa handle) · ESPIONAGE
TGR-STA-1030 (aka UNC6619) is a previously undocumented Asian state-aligned cyber espionage group discovered by Palo Alto Networks Unit 42 that compromised 70+ government and critical infrastructure
Palo Alto Networks Unit 42 revealed in February 2026 a massive state-sponsored cyber espionage operation they term the 'Shadow Campaigns,' attributed to a newly discovered threat group tracked as TGR-STA-1030 (TGR = Temporary Group, STA = State-aligned). Google Mandiant independently tracks the same activity cluster as UNC6619.
Unit 42 assesses with high confidence that TGR-STA-1030 is a state-aligned group operating from Asia, based on: frequent use of regional tooling and services (VShell, Behinder, Godzilla, Zhiyuan OA exploits), language setting preferences, targeting aligned with regional geopolitical interests, upstream infrastructure connections to AS 9808 (a major ISP in the group's operating region), GMT+8 operational hours, and one operator using the handle 'JackMa' (referencing the Alibaba co-founder). The group has been active since at least January 2024.
Over the past year, TGR-STA-1030 compromised at least 70 organizations across 37 countries — approximately 1 in 5 nations globally. Between November–December 2025, the group conducted active reconnaissance against government infrastructure in 155 countries. Confirmed compromises include: 5 national-level law enforcement/border control entities, 3 ministries of finance, one nation's parliament, a senior elected official, national telecommunications companies, and numerous ministries covering interior, foreign affairs, trade, economy, immigration, mining, justice, and energy.
Initial access combines phishing and N-day exploitation. Phishing emails impersonate government reorganization announcements with links to MEGA-hosted ZIP archives containing the custom Diaoyu Loader (DiaoYu.exe — 'Diaoyu' translates to 'fishing/phishing' in Chinese). The loader employs dual anti-sandbox guardrails: horizontal screen resolution ≥1440 and presence of a companion pic1.png file. It checks for 5 specific AV products (Kaspersky, Avira, Bitdefender, SentinelOne, Symantec) before downloading Cobalt Strike payloads from GitHub repositories disguised as WordPress files. N-day exploits target SAP, Microsoft Exchange, Microsoft OMI, Spring Data Commons, Atlassian Crowd (CVE-2019-11580), D-Link, Struts2, Chinese OA platforms (Zhiyuan, Weaver Ecology), and Commvault.
Post-exploitation tooling is extensive: C2 frameworks include Cobalt Strike (transitioning to VShell, a Go-based C2), Havoc, SparkRat, and Sliver. Web shells include Behinder, Neo-reGeorg, and Godzilla (obfuscated via Tas9er GitHub project). Tunneling uses GOST, FRPS, and IOX. The group deploys a novel eBPF rootkit — ShadowGuard — unique to this actor. ShadowGuard operates entirely within kernel space, hiding up to 32 processes simultaneously, concealing files/directories named 'swsecret', and intercepting syscalls to evade user-space analysis tools. Uses custom kill signals (-900/-901) for process allow-listing.
Infrastructure follows a multi-tiered approach: victim-facing C2 on VPS in US/UK/Singapore (appearing legitimate), relay servers with SSH/RDP, proxy layer using DataImpulse residential proxies and Tor, with upstream connections occasionally exposing direct connections from AS 9808 when tunnels collapse. Domains use .me/.live/.help/.tech TLDs, including gouvn.me (targeting Francophone governments), dog3rj.tech (possible 'DOGE Jr' reference for European targeting), and zamstats.me (Zambia targeting).
Geopolitical targeting correlates with real-world events: Honduras scanning 30 days before Taiwan-related elections, Czech infrastructure scanning after Dalai Lama meeting, Brazil's Ministry of Mines and Energy compromise amid rare earth competition, Mexico ministry compromise within 24 hours of tariff announcements, Venezuela reconnaissance following Operation Absolute Resolve, and increased Americas scanning during US government shutdown. The group exfiltrated financial negotiations, banking information, military operational updates, and diplomatic communications.
Weaknesses (CWE)
CWE-287, CWE-94
Target sectors: Government, Law Enforcement, Defense, Finance, Energy, Mining, Telecommunications, Trade, Diplomacy, Critical Infrastructure
Target regions: Global — 37 countries confirmed, 155 countries reconnaissance, Americas, Europe, Africa, Asia-Pacific, Middle East
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 29 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, CRITICAL, threat intelligence, cybersecurity, CVE-2019-11580, T1595.002, T1583.001, T1583.003, T1608.001, T1566.002, T1190, T1204.002, T1505.003, T1574.002, T1014