Threat reportAPTTL-2026-0109

TGR-STA-1030 / UNC6619 Shadow Campaigns — China-Nexus APT Breaches 70+ Government Organizations Across 37 Countries, Recons 155 Nations, Novel ShadowGuard eBPF Rootkit, Diaoyu Loader, Event-Driven Geopolitical Targeting

criticalACTIVE

TGR-STA-1030 / UNC6619 Shadow Campaigns (TL-2026-0109) is a critical-severity advanced persistent threat campaign, first published 2026-02-06. It is attributed to TGR-STA-1030 (China) with high confidence, references 1 CVE (CVE-2019-11580), maps to 27 MITRE ATT&CK techniques (T1014, T1021.001, T1021.004), and is covered by 9 detection rules and 29 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
1Referenced vulnerabilities
Techniques
27MITRE ATT&CK
Actors
1TGR-STA-1030
Detection rules
9SPL · KQL · Sigma
IOCs
29Indicators of compromise

Key facts for TL-2026-0109

Threat ID
TL-2026-0109
Severity
CRITICAL
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution
TGR-STA-1030
Attribution confidence
HIGH
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
Government, Law Enforcement, Defense, Finance, Energy, Mining, Telecommunications, Trade, Diplomacy, Critical Infrastructure
Target regions
Global — 37 countries confirmed, 155 countries reconnaissance, Americas, Europe, Africa, Asia-Pacific, Middle East
Detection rules
9
Indicators of compromise
29

Malware and tooling in TGR-STA-1030 / UNC6619 Shadow Campaigns

Malware and tooling: ShadowGuard, Behinder, Cobalt Strike, Godzilla, SLIVER, VShell

How TGR-STA-1030 / UNC6619 Shadow Campaigns works

TGR-STA-1030 (aka UNC6619) is a previously undocumented Asian state-aligned cyber espionage group discovered by Palo Alto Networks Unit 42 that compromised 70+ government and critical infrastructure organizations across 37 countries in 2025 and conducted active reconnaissance against 155 countries. Operating from GMT+8 timezone with upstream connections to AS 9808, the group targets government ministries handling finance, trade, energy, law enforcement, and diplomacy. Uses Diaoyu Loader for initial access via phishing and MEGA file hosting, deploys Cobalt Strike/VShell/Havoc/Sliver C2 frameworks, Behinder/Godzilla/Neo-reGeorg web shells, and a novel eBPF rootkit named ShadowGuard unique to this group. Campaign dubbed 'Shadow Campaigns' by Unit 42.

Palo Alto Networks Unit 42 revealed in February 2026 a massive state-sponsored cyber espionage operation they term the 'Shadow Campaigns,' attributed to a newly discovered threat group tracked as TGR-STA-1030 (TGR = Temporary Group, STA = State-aligned). Google Mandiant independently tracks the same activity cluster as UNC6619.

Unit 42 assesses with high confidence that TGR-STA-1030 is a state-aligned group operating from Asia, based on: frequent use of regional tooling and services (VShell, Behinder, Godzilla, Zhiyuan OA exploits), language setting preferences, targeting aligned with regional geopolitical interests, upstream infrastructure connections to AS 9808 (a major ISP in the group's operating region), GMT+8 operational hours, and one operator using the handle 'JackMa' (referencing the Alibaba co-founder). The group has been active since at least January 2024.

Over the past year, TGR-STA-1030 compromised at least 70 organizations across 37 countries — approximately 1 in 5 nations globally. Between November–December 2025, the group conducted active reconnaissance against government infrastructure in 155 countries. Confirmed compromises include: 5 national-level law enforcement/border control entities, 3 ministries of finance, one nation's parliament, a senior elected official, national telecommunications companies, and numerous ministries covering interior, foreign affairs, trade, economy, immigration, mining, justice, and energy.

Initial access combines phishing and N-day exploitation. Phishing emails impersonate government reorganization announcements with links to MEGA-hosted ZIP archives containing the custom Diaoyu Loader (DiaoYu.exe — 'Diaoyu' translates to 'fishing/phishing' in Chinese). The loader employs dual anti-sandbox guardrails: horizontal screen resolution ≥1440 and presence of a companion pic1.png file. It checks for 5 specific AV products (Kaspersky, Avira, Bitdefender, SentinelOne, Symantec) before downloading Cobalt Strike payloads from GitHub repositories disguised as WordPress files. N-day exploits target SAP, Microsoft Exchange, Microsoft OMI, Spring Data Commons, Atlassian Crowd (CVE-2019-11580), D-Link, Struts2, Chinese OA platforms (Zhiyuan, Weaver Ecology), and Commvault.

Post-exploitation tooling is extensive: C2 frameworks include Cobalt Strike (transitioning to VShell, a Go-based C2), Havoc, SparkRat, and Sliver. Web shells include Behinder, Neo-reGeorg, and Godzilla (obfuscated via Tas9er GitHub project). Tunneling uses GOST, FRPS, and IOX. The group deploys a novel eBPF rootkit — ShadowGuard — unique to this actor. ShadowGuard operates entirely within kernel space, hiding up to 32 processes simultaneously, concealing files/directories named 'swsecret', and intercepting syscalls to evade user-space analysis tools. Uses custom kill signals (-900/-901) for process allow-listing.

Infrastructure follows a multi-tiered approach: victim-facing C2 on VPS in US/UK/Singapore (appearing legitimate), relay servers with SSH/RDP, proxy layer using DataImpulse residential proxies and Tor, with upstream connections occasionally exposing direct connections from AS 9808 when tunnels collapse. Domains use .me/.live/.help/.tech TLDs, including gouvn.me (targeting Francophone governments), dog3rj.tech (possible 'DOGE Jr' reference for European targeting), and zamstats.me (Zambia targeting).

Geopolitical targeting correlates with real-world events: Honduras scanning 30 days before Taiwan-related elections, Czech infrastructure scanning after Dalai Lama meeting, Brazil's Ministry of Mines and Energy compromise amid rare earth competition, Mexico ministry compromise within 24 hours of tariff announcements, Venezuela reconnaissance following Operation Absolute Resolve, and increased Americas scanning during US government shutdown. The group exfiltrated financial negotiations, banking information, military operational updates, and diplomatic communications.

MITRE ATT&CK techniques used in TL-2026-0109

defense-evasion

T1014 Rootkit; T1027 Obfuscated Files or Information; T1497.001 System Checks; T1564.001 Hidden Files and Directories

lateral-movement

T1021.001 Remote Desktop Protocol; T1021.004 SSH

exfiltration

T1041 Exfiltration Over C2 Channel

discovery

T1046 Network Service Discovery; T1518.001 Security Software Discovery

command-and-control

T1071.001 Web Protocols; T1090.003 Multi-hop Proxy; T1572 Protocol Tunneling

collection

T1114.002 Remote Email Collection

initial-access

T1190 Exploit Public-Facing Application; T1566.002 Spearphishing Link

execution

T1204.002 Malicious File

persistence

T1505.003 Web Shell; T1574.001 DLL

credential-access

T1539 Steal Web Session Cookie; T1649 Steal or Forge Authentication Certificates

resource-development

T1583.001 Domains; T1583.003 Virtual Private Server; T1588.002 Tool; T1608.001 Upload Malware; T1608.002 Upload Tool

reconnaissance

T1595.002 Vulnerability Scanning

defense-impairment

T1685 Disable or Modify Tools

Remediation for TGR-STA-1030 / UNC6619 Shadow Campaigns

Patches

  • CVE-2019-11580 — Atlassian Crowd RCE (confirmed exploited by TGR-STA-1030)

Immediate actions

  • Audit email servers for unauthorized access — group exfiltrated financial negotiations, banking data, military updates from compromised email systems
  • Search for ShadowGuard eBPF rootkit indicators: files/directories named 'swsecret', check for hidden processes using kernel-level tools (not just ps)
  • Block known C2 domains: gouvn.me, dog3rj.tech, zamstats.me, 888910.xyz
  • Monitor for connections to/from AS 9808 from government networks
  • Check for Behinder, Neo-reGeorg, and Godzilla web shells on external-facing web servers

Workarounds

  • Restrict MEGA file hosting service access from government email networks
  • Block execution of files named DiaoYu.exe and suspicious Python loaders from MEGA-downloaded archives
  • Deploy DNS sinkholing for TGR-STA-1030 C2 domains (.me, .live, .help, .tech TLDs associated with government-impersonating names)

Longer-term hardening

  • Patch all N-day vulnerabilities targeted by TGR-STA-1030: SAP Solution Manager, Microsoft Exchange, OMI, Atlassian Crowd (CVE-2019-11580), Struts2, D-Link, Commvault, Chinese OA platforms
  • Implement phishing-resistant MFA for all government email systems
  • Deploy eBPF monitoring solutions to detect kernel-level rootkits like ShadowGuard
  • Implement network segmentation between internet-facing and internal government systems
  • Establish threat intelligence sharing agreements across targeted government sectors
  • Monitor VShell C2 indicators: Go-based framework using 5-digit ephemeral TCP ports with ordered numbers

CVEs associated with TGR-STA-1030 / UNC6619 Shadow Campaigns

CVE-2019-11580

Weaknesses (CWE) in TGR-STA-1030 / UNC6619 Shadow Campaigns

CWE-287, CWE-94

Timeline of TGR-STA-1030 / UNC6619 Shadow Campaigns

  • Unit 42 identifies TGR-STA-1030 actor infrastructure dating as far back as January 2024, establishing the group has been active for at least two years. Source: https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/
  • TGR-STA-1030 copies X.509 certificate with CN gouvn.me from victim-facing VPS to a Tencent server in the actors' region — visible for 4 days. Operational security mistake revealing upstream infrastructure. Source: https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/
  • Unit 42 first identifies TGR-STA-1030 investigating phishing campaigns targeting European governments. Emails impersonate ministry reorganization announcements with links to MEGA-hosted archives containing Diaoyu Loader. Source: https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/
  • Estonian government entity identifies and uploads TGR-STA-1030 phishing archive ('Changes to the organizational structure of the Police and Border Guard Board.zip') to public malware repository. Source: https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/
  • TGR-STA-1030 applies concerted focus toward Germany, initiating connections to over 490 IP addresses hosting government infrastructure. Source: https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/
  • After Czech President Petr Pavel meets with the Dalai Lama in India, TGR-STA-1030 begins scanning Czech government infrastructure including army, police, parliament, presidency, and ministries. Source: https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/
  • Malicious traffic from compromised Mexico ministries first seen within 24 hours of Mexico News Daily reporting on tariff investigation — demonstrating event-driven targeting. Source: https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/
  • During US government shutdown, TGR-STA-1030 expands reconnaissance across Americas: Brazil, Canada, Dominican Republic, Guatemala, Honduras, Jamaica, Mexico, Panama, Trinidad and Tobago. 200+ Honduras IPs scanned 30 days before Taiwan-related election. Source: https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/
  • NVISO publishes comprehensive research on VShell, the Go-based C2 framework increasingly favored by TGR-STA-1030 over Cobalt Strike. Source: https://blog.nviso.eu/wp-content/uploads/2025/11/VShell.pdf
  • TGR-STA-1030 conducts active reconnaissance against government infrastructure across 155 countries between November and December 2025 — nearly 80% of all nations. Focused scanning of government IP addresses, not broad IPv4 sweeps. Source: https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/
  • Following Operation Absolute Resolve (Jan 3, 2026), TGR-STA-1030 conducts extensive reconnaissance targeting 140+ Venezuelan government IPs and likely compromises Venezolana de Industria Tecnológica facility. Source: https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/
  • Palo Alto Networks Unit 42 publishes 'The Shadow Campaigns: Uncovering Global Espionage' — full disclosure of TGR-STA-1030 operations, tooling, infrastructure, and victimology across 37 countries. Source: https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/
  • Original threat creation date preserved for Threadlinqs Intelligence database entry.
  • As of 2026-05-29, TGR-STA-1030/UNC6619 "Shadow Campaigns" remains an active China-nexus state espionage actor: Unit 42's Feb 2026 disclosure and follow-on coverage (Axios: "ongoing") report no takedown, indictment, or defunct/rebrand. Its custom ShadowGuard eBPF rootkit and Diaoyu Loader stay in use, and CVE-2019-11580 (CISA KEV) is patchable yet still exploited as an N-day.

Sources cited for TGR-STA-1030 / UNC6619 Shadow Campaigns

Detection coverage for TL-2026-0109

As of 2026-02-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0109 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
29 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats