# TGR-STA-1030 / UNC6619 Shadow Campaigns — China-Nexus APT Breaches 70+ Government Organizations Across 37 Countries, Recons 155 Nations, Novel ShadowGuard eBPF Rootkit, Diaoyu Loader, Event-Driven Geopolitical Targeting

> TGR-STA-1030 (aka UNC6619) is a previously undocumented Asian state-aligned cyber espionage group discovered by Palo Alto Networks Unit 42 that compromised 70+ government and critical infrastructure organizations across 37 countries in 2025 and conducted active reconnaissance against 155 countries. Operating from GMT+8 timezone with upstream connections to AS 9808, the group targets government ministries handling finance, trade, energy, law enforcement, and diplomacy. Uses Diaoyu Loader for initial access via phishing and MEGA file hosting, deploys Cobalt Strike/VShell/Havoc/Sliver C2 frameworks, Behinder/Godzilla/Neo-reGeorg web shells, and a novel eBPF rootkit named ShadowGuard unique to this group. Campaign dubbed 'Shadow Campaigns' by Unit 42.

- **Published:** 2026-02-06T12:00:00Z
- **Last reviewed:** 2026-02-06T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0109
- **ID:** TL-2026-0109
- **Severity:** CRITICAL
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** TGR-STA-1030 (China)
- **Detections:** 9 · **IOCs:** 29 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2019-11580

## Description

Palo Alto Networks Unit 42 revealed in February 2026 a massive state-sponsored cyber espionage operation they term the 'Shadow Campaigns,' attributed to a newly discovered threat group tracked as TGR-STA-1030 (TGR = Temporary Group, STA = State-aligned). Google Mandiant independently tracks the same activity cluster as UNC6619.

Unit 42 assesses with high confidence that TGR-STA-1030 is a state-aligned group operating from Asia, based on: frequent use of regional tooling and services (VShell, Behinder, Godzilla, Zhiyuan OA exploits), language setting preferences, targeting aligned with regional geopolitical interests, upstream infrastructure connections to AS 9808 (a major ISP in the group's operating region), GMT+8 operational hours, and one operator using the handle 'JackMa' (referencing the Alibaba co-founder). The group has been active since at least January 2024.

Over the past year, TGR-STA-1030 compromised at least 70 organizations across 37 countries — approximately 1 in 5 nations globally. Between November–December 2025, the group conducted active reconnaissance against government infrastructure in 155 countries. Confirmed compromises include: 5 national-level law enforcement/border control entities, 3 ministries of finance, one nation's parliament, a senior elected official, national telecommunications companies, and numerous ministries covering interior, foreign affairs, trade, economy, immigration, mining, justice, and energy.

Initial access combines phishing and N-day exploitation. Phishing emails impersonate government reorganization announcements with links to MEGA-hosted ZIP archives containing the custom Diaoyu Loader (DiaoYu.exe — 'Diaoyu' translates to 'fishing/phishing' in Chinese). The loader employs dual anti-sandbox guardrails: horizontal screen resolution ≥1440 and presence of a companion pic1.png file. It checks for 5 specific AV products (Kaspersky, Avira, Bitdefender, SentinelOne, Symantec) before downloading Cobalt Strike payloads from GitHub repositories disguised as WordPress files. N-day exploits target SAP, Microsoft Exchange, Microsoft OMI, Spring Data Commons, Atlassian Crowd (CVE-2019-11580), D-Link, Struts2, Chinese OA platforms (Zhiyuan, Weaver Ecology), and Commvault.

Post-exploitation tooling is extensive: C2 frameworks include Cobalt Strike (transitioning to VShell, a Go-based C2), Havoc, SparkRat, and Sliver. Web shells include Behinder, Neo-reGeorg, and Godzilla (obfuscated via Tas9er GitHub project). Tunneling uses GOST, FRPS, and IOX. The group deploys a novel eBPF rootkit — ShadowGuard — unique to this actor. ShadowGuard operates entirely within kernel space, hiding up to 32 processes simultaneously, concealing files/directories named 'swsecret', and intercepting syscalls to evade user-space analysis tools. Uses custom kill signals (-900/-901) for process allow-listing.

Infrastructure follows a multi-tiered approach: victim-facing C2 on VPS in US/UK/Singapore (appearing legitimate), relay servers with SSH/RDP, proxy layer using DataImpulse residential proxies and Tor, with upstream connections occasionally exposing direct connections from AS 9808 when tunnels collapse. Domains use .me/.live/.help/.tech TLDs, including gouvn.me (targeting Francophone governments), dog3rj.tech (possible 'DOGE Jr' reference for European targeting), and zamstats.me (Zambia targeting).

Geopolitical targeting correlates with real-world events: Honduras scanning 30 days before Taiwan-related elections, Czech infrastructure scanning after Dalai Lama meeting, Brazil's Ministry of Mines and Energy compromise amid rare earth competition, Mexico ministry compromise within 24 hours of tariff announcements, Venezuela reconnaissance following Operation Absolute Resolve, and increased Americas scanning during US government shutdown. The group exfiltrated financial negotiations, banking information, military operational updates, and diplomatic communications.

## MITRE ATT&CK

- T1595.002 Vulnerability Scanning
- T1583.001 Domains
- T1583.003 Virtual Private Server
- T1608.001 Upload Malware
- T1566.002 Spearphishing Link
- T1190 Exploit Public-Facing Application
- T1204.002 Malicious File
- T1505.003 Web Shell
- T1574.001 DLL
- T1014 Rootkit
- T1497.001 System Checks
- T1027 Obfuscated Files or Information
- T1564.001 Hidden Files and Directories
- T1649 Steal or Forge Authentication Certificates
- T1046 Network Service Discovery
- T1021.004 SSH
- T1114.002 Remote Email Collection
- T1071.001 Web Protocols
- T1090.003 Multi-hop Proxy
- T1572 Protocol Tunneling
- T1041 Exfiltration Over C2 Channel
- T1608.002 Upload Tool
- T1588.002 Tool
- T1685 Disable or Modify Tools
- T1539 Steal Web Session Cookie
- T1518.001 Security Software Discovery
- T1021.001 Remote Desktop Protocol

## Sources

- [Unit 42: The Shadow Campaigns — Uncovering Global Espionage](https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/)
- [The Hacker News: TGR-STA-1030 Breaches 70 Government Entities](https://thehackernews.com/2026/02/asian-state-backed-group-tgr-sta-1030.html)
- [CSO Online: New APT Breached 37 Countries](https://www.csoonline.com/article/4128378/new-apt-group-breached-gov-and-critical-infrastructure-orgs-in-37-countries.html)
- [SecurityWeek: Cyberspy Group Hacked 37 Countries](https://www.securityweek.com/cyberspy-group-hacked-governments-and-critical-infrastructure-in-37-countries/)
- [Security Boulevard: Espionage Operations Against Dozens of Governments](https://securityboulevard.com/2026/02/threat-group-running-espionage-operations-against-dozens-of-governments/)
- [TechRepublic: Asian Cyber Espionage Campaign Breached 37 Countries](https://www.techrepublic.com/article/news-asian-cyber-espionage-campaign-breached-37-countries/)
- [Economic Times India: Hackers Breach Govt Systems in 37 Countries](https://economictimes.indiatimes.com/tech/technology/hackers-breach-govt-systems-in-37-countries-in-vast-spying-plot/articleshow/128080291.cms)
- [NVISO: VShell C2 Framework Research](https://blog.nviso.eu/wp-content/uploads/2025/11/VShell.pdf)
- [CyberMaterial: Asian State Group Breaches 70 Gov Entities](https://www.cybermaterial.com/p/asian-state-group-breaches-70-gov)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0109
