Full Report
And their toolkit includes a new, Linux kernel rootkit A state-aligned cyber group in Asia compromised government and critical infrastructure organizations across 37 countries in an ongoing espionage campaign, according to security researchers.…
Analysis Summary
# Threat Actor: TGR-STA-1030 (Unattributed Asian State-Aligned Group)
## Attribution & Identity
**Identification:** A state-aligned cyber group operating out of Asia.
**Aliases/Known Groups:** Tracked as **TGR-STA-1030** by Palo Alto Networks Unit 42. CISA is also aware of and tracking this crew.
**Known Associations:** State-aligned, suggesting ties to an Asian government. Attribution to a specific country was declined by researchers.
## Activity Summary
This group is engaged in an ongoing, large-scale espionage campaign targeting government and critical infrastructure organizations across 37 countries. They have successfully compromised at least 70 organizations, maintaining access to several for months. The primary objective appears to be espionage, involving exfiltration of sensitive data like financial negotiations, contracts, banking information, and military operational updates from victim email servers.
The campaign has been observed demonstrating opportunistic targeting based on geopolitical events:
* **October 2025:** Scanned government infrastructure across North, Central, and South America during the US government shutdown.
* **July 2025:** Showed a concerted focus on Germany, initiating connections to over 490 IP addresses hosting government infrastructure.
* **Following July/August 2025:** Increased scanning of Czech infrastructure (army, police, parliament, ministries) after a high-profile meeting between the Czech President and the Dalai Lama.
* **Post-January 3, 2026:** Conducted extensive reconnaissance targeting at least 140 government-owned IP addresses following the apprehension of Venezuelan President Nicolás Maduro.
## Tactics, Techniques & Procedures
- **Initial Access:** Phishing emails utilizing lures related to ministry or department reorganization.
- **Exploitation:** Exploitation of known vulnerabilities in **Microsoft Exchange, SAP, and Atlassian products**.
- **Malware Deployment:** Used a malware loader originally named "DiaoYu.exe" (phishing). This loader specifically checks for only five antivirus products (Kaspersky, Avira, Bitdefender, SentinelOne, and Symantec) to maintain a minimal code footprint.
- **Kernel-Level Persistence/Evasion:** Deployed a new, stealthy **Linux kernel rootkit called ShadowGuard**.
- **Evasion Technique:** ShadowGuard is an **Extended Berkeley Packet Filter (eBPF) backdoor** designed to hide process information, directories, and files at the kernel level, making detection extremely difficult.
- **Reconnaissance:** Conducted active reconnaissance against 155 government entities globally between November and December 2025.
## Targeting
**Sectors:** Government, Critical Infrastructure, National Telecommunications.
**Specific Sub-Sectors/Entities Hit:** National police/border control entities (5), a nation's parliament, senior elected officials, ministries of finance, ministries of economy, defense, foreign affairs, and commerce.
**Geography:** Compromised organizations in 37 countries. Active reconnaissance observed across the Americas, Europe, Asia, and Africa. Researchers noted a specific focus on Germany.
**Victims:** At least 70 organizations compromised in total.
## Tools & Infrastructure
- **Malware Families Used:**
- ShadowGuard (New Linux kernel rootkit/eBPF backdoor)
- DiaoYu.exe (Malware loader)
- **Infrastructure:** Phishing links hosted on `mega[.]nz` were observed in February 2025 campaigns. (No specific C2 domains or IPs provided for general campaigns, only target IP ranges for reconnaissance mentioned.)
## Implications
The campaign demonstrates high-level, sustained state-sponsored espionage with significant reach (37 countries). The use of ShadowGuard—a novel, stealthy Linux kernel rootkit—indicates a strong adversary focused on deep persistence and maintaining access to gather intelligence with long-term consequences for national security and critical services. Their method of tailoring reconnaissance based on concurrent geopolitical events shows adaptive targeting capabilities.
## Mitigations
- Focus hardening efforts on known exploited vulnerabilities in Microsoft Exchange, SAP, and Atlassian products.
- Enhance behavioral monitoring, particularly on Linux systems, to detect anomalies associated with kernel-level activity or eBPF hooks, given the use of ShadowGuard.
- Review email security gateways for known phishing lures related to government reorganization.
- Monitor for suspicious connections directed at infrastructure IP spaces during periods of geopolitical tension.