CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Asian State-Backed Group TGR-STA-1030 Targets 70 Government and Infrastructure Entities

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A previously undocumented cyber espionage group, TGR-STA-1030, has breached at least 70 government and critical infrastructure organizations across 37 countries over the past year. The group, assessed to be of Asian origin, leverages phishing emails and exploits N-day vulnerabilities to deploy malware and maintain long-term access for espionage purposes. Targets include national law enforcement, ministries of finance, and departments related to economic, trade, natural resources, and diplomatic functions. The group uses a variety of tools, including Cobalt Strike, Behinder, and a Linux kernel rootkit named ShadowGuard.

Timeline

  1. 06.02.2026 14:07 1 articles · 10h ago

    TGR-STA-1030 Compromises 70 Government and Infrastructure Entities

    A previously undocumented cyber espionage group, TGR-STA-1030, has breached at least 70 government and critical infrastructure organizations across 37 countries over the past year. The group, assessed to be of Asian origin, leverages phishing emails and exploits N-day vulnerabilities to deploy malware and maintain long-term access for espionage purposes. Targets include national law enforcement, ministries of finance, and departments related to economic, trade, natural resources, and diplomatic functions. The group uses a variety of tools, including Cobalt Strike, Behinder, and a Linux kernel rootkit named ShadowGuard.

    Show sources

Information Snippets