Skip to content
Unit 42 identifies TGR-STA

Unit 42 identifies TGR-STA

Industrialcyber.Co February 6, 2026

Researchers from Palo Alto Networks ’ Unit 42 have identified a previously unreported cyber espionage group, which it tracks as TGR-STA-1030 (aka UNC6619), referring to its activity as the Shadow Campaigns. Unit 42 assesses with high confidence that the group is state-aligned and operates out of Asia. Over the past year, the actors have compromised government and critical infrastructure organizations in 37 countries, meaning roughly one in five countries worldwide experienced a critical breach linked to the group during that period. Unit 42 further observed the group conducting active reconnaissance against government infrastructure in 155 countries between November and December 2025.

“Unit 42 first identified TGR-STA-1030 (aka UNC6619) upon investigating a cluster of malicious phishing campaigns (referred to here as the Shadow Campaigns) targeting European governments in early 2025,” researchers detailed in the Thursday post. “We use the prefix TGR-STA as a placeholder to denote a temporary group of state-aligned activity while we continue to refine attribution to a specific organization.”

The post noted that over the course of the past year, the group has substantially increased its scanning and reconnaissance efforts. This shift follows the group’s evolution from phishing emails to exploits for initial access. Impacted organizations include ministries and departments of interior, foreign affairs, finance, trade, economy, immigration, mining, justice and energy.

“Most emblematic of this activity, we observed the group scanning infrastructure across 155 countries between November and December 2025,” Unit 42 researchers pointed out. “The group’s reconnaissance efforts shed light on its global interests. We have also observed the group’s success at compromising several government and critical infrastructure organizations globally. We assess that over the past year, the group compromised at least 70 organizations across 37 countries. The attackers were able to maintain access to several of the impacted entities for months.”

Unit 42 added that while this group might be pursuing espionage objectives, its methods, targets and scale of operations are alarming, with potential long-term consequences for national security and key services. “By closely monitoring the timing of the group’s operations, we have drawn correlations between several of its campaigns and real-world events. These correlations inform assessments as to the group’s potential motivations.”

During the U.S. government shutdown that began in October 2025, Unit 42 mentioned that the group began to display greater interest in organizations and events occurring across North, Central, and South American countries. “Over that month, we observed scanning of government infrastructure across Brazil, Canada, Dominican Republic, Guatemala, Honduras, Jamaica, Mexico, Panama, and Trinidad and Tobago. Perhaps the most pronounced reconnaissance occurred on Oct. 31, 2025, when we observed connections to at least 200 IP addresses hosting Government of Honduras infrastructure. The timing of this activity falls just 30 days prior to the national election, in which both candidates signaled openness to restoring diplomatic relations with Taiwan.”

In addition to reconnaissance activities, Unit 42 assessed that the group likely compromised government entities across Bolivia, Brazil, Mexico, Panama, and Venezuela.

Unit 42 researchers said the group targeted government and mining-linked entities across Latin America, with activity closely aligned to geopolitical and economic developments. In Bolivia, the actors likely compromised a mining-sector entity, potentially tied to an interest in rare earth minerals amid heightened political debate over mining rights during the 2025 presidential election. In Brazil, the group likely breached the Ministry of Mines and Energy as the country emerged as a strategic alternative source of rare earths, following a surge in exports and increased U.S. engagement, including a $465 million investment in a Brazilian producer.

The researchers also linked intrusions in Mexico to international trade negotiations, noting that malicious traffic from government ministry networks appeared within a day of reports on potential new tariffs. In Panama, the group likely compromised government systems connected to an investigation following the destruction of a controversial monument. In Venezuela, activity intensified after the United States launched Operation Absolute Resolve in January 2026, with widespread reconnaissance of government networks and a likely breach of a state-linked technology facility tied to longstanding government–Asia technology cooperation.

Throughout 2025, Unit 42 identified that the TGR-STA-1030 group intensified its activity across Europe, with a marked focus on government and European Union infrastructure. In July, the group concentrated on Germany, initiating connections to more than 490 IP addresses linked to government systems. In August, scanning activity expanded to the Czech government infrastructure following a private meeting between Czech President Petr Pavel and the Dalai Lama in India, affecting networks tied to the military, police, parliament, and several ministries. After reports in early November that the Czech president would co-patronize the Dalai Lama’s 90th birthday gala, the group conducted a second, more targeted round of scanning focused on the president’s website.

The group also directed significant reconnaissance at EU institutions, attempting connections to more than 600 IP addresses associated with europa[dot]eu domains in late August. Beyond reconnaissance, the actors likely compromised government entities across multiple European countries, including Cyprus, Czechia, Germany, Greece, Italy, Poland, Portugal, and Serbia. At least one finance ministry was breached, with the activity aimed at collecting intelligence related to international development at both the national and EU levels.

Unit 42 also highlighted that the group likely compromised government infrastructure in Cyprus in early 2025, with the activity coinciding with efforts by an Asian nation to expand economic partnerships across Europe. The timing also aligned with Cyprus’s preparations to assume the presidency of the Council of the European Union later that year.

In Greece, the actors likely compromised infrastructure linked to the Syzefxis Project, a national initiative designed to modernize public sector organizations through high-speed connectivity.

Across Asia and Oceania, the group conducted broad scanning but showed a clear focus on countries bordering the South China Sea and the Gulf of Thailand, routinely probing government networks in Indonesia, Thailand, and Vietnam. In early November 2025, the group initiated connections to dozens of IP addresses associated with Thai government infrastructure. The activity extended beyond standard web services, with attempts to access SSH services on systems linked to Australia’s Treasury Department, Afghanistan’s Ministry of Finance, and Nepal’s Office of the Prime Minister and Council of Ministers.

Beyond reconnaissance, the group likely compromised government and critical infrastructure entities across a wide range of countries, including Afghanistan, Bangladesh, India, Indonesia, Japan, Malaysia, Mongolia, Papua New Guinea, Saudi Arabia, Sri Lanka, South Korea, Taiwan, Thailand, Uzbekistan, and Vietnam.

In conclusion, the Unit 42 researchers said that TGR-STA-1030 remains an active threat to government and critical infrastructure worldwide. The group primarily targets government ministries and departments for espionage purposes.

“We assess that it prioritizes efforts against countries that have established or are exploring certain economic partnerships,” according to the post. “Over the past year, this group has compromised government and critical infrastructure organizations across 37 countries. Given the scale of compromise and the significance of the impacted government entities, we are working with industry peers and government partners to raise awareness of the threat and disrupt this activity.”