Asian Cyber Espionage Campaign Hit 37 Countries

Asian Cyber Espionage Campaign Breached 37 Countries

Asian Cyber Espionage Campaign Breached 37 Countries

Image: DC_Studio (Envato)

Palo Alto Networks says an Asian cyber espionage campaign breached 70 organizations in 37 countries, targeting government agencies and critical infrastructure.

Written By
Kezia Jungco
Kezia Jungco
Feb 6, 2026

A sprawling cyber espionage campaign linked to an Asian state-aligned hacking group has compromised government agencies and critical infrastructure in 37 countries.

Palo Alto Networks noted that the activity affected at least 70 organizations over the past year, including ministries responsible for trade, energy, finance, border control, and diplomacy. Security researchers say the scale and economic focus of the operation are striking, with attackers appearing to collect intelligence tied to rare earth minerals, trade negotiations, and geopolitical relationships.

The campaign underscores how state-backed cyber operations continue to expand quietly and pose long-term risks to governments and essential services worldwide.

A sweeping operation with global reach

According to Cybersecurity Dive, Palo Alto Networks said that the campaign was the most wide-reaching cyberespionage operation attributed to a single government hacking group since the 2020 SolarWinds breach.

The company tracked the activity as TGR-STA-1030 and described it as operating out of Asia, without naming a specific government.

“Its methods, targets, and scale of operations are alarming, with potential long-term consequences for national security and key services,” the report explained.

Axios noted that the attackers successfully breached five national law enforcement and border control agencies, three ministries of finance, and several other government agencies tied to diplomacy, trade, and natural resources.

Identified victims included the following:

  • Brazil’s Ministry of Mines and Energy
  • The parliament and army of the Czech Republic
  • A Mongolian police agency
  • An Indonesian government official
  • A Taiwanese power equipment supplier
  • National-level telecommunications companies

Peter Renals, principal security researcher in Palo Alto Networks’ Unit 42 threat intelligence team, told Axios that government agencies and critical infrastructure organizations in the US and UK weren’t affected.

Advertisement

Must-read security coverage

Economic intelligence and geopolitical timing

Researchers said the timing of several intrusions strongly suggested an interest in economic and political intelligence, particularly around trade policy, rare earth minerals, and diplomatic relationships.

“They’re very much targeting and collecting and doing the espionage that they want, while staying right under that threshold of drawing too much attention,” Renals told Axios.

AOL also reported that in Honduras, hackers targeted hundreds of government IP addresses roughly a month before a presidential election in which candidates expressed interest in restoring diplomatic relations with Taiwan. In Mexico, malicious activity was detected against two ministers shortly after reports emerged about trade investigations tied to tariff proposals.

European governments were also heavily targeted. Palo Alto Networks said hackers increased reconnaissance against Czech government systems following a meeting between President Petr Pavel and the Dalai Lama.

“Weeks after the Czech Republic’s president met with the Dalai Lama, hackers began scanning the networks of the Czech military, the national police, the parliament, and multiple national government bureaus,” Cybersecurity Dive noted.

Separately, the group intensified its focus on Germany over the summer, targeting nearly 500 IP addresses connected to government infrastructure, according to reporting summarized by AOL.

Stealthy techniques and an ongoing threat

The attackers relied on phishing emails and exploitation of known software vulnerabilities to gain initial access, then moved laterally through compromised networks to maintain persistence.

Cybersecurity Drive said that the group has attempted to exploit vulnerabilities in Microsoft Exchange Server, SAP Solution Manager, and more than a dozen other products and services.

Researchers also identified a previously undocumented Linux kernel rootkit, dubbed ShadowGuard. This allowed attackers to hide malicious activity at the kernel level and evade detection by security tools.

Advertisement

Between November and December, the group scanned infrastructure in 155 countries, showing continued interest in future attacks. Palo Alto Networks said it notified affected governments and industry partners but warned the threat actor remains active.

Read TechRepublic’s coverage of the UK Foreign Office cyber breach to understand how the attack was disclosed and why it matters for government security.

Kezia Jungco

Kezia Jungco is a technology writer and researcher specializing in artificial intelligence, data analytics, CRM software, cloud infrastructure, cybersecurity, and emerging business technologies. With more than five years of experience evaluating software platforms and technology solutions, she helps business leaders understand the tools and trends shaping the future of work. Kezia has extensive hands-on experience testing and analyzing generative AI platforms, chatbots, natural language processing (NLP) tools, CRM systems, and business software. Her work focuses on translating complex technologies into practical insights that help organizations make informed decisions about technology adoption, operational efficiency, and digital transformation. As a staff writer for TechnologyAdvice, Kezia covers AI innovation, business applications of machine learning, data-driven technologies, cloud computing, cybersecurity, and sales technology. Her background in journalism, research, and education enables her to combine rigorous analysis with clear, accessible reporting for both enterprise and consumer audiences. Kezia holds a bachelor's degree in Development Communication with a major in Development Journalism from the University of the Philippines Los Baños. She has also completed professional training in artificial intelligence, data privacy, and information security. Her work has been featured in TechnologyAdvice, TechRepublic, eWeek, Datamation, and Selling Signals, where she helps readers navigate a rapidly evolving technology landscape with practical, research-driven guidance.