Signal
Submitted
Feb 14, 2026, 12:22 UTC
A state-aligned Asian cyberespionage group breached at least 70 organizations across 37 countries in a wide-reaching campaign targeting government and critical infrastructure since 2025.
Between early 2025 and early 2026, a massive cyberespionage campaign attributed to a state-aligned group operating from Asia compromised over 70 organizations in 37 countries. The group, named TGR-STA-1030 by Palo Alto Networks, targeted key government entities including law enforcement, border control, ministries of finance, and agencies related to diplomacy, trade, and natural resources. Notable targets included Brazil's Ministry of Mines and Energy, the Czech Republic's parliament and army, an Indonesian government official, and Taiwan's power equipment suppliers. The attackers used phishing and vulnerability exploitation, deploying a new Linux kernel rootkit to evade detection and maintain persistent access. The group conducted reconnaissance in 155 countries, scanning for future targets, and showed interest in economic intelligence focusing on mining, rare earths, trade policy, and diplomacy. This ongoing campaign has potential long-term national security consequences, with the group still active and targeting critical government infrastructure globally. Palo Alto Networks has engaged with affected countries and warned that the group remains a threat internationally.
Confidence: High
The article clearly describes a hostile cyberespionage campaign by a state-aligned Asian hacking group targeting multiple governments and critical infrastructure, constituting aggressor activity. No defense preparation or response actions are described.
Source URL
https://axios.com/2026/02/05/cyberespionage-government-hacking-campaign-palo-alto-networks
Source reliability
C
Info credibility
4
Event time
Feb 5, 2026, 11:00 UTC
Event time confidence
unknown
Location
Brazil's Ministry of Mines and Energy, Czech Republic's parliament and army, Indonesian government official, Taiwanese power equipment supplier
Primary actor
TGR-STA-1030
Country
Brazil
Countries
Brazil
Tags
offensive cyber operations, state-aligned hacking, TGR-STA-1030, phishing, Linux rootkit, economic intelligence, government hacking, Palo Alto Networks, Asia, SolarWinds comparison
Nodes
Node 1: Borders