Also known as: TGR-STA-1030, Shadow Campaigns, APT28, tracked as, Head Mare, 21, 2026, Kyrgyzstan, Kazakhstan, defense industries, Awaken Likho, Bearlyfy, Librarian Ghouls, Librarian Likho, Rezet, Core Werewolf, Lone Wolf, Moonshine Trickster, Ratopak Spider, UAC-0008, Romania, Fancy Bear, UAC-0001, its NATO allies, Outrider Tiger, Fishing Elephant, Earth Vetala, MERCURY, Mango Sandstorm, Static Kitten, including diplomatic, maritime, financial, telecom entities, Archer RAT, RUSTRIC, detects installed security software, establishes contact with a, CHAR, Olalampo, Storm-0842, Red Sandstorm, DUNE, Bloody Wolf, SkyCloak, laboo.boo, Clubfoot Wolf, Void Arachne, Watch Wolf, Forest Blizzard, TA450, MuddyWater, Banished Kitten, HOPPINGANT by researchers, Yorotrooper, Tomiris
UNC6619 is a high‑sophistication state‑backed actor whose footprint spans roughly 37 countries including Russia, Poland, Germany, the United States, China, India, and several European Union members. The group’s methodology blends social engineering (phishing emails that link to bogus video‑conferencing portals or embed malicious Office attachments) with exploitation of publicly available applications such as TrueConf and Microsoft Office zero‑days (CVE‑2026‑21509/13). After initial compromise the actor deploys a PowerShell‑based backdoor named PhantomHeart, which uses HTTP or SSH tunnels for command and control. Persistence is achieved via disguised scheduled‑task updates in the LiteManager directory, COM hijacking, and server‑side evasion that filters DLL delivery by geographic region and User–Agent headers. UNC6619 expands lateral reach through a mix of custom Remote Access Tools (e.g., AnyDesk) and SSH tunnels. Its operational toolbox also includes malicious DLL installers disguised as legitimate updates, steganographic payload carriers in Office macros and PNG images, RAR‑archived utilities such as Smart Install Maker and PUMAKIT kernel‑level rootkits, and destructive wiper commands that target user profile directories. The group uses Filen.io cloud storage not only for file delivery but also for encrypted C2 communication and exfiltration over SMTP. In addition to espionage, selected campaigns exhibit sabotage capabilities: deleting files, disabling native endpoint protection, and deploying ransomware variants such as LockBit. Strategically the group focuses on government ministries, critical‑infrastructure sectors (energy, telecommunications, transportation), defense supply chains, financial services, and technology vendors supporting emerging economies. Operations tend to combine long‑term persistence with opportunistic data exfiltration, often exploiting high‑value targets in the geopolitical context of Asia and Europe. Beyond UNC6619, analysts have linked related tool families—Behinder, Neo‑reGeorg, Godzilla, VShell—and cloud‑based components such as PRISMEX and various Prismex sub‑components. Though not all are exclusive to UNC6619, they appear consistently across related campaigns, indicating shared infrastructure or threat‑sharing among state‑aligned actors. Overall the actor exhibits an ability to adapt quickly to emerging zero‑days, leverage widely available cloud services for covert C2, and persist under the guise of legitimate software updates, thereby complicating detection and mitigation efforts.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC6619, also known as TGR‑STA‑1030 or Shadow Campaigns, is a state‑aligned Asian cyberespionage group that has conducted operations against more than 150 countries. The actor relies on sophisticated spear‑phishing, exploitation of zero‑day vulnerabilities and cloud‑based command‑and‑control (e.g., Filen.io) to gain persistence for espionage and, in some instances, sabotage through destructive payloads.
Goals & Targeting
UNC6619’s primary objective is targeted cyberespionage aimed at collecting strategic information from governments, critical‑infrastructure operators, defense contractors, and financial institutions. The actor also demonstrates a dual capacity for sabotage—deploying destructive wiper payloads against user profiles—to disrupt operations or to signal geopolitical posturing. Target selection focuses disproportionately on nations with significant military or economic ties to the region of origin, but the scope remains global with a particular emphasis on Asia‑Pacific and European state‑affiliated entities. The strategic goals align with broader state interests: securing trade agreements, influencing political outcomes through intelligence gathering, undermining confidence in critical infrastructure, and coercing adversaries by damaging data integrity or availability.
Enhanced Description
Key Capabilities
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
41
Tools
0
Campaigns
49
IOCs
0
Observed Data
0
Tactics