Skip to main content
See every side of every news story
Published loading...Updated

Asia-based spies hacked 37 countries' critical networks

The Asia-based group infiltrated 70 organizations in 37 countries, targeting sensitive data including emails and financial dealings linked to military and diplomatic matters.

  • On Thursday, Palo Alto Networks' Unit 42 reported an Asia-based, state-aligned hacking group breached at least 70 organisations in 37 countries over the past year, maintaining access for months.
  • Unit 42 said the crew targeted diplomatic and trade events, pursuing espionage to collect state and commercial intelligence on rare earth minerals and trade deals.
  • Researchers found the attackers used a phishing loader named DiaoYu, exploited Microsoft Exchange, SAP, Atlassian flaws, and deployed the ShadowGuard rootkit; Unit 42 confirmed data exfiltration from victim email servers.
  • CISA confirmed it is aware of the group and said it is working with partners to stop exploitation, while Palo Alto Networks' Unit 42 notified victim organisations and offered assistance.
  • Amid diplomatic tensions, reconnaissance was observed in more than 490 IP addresses, with a focus on Germany and Honduras, while China recently barred Palo Alto products and its embassy in Prague called the allegations unsubstantiated.
Insights by Ground AI

11 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 34% of the sources lean Left, 33% of the sources are Center, 33% of the sources lean Right
34% Left

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

Cybersecurity Dive broke the news in on Thursday, February 5, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal