UNC6619 is a state-aligned cyberespionage group from Asia known for deploying web shells against governments and critical infrastructure.
Analyst brief
UNC6619, also tracked as TGR-STA-1030, is a state-aligned cyberespionage group operating out of Asia. The actor primarily targets government ministries and critical infrastructure organizations, with extensive reconnaissance conducted against nations in the South China Sea and Gulf of Thailand regions. Key TTPs include the deployment of web shells such as Behinder, Neo-reGeorg, and Godzilla on external and internal web servers to maintain access and enable lateral movement. Defenders should focus on detecting anomalous web server file uploads, suspicious web shell traffic, and C2 communications, particularly those directed to infrastructure in that region.
UNC6619
TGR-STA-1030Shadow Campaigns
unknown
TGR-STA-1030 is a state-aligned cyberespionage group operating out of Asia, known for compromising government and critical infrastructure organizations across 37 countries. The group frequently deploys web shells, such as Behinder, Neo-reGeorg, and Godzilla, on both external and internal web servers to maintain access and enable lateral movement. TGR-STA-1030 has conducted extensive reconnaissance against government infrastructure, particularly focusing on nations in the South China Sea and Gulf of Thailand regions, as well as European countries like Germany. The group primarily targets government ministries and departments for espionage purposes, especially those exploring specific economic partnerships.