US China
– Getty Images

Palo Alto Networks has found itself in a case of accused Sino-washing in relation to a recent threat report.

According to Reuters, a draft report from Palo Alto research Unit 42 tied a prolific hacking group to China, only for the explicit mention to be removed from its official release.

Titled The Shadow Campaigns: Uncovering Global Espionage, the report focuses on TGR-STA-1030, a state-aligned actor that has compromised government and critical infrastructure across almost 40 countries, effectively hitting one in five nations globally. The attackers used sophisticated phishing lures to gain initial access and leveraged a wide array of known vulnerabilities in software like Microsoft Exchange and SAP.

Sources told Reuters the group was connected ​to Beijing in the draft report, while the final version instead described the group as a “state-aligned group that operates out of Asia.”

According to the sources, Palo Alto executives allegedly ordered the change following its reported blacklisting by Chinese authorities at the start of the year. The January boycott was based on claims Beijing had instructed domestic firms to stop using cybersecurity software from more than a dozen U.S. and Israeli firms, citing national security concerns.

Aside from Palo Alto, the blacklist featured its now subsidiary CyberArk, Cato Networks, Mandiant, Wiz, CrowdStrike, SentinelOne, Cato Networks, and more. Also on the list were VMware and Fortinet, which, like Palo Alto, have a China-based presence where the others do not.

The reported blacklist reflects amendments to the China Cybersecurity Law (CSL), which came into effect on January 1 of this year. Those changes, which aim to strengthen China’s cybersecurity stance with immediate and elevated penalties alongside clearer liability for organizations, were also recognized by telecom vendor giant Nokia as it consolidates its Chinese operations.

Palo Alto executives were reportedly concerned about the potential for retaliation by Chinese authorities against either the company’s staff in China or its clients abroad. The firm operates multiple offices in mainland China, including major hubs such as Beijing, Shanghai, and Guangzhou, along with an office in Macau.

That footprint has not stopped it from naming China in previous reports; the same is true for Fortinet’s various reports on similar groups to TGR-STA-1030.

While Palo Alto seemingly removed mention of China from its recent report, context in the research pointing to the nation was kept in place, such as the time zone in which the hackers operate in, as well as timing around political flashpoints such as a meeting between Czechia’s president and the Dalai Lama, and a diplomatic visit likely linked to a state trip to Beijing by the king of Thailand.

In response to the report, Palo Alto’s VP of global communications, Nicole Hockin, said the company’s report intentionally avoided attributing the activity to any specific source, emphasizing that this decision had no connection to “procurement regulations in China.” She described any claims suggesting otherwise as “speculative and false,” adding that the report’s wording was chosen to “how to best inform and protect governments about this widespread campaign.”

The Chinese Embassy in Washington, meanwhile, stated that it opposes “all forms of cyberattacks” and noted that attributing hacks was “a complex technical issue.” The embassy expressed hope that “relevant parties will adopt a professional and responsible attitude, basing their characterization of cyber incidents on sufficient evidence, rather than unfounded speculation and accusations.”

In another recent case of cyber espionage, all of Singapore's main telecom operators were revealed to have been breached by a China-linked actor last year. In response to that breach, Singapore's Chinese Embassy denied all involvement in the attacks, adding China clamped down on all forms of cyberattacks in accordance with the law.