logo

The spy who logged me in.

ID: 1f5739ab-9f19-5efe-9f31-ebcf3b89d6e0

STIX ID: report--1f5739ab-9f19-5efe-9f31-ebcf3b89d6e0

Feed Name: Proofpoint Blog

Threat Score
90/100

Date Published: 2026-05-09

Date Updated: 2026-05-15

...
...

Proofpoint researcher Mark Kelly reports that China-linked APT TA416 has resumed large-scale spearphishing and PlugX malware campaigns targeting European governments, EU/NATO diplomatic missions, and Middle Eastern entities. The group has evolved tactics between mid-2025 and early 2026 — using fake Cloudflare verification pages, Microsoft OAuth redirect abuse, and malicious C# project files — reflecting shifting geopolitical priorities and continued intelligence-gathering focus.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.