logo

European-Chinese geopolitical issues drive renewed cyberespionage campaign

ID: 96b72816-3573-55ed-a247-267a99402112

STIX ID: report--96b72816-3573-55ed-a247-267a99402112

Feed Name: CyberScoop

Threat Score
85/100

Date Published: 2026-04-01

Date Updated: 2026-04-21

Author: Tim Starks

...
...

Proofpoint research found that China-linked APT TA416 (aka Twill Typhoon/Mustang Panda) renewed cyberespionage targeting of European diplomatic missions and NATO/EU mailboxes beginning mid-2025 and expanded targeting to the Middle East after the Iran conflict; the group used phishing, web bugs and DLL-sideloaded PlugX backdoors in varied infection chains to gather intelligence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.