TA416 Resumes Cyber Espionage Against European Governments Amid Geopolitical Tensions
ID: cc2b67ff-8a98-57a8-9ac5-87da193c8578
STIX ID: report--cc2b67ff-8a98-57a8-9ac5-87da193c8578
Feed Name: ThreatCluster
TA416, a Chinese state-backed APT, resumed intensive cyber espionage against European governments and diplomatic/NATO targets from mid-2025 and expanded operations to Middle Eastern government entities after the Iran conflict. The group uses diverse malware delivery techniques—freemail accounts, compromised mailboxes, web-bug reconnaissance, Cloudflare Turnstile abuse, and C# project files—to distribute and deploy a customized PlugX backdoor; the activity was reported active as of April 1, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
