logo

TA416 Resumes Cyber Espionage Against European Governments Amid Geopolitical Tensions

ID: cc2b67ff-8a98-57a8-9ac5-87da193c8578

STIX ID: report--cc2b67ff-8a98-57a8-9ac5-87da193c8578

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-04-01

Date Updated: 2026-04-05

...
...

TA416, a Chinese state-backed APT, resumed intensive cyber espionage against European governments and diplomatic/NATO targets from mid-2025 and expanded operations to Middle Eastern government entities after the Iran conflict. The group uses diverse malware delivery techniques—freemail accounts, compromised mailboxes, web-bug reconnaissance, Cloudflare Turnstile abuse, and C# project files—to distribute and deploy a customized PlugX backdoor; the activity was reported active as of April 1, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.