logo

TA416 Broadens Europe Spy Campaign With Web Bugs and Malware

ID: 3572c49a-769c-570e-81e5-f376e9649723

STIX ID: report--3572c49a-769c-570e-81e5-f376e9649723

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-04-02

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

TA416, a China-aligned threat actor, resumed large-scale espionage from mid-2025 through early 2026 against European governments and expanded into Middle Eastern diplomatic targets. The group uses web-bug reconnaissance in spearphishing, fake Cloudflare/Microsoft login lures, ZIP/CSProj delivery chains and DLL sideloading to deploy an evolving, customized PlugX backdoor with RC4-encrypted C2 and other stealth measures; defenders should strengthen layered email, identity and network controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.