logo

From Taiwan to Tehran: How TA416 Pivots its PlugX Backdoor to Global Flashpoints

ID: a310e1ab-5a07-58de-804f-60e79dacc52b

STIX ID: report--a310e1ab-5a07-58de-804f-60e79dacc52b

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-04-08

Date Updated: 2026-04-23

Author: Ddos

...
...

Proofpoint reports that TA416, a China-aligned APT, has shifted from a Southeast Asia focus back to targeting European and NATO/EU diplomatic entities since mid-2025 and expanded opportunistically to Middle Eastern government and diplomatic targets in March 2026; the group uses evolving spearphishing techniques and delivery methods (web bugs, Cloudflare Turnstile abuse, OAuth redirect abuse, MSBuild/C#) to deploy updated PlugX backdoors for long-term stealthy access, and defenders in affected sectors should expect continued experimentation with initial access vectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.