From Taiwan to Tehran: How TA416 Pivots its PlugX Backdoor to Global Flashpoints
ID: a310e1ab-5a07-58de-804f-60e79dacc52b
STIX ID: report--a310e1ab-5a07-58de-804f-60e79dacc52b
Feed Name: securityonline.info
Proofpoint reports that TA416, a China-aligned APT, has shifted from a Southeast Asia focus back to targeting European and NATO/EU diplomatic entities since mid-2025 and expanded opportunistically to Middle Eastern government and diplomatic targets in March 2026; the group uses evolving spearphishing techniques and delivery methods (web bugs, Cloudflare Turnstile abuse, OAuth redirect abuse, MSBuild/C#) to deploy updated PlugX backdoors for long-term stealthy access, and defenders in affected sectors should expect continued experimentation with initial access vectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
