logo

Chinese Hackers Target European Governments in Espionage Campaigns

ID: b53168d0-a2c3-596a-bfa8-63c1bcedd4ed

STIX ID: report--b53168d0-a2c3-596a-bfa8-63c1bcedd4ed

Feed Name: Infosecurity Magazine (News)

Threat Score
90/100

Date Published: 2026-04-01

Date Updated: 2026-04-22

...
...

Proofpoint observed TA416 (Mustang Panda) reemerge in mid‑2025 through early‑2026 with espionage campaigns targeting EU and NATO diplomatic missions and later expanding to Middle Eastern government and diplomatic entities; the group used web bugs and multiple evolving initial access methods (spoofed Cloudflare Turnstile pages, abused Entra ID OAuth redirects, malicious C# project files) to deliver a signed executable, malicious DLL and encrypted payload triad that loads a customized PlugX backdoor, leveraging cloud hosting, re-registered domains and CDN masking to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.