Chinese Hackers Target European Governments in Espionage Campaigns
ID: b53168d0-a2c3-596a-bfa8-63c1bcedd4ed
STIX ID: report--b53168d0-a2c3-596a-bfa8-63c1bcedd4ed
Feed Name: Infosecurity Magazine (News)
Proofpoint observed TA416 (Mustang Panda) reemerge in mid‑2025 through early‑2026 with espionage campaigns targeting EU and NATO diplomatic missions and later expanding to Middle Eastern government and diplomatic entities; the group used web bugs and multiple evolving initial access methods (spoofed Cloudflare Turnstile pages, abused Entra ID OAuth redirects, malicious C# project files) to deliver a signed executable, malicious DLL and encrypted payload triad that loads a customized PlugX backdoor, leveraging cloud hosting, re-registered domains and CDN masking to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
