logo

The spy who logged me in.

ID: 25d7e874-6ea3-5903-aa89-4319ec5b343a

STIX ID: report--25d7e874-6ea3-5903-aa89-4319ec5b343a

Feed Name: The CyberWire

Threat Score
85/100

Date Published: 2026-05-09

Date Updated: 2026-05-11

...
...

Researchers report that China-linked threat actor TA416 has resumed large-scale phishing and PlugX malware campaigns targeting European governments, diplomatic missions tied to the EU and NATO, and more recently Middle Eastern entities; the group used evolving techniques such as fake Cloudflare verification pages, Microsoft OAuth redirect abuse, and malicious C# project files to deliver customized PlugX, reflecting shifting geopolitical priorities and continued intelligence-gathering emphasis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.