The spy who logged me in.
ID: 25d7e874-6ea3-5903-aa89-4319ec5b343a
STIX ID: report--25d7e874-6ea3-5903-aa89-4319ec5b343a
Feed Name: The CyberWire
Researchers report that China-linked threat actor TA416 has resumed large-scale phishing and PlugX malware campaigns targeting European governments, diplomatic missions tied to the EU and NATO, and more recently Middle Eastern entities; the group used evolving techniques such as fake Cloudflare verification pages, Microsoft OAuth redirect abuse, and malicious C# project files to deliver customized PlugX, reflecting shifting geopolitical priorities and continued intelligence-gathering emphasis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
