China-Linked TA416 Targets European Governments with PlugX and OAuth-Based Phishing
ID: a95ac2b7-eef2-5cfa-9467-f68e1f723b18
STIX ID: report--a95ac2b7-eef2-5cfa-9467-f68e1f723b18
Feed Name: The Hacker News
Proofpoint researchers attribute renewed campaigns against EU/NATO diplomatic and government entities to China-aligned TA416, which has delivered customized PlugX backdoors and used web bugs for reconnaissance. The actor has iterated its infection chains — abusing OAuth redirects, Cloudflare Turnstile challenge pages, and MSBuild/CSPROJ-based delivery to fetch DLL side‑loading triads from attacker-controlled infrastructure (Azure Blob, Google Drive, compromised SharePoint, and attacker domains). TA416 shows overlaps with Mustang Panda and demonstrates high operational sophistication and long-term persistence, expanding targeting to the Middle East amid geopolitical conflict.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
