logo

China-Linked TA416 Targets European Governments with PlugX and OAuth-Based Phishing

ID: a95ac2b7-eef2-5cfa-9467-f68e1f723b18

STIX ID: report--a95ac2b7-eef2-5cfa-9467-f68e1f723b18

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-04-03

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Proofpoint researchers attribute renewed campaigns against EU/NATO diplomatic and government entities to China-aligned TA416, which has delivered customized PlugX backdoors and used web bugs for reconnaissance. The actor has iterated its infection chains — abusing OAuth redirects, Cloudflare Turnstile challenge pages, and MSBuild/CSPROJ-based delivery to fetch DLL side‑loading triads from attacker-controlled infrastructure (Azure Blob, Google Drive, compromised SharePoint, and attacker domains). TA416 shows overlaps with Mustang Panda and demonstrates high operational sophistication and long-term persistence, expanding targeting to the Middle East amid geopolitical conflict.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.