Threats · 164 days ago
Chinese state-backed group TA416 resumed cyber espionage against European diplomatic missions in mid-2025 after a two-year pause. The group targets EU and NATO diplomatic mailboxes using a mix of web bugs—tracking pixels that reveal when emails are opened—and diverse malware delivery methods including Cloudflare Turnstile abuse, OAuth redirect flows, and C# project files.
TA416 deploys a custom PlugX backdoor via DLL sideloading, frequently changing its infection chains to evade detection. The group expanded its focus to Middle Eastern diplomatic targets after the Iran conflict began in early 2026. This campaign emphasizes low-noise reconnaissance and iterative testing to improve infection success.
Defenders should not rely solely on signature or attachment scanning. Monitoring HTTP requests for tracking pixels, unusual OAuth redirects, and network indicators of PlugX command-and-control is critical. Incident response must assume mailbox reconnaissance even without malware binaries.
3 sources covering this story
China-Linked TA416 Targets European Governments with PlugX and OAuth-Based Phishing
TA416 targeted European governments from mid-2025 using PlugX and OAuth abuse, enabling cyber espionage against EU and NATO entities.
European-Chinese geopolitical issues drive renewed cyberespionage campaign
Proofpoint researchers say the group behind the surge, TA416, had turned away from Europe for a few years.
Chinese Hackers Target European Governments in Espionage Campaigns
Chinese state-backed group TA416 had suspended its cyber espionage operations in Europe since 2023, noted Proofpoint
Part of the PlainSec briefing for 2026-04-04