Chinese APT TA416 Resumes Stealthy Espionage on European Diplomats
Chinese state-backed group TA416 resumed cyber espionage against European diplomatic missions in mid-2025 after a two-year pause. The group targets EU and NATO diplomatic mailboxes using a mix of web bugs—tracking pixels that reveal when emails are opened—and diverse malware delivery methods including Cloudflare Turnstile abuse, OAuth redirect flows, and C# project files.
TA416 deploys a custom PlugX backdoor via DLL sideloading, frequently changing its infection chains to evade detection. The group expanded its focus to Middle Eastern diplomatic targets after the Iran conflict began in early 2026. This campaign emphasizes low-noise reconnaissance and iterative testing to improve infection success.
Defenders should not rely solely on signature or attachment scanning. Monitoring HTTP requests for tracking pixels, unusual OAuth redirects, and network indicators of PlugX command-and-control is critical. Incident response must assume mailbox reconnaissance even without malware binaries.