Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
state-sponsored-espionagegovernment-diplomatic-threatphishing-campaign-intelligenceremote-access-implant

TA416 Revives Espionage Against European Governments and NATO Missions

Updated 2mo agoFirst seen Apr 1, 20267 sources

Proofpoint reported that China-aligned threat actor TA416 resumed sustained cyberespionage against European government, diplomatic, and NATO-linked targets from mid-2025, ending a lull in its EU-focused activity. The campaign heavily targeted diplomatic missions to the EU and NATO, with lures tied to geopolitical issues including EU-China trade tensions, the Russia-Ukraine war, rare earth exports, humanitarian concerns, interview requests, collaboration proposals, and claims about Europe sending troops to Greenland. Researchers said the actor used reconnaissance-focused web bugs and phishing emails to profile victims before attempting malware delivery.

The intrusion chains evolved repeatedly but consistently aimed to install a customized PlugX backdoor via DLL sideloading. Proofpoint observed fake Cloudflare Turnstile pages, abuse of Microsoft Entra ID OAuth redirects, and renamed MSBuild binaries paired with malicious C# project files, alongside updates to TA416's PlugX loader, persistence mechanisms, command-and-control protocol, and configuration encryption. The group also relied on re-registered domains, Cloudflare CDN masking, and VPS infrastructure, and in March 2026 expanded targeting to Middle Eastern diplomatic and government entities after conflict erupted in Iran, indicating intelligence collection driven by fast-moving geopolitical developments.

Share:
TA416 Revives Espionage Against European Governments and NATO Missions
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Apr 21, 20262mo ago

TA416 targets Indian banks and US-Korea policy circles with LotusLite

By April 2026, Acronis attributed a newly identified campaign to TA416/Mustang Panda that primarily targeted financial organizations in India and also targeted individuals in US-Korea diplomatic and policy circles using Victor Cha-themed lures. The activity used malicious files, DLL sideloading, Registry persistence, and a LotusLite backdoor variant for espionage rather than banking theft.

Chinese APT Targets Indian Banks, Korean Policy Circles
Mar 26, 20263mo ago

Proofpoint publishes analysis of renewed TA416 espionage activity

Proofpoint publicly reported that TA416 had resumed European government espionage from mid-2025 and documented updates to its PlugX tooling, infrastructure, and targeting patterns. The report also noted overlap with public reporting on RedDelta, Red Lich, Vertigo Panda, SmugX, and DarkPeony while distinguishing the activity from UNK_SteadySplit.

Mar 1, 20264mo ago

TA416 expands targeting to Middle Eastern diplomatic and government entities

In March 2026, Proofpoint observed TA416 broaden its espionage activity to diplomatic and government targets in the Middle East following the outbreak of conflict in Iran. Researchers assessed the expansion as likely driven by new geopolitical intelligence collection priorities.

Jun 1, 20251y ago

TA416 runs evolving phishing and malware delivery campaigns in Europe

During the renewed European campaign, TA416 used reconnaissance web bugs, phishing lures, fake Cloudflare Turnstile pages, Microsoft Entra ID OAuth redirect abuse, and renamed MSBuild executables with malicious C# project files. These infection chains were designed to deliver a customized PlugX backdoor via DLL sideloading.

TA416 resumes sustained espionage against European government targets

From mid-2025, the China-aligned threat actor TA416 renewed sustained targeting of European government and diplomatic organizations after a lull in EU-focused activity. The campaign concentrated on diplomatic missions and delegations linked to the EU and NATO amid heightened geopolitical tensions.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

30 LINKEDOpen in app
Threat actors
2 linked
Affected products
3 linked
Microsoft Entra IdGoogle DriveWindows
Organizations
18 linked
GoogleProofpointCloudflareMicrosoft CorporationAcronisHDFC BankAlamyWirestock, Inc.Arctic WolfStrikeReadyTrend MicroCanonCrowdStrikeInfosecurity MagazineDarktraceXNNET LLCKaopu Cloud HK LimitedEvoxt Enterprise
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

TA416 Revives Espionage Against European Governments and NATO Missions | Mallory