Proofpoint reported that China-aligned threat actor TA416 resumed sustained cyberespionage against European government, diplomatic, and NATO-linked targets from mid-2025, ending a lull in its EU-focused activity. The campaign heavily targeted diplomatic missions to the EU and NATO, with lures tied to geopolitical issues including EU-China trade tensions, the Russia-Ukraine war, rare earth exports, humanitarian concerns, interview requests, collaboration proposals, and claims about Europe sending troops to Greenland. Researchers said the actor used reconnaissance-focused web bugs and phishing emails to profile victims before attempting malware delivery.
The intrusion chains evolved repeatedly but consistently aimed to install a customized PlugX backdoor via DLL sideloading. Proofpoint observed fake Cloudflare Turnstile pages, abuse of Microsoft Entra ID OAuth redirects, and renamed MSBuild binaries paired with malicious C# project files, alongside updates to TA416's PlugX loader, persistence mechanisms, command-and-control protocol, and configuration encryption. The group also relied on re-registered domains, Cloudflare CDN masking, and VPS infrastructure, and in March 2026 expanded targeting to Middle Eastern diplomatic and government entities after conflict erupted in Iran, indicating intelligence collection driven by fast-moving geopolitical developments.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
By April 2026, Acronis attributed a newly identified campaign to TA416/Mustang Panda that primarily targeted financial organizations in India and also targeted individuals in US-Korea diplomatic and policy circles using Victor Cha-themed lures. The activity used malicious files, DLL sideloading, Registry persistence, and a LotusLite backdoor variant for espionage rather than banking theft.
Proofpoint publicly reported that TA416 had resumed European government espionage from mid-2025 and documented updates to its PlugX tooling, infrastructure, and targeting patterns. The report also noted overlap with public reporting on RedDelta, Red Lich, Vertigo Panda, SmugX, and DarkPeony while distinguishing the activity from UNK_SteadySplit.
In March 2026, Proofpoint observed TA416 broaden its espionage activity to diplomatic and government targets in the Middle East following the outbreak of conflict in Iran. Researchers assessed the expansion as likely driven by new geopolitical intelligence collection priorities.
During the renewed European campaign, TA416 used reconnaissance web bugs, phishing lures, fake Cloudflare Turnstile pages, Microsoft Entra ID OAuth redirect abuse, and renamed MSBuild executables with malicious C# project files. These infection chains were designed to deliver a customized PlugX backdoor via DLL sideloading.
From mid-2025, the China-aligned threat actor TA416 renewed sustained targeting of European government and diplomatic organizations after a lull in EU-focused activity. The campaign concentrated on diplomatic missions and delegations linked to the EU and NATO amid heightened geopolitical tensions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 164 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcethehackernews.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcecyberscoop.com
Open sourceproofpoint.com
Open sourceinfosec.pub
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.