China-linked threat activity was reported against both critical infrastructure in India and diplomatic targets in Europe, with researchers describing sustained espionage and pre-positioning operations rather than confirmed destructive attacks. Recorded Future’s Insikt Group said intrusions hit seven Indian State Load Dispatch Centers near the disputed Ladakh border, as well as India’s national emergency response apparatus and an Indian logistics subsidiary, using ShadowPad malware, compromised DVR/IP camera devices for command-and-control, and the FastReverseProxy tool. The activity was assessed as likely intended to establish access and collect intelligence inside India’s power sector.
Separately, Proofpoint said China-aligned actor TA416 increased operations against European diplomatic entities as Russia-Ukraine tensions escalated, including targeting a person involved in refugee and migrant services. The campaigns used web bugs to confirm active recipients before sending malicious links that ultimately deployed updated PlugX malware through ZIP archives, droppers, and DLL search-order hijacking. Proofpoint found substantial overlap between TA416 and the publicly reported Red Delta cluster, while Beijing publicly denied involvement in the India-related accusations and said it opposes cyberattacks.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
In late March 2022, SentinelLabs concluded that malware distributed in Ukraine and disguised as a request for video documentation of Russian aggression was associated with the suspected Chinese threat actor Scarab. The activity was described as one of the first public examples of a Chinese threat actor targeting Ukraine since the invasion began.
On February 28, 2022, TA416 used a compromised email account belonging to a diplomat from a European NATO country to target another country's diplomatic offices. The campaign delivered a compressed archive that fetched a decoy document, a legitimate executable, a malicious loader, and an encrypted PlugX payload.
Beginning on January 17, 2022, TA416 used a previously observed actor-controlled IP in phishing emails to deliver malicious ZIP files to European diplomatic entities that had earlier received web bug emails. The lures used geopolitical themes and led to a PlugX infection chain using a PE dropper and DLL search order hijacking.
Proofpoint observed TA416 using web bug reconnaissance campaigns against European diplomatic entities starting in early November 2021. The tracking pixels were used to confirm valid email accounts and whether recipients opened phishing emails.
In August 2020, TA416 impersonated UN personnel and targeted governmental entities in Europe using a Dropbox URL to deliver a PlugX variant. Proofpoint said this activity aligned with Recorded Future's publicly reported Red Delta analysis.
China denied involvement in the reported attacks on India's power grid. Foreign ministry spokesperson Zhao Lijian said Beijing opposes cyberattacks and urged caution in attributing such activity to governments.
Insikt Group reported network intrusions affecting seven Indian State Load Dispatch Centers near the disputed Ladakh border, along with an Indian national emergency response team and the Indian subsidiary of a logistics company. The operation used ShadowPad and FastReverseProxy, and was assessed as likely pre-positioning and intelligence collection against critical infrastructure.
Proofpoint reported ongoing China-aligned TA416 espionage targeting European diplomatic entities and at least one individual involved in refugee and migrant services. The company said the activity aligned with Chinese interest in refugee policies and logistics during the Russia-Ukraine conflict period.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 55 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.