Threat Intelligence, Government security, Critical Infrastructure Security

New Chinese cyberespionage campaigns strike Europe

China Flag Made of Binary Code and Chinese Symbols on Red Backgr

Chinese state-sponsored threat operation TA416 has reemerged from a two-year hiatus to compromise European governments in a series of cyberespionage campaigns since mid-2025, reports Infosecurity Magazine.

Tracking pixel and malware delivery intrusions conducted by TA416 to facilitate the deployment of the PlugX malware in targeted systems involved several alterations in initial access techniques, according to a Proofpoint report. After initially leveraging spoofed Cloudflare Turnstile challenge pages from September 2025 to January 2026 and exploiting Microsoft Entra ID third-party apps from December 2025 to January 2026, TA416 proceeded to harness archives with a renamed Microsoft MSBuild executable and illicit C# project files since February.

Moreover, Middle Eastern government and diplomatic entities have also been targeted by the group since the escalation of the conflict in Iran last month. Additional findings showed that while TA416 has significant overlaps with fellow Mustang Panda cluster UNK_SteadySplit, the relationship between the two groups remains inconclusive.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds