TA416 European government espionage campaign
Campaign
Summary
Hide ▲
Show ▼
TA416 has resumed cyber espionage activity, targeting European governments and EU/NATO diplomatic missions with a renewed malware-delivery operation that raises cross-border intelligence risk. The group repeatedly changed its infection chain, using Cloudflare Turnstile, OAuth redirects, and C# project files to deliver a customized PlugX backdoor. In March 2026, the operation expanded to Middle East diplomatic and government entities after conflict broke out in Iran.
Related Happenings
UNC6508 China-linked REDCap espionage campaign
Campaign
H score39
First: 15.06.2026 17:00
Last: 15.06.2026 17:00
Sources 1
About this happening:
UNC6508 ran a China-linked espionage campaign against exposed REDCap servers used by North American medical, academic, and military research networks. The operatio...
UNC6508 China-linked REDCap espionage campaign
CampaignAbout this happening: UNC6508 ran a China-linked espionage campaign against exposed REDCap servers used by North American medical, academic, and military research networks. The operatio...
Webworm expanded European government and South Africa university espionage campaign
Campaign
H score24
First: 20.05.2026 14:30
Last: 20.05.2026 14:30
Sources 1
About this happening:
Webworm expanded its 2025 espionage campaign into European government organizations and a university in South Africa, widening the cross-region targeting risk. The ope...
Webworm expanded European government and South Africa university espionage campaign
CampaignAbout this happening: Webworm expanded its 2025 espionage campaign into European government organizations and a university in South Africa, widening the cross-region targeting risk. The ope...
Secret Blizzard Kazuar modular P2P botnet
Malware Activity
H score28
First: 16.05.2026 17:15
Last: 16.05.2026 17:15
Sources 1
About this happening:
Kazuar is being used in a multi-stage campaign in Ukraine that ESET says likely involves Gamaredon providing access and Turla/Secret Blizzard delivering the ba...
Secret Blizzard Kazuar modular P2P botnet
Malware ActivityAbout this happening: Kazuar is being used in a multi-stage campaign in Ukraine that ESET says likely involves Gamaredon providing access and Turla/Secret Blizzard delivering the ba...
Shadow-Aether-040 AI-augmented campaign against Mexican government entities
Campaign
H score41
First: 13.05.2026 16:00
Last: 13.05.2026 16:00
Sources 1
About this happening:
The Shadow-Aether-040 campaign used AI agents and custom tooling to compromise six government entities in Mexico, increasing the risk of follow-on intrusion and data...
Shadow-Aether-040 AI-augmented campaign against Mexican government entities
CampaignAbout this happening: The Shadow-Aether-040 campaign used AI agents and custom tooling to compromise six government entities in Mexico, increasing the risk of follow-on intrusion and data...
FamousSparrow Azerbaijanian oil-and-gas targeting campaign
Campaign
H score32
First: 13.05.2026 16:00
Last: 13.05.2026 16:00
Sources 1
About this happening:
The China-linked FamousSparrow group ran a targeted cyberespionage campaign against an Azerbaijanian oil-and-gas company in the South Caucasus, highlighting a new...
FamousSparrow Azerbaijanian oil-and-gas targeting campaign
CampaignAbout this happening: The China-linked FamousSparrow group ran a targeted cyberespionage campaign against an Azerbaijanian oil-and-gas company in the South Caucasus, highlighting a new...
Timeline
-
03.04.2026 20:34 1 articles · 3mo ago
TA416 expands espionage campaign to Middle Eastern government targets
Campaign Scope UpdateTA416 expanded its espionage campaign to Middle Eastern government and diplomatic entities after the outbreak of the U.S.-Israel-Iran conflict in late February 2026, while linking to archives hosted on Google Drive or a compromised SharePoint instance to refine its PlugX delivery chain and collect regional intelligence.
Show sources
- China-Linked TA416 Targets European Governments with PlugX and OAuth-Based Phishing — thehackernews.com — 03.04.2026 20:34
-
01.04.2026 15:05 1 articles · 3mo ago
Initial report: TA416 European government espionage campaign
Initial DisclosureThe renewed operation first surfaced in mid-2025 with web-bug and malware-delivery activity aimed at European government targets. Early targeting centered on EU and NATO diplomatic missions before the campaign later widened.
Show sources
- Chinese Hackers Target European Governments in Espionage Campaigns — www.infosecurity-magazine.com — 01.04.2026 15:05