← Back to feed
PhishingEmerging1 sourceMay 9, 2026 · 07:00via The CyberWire

The spy who logged me in. [Research Saturday]

Brief

Mark Kelly , Staff Threat Researcher at Proofpoint , is discussing their work on "I’d come running back to EU again: TA416 resumes European government espionage campaigns."

China-linked threat group TA416 has resumed large-scale phishing and malware campaigns targeting European governments, diplomatic missions tied to the EU and NATO, and more recently Middle Eastern entities following the outbreak of conflict in Iran.

The group has continually evolved its tactics between mid-2025 and early 2026, using techniques like fake Cloudflare verification pages, Microsoft OAuth redirect abuse, and malicious C# project files to deliver customized PlugX malware through spearphishing campaigns.

Read more on The CyberWire