TA416 Strikes Back: Chinese Espionage Floods European Diplomats' Inboxes
Chinese hackers from TA416 are back, hitting European governments with web bugs and PlugX malware after a two-year lull. Proofpoint warns of rapid evolution in tactics targeting diplomats.
Threat DigestApr 02, 20263 min read
⚡ Key Takeaways
TA416 resumed Europe-focused espionage in mid-2025 with web bugs and PlugX malware.𝕏
Tactics evolved rapidly: Cloudflare abuse to C# loaders, expanding to Middle East.𝕏
Infrastructure uses re-registered domains and VPS to evade detection—parallels pre-war Russian ops.𝕏
The 60-Second TL;DR
TA416 resumed Europe-focused espionage in mid-2025 with web bugs and PlugX malware.
Tactics evolved rapidly: Cloudflare abuse to C# loaders, expanding to Middle East.
Infrastructure uses re-registered domains and VPS to evade detection—parallels pre-war Russian ops.