INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Cyberespionage Campaigns by European and Chinese Hackers

| 2026-04-01 14:31 CRITICAL HIGH
Executive Summary AI-generated
The surge in cyberattacks targeting European government entities has escalated, with the Chinese cyberespionage group TA416 shifting its focus back to the continent after years of focusing on other parts of the world. The group's return to European government targeting occurred during heightened EU-China tensions over trade and conflicts such as Ukraine-Russia war and rare earths exports. TA416 had previously been spotted in Europe, but stepped away from the continent afterward. Its renewed focus has led to a variety of web bug and malware delivery methods, including reconnaissance by dangling lures about troops being sent to Greenland, phishing emails about humanitarian concerns, interview requests and collaboration proposals, and targeted attacks on diplomatic missions and delegations to NATO and the EU.
Technical Mitigations AI-generated
* Use a reputable antivirus software and keep it up to date to prevent malware infections. * Implement a firewall on your computer or network to block unauthorized access from external sources. * Regularly update operating system, browser, and other software versions to ensure you have the latest security patches. * Use strong passwords and enable multi-factor authentication (MFA) whenever possible to add an extra layer of security for sensitive information.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Mustang PandaMustang Panda TONESHELLTONESHELLPlugXPlugX
Target & Sectors
NORTH_AMERICA NORTH_AMERICA APAC APAC EUROPE EUROPE MIDDLE_EAST MIDDLE_EAST
Incident Timeline
‎mid-2025
Threat actors used China's state-backed hacking groups to target European diplomatic missions.
organisation EU
organisation NATO
target_region EUROPE
source_region China
‎September 2025
Threat actors used spear phishing to gain initial access into compromised systems.
‎October 2025
Mustang Panda used Arctic Wolf to target Belgian and Hungarian diplomats in October 2025.
threat_actor Mustang Panda
tactic Espionage
source_region Belgium
source_region Hungary
‎December 2025
Threat actors used spoofed Cloudflare Turnstile challenge pages to gain unauthorized access to ZIP archives.
‎January 2026
Threat actors used spoofed Cloudflare Turnstile challenge pages to gain access to ZIP archives.
‎February 2026
Microsoft's TA416 exploit was used to target users of its Entra ID third-party applications.
organisation Microsoft
‎March 2026
Threat actors used Proofpoint's software to target Iranian diplomatic and government entities in the Middle East.
target_region Iran, Islamic Republic of
target_region MIDDLE_EAST
‎mid-2025 to early 2026
TA416 launched broad web bug and malware delivery campaigns in Europe from mid-2025 to early 2026.
target_region EUROPE
tactic Espionage
‎April 1
TA416 exploited vulnerabilities in Cloudflare Turnstile challenge pages to target its victims.
organisation Cloudflare Turnstile
organisation OAuth
malware PlugX
‎2025-2026
Threat actors used a previously unknown vulnerability in the TA416 network to gain unauthorized access to sensitive data of Chinese state-owned enterprises.
‎2026/04/01
Mustang Panda launched a fresh wave of cyber espionage campaigns against European governments.
threat_actor Mustang Panda
organisation APT
organisation Twill Typhoon
organisation Chinese Hackers Target European Governments
organisation EU
organisation NATO
organisation DLL
organisation LNK
organisation IP
organisation RedDelta
organisation UNC6384
organisation SmugX
organisation DarkPeony
organisation CerenaKeeper
organisation Trend Micro
organisation Stately Taurus
organisation HoneyMyte
organisation TA416’s Infrastructure TA416
organisation VPS
organisation Evoxt Enterprise
organisation XNNET LLC
organisation the Cloudflare Content Delivery Network
organisation CDN
organisation CyberScoop
organisation The Washington Post
organisation POLITICO
‎early 2026
Threat actors used a variety of web bug and malware delivery methods to target Europe, including setting up reconnaissance by dangling lures about troops being sent to Greenland.
target_region Greenland
tactic Reconnaissance
target_region EUROPE
Intelligence Sources