[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fn8aCLKaPOg-rVpCMNAO2XDnnX46DkDJJ5BMH3Nshq3A":3},{"article":4,"iocs":28,"watch_terms":37},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":18,"category":19,"article_tags":22},"40bf1f13-c41c-4c0e-bfe5-fa4ef899385a","European-Chinese geopolitical issues drive renewed cyberespionage campaign","european-chinese-geopolitical-issues-drive-renewed-cyberespionage-campaign","Proofpoint researchers say the group behind the surge, TA416, had turned away from Europe for a few years. The post European-Chinese geopolitical issues drive renewed cyberespionage campaign appeared first on CyberScoop.","Proofpoint researchers report that Chinese cyberespionage group TA416 (also tracked as Twill Typhoon, Mustang Panda) has renewed operations against European diplomatic missions and EU\u002FNATO entities since mid-2025, coinciding with escalating EU-China tensions over trade, Ukraine support, and rare earth exports. The group employs phishing, web bugs, and PlugX backdoor delivery via DLL sideloading, with lures ranging from Greenland troop deployments to humanitarian concerns. TA416 simultaneously expanded into Middle Eastern government targeting in March 2025 following regional conflict, marking the first observed shift into that theater.","Chinese APT TA416 resumes Europe targeting after years away, focusing on NATO and EU diplomacy.","A Chinese cyberespionage group has shifted its gaze back to Europe after years of focusing on other parts of the world, Proofpoint research published Wednesday found. The surge began in mid-2025, with a bevy of issues bubbling up between China and Europe, the company said. Proofpoint labels the government-linked group TA416, but other companies track it as Twill Typhoon, Mustang Panda or other names. “This renewed focus most heavily targeted individuals or mailboxes associated with diplomatic missions and delegations to NATO and the EU,” Proofpoint’s Mark Kelly and Georgi Mladenov wrote. “TA416’s return to European government targeting occurred during heightened EU–China tensions over trade, the Russia–Ukraine war, and rare earths exports, and commenced immediately following the 25th EU–China summit.” Separately, the same group took up targeting the Middle East in March after the start of the conflict in Iran, something it had never been spotted doing before, Proofpoint found. “This aligns with a trend observed by Proofpoint of some state-aligned threat actors shifting targeting toward Middle Eastern government and diplomatic entities in the aftermath of the war,” the firm said. “This likely reflects an effort to gather regional intelligence on the status, trajectory, and broader geopolitical implications of the conflict.” TA416 was active in Europe in 2022 and 2023, coinciding with the onset of the Ukraine-Russia war, but stepped away from the continent afterward, according to the researchers. Its focus turned to Southeast Asia, Taiwan and Mongolia for a couple years. The group’s focus on Europe through early 2026 used a variety of web bug and malware delivery methods, including setting up reconnaissance by dangling lures about Europe sending troops to Greenland. It also included phishing emails about humanitarian concerns, interview requests and collaboration proposals, Proofpoint said. “During this period, TA416 repeatedly altered its initial infection chains while maintaining a consistent goal of loading the group’s customized PlugX backdoor via DLL sideloading triads,” the researchers wrote. Proofpoint’s is not the only report of late about Chinese cyberespionage groups targeting Europe, with another focused on LinkedIn solicitations to NATO and European institutions. Share Facebook LinkedIn Twitter Copy Link","https:\u002F\u002Fcyberscoop.com\u002Feuropean-chinese-geopolitical-issues-drive-renewed-cyberespionage-campaign\u002F",null,"2026-04-01T14:31:33+00:00","2026-04-01T16:00:11.132253+00:00",8,[],"6cbdd207-aaa1-4176-9534-e156b125e917",{"id":18,"icon":13,"name":20,"slug":21},"Nation-state","nation-state",[23],{"category":24},{"id":25,"icon":13,"name":26,"slug":27},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[29,33],{"type":30,"value":31,"context":32},"malware","PlugX","Customized backdoor consistently loaded by TA416 via DLL sideloading triads",{"type":34,"value":35,"context":36},"mitre_attack","T1574.002","DLL sideloading technique used in TA416 infection chains",[]]