Tag: OAuth-Based Phishing

China-Linked TA416 Targets European Governments with PlugX and OAuth-Based Phishing
News

China-Linked TA416 Targets European Governments with PlugX and OAuth-Based Phishing

After two years of little targeting in the region, a threat actor associated with China has turned its attention on European governments and diplomatic institutions since mid-2025. TA416, a cluster of activity that overlaps with DarkPeony, RedDelta, Red Lich, SmugX, UNC6384, and Vertigo Panda, has been linked to the campaign. According to Proofpoint analysts Mark Kelly and Georgi Mladenov, this TA416 activity involved several rounds of web bug and malware delivery campaigns against diplomatic missions to the European Union and NATO in several European nations. During this time, TA416 routinely updated its proprietary PlugX payload, abused Cloudflare Turnstile challenge pages, abused OAuth redirects, and used C# project files to modify its infection chain read more about China-Lin...