
About this episode
Mark Kelly, Staff Threat Researcher at Proofpoint, is discussing their work on "I’d come running back to EU again: TA416 resumes European government espionage campaigns." China-linked threat group TA416 has resumed large-scale phishing and malware campaigns targeting European governments, diplomatic missions tied to the EU and NATO, and more recently Middle Eastern entities following the outbreak of conflict in Iran.
The group has continually evolved its tactics between mid-2025 and early 2026, using techniques like fake Cloudflare verification pages, Microsoft OAuth redirect abuse, and malicious C# project files to deliver customized PlugX malware through spearphishing campaigns. Researchers say the renewed activity reflects shifting geopolitical priorities tied to EU-China tensions, the Russia-Ukraine war, and instability in the Middle East, while highlighting TA416’s ongoing focus on intelligence gathering against diplomatic networks.
The research and executive brief can be found here:
I’d come running back to EU again: TA416 resumes European government espionage campaigns
Get every episode summarized
Each time CyberWire Daily publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from CyberWire Daily

Clear your calendar, it’s Patch Tuesday.
CyberWire Daily
Sep 9, 202630:40completed

Worming its way through WeChat.
CyberWire Daily
Sep 8, 202630:03completed

This call may be monitored. [Special Edition]
CyberWire Daily
Sep 7, 202638:33pending

When hackers control the clock. [T-Minus: Space-Cyber Briefing]
CyberWire Daily
Sep 6, 202623:43pending