PULSE NAME
TA416 resumes European government espionage campaigns
WHITE MUSTANG PANDA AlienVault 2026-04-07 Modified: 2026-04-07
256
IOCs
HIGH VOLUME
Since mid-2025, China-aligned threat actor TA416 has resumed targeting European government and diplomatic organizations after a two-year operational shift to Southeast Asia. The campaigns primarily focused on diplomatic missions to the EU and NATO, using web bug reconnaissance and malware delivery through compromised accounts and attacker-controlled infrastructure. In March 2026, TA416 expanded operations to Middle Eastern diplomatic entities following the Iran conflict outbreak. Throughout this period, the actor continuously evolved infection chains, utilizing fake Cloudflare Turnstile pages, OAuth redirect abuse, and C# project files to deliver a customized PlugX backdoor via DLL sideloading. The group employed both broad reconnaissance campaigns and targeted malware delivery, demonstrating sophisticated tradecraft including use of re-registered legitimate domains and cloud infrastructure for command and control operations.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
PlugX - S0013 Thoper TVT DestroyRAT Sogu Kaba Korplug TONESHELL PUBLOAD
Indicators of Compromise (44 / 256 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 0538e73fc195c3b4441721d4c60d0b96 2026-04-07
FileHash-MD5 06fcc2a56de5acdf1ca1847c79cca9e9 2026-04-07
FileHash-MD5 0749f8e05b6f0b4d200eadb4f7bb28e4 2026-04-07
FileHash-MD5 0aad27ddd173bfae8009b1ecb46f29b0 2026-04-07
FileHash-MD5 0f9bf9bdfc6f9471345a6a64bb0e57da 2026-04-07
FileHash-MD5 2226d3e8843b3e2c228da3a3fdc56e7b 2026-04-07
FileHash-MD5 319e0fce4e637a5412e125d6c99348d7 2026-04-07
FileHash-MD5 381247c1d4c68a406237d7d3aa030930 2026-04-07
FileHash-MD5 42fd91f217aeaeef241a27962643d070 2026-04-07
FileHash-MD5 52f6beda7097db23ec1b395eff9efb4a 2026-04-07
FileHash-MD5 5c92f0a474846a8df4aaff5c3b16af34 2026-04-07
FileHash-MD5 637dbccf9d5d5fb9e41cadbf0803bc55 2026-04-07
FileHash-MD5 65658848c424482eaa4bac6e53c25146 2026-04-07
FileHash-MD5 69f3f25b4049e8ed198ba2c76a2a137f 2026-04-07
FileHash-MD5 769687f93869a70511aac1ef7c752455 2026-04-07
FileHash-MD5 7a183bd25d190662c3008c794f6cb604 2026-04-07
FileHash-MD5 7a75e713db41c28378e823322fdea0fd 2026-04-07
FileHash-MD5 7ca528c170164f9945c87d5ba673b7b0 2026-04-07
FileHash-MD5 80fc64b636834e85ed58220d456cd5c5 2026-04-07
FileHash-MD5 8a1a090b2c5de4a3c31b4062685aff9f 2026-04-07
FileHash-MD5 90edc0cecd3f762c36a38a5642e0d939 2026-04-07
FileHash-MD5 95254a16917d2c458ea5143ad35373cd 2026-04-07
FileHash-MD5 9a574029357cbbba709a18f8d34df77f 2026-04-07
FileHash-MD5 a12357ff6c0f7b021f32b0c9cd3d01c4 2026-04-07
FileHash-MD5 a29e49a21bf3469a0044be2e2b989ad3 2026-04-07
FileHash-MD5 a8082a80cef9ccee9d7a35f5366e3afb 2026-04-07
FileHash-MD5 a9c77dbe140490c5a22c3ae2536a8b32 2026-04-07
FileHash-MD5 adb67ffe941a706b6343f94413f6e5f2 2026-04-07
FileHash-MD5 bbcfb30c493faa48c07d1d46c9daf8da 2026-04-07
FileHash-MD5 bd6c687a3908052ee14b7d5178442a72 2026-04-07
FileHash-MD5 c24a8d717176ba9b1e53991b13ef9ba9 2026-04-07
FileHash-MD5 c27462566a4cc90b015664ab55caa250 2026-04-07
FileHash-MD5 c3c98201b693760f4de8495595ebbe7d 2026-04-07
FileHash-MD5 c647e6e683a88af07d861847a18468f8 2026-04-07
FileHash-MD5 d71ff71b7d5b7daf4ad892b0e7baca03 2026-04-07
FileHash-MD5 dd82199fe9a36850aaaa6bf28293380a 2026-04-07
FileHash-MD5 ddd5f542c15be47f9e1d8a52768a1b1a 2026-04-07
FileHash-MD5 e78d4f1f53123ceffedac6d4698438b9 2026-04-07
FileHash-MD5 e7cb954f4bbdbadbd2c0206577621683 2026-04-07
FileHash-MD5 f15c9d7385cffd1d04e54c5ffdb76526 2026-04-07
FileHash-MD5 f331af4c164a40d13b24def0818e0198 2026-04-07
FileHash-MD5 f517f01384310145d989ec45a649d9c3 2026-04-07
FileHash-MD5 fa107167ff9303c06c8c7c518a7a1923 2026-04-07
FileHash-MD5 fb56f1d79d491a2557112d072baf5ab2 2026-04-07