European-Chinese geopolitical issues drive renewed cyberespionage campaign
2026-04-01T14:51:40Z•b91fc053d79b3110e8216f2f6d04dbaec75e6afc2c2329999cbc95244de8cd12
AI-assisted malwareDeepLoadHandalaIranian APTRedLineTA416axioscredential-theftcyberespionageinfostealerobfuscationopen-source compromisere-infectionsupply-chainthreat-actor
What happened
Multiple CyberScoop reports describe a surge in high-impact cyber activity: Proofpoint attributes renewed European-targeting by TA416 to geopolitical tensions; a malicious supply‑chain compromise of the widely‑used axios library threatens large‑scale downstream developer and application compromise; ReliaQuest details DeepLoad, an AI-assisted credential‑stealing malware that obfuscates behavior, logs keystrokes, and re‑infects hosts after remediation; Iranian-linked Handala claims to have accessed the personal email of FBI Director Kash Patel (FBI says no government data taken); and an alleged
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cyberscoop
- Record identifier
- b91fc053d79b3110e8216f2f6d04dbaec75e6afc2c2329999cbc95244de8cd12
- Enrichment time
- 2026-04-01T14:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.