China-Linked TA416 Targets European Governments with PlugX and OAuth-Based Phishing
2026-04-04T13:24:07Z•3944ab2c87dc4fedeef1792cf34af5b7c6179d8eb64150661bad3fe4999c7465
AGEWHEEZEAxiosCERT‑UA impersonationCVE-2025-55182CVE-2026-20093CVE-2026-3502CVE-2026-5281CasbaneiroChrome zero-dayCisco IMCDPRKDrift exploitOAuth phishingPlugXREF1695 (crypto miners)React2ShellSparkCatTA416TrueConfUNC1069cookie‑controlled PHP web shellscron persistencedurable noncesmobile malwarenpm supply chain
What happened
This collection highlights a surge of active, high-impact threats across multiple vectors: state-aligned and financially motivated supply-chain and social-engineering campaigns, active zero-day exploitation, large-scale webhosting compromises, and novel persistence/control techniques. Notable activity includes China-linked TA416 targeting European government/diplomatic organizations (PlugX, OAuth phishing), North Korea–attributed UNC1069 compromising the Axios npm package, a large-scale React2Shell campaign (Next.js/credential theft), Microsoft-documented cookie-controlled PHP web shells pers‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 3944ab2c87dc4fedeef1792cf34af5b7c6179d8eb64150661bad3fe4999c7465
- Enrichment time
- 2026-04-04T13:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.