China-Linked TA416 Targets European Governments with PlugX and OAuth-Based Phishing

2026-04-04T07:24:10Z3f269577b7a3f340c0911ca54b5836c3873379d54455120772253e700518c35f
AGEWHEEZEAxiosCERT-UACVE-2025-55182CVE-2026-20093CVE-2026-3502CVE-2026-5281Chrome zero-dayCisco IMCDriftOAuth-phishingPHP web shellsPlugXReact2ShellSolanaSparkCatTA416TrueConfUNC1069WhatsApp malware','Vertex AIcookie-controlled web shellscredential harvestingmobile malwarenpm supply chainsupply-chain compromise

What happened

A collection of early-April 2026 security stories highlighting active, high-impact activity: China-linked TA416 resumed targeting European government/diplomatic organizations using PlugX and OAuth-based phishing; Microsoft documented cookie-controlled PHP web shells persisting via cron on Linux hosts; North Korean UNC1069 attributed for a targeted social-engineering compromise of the Axios npm package; a $285M Solana/Drift theft tied to a durable-nonce social engineering attack; large-scale credential harvesting exploiting the React2Shell flaw in Next.js (CVE-2025-55182); an actively exploited

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
3f269577b7a3f340c0911ca54b5836c3873379d54455120772253e700518c35f
Enrichment time
2026-04-04T07:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.