China-Linked TA416 Targets European Governments with PlugX and OAuth-Based Phishing
2026-04-04T01:24:10Z•60c7465297296e27c0fd272c11055716fc2f978b22e54e1aaa662b4e988480d7
AGEWHEEZEAxiosCVE-2025-55182CVE-2026-20093CVE-2026-3502CVE-2026-5281Chrome zero-dayCisco IMCDPRKDriftDurable nonceOAuth phishingPHP web shellPlugXReact2ShellSparkCatTA416TrueConfUNC1069cookie-controlled web shellscryptocurrency theftmobile malwarenpm supply chainphishingsupply-chain compromise','Vertex AI','Anthropic leak
What happened
Multiple high-impact incidents and disclosures across April 2026: China-aligned TA416 resumed targeting European government/diplomatic organizations using PlugX and OAuth-based phishing; North Korean-linked UNC1069 carried out a targeted social-engineering compromise of the Axios npm maintainer (npm supply-chain compromise); a novel Solana attack using durable nonces led to a ~$285M Drain of Drift funds; large-scale credential theft operation exploited React2Shell (CVE-2025-55182) to harvest keys and secrets; Microsoft documented cookie-controlled PHP web shells persisting via cron; mobile Spy
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 60c7465297296e27c0fd272c11055716fc2f978b22e54e1aaa662b4e988480d7
- Enrichment time
- 2026-04-04T01:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.