China-Linked TA416 Targets European Governments with PlugX and OAuth-Based Phishing

2026-04-04T19:24:09Za7bad375ebb948aa806eeda3e2a6c57dcc89fb66d10da06c09f1ab14891e8501
AGEWHEEZEAnthropicAugmented MarauderCVE-2025-55182CVE-2026-20093CVE-2026-3502','Chrome zero-day','Cisco IMC','TrueConf','DarkSwoCVE-2026-5281CasbaneiroClaude CodeDPRKHorabotMetamorfoNext.jsOAuth phishingPHP web shellPlugXREF1695React2ShellSparkCatTA416UAC-0255UNC1069cookie-controlled web shellsnpmsupply-chain

What happened

A broad set of active campaigns and disclosures affecting governments, cloud platforms, software supply chains and end users were reported. China-linked TA416 resumed targeting European government and diplomatic organizations (PlugX, OAuth-based phishing); North Korean UNC1069 and DPRK-linked actors carried out tailored social‑engineering supply‑chain attacks against the Axios npm package; a large credential‑harvesting campaign exploited CVE-2025-55182 against Next.js hosts; Microsoft described cookie‑controlled PHP web shells and WhatsApp‑delivered VBS malware; researchers disclosed mobile (i

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
a7bad375ebb948aa806eeda3e2a6c57dcc89fb66d10da06c09f1ab14891e8501
Enrichment time
2026-04-04T19:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.