TA416 European Government Espionage Campaigns: DNS Deep Dive

Proofpoint reported1 that the China-aligned threat actor TA416 resumed targeting European government and diplomatic organizations from mid-2025 onward, later expanding to Middle Eastern entities. The campaigns paired web bug reconnaissance with malware delivery, rotating through several initial infection chains to ultimately deploy the group's customized PlugX backdoor.

The original analysis publicized 96 network IoCs. Aided by the WhoisXML API MCP Server2, we filtered out domains potentially belonging to legitimate entities and narrowed our investigation to 91 IoCs.

Our DNS deep dive into the TA416 espionage campaigns led to these discoveries:

  • 122 unique client IP addresses that communicated with five of the domain IoCs
  • Three domain IoCs that were bulk-registered with 5–15 look-alikes each
  • 45,197 email-connected domains, 15 of which were confirmed malicious
  • 69 IP addresses, 60 of which were confirmed malicious
  • 117 IP-connected domains
  • 295 string-connected domains

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

  • [1] https://www.proofpoint.com/us/blog/threat-insight/id-come-running-back-eu-again-ta416-resumes-european-government-espionage
  • [2] https://main.whoisxmlapi.com/ai/mcp-server
Try our WhoisXML API for free
Get started