A China-linked cyber-espionage crew ran continuous spying campaigns against maritime and shipping organizations in at least seven European Union member states through 2025, the European Union Agency for Cybersecurity reported this week. The agency described a “sustained tempo” of intrusions aimed at espionage and intelligence collection, and did not name the affected countries or companies.

ENISA attributed the campaigns to Mustang Panda, a group also tracked as Twill Typhoon and RedDelta, and called it a significant threat capable of repeated attacks on the maritime sector and public administration.

The agency said transport and logistics are of particular interest for economic and political reasons tied to geopolitical developments. ENISA ranks transport among the bloc’s most targeted sectors, at about 11% of recorded incidents.

Mustang Panda’s tie to Beijing is documented outside the report. In court filings unsealed in January 2025, the U.S. Department of Justice stated that the Chinese government paid the group to build a custom version of the PlugX remote-access tool used to steal data from victim networks, and that the FBI deleted the malware from roughly 4,258 U.S. computers. The same filings listed European shipping companies and several European governments among its targets, putting the maritime focus on record before ENISA’s report.

The group is not new to European networks. It was caught targeting EU diplomatic missions in 2022 and ENISA named it a key threat the next year. Security researchers have also documented Mustang Panda turning its tools on Russian government and defense-sector targets, even as Beijing and Moscow describe a close partnership.

…

Archived

  • susieq0044@sh.itjust.works
    link
    fedilink
    arrow-up
    2
    ·
    16 hours ago

    China does what it wants. It supports Putin in Ukraine, spy all over the place… they pretend to be friendly but in reality they care only about themselves, their five-year plan-, communist- dictatorship.