Back Crnasia China-aligned TA419 targets US AI policy experts in phishing campaigns
Proofpoint says China-aligned TA419 impersonated public figures to target US AI policy experts with credential phishing.
A China-aligned threat actor tracked as TA419 targeted AI policy experts at US think tanks, universities, and legal organizations in credential phishing campaigns, according to new research from Proofpoint.
The campaigns, observed in July 2026, involved attackers impersonating prominent economists and AI policymakers. Proofpoint said TA419 is an espionage-motivated group that it has observed targeting individuals at US- and Japan-based think tanks, defense contractors, universities, and law firms since at least April 2025.
Beginning on July 8, the group impersonated Lynne Edwards Parker, a former principal deputy director at the White House Office of Science and Technology Policy, and economist and foreign policy expert Heidi Crebo-Rediker.
The campaigns targeted AI policy experts working at US think tanks, universities, and law firms. Initial emails invited recipients to join a fictitious "AI Policy Advisory Committee" or contribute to a Senate Committee on Foreign Relations report on AI export controls and supply chains.
The first messages did not contain the credential-stealing link. Proofpoint said TA419 used the emails to obtain a response before sending a shortened URL that claimed to provide additional information.
That link redirected targets through attacker-controlled infrastructure to a fake OneDrive page designed to steal access to cloud accounts. The campaign used an adversary-in-the-middle, or AitM, phishing technique that relayed the victim's authentication process through infrastructure controlled by the attackers.
Proofpoint also linked TA419 to an earlier campaign in February 2026 in which the group impersonated a senior Anthropic employee. The target was an AI policy analyst at a US think tank.
The email used the subject line "Request for Feedback on Military Integration of Claude" and referred to discussions around US military use of Anthropic's Claude models. Proofpoint said the campaign led to a similar AitM credential phishing chain.
Proofpoint assesses that the AI-focused activity likely supports wider Chinese intelligence objectives to better understand developments in US AI policy and regulation.
TA419 modifies phishing tools to target Microsoft accounts
TA419's phishing infrastructure used URL-shortening services followed by multiple attacker-controlled domains. In the July campaigns, Proofpoint identified driftshare[.]co as the first-stage domain and globalfileshareplatform[.]com as the second-stage phishing domain.
The first domain displayed a fake OneDrive loading page while running a Cloudflare Turnstile check. Targets were then redirected to an AitM phishing page hosted on the second domain.
Proofpoint said the phishing chain targeted Microsoft 365 and Entra ID accounts through Microsoft's OfficeHome application. The attack was based on a modified version of Frameless BitB, an open-source Browser-in-the-Browser phishing toolkit.
TA419 modified the toolkit with telemetry and automation capabilities that tracked targets as they moved through the Microsoft sign-in process, including MFA.
The phishing proxy relayed the authentication request to genuine Microsoft infrastructure while injecting malicious scripts into the session. This allowed passwords, MFA codes, and conditional access checks to complete while the attackers captured session cookies, according to Proofpoint.
Proofpoint said the modified toolkit used an attacker-controlled OneDrive account to host lure documents and monitored how targets interacted with the file listing. The modified scripts could then trigger a fake Chrome browser window, track the victim's position in the Microsoft sign-in process, automatically select "Keep me signed in," and submit validated one-time codes.
The report said this custom telemetry gave TA419 operators a live view of each session.
TA419 infrastructure shows a longer-running campaign
Proofpoint's infrastructure data indicates that the activity extended beyond the July campaign, with related infrastructure indicators dating from December 2025 through July 2026.
The group typically used domains themed around file-sharing and cloud services, while Proofpoint also linked TA419 to domains impersonating the Japan-Taiwan Exchange Association, The Heritage Foundation, and Shinjirō Koizumi's official website.
Proofpoint found that TA419 generally used Cloudflare's content delivery network to conceal the backend IP addresses of its domains, while domains were typically registered through NameSilo.
Email headers from several campaigns also exposed virtual private servers that Proofpoint assessed were controlled by the group. The observed servers shared a self-signed TLS certificate, while Proofpoint said TA419 used residential proxy services to send emails in other cases.
Proofpoint said TA419 has previously focused on targets connected to defense, national security, energy, international relations, and foreign policy, mainly in the US and Japan. It described the targeting of AI policy specialists as an extension of that existing activity rather than a separate campaign focus.
Proofpoint has also previously reported AI-related phishing activity by another China-aligned actor it tracks as UNK_SweetSpecter. The company said China-aligned actors have also targeted sectors including semiconductors and rare earths that are important to the supply chains for AI and other strategic technologies.
Proofpoint said it expects TA419 to continue targeting think tanks and policy specialists working on technologies and regions of interest to the Chinese government. The company also expects the group to continue impersonating real subject-matter experts in future campaigns.
Proofpoint recommends phishing-resistant, origin-bound authentication such as passkeys for organizations in TA419's target set, and advises individuals to verify unexpected subject-matter outreach through an independent communication channel.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
