Skip to content
Hallucinating Credibility: China

Hallucinating Credibility: China

Proofpoint • October 1, 2026

In July 2026, a China-aligned threat actor Proofpoint tracks as TA419 conducted multiple credential phishing campaigns impersonating prominent economists and artificial intelligence (AI) policymakers to target AI experts working for US think tanks, universities, and legal sector organizations.

TA419 also previously impersonated a prominent Anthropic employee to target an AI policy expert at a US think tank in February 2026.

This activity likely supports wider Chinese intelligence objectives to better understand ongoing developments within the US AI policy and regulatory landscape and occurs amid intense strategic competition , accusations of model distillation , and export controls involving the US and China.

In July 2026, TA419 impersonated multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team, in credential phishing campaigns targeting AI policy experts in the US. The group first sent benign conversation starter emails, which included calls to action themed around AI policy such as joining an “AI Policy Advisory Committee”, to build rapport and solicit a response from the target. Once the target replied, TA419 followed up with a multi-stage URL redirection chain that led to an Adversary-in-the-Middle (AitM) credential phish that employed a customized version of the open-source Browser-in-the-Browser (BitB) phishing tool Frameless BitB .

TA419 is a China-aligned and espionage-motivated threat actor that Proofpoint has observed conducting regular targeted credential phishing campaigns against individuals working for US- and Japan-based think tanks, defense contractors, universities, and law firms since at least April 2025. The group’s activity has not been previously reported publicly.

TA419 Activity Targeting AI Policy Analysts

Beginning on 8 July 2026, TA419 impersonated Lynne Edwards Parker, the former Principal Deputy Director of the White House Office of Science and Technology Policy, and then Heidi Crebo-Rediker, a prominent economist and foreign policy expert, in campaigns targeting AI policy experts at US think tanks, universities, and law firms.

Figure 1. TA419 campaign spoofing former White House Office of Science and Technology Policy employee.

In both cases, the group opened with benign outreach, inviting targets to join a fictitious "AI Policy Advisory Committee" or to contribute to a Senate Committee on Foreign Relations report on AI export controls and supply chains.

Figure 2. TA419 campaign inviting users to contribute to AI supply chain report.

If the target replied, TA419 followed up with a shortened URL that purported to additional information. The link ultimately led to a fake OneDrive AitM credential phishing page designed to gain access to the target’s cloud account.

In February 2026, the group impersonated a senior employee of the AI company Anthropic to target an AI policy analyst at a US think tank. The email used the subject line "Request for Feedback on Military Integration of Claude," referencing the debate over US military use of Anthropic's Claude models. This campaign led to a similar AitM credential phishing chain.

TA419 uses URL shortener services to redirect targets to a series of actor-controlled domains. The first actor-controlled domain serves as an initial filter; it conducts a Cloudflare Turnstile check behind a fake OneDrive loading screen before redirecting the target to an AitM credential phishing page hosted on a second TA419-controlled domain. Both July 2026 campaigns targeting US AI policy experts used the same first-stage domain ( driftshare[.]co ) and second-stage domain ( globalfileshareplatform[.]com ).

Figure 3. Example TA419 AitM and BitB phishing page observed in July 2026.

The AitM phishing chain used by TA419 targets Microsoft 365 / Entra ID through the first-party OfficeHome application ( client_id=4765445b-32c6-49b0-83e6-1d93765276ca ). It is built on Frameless BitB , an open-source Browser-in-the-Browser kit, which contains the BitB overlay alongside an Evilginx phishlet for Microsoft 365 and server-side substitution rules that inject the kit into proxied pages.

TA419 has extended this kit with a custom telemetry and automation module that tracks and drives the target's progress through the Microsoft sign-in flow, including multi-factor authentication (MFA). The page the target lands on is the genuine Microsoft /common/oauth2/v2.0/authorize response, relayed in real time, into which the proxy injects two malicious scripts: /secondary/script.js and /secondary/observe.js . Behind a BitB overlay, the proxy relays the sign-in to genuine Microsoft infrastructure, so the target's password, MFA code, and conditional access checks all succeed while the attacker captures the resulting session cookies. The primary client-side scripts used function as follows:

/secondary/script.js is the Frameless BitB driver, an adapted copy of the open-source file. It attaches a Shadow DOM to a container element and fills it with a OneDrive folder listing containing lure documents. The real documents are hosted in an attacker-controlled OneDrive account and reached through a proxy path that turns a 1drv.ms link into an embeddable same-origin page. /secondary/script.js also loads another script ( /primary/script.js ) into the same Shadow DOM.

/primary/script.js is likewise adapted from Frameless BitB, but its body has been replaced. TA419's version intercepts the target's interaction with the listing. It registers clicks and touch handlers and watches for OneDrive's own permission-denied banner, so that either a click on the document or Microsoft's own prompt for authentication raises the fake Chrome browser BitB overlay.

/secondary/observe.js is a custom script which handles telemetry and automation against the relayed sign-in page, reporting the victim's position in the login flow back to the attacker and giving a live view of each session. The same script auto-accepts "Keep me signed in" to extend the stolen session and auto-submits one-time codes as soon as they validate.

TA419 consistently uses Cloudflare’s content delivery network (CDN) to obscure the backend hosting IP address for its domains, which are typically registered via NameSilo. The group’s credential phishing domains are typically themed around file sharing sites and cloud services.

Figure 4. Timeline of TA419 domain registrations.

TA419 also occasionally registers domains impersonating specific organizations and uses these to conduct phishing campaigns.

Japan-Taiwan Exchange Association

The Heritage Foundation

Shinjirō Koizumi’s Official Website

(current Japanese Minister of Defense)

Table 1. Entities spoofed by TA419 during 2026.

On multiple occasions in 2026, the first hop Received headers in TA419 phishing emails exposed likely actor-controlled virtual private servers (VPS) used to send the email. All of the observed servers shared a self-signed TLS certificate present on a high ephemeral port, which featured the subject and issuer distinguished name (DN) C=US, ST=Kansas, L=Millsstad,O=Castro Inc, CN=CI . This certificate is likely associated with a covert network that serves as anonymization infrastructure for TA419’s operations. In other cases, the group was observed sending emails via residential proxy services.

Figure 5. Example TA419 email headers showing actor-controlled VPS 108.61.163[.]187.

TA419 has consistently shown an interest in defense, national security, energy, international relations, and foreign policy targets, predominantly with a nexus to the US and Japan. The targeting of AI policy experts represents an extension of that remit rather than a departure from it. More widely, Proofpoint has previously reported on another China-aligned threat actor, UNK_SweetSpecter, conducting AI-related phishing activity, and regularly observes China-aligned actors targeting other industries, such as semiconductors and rare earths, vital to the supply chain of AI and other strategic technologies.

Proofpoint assesses that TA419 will likely continue targeting think tanks and policy experts working on technologies, and in geographies, of particular interest to the Chinese government. These campaigns will likely also continue spoofing the identities of real subject-matter experts.

Organizations in the scope of TA419 activity should consider phishing-resistant, origin-bound authentication such as passkeys. Individual targets in scope of TA419 activity should treat unsolicited subject-matter outreach as a plausible pretext stage and seek to verify the legitimacy of such unexpected communications via another independent medium.

Attacker-controlled email address

Attacker-controlled email address

hcrediker@outlook[.]com

Attacker-controlled email address

First stage redirect domain

globalfileshareplatform[.]com

Second stage AitM phishing domain

First stage redirect domain

Second stage AitM phishing domain

First stage redirect domain

Second stage AitM phishing domain

First stage redirect domain

First stage redirect domain

Second stage AitM phishing domain

onecloudfilesync[.]com

Second stage AitM phishing domain

First stage redirect domain

First stage redirect domain

publicsharefile[.]cloud

Second stage AitM phishing domain

fileswiftonline[.]cloud

Second stage AitM phishing domain

First stage redirect domain

b314a1499cd728ca3e54b7150661fd0c7d2279065fe3f570f0f66c395d744460

O=Castro Inc Certificate SHA256 Fingerprint