Skip to content
China-Aligned TA419 Targets US AI Experts with Phishing Campaigns

China-Aligned TA419 Targets US AI Experts with Phishing Campaigns

First seen 1 Oct 2026, 15:02 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 16:03 UTC
  • •TA419 impersonated AI policy experts to conduct phishing attacks.
  • •The phishing method involved benign outreach followed by credential theft.
  • •This campaign is linked to broader Chinese intelligence objectives regarding US AI policy.

In July 2026, the China-aligned threat actor TA419 conducted credential phishing campaigns targeting AI policy experts at US think tanks, universities, and law firms. The group impersonated prominent figures, including Lynne Parker and Heidi Crebo-Rediker, to build rapport through benign emails inviting recipients to join a fictitious 'AI Policy Advisory Committee'. After initial contact, victims received a multi-stage URL redirect leading to an adversary-in-the-middle credential phishing page that captured login credentials. This activity is part of a broader Chinese intelligence effort to gather insights on US AI policy amid ongoing geopolitical tensions. TA419 has been active since at least April 2025, with previous campaigns targeting defense and national security sectors. The phishing tool used, Frameless BitB, allows real-time session hijacking, making it particularly dangerous. The group’s activities have not been publicly reported before this incident.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-07-08
TA419 phishing campaign begins
TA419 impersonated Lynne Parker and Heidi Crebo-Rediker to target AI policy experts in the US.
Proofpoint
2026-10-01
Proofpoint reports on TA419
Proofpoint published findings on TA419's credential phishing campaigns targeting US AI policy experts.
Infosecurity-Magazine

More articles in this cluster (5)

Following this threat?

Track TA419 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Who are the targets of TA419?
TA419 targets AI policy experts at US think tanks, universities, and law firms.
What phishing method is used by TA419?
TA419 uses benign initial outreach followed by a multi-stage URL redirect to a credential phishing page.
How can organizations protect themselves?
Organizations should adopt phishing-resistant sign-in methods and verify unsolicited outreach through independent channels.