Infosecurity-Magazine China-Aligned TA419 Targets US AI Experts with Phishing Campaigns
Article Content
- •TA419 impersonated AI policy experts to conduct phishing attacks.
- •The phishing method involved benign outreach followed by credential theft.
- •This campaign is linked to broader Chinese intelligence objectives regarding US AI policy.
In July 2026, the China-aligned threat actor TA419 conducted credential phishing campaigns targeting AI policy experts at US think tanks, universities, and law firms. The group impersonated prominent figures, including Lynne Parker and Heidi Crebo-Rediker, to build rapport through benign emails inviting recipients to join a fictitious 'AI Policy Advisory Committee'. After initial contact, victims received a multi-stage URL redirect leading to an adversary-in-the-middle credential phishing page that captured login credentials. This activity is part of a broader Chinese intelligence effort to gather insights on US AI policy amid ongoing geopolitical tensions. TA419 has been active since at least April 2025, with previous campaigns targeting defense and national security sectors. The phishing tool used, Frameless BitB, allows real-time session hijacking, making it particularly dangerous. The group’s activities have not been publicly reported before this incident.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track TA419 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Who are the targets of TA419?
What phishing method is used by TA419?
How can organizations protect themselves?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…