Ciberseguridadlatam Chinese TA419 Group Targets AI Policy Experts with Phishing Campaigns
Article Content
- •TA419 is targeting U.S. AI policy experts using sophisticated phishing techniques.
- •The group impersonated credible figures, including a former OSTP official, to gain trust.
- •Microsoft AitM techniques were used to bypass multifactor authentication.
The Chinese cyberespionage group TA419 has been targeting U.S. AI policy experts through credential phishing campaigns. These attacks, documented by Proofpoint, involved impersonating a former White House OSTP official and prominent economists to gain access to sensitive accounts. The phishing tactics employed included the use of Microsoft AitM (Adversary-in-the-Middle) techniques, allowing attackers to intercept credentials even with multifactor authentication. The campaigns, which began in July 2026, aimed to compromise experts at think tanks and universities, providing strategic insights into regulatory frameworks and technological competition between the U.S. and China. The operation reflects a shift in TA419's focus towards high-value targets within the AI policy domain, indicating a growing interest in influencing AI governance and research. Current status indicates ongoing threats as the group continues to refine its tactics.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track APT41 and Anthropic in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Who is targeted by TA419?
What methods are being used in these attacks?
How can organizations protect themselves?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…