ThreatBeaconXThreatBeaconXSubscribe
CriticalThreat Intelligence · 6 min read

TA419 Targets AI Policy Experts Through Microsoft 365 Credential Phishing

China-aligned espionage actor TA419 has conducted targeted credential-phishing campaigns against artificial intelligence policy experts working for U.S. think tanks, universities, and legal organizations. According to Proofpoint, the campaigns observed in July 2026 involved impersonating prominent economists and AI policymakers to establish credibility with targeted individuals. After the target responded to an initial benign email, TA419 followed up with shortened URLs that redirected victims through attacker-controlled infrastructure to Adversary-in-the-Middle (AitM) credential-phishing pages. The phishing infrastructure used a customized version of the open-source Frameless Browser-in-the-Browser (BitB) framework to target Microsoft 365 and Entra ID credentials. The operation was additionally capable of capturing passwords, MFA codes, and resulting session cookies, allowing attackers to potentially hijack authenticated cloud sessions. Proofpoint assesses that the activity likely supports broader Chinese intelligence objectives focused on understanding U.S. AI policy, regulation, export controls, and developments surrounding strategic AI technologies.

Written by Fred·Published Oct 4, 2026

Description

TA419 is a China-aligned, espionage-motivated threat actor that Proofpoint has observed conducting targeted credential-phishing campaigns against organizations and individuals connected to think tanks, defense contractors, universities, and law firms in the United States and Japan since at least April 2025.

In July 2026, the group expanded this activity toward individuals involved in AI policy and regulation. TA419 impersonated prominent subject-matter experts and used legitimate-looking policy discussions to establish trust before attempting to steal Microsoft 365 credentials and authenticated sessions. 

The targeting comes amid increasing strategic competition surrounding AI technologies, model development, AI regulation, and export controls between the United States and China.

Technical Description

TA419's campaigns use a multi-stage social-engineering and credential-theft process.

The initial email is designed to appear legitimate and generally does not immediately contain an obvious malicious payload. Instead, the attacker impersonates a recognized policy expert and attempts to initiate a conversation.

Examples included invitations to participate in a fictitious "AI Policy Advisory Committee" or requests to contribute to a report concerning AI export controls and supply chains.

After the target responds, TA419 sends a shortened URL that redirects through attacker-controlled infrastructure and ultimately presents a fake OneDrive experience followed by an AitM credential-phishing page. 

The campaign specifically targets Microsoft 365 / Entra ID authentication through Microsoft's first-party OfficeHome application:

client_id=4765445b-32c6-49b0-83e6-1d93765276ca

The phishing infrastructure uses a customized implementation of Frameless BitB, combined with an Evilginx Microsoft 365 phishlet and server-side substitution rules.

Attack Overview

The observed attack chain can be summarized as:

Impersonation → Benign outreach → Victim response → URL redirection → Cloudflare Turnstile → Fake OneDrive page → BitB overlay → AitM authentication → Credential/MFA capture → Session-cookie theft

TA419 began campaigns on July 8, 2026, impersonating individuals including former White House Office of Science and Technology Policy leadership personnel and prominent economists.

The group also previously impersonated a senior Anthropic employee in February 2026 to target an AI policy analyst at a U.S. think tank. 

TA419 Targeting Activity

Two July campaigns specifically impersonated:

  • Lynne Edwards Parker, former Principal Deputy Director of the White House Office of Science and Technology Policy.
  • Heidi Crebo-Rediker, an economist and foreign-policy expert.

The phishing emails were directed toward AI policy experts working at U.S. think tanks, universities, and law firms.

The lures included:

  • Invitations to join a fictitious AI Policy Advisory Committee.
  • Requests to contribute to a Senate Committee on Foreign Relations report.
  • Discussions involving AI export controls and supply chains.

The attackers also previously impersonated a senior Anthropic employee using the subject:

Request for Feedback on Military Integration of Claude

This campaign referenced the debate surrounding U.S. military use of Anthropic's Claude models. 

Infection Chain

TA419 uses URL-shortening services and multiple attacker-controlled domains as part of its phishing infrastructure.

For the July 2026 campaigns, the observed chain included:

driftshare[.]co

→ initial filtering and redirect infrastructure

→ fake OneDrive loading experience

→ globalfileshareplatform[.]com

→ AitM credential-phishing page

The first-stage domain performs a Cloudflare Turnstile check while presenting a fake OneDrive loading screen before redirecting the victim to the second-stage phishing infrastructure. 

Browser-in-the-Browser and AitM Technique

TA419's phishing platform is built around the open-source Frameless BitB framework.

The framework creates a convincing browser interface inside the victim's existing browser window, making the phishing page appear to be a legitimate Microsoft authentication window.

The attacker simultaneously proxies the victim's authentication session to genuine Microsoft infrastructure.

As a result, the victim may successfully complete:

  • Password authentication.
  • MFA verification.
  • Conditional Access checks.

While these controls appear to function normally, the attacker can capture the resulting authenticated session cookies.

This allows the campaign to move beyond simple password theft and potentially enable session hijacking. 

Custom Telemetry and Automation

TA419 modified the phishing framework with custom telemetry and automation functionality.

The observed scripts include:

/secondary/script.js

/primary/script.js

/secondary/observe.js

The /secondary/script.js component is adapted from Frameless BitB and creates a Shadow DOM containing a OneDrive-style folder listing with lure documents.

The /primary/script.js component monitors victim interactions with the fake document listing and can trigger the browser overlay when the user interacts with the document or encounters Microsoft's authentication prompt.

The /secondary/observe.js component provides attacker-side telemetry regarding the victim's position in the authentication process.

It can also automatically select "Keep me signed in" and submit one-time authentication codes once they become valid. 

Infrastructure

TA419 commonly uses Cloudflare's CDN to conceal backend hosting infrastructure.

Its phishing domains are typically registered through NameSilo and are commonly themed around:

  • File-sharing services.
  • Cloud-storage services.
  • Document-sharing platforms.

The group has also registered domains impersonating specific organizations and public figures.

Observed impersonation domains include:

tw-koryu[.]org

heritiages[.]org

heritiage[.]org

shinjirou[.]info

These domains impersonated the Japan-Taiwan Exchange Association, The Heritage Foundation, and the official website of Shinjirō Koizumi. 

Email Infrastructure

TA419 has also been observed using actor-controlled VPS infrastructure to send phishing emails.

One observed VPS was:

108.61.163[.]187

Multiple observed servers shared a self-signed TLS certificate with the following distinguished name:

C=US, ST=Kansas, L=Millsstad,O=Castro Inc, CN=CI

Proofpoint assesses that this certificate may be associated with covert anonymization infrastructure used by TA419.

The group has also used residential proxy services for email delivery. 

Potential Impact

Successful exploitation of this phishing technique could allow attackers to obtain:

  • Microsoft 365 credentials.
  • Entra ID credentials.
  • MFA codes.
  • Authenticated session cookies.
  • Access to cloud applications.
  • Access to sensitive policy and research information.
  • Access to organizational email and documents.
  • Potential access to additional cloud resources through compromised accounts.

Because TA419 focuses on individuals involved in AI policy, defense, national security, international relations, and foreign policy, successful account compromise could provide intelligence value beyond the initially targeted mailbox. 

Recommendations

Immediate Actions

  1. Search email telemetry for the identified TA419 sender addresses and domains.
  2. Review Microsoft 365 and Entra ID authentication logs for suspicious sign-ins associated with targeted users.
  3. Investigate unusual MFA events, session activity, and authentication from unexpected locations.
  4. Revoke active sessions and refresh tokens for suspected compromised accounts.
  5. Reset credentials for affected users where compromise is suspected.
  6. Review mailbox rules, OAuth applications, delegated permissions, and suspicious forwarding configurations.
  7. Block identified phishing domains through DNS, secure web gateways, email security controls, and endpoint security platforms.
  8. Hunt for access to suspicious OneDrive links and unexpected external file-sharing services.
  9. Review Conditional Access and identity-protection alerts for affected users.
  10. Correlate email, identity, endpoint, proxy, and cloud telemetry to identify additional targeted users.

Preventive Actions

  • Implement phishing-resistant authentication such as passkeys or FIDO2 security keys.
  • Strengthen Conditional Access policies for privileged and high-value accounts.
  • Monitor unusual session-cookie and token activity.
  • Enforce strong MFA for all cloud identities.
  • Implement risk-based authentication controls.
  • Train high-value personnel to independently verify unexpected policy-related communications.
  • Establish an out-of-band verification process for sensitive invitations and requests.
  • Monitor newly registered lookalike domains targeting executives and subject-matter experts.
  • Monitor suspicious URL-shortener activity.
  • Implement advanced email authentication and anti-impersonation controls.
  • Restrict legacy authentication protocols.
  • Continuously monitor Microsoft 365 and Entra ID audit logs.
  • Conduct targeted phishing simulations for high-value users.

Proofpoint specifically recommends phishing-resistant, origin-bound authentication such as passkeys and independently verifying unsolicited subject-matter outreach through another communication channel. 

IOC

Email Addresses

leparker@mail[.]com
hcrediker@mail[.]com
hcrediker@outlook[.]com

Domains

driftshare[.]co
globalfileshareplatform[.]com
quickfly[.]online
smartsyncbox[.]com
cirrushare[.]co
mypublicshare[.]com
goshshare[.]online
synchvault[.]co
cloudsyncpulse[.]com
onecloudfilesync[.]com
msfile[.]online
winsync[.]cloud
publicsharefile[.]cloud
fileswiftonline[.]cloud
sharehub[.]space
tw-koryu[.]org
heritiages[.]org
heritiage[.]org
shinjirou[.]info

IP Address

108.61.163[.]187

TLS Certificate SHA-256

b314a1499cd728ca3e54b7150661fd0c7d2279065fe3f570f0f66c395d744460

The indicators above are reported by Proofpoint as associated with TA419 activity and should be validated against organizational telemetry before being treated as evidence of compromise. 

Conclusion

TA419's activity demonstrates how sophisticated credential-phishing operations can use trust and impersonation as the initial attack vector rather than immediately relying on malicious attachments or conventional malware.

By impersonating respected AI policy experts and initiating apparently legitimate conversations, the actor attempts to establish credibility before moving victims toward a highly convincing Microsoft authentication workflow.

The combination of social engineering, URL redirection, Browser-in-the-Browser technology, AitM phishing, MFA interception, and session-cookie theft makes the campaign particularly relevant to organizations working on AI policy, technology, defense, research, and national-security matters.

Proofpoint expects TA419 to continue targeting think tanks and policy experts working on technologies and geographic regions of strategic interest to the Chinese government, including continued impersonation of legitimate subject-matter experts.