Zero Day Room
Live
Threats

TA419 Phishing Campaign Impersonates AI Experts

A China-aligned espionage group, tracked as TA419, has been running credential phishing campaigns since July 2026.

Threats: A China-aligned espionage group, tracked as TA419, has been running credential phishing campaigns since July 2026

A China-aligned espionage group tracked as TA419 has been running credential phishing campaigns since at least April 2025, with a new wave of attacks targeting US and Japan-based think tanks, defense contractors, and policy experts starting on 8 July 2026. The group impersonates well-known AI and government figures to steal Microsoft 365 credentials, multi-factor authentication codes, and session cookies, likely feeding Chinese intelligence gathering on US AI policy and regulation.

Mark Kelly said: "In July 2026, TA419 impersonated multiple individuals." The campaign begins with seemingly harmless emails proposing collaboration. If the target replied, TA419 followed up with a malicious link. This initiates a multi-stage URL redirection chain that ultimately leads to a sophisticated adversary-in-the-middle credential phishing attack. The attackers use a customized version of the open-source Frameless BitB browser-in-the-browser phishing tool, which presents victims with a fake OneDrive loading screen and a Cloudflare Turnstile check to appear legitimate. A custom script reports the victim's progress to the attackers in real time, while Cloudflare's content delivery network is used to obscure the backend hosting IP address.

Tactical Execution

The campaign's technical execution relies on a carefully crafted deception. After clicking the link, targets are led through a redirection chain that ends at a counterfeit Microsoft 365 login portal. This adversary-in-the-middle proxy, assembled from the Frameless BitB kit, captures everything entered by the user. It harvests passwords, one-time codes, and, critically, session cookies. Possession of these cookies allows the attacker to bypass multi-factor authentication entirely and maintain access to the victim's cloud account. The operation uses dozens of phishing and spoofed-sender domains, registered via NameSilo and themed around file-sharing and cloud services to avoid suspicion.

Targeted Individuals and Organizations

TA419's phishing emails have specifically impersonated three high-profile individuals to lend credibility to their approach. The spoofed identities and their associated targets reveal a focus on defense and foreign policy sectors.

Impersonated FigureRole / AffiliationCampaign PeriodTargeted Sector / Entity
Lynne ParkerFormer Principal Deputy Director, White House Office of Science and Technology PolicyJuly 2026US think tanks, AI policy analysts
Heidi Crebo-RedikerFormer State Department Chief Economist, foreign policy expertJuly 2026Defense, international relations
Senior Anthropic EmployeeAI company executiveFebruary 2026Technology and AI policy

The group has also spoofed the domains of specific organizations, including The Heritage Foundation, the Japan-Taiwan Exchange Association, and the official website of Japanese Minister of Defense Shinjirō Koizumi. This narrow targeting, affecting fewer than 10 individuals, indicates a highly selective intelligence-gathering operation rather than a broad-brush campaign. The email subject lines were tailored to the ruse, with one example being "Request for Feedback on Military Integration of Claude."

Context and Response

This activity aligns with broader patterns of Chinese cyber-espionage. A House committee reported similar tactics used by Chinese state-linked actors in 2025, and 58% of state-sponsored intrusions against the technology sector are attributed to China-nexus adversaries. The campaign appears designed to support Chinese intelligence objectives around understanding and influencing US AI policy and regulation, a strategic area highlighted by recent US actions like the AI Diffusion Rule which established licensing requirements for advanced computing chips and model weights. Proofpoint, which published the first public research on TA419 on October 1, advises organizations to adopt phishing-resistant sign-in methods such as passkeys. Researchers note that TA419 is likely to continue targeting think tanks and policy experts, a pattern consistent with a previous campaign tracked as UNK_SweetSpecter two years ago.

Related coverage

More from Threats