TA419 Phishing Campaign Impersonates AI Experts
A China-aligned espionage group, tracked as TA419, has been running credential phishing campaigns since July 2026.

A China-aligned espionage group tracked as TA419 has been running credential phishing campaigns since at least April 2025, with a new wave of attacks targeting US and Japan-based think tanks, defense contractors, and policy experts starting on 8 July 2026. The group impersonates well-known AI and government figures to steal Microsoft 365 credentials, multi-factor authentication codes, and session cookies, likely feeding Chinese intelligence gathering on US AI policy and regulation.
Mark Kelly said: "In July 2026, TA419 impersonated multiple individuals." The campaign begins with seemingly harmless emails proposing collaboration. If the target replied, TA419 followed up with a malicious link. This initiates a multi-stage URL redirection chain that ultimately leads to a sophisticated adversary-in-the-middle credential phishing attack. The attackers use a customized version of the open-source Frameless BitB browser-in-the-browser phishing tool, which presents victims with a fake OneDrive loading screen and a Cloudflare Turnstile check to appear legitimate. A custom script reports the victim's progress to the attackers in real time, while Cloudflare's content delivery network is used to obscure the backend hosting IP address.
Tactical Execution
The campaign's technical execution relies on a carefully crafted deception. After clicking the link, targets are led through a redirection chain that ends at a counterfeit Microsoft 365 login portal. This adversary-in-the-middle proxy, assembled from the Frameless BitB kit, captures everything entered by the user. It harvests passwords, one-time codes, and, critically, session cookies. Possession of these cookies allows the attacker to bypass multi-factor authentication entirely and maintain access to the victim's cloud account. The operation uses dozens of phishing and spoofed-sender domains, registered via NameSilo and themed around file-sharing and cloud services to avoid suspicion.
Targeted Individuals and Organizations
TA419's phishing emails have specifically impersonated three high-profile individuals to lend credibility to their approach. The spoofed identities and their associated targets reveal a focus on defense and foreign policy sectors.
| Impersonated Figure | Role / Affiliation | Campaign Period | Targeted Sector / Entity |
|---|---|---|---|
| Lynne Parker | Former Principal Deputy Director, White House Office of Science and Technology Policy | July 2026 | US think tanks, AI policy analysts |
| Heidi Crebo-Rediker | Former State Department Chief Economist, foreign policy expert | July 2026 | Defense, international relations |
| Senior Anthropic Employee | AI company executive | February 2026 | Technology and AI policy |
The group has also spoofed the domains of specific organizations, including The Heritage Foundation, the Japan-Taiwan Exchange Association, and the official website of Japanese Minister of Defense ShinjirÅ Koizumi. This narrow targeting, affecting fewer than 10 individuals, indicates a highly selective intelligence-gathering operation rather than a broad-brush campaign. The email subject lines were tailored to the ruse, with one example being "Request for Feedback on Military Integration of Claude."
Context and Response
This activity aligns with broader patterns of Chinese cyber-espionage. A House committee reported similar tactics used by Chinese state-linked actors in 2025, and 58% of state-sponsored intrusions against the technology sector are attributed to China-nexus adversaries. The campaign appears designed to support Chinese intelligence objectives around understanding and influencing US AI policy and regulation, a strategic area highlighted by recent US actions like the AI Diffusion Rule which established licensing requirements for advanced computing chips and model weights. Proofpoint, which published the first public research on TA419 on October 1, advises organizations to adopt phishing-resistant sign-in methods such as passkeys. Researchers note that TA419 is likely to continue targeting think tanks and policy experts, a pattern consistent with a previous campaign tracked as UNK_SweetSpecter two years ago.





