VMTech
Discuss a project →

TA419 phishing campaign targets U.S. AI policy specialists

TA419 phishing campaign targets U.S. AI policy specialists

China-aligned threat actor TA419 has targeted artificial intelligence policy experts at U.S. think tanks, universities and legal-sector organizations with Microsoft adversary-in-the-middle (AitM) credential-phishing campaigns. Proofpoint said the activity includes a February 2026 operation aimed at an AI policy expert at a U.S. think tank, using an email titled “Request for Feedback on Military Integration of Claude.”

The espionage-motivated group has conducted credential-phishing operations against people associated with U.S. and Japanese think tanks, defence contractors, universities and law firms since at least April 2025. Around July 2026, it also impersonated several people, including a former member of the White House Office of Science and Technology Policy leadership team, in campaigns directed at U.S. AI policy specialists.

Trust-building outreach precedes the credential theft

TA419 begins with apparently benign invitations intended to establish trust. The more overtly malicious stage is triggered only after a recipient responds. The actor then sends a shortened URL that initiates a multi-stage redirection chain and ultimately presents a OneDrive AitM credential-phishing page after a Cloudflare Turnstile check.

Proofpoint assessed that the operations likely support broader Chinese intelligence objectives to understand developments in the U.S. AI policy and regulatory landscape. The activity is taking place amid strategic competition between the United States and China, including disputes involving model distillation and export controls.

Frameless BitB makes the Microsoft sign-in look legitimate

The phishing page uses Frameless BitB, a variant of the browser-in-the-browser technique. It creates the visual impression of a trusted website or login window within a legitimate browser session using HTML, CSS and JavaScript, but does not rely on an iframe. This helps the fraudulent sign-in experience resemble a normal authentication prompt.

Proofpoint said TA419 expanded the open-source tool with a bespoke telemetry and automation module. The module follows the target’s Microsoft sign-in flow, while an AitM proxy captures credential information and relays authentication details to genuine Microsoft infrastructure in the background.

This design is significant because the victim can complete a successful sign-in without a visible warning that credentials and resulting session cookies have been captured. TA419 has shown sustained interest in defence, national security, energy, international relations and foreign-policy targets with U.S. and Japanese connections; Proofpoint described the focus on AI policy as an extension of that remit.

Authentication and verification are practical controls

Organizations can reduce exposure by enabling phishing-resistant authentication methods such as passkeys. Teams handling policy, research or legal correspondence should also treat unsolicited specialist outreach cautiously and independently verify the sender before following shortened links or entering Microsoft credentials. For businesses, the practical implication is to pair passkey deployment with a clear process for validating unexpected requests that seek to build trust before directing staff to sign in.

#cybersecurity#phishing#identitysecurity#aipolicy
Open analytics
On the site 0 views
min read 4 04.10.2026
Instagram

TA419 phishing campaign targets U.S. AI policy specialists

Open the post on Instagram ↗