Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles
Key Findings
In July 2026, a China-aligned threat actor Proofpoint tracks as TA419 conducted multiple credential phishing campaigns impersonating prominent economists and artificial intelligence (AI) policymakers to target AI experts working for US think tanks, universities, and legal sector organizations.
TA419 also previously impersonated a prominent Anthropic employee to target an AI policy expert at a US think tank in February 2026.
This activity likely supports wider Chinese intelligence objectives to better understand ongoing developments within the US AI policy and regulatory landscape and occurs amid intense strategic competition, accusations of model distillation, and export controls involving the US and China.
Overview
In July 2026, TA419 impersonated multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team, in credential phishing campaigns targeting AI policy experts in the US. The group first sent benign conversation starter emails, which included calls to action themed around AI policy such as joining an “AI Policy Advisory Committee”, to build rapport and solicit a response from the target. Once the target replied, TA419 followed up with a multi-stage URL redirection chain that led to an Adversary-in-the-Middle (AitM) credential phish that employed a customized version of the open-source Browser-in-the-Browser (BitB) phishing tool Frameless BitB.
TA419 is a China-aligned and espionage-motivated threat actor that Proofpoint has observed conducting regular targeted credential phishing campaigns against individuals working for US- and Japan-based think tanks, defense contractors, universities, and law firms since at least April 2025. The group’s activity has not been previously reported publicly.
TA419 Activity Targeting AI Policy Analysts
Beginning on 8 July 2026, TA419 impersonated Lynne Edwards Parker, the former Principal Deputy Director of the White House Office of Science and Technology Policy, and then Heidi Crebo-Rediker, a prominent economist and foreign policy expert, in campaigns targeting AI policy experts at US think tanks, universities, and law firms.
Figure 1. TA419 campaign spoofing former White House Office of Science and Technology Policy employee.
In both cases, the group opened with benign outreach, inviting targets to join a fictitious “AI Policy Advisory Committee” or to contribute to a Senate Committee on Foreign Relations report on AI export controls and supply chains.
Figure 2. TA419 campaign inviting users to contribute to AI supply chain report.
If the target replied, TA419 followed up with a shortened URL that purported to share additional information. The link ultimately led to a fake OneDrive AitM credential phishing page designed to gain access to the target’s cloud account.
In February 2026, the group impersonated a senior employee of the AI company Anthropic to target an AI policy analyst at a US think tank. The email used the subject line “Request for Feedback on Military Integration of Claude,” referencing the debate over US military use of Anthropic’s Claude models. This campaign led to a similar AitM credential phishing chain.
Infection Chain
TA419 uses URL shortener services to redirect targets to a series of actor-controlled domains. The first actor-controlled domain serves as an initial filter; it conducts a Cloudflare Turnstile check behind a fake OneDrive loading screen before redirecting the target to an AitM credential phishing page hosted on a second TA419-controlled domain. Both July 2026 campaigns targeting US AI policy experts used the same first-stage domain (driftshare[.]co) and second-stage domain (globalfileshareplatform[.]com).
Figure 3. Example TA419 AitM and BitB phishing page observed in July 2026.
The AitM phishing chain used by TA419 targets Microsoft 365 / Entra ID through the first-party OfficeHome application (client_id=4765445b-32c6-49b0-83e6-1d93765276ca). It is built on Frameless BitB, an open-source Browser-in-the-Browser kit, which contains the BitB overlay alongside an Evilginx phishlet for Microsoft 365 and server-side substitution rules that inject the kit into proxied pages.
TA419 has extended this kit with a custom telemetry and automation module that tracks and drives the target’s progress through the Microsoft sign-in flow, including multi-factor authentication (MFA). The page the target lands on is the genuine Microsoft /common/oauth2/v2.0/authorize response, relayed in real time, into which the proxy injects two malicious scripts: /secondary/script.js and /secondary/observe.js. Behind a BitB overlay, the proxy relays the sign-in to genuine Microsoft infrastructure, so the target’s password, MFA code, and conditional access checks all succeed while the attacker captures the resulting session cookies. The primary client-side scripts used function as follows:
/secondary/script.js is the Frameless BitB driver, an adapted copy of the open-source file. It attaches a Shadow DOM to a container element and fills it with a OneDrive folder listing containing lure documents. The real documents are hosted in an attacker-controlled OneDrive account and reached through a proxy path that turns a 1drv.ms share link into an embeddable same-origin page. /secondary/script.js also loads another script (/primary/script.js) into the same Shadow DOM.
/primary/script.js is likewise adapted from Frameless BitB, but its body has been replaced. TA419’s version intercepts the target’s interaction with the listing. It registers clicks and touch handlers and watches for OneDrive’s own permission-denied banner, so that either a click on the document or Microsoft’s own prompt for authentication raises the fake Chrome browser BitB overlay.
/secondary/observe.js is a custom script which handles telemetry and automation against the relayed sign-in page, reporting the victim’s position in the login flow back to the attacker and giving a live view of each session. The same script auto-accepts “Keep me signed in” to extend the stolen session and auto-submits one-time codes as soon as they validate.
Infrastructure
TA419 consistently uses Cloudflare’s content delivery network (CDN) to obscure the backend hosting IP address for its domains, which are typically registered via NameSilo. The group’s credential phishing domains are typically themed around file sharing sites and cloud services.
Figure 4. Timeline of TA419 domain registrations.
TA419 also occasionally registers domains impersonating specific organizations and uses these to conduct phishing campaigns.
Impersonated Entity
TA419 Domain
Japan-Taiwan Exchange Association
tw-koryu[.]org
The Heritage Foundation
heritiages[.]org
heritiage[.]org
Shinjirō Koizumi’s Official Website
(current Japanese Minister of Defense)
shinjirou[.]info
Table 1. Entities spoofed by TA419 during 2026.
On multiple occasions in 2026, the first hop Received headers in TA419 phishing emails exposed likely actor-controlled virtual private servers (VPS) used to send the email. All of the observed servers shared a self-signed TLS certificate present on a high ephemeral port, which featured the subject and issuer distinguished name (DN) C=US, ST=Kansas, L=Millsstad,O=Castro Inc, CN=CI. This certificate is likely associated with a covert network that serves as anonymization infrastructure for TA419’s operations. In other cases, the group was observed sending emails via residential proxy services.
Figure 5. Example TA419 email headers showing actor-controlled VPS 108.61.163[.]187.
Conclusion
TA419 has consistently shown an interest in defense, national security, energy, international relations, and foreign policy targets, predominantly with a nexus to the US and Japan. The targeting of AI policy experts represents an extension of that remit rather than a departure from it. More widely, Proofpoint has previously reported on another China-aligned threat actor, UNK_SweetSpecter, conducting AI-related phishing activity, and regularly observes China-aligned actors targeting other industries, such as semiconductors and rare earths, vital to the supply chain of AI and other strategic technologies.
Proofpoint assesses that TA419 will likely continue targeting think tanks and policy experts working on technologies, and in geographies, of particular interest to the Chinese government. These campaigns will likely also continue spoofing the identities of real subject-matter experts.
Recommendations
Organizations in the scope of TA419 activity should consider phishing-resistant, origin-bound authentication such as passkeys. Individual targets in scope of TA419 activity should treat unsolicited subject-matter outreach as a plausible pretext stage and seek to verify the legitimacy of such unexpected communications via another independent medium.
Indicators
Indicator
Type
Description
First Seen
leparker@mail[.]com
Email address
Attacker-controlled email address
July 2026
hcrediker@mail[.]com
Email address
Attacker-controlled email address
July 2026
hcrediker@outlook[.]com
Email address
Attacker-controlled email address
July 2026
driftshare[.]co
Domain
First stage redirect domain
July 2026
globalfileshareplatform[.]com
Domain
Second stage AitM phishing domain
July 2026
quickfly[.]online
Domain
First stage redirect domain
May 2026
smartsyncbox[.]com
Domain
Second stage AitM phishing domain
May 2026
cirrushare[.]co
Domain
First stage redirect domain
April 2026
mypublicshare[.]com
Domain
Second stage AitM phishing domain
March 2026
goshshare[.]online
Domain
First stage redirect domain
March 2026
synchvault[.]co
Domain
First stage redirect domain
March 2026
cloudsyncpulse[.]com
Domain
Second stage AitM phishing domain
March 2026
onecloudfilesync[.]com
Domain
Second stage AitM phishing domain
February 2026
msfile[.]online
Domain
First stage redirect domain
February 2026
winsync[.]cloud
Domain
First stage redirect domain
February 2026
publicsharefile[.]cloud
Domain
Second stage AitM phishing domain
February 2026
fileswiftonline[.]cloud
Domain
Second stage AitM phishing domain
December 2025
sharehub[.]space
Domain
First stage redirect domain
December 2025
tw-koryu[.]org
Domain
Sender domain
May 2026
heritiages[.]org
Domain
Sender domain
March 2026
heritiage[.]org
Domain
Sender domain
March 2026
shinjirou[.]info
Domain
Sender domain
February 2026
b314a1499cd728ca3e54b7150661fd0c7d2279065fe3f570f0f66c395d744460
TLS certificate
O=Castro Inc Certificate SHA256 Fingerprint
February 2026Proofpoint Threat InsightRead More