The Fake Committee That Steals Your Session: Inside TA419's Phishing Campaign Against US AI Policy Experts
Proofpoint unmasks TA419, a China-aligned espionage group that impersonated a former White House OSTP official and an Anthropic executive to phish US AI policy experts — using an open-source Browser-in-the-Middle kit that defeats MFA by relaying the real Microsoft login in real time.
On October 1, 2026, Proofpoint published research with a title that reads like a warning to an entire professional community: “Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy.” The report describes a credential-phishing apparatus that spent at least a year — publicly undocumented until now — impersonating real, named people in the American AI policy world to steal the email sessions of the exact experts who shape US AI regulation.
The timing is not incidental. The campaign unfolded amid what Proofpoint characterizes as intense strategic competition between Washington and Beijing, including accusations of model distillation and a widening regime of AI export controls. Understanding what US regulators are thinking — and who is advising them — has become an intelligence objective in its own right.
Who TA419 is
Proofpoint tracks the group as TA419, a China-aligned, espionage-motivated threat actor it has observed conducting targeted credential phishing since at least April 2025. Its historical targets cluster around US- and Japan-based think tanks, defense contractors, universities, and law firms, with thematic interests in defense, national security, energy, and foreign policy. The targeting of AI policy experts, Proofpoint notes, is an extension of that remit rather than a departure from it — the technology simply became the newest terrain of statecraft.
Notably, the group’s activity had never been publicly reported before this disclosure.
The lure: a committee that never existed
The July 2026 campaign began, as the best social engineering does, with something completely benign. Beginning on July 8, TA419 sent conversation-starter emails impersonating Lynne Edwards Parker, the former Principal Deputy Director of the White House Office of Science and Technology Policy. A parallel wave spoofed Heidi Crebo-Rediker, a prominent economist and foreign policy expert.
The emails invited targets — AI policy experts at US think tanks, universities, and legal-sector organizations — to join a fictitious “AI Policy Advisory Committee,” or to contribute to a Senate Committee on Foreign Relations report on AI export controls and supply chains. Both pretexts are precisely calibrated to flatter the self-image of a policy professional: you are important enough to be consulted.
No links, no attachments, no payload. The first email only wants a reply. Once the target answered, TA419 followed up with a shortened URL purporting to share “additional information” — and that is where the machinery starts.
The February rehearsal: a fake Anthropic executive
The July campaign had a dress rehearsal. In February 2026, TA419 impersonated a senior employee of Anthropic to target an AI policy analyst at a US think tank. The subject line — “Request for Feedback on Military Integration of Claude” — was engineered to plug directly into a live and contentious debate over US military use of Anthropic’s Claude models. A policy analyst receiving that email has every professional reason to engage. That campaign led to the same adversary-in-the-middle credential-phishing chain as the July waves.
The choice of an AI-company identity is the tell: TA419 is not spraying credentials indiscriminately. It studies the discourse of its target community and impersonates the people that community already trusts.
The infection chain: a relayed, genuine Microsoft login
The technical core of the campaign is a multi-stage redirection chain built to survive modern email security. The shortened URL leads to a first actor-controlled domain (driftshare[.]co in the July runs) that serves a fake OneDrive loading screen while quietly performing a Cloudflare Turnstile check — filtering out automated scanners and sandboxes before any malicious content is shown. Human targets pass; research infrastructure does not.
Survivors are redirected to a second actor-controlled domain (globalfileshareplatform[.]com) hosting the actual credential-phishing page. This is not a lookalike HTML mock-up of a Microsoft login. It is the genuine Microsoft /common/oauth2/v2.0/authorize response, relayed in real time through an adversary-in-the-middle proxy, into which two malicious scripts are injected.
The kit is built on Frameless BitB, an open-source Browser-in-the-Middleware (“Browser-in-the-Browser”) phishing tool. TA419 did not merely deploy it; it extended it:
/secondary/script.jsattaches a Shadow DOM to the page and fills it with a plausible OneDrive folder listing containing the lure documents — real files hosted in an attacker-controlled OneDrive account, reached through a proxy that converts a 1drv.ms share link into an embeddable same-origin page./primary/script.jswatches the target’s interaction with that listing. A click on any document — or Microsoft’s own permission-denied banner prompting for authentication — raises the fake Chrome-browser BitB overlay./secondary/observe.jsis TA419’s custom contribution: a telemetry and automation module that reports the victim’s position in the login flow back to the operator, auto-accepts the “Keep me signed in” prompt to extend the stolen session’s lifetime, and auto-submits one-time codes the moment they validate.
Because the proxy relays the real Microsoft infrastructure end to end, the target’s password, MFA code, and conditional-access checks all genuinely succeed — from Microsoft’s point of view, this is a legitimate sign-in. The attacker harvests the resulting session cookies, MFA included. The chain targets Microsoft 365 / Entra ID through the first-party OfficeHome application.
Infrastructure and attribution breadcrumbs
TA419’s operational hygiene is disciplined: domains registered via NameSilo, backend hosting hidden behind Cloudflare’s CDN, phishing domains themed around file-sharing and cloud services, and email sometimes sent through residential proxy services. On multiple occasions in 2026, however, exposed Received headers revealed likely actor-controlled VPS hosts — all sharing a distinctive self-signed TLS certificate with the DN C=US, ST=Kansas, L=Millsstad, O=Castro Inc, CN=CI, suggesting a covert anonymization network reused across the operation.
The group also registers lookalike domains for specific organizations it spoofs, including the Japan-Taiwan Exchange Association (tw-koryu[.]org), the Heritage Foundation (heritiages[.]org), and the official website of Shinjirō Koizumi, Japan’s current Minister of Defense. The footprint of a group tracking both US and Japanese policy circles is unmistakable.
Why this matters beyond security teams
Three features make this campaign significant for anyone in the AI industry.
First, the target set is the policy layer, not the technology layer. TA419 is not chasing model weights or GPU schematics here — it is harvesting the correspondence of the people who write, critique, and advise on AI policy. The intelligence product is insight into the US regulatory landscape itself. Proofpoint’s assessment is blunt: the activity likely supports wider Chinese intelligence objectives around US AI policy and regulatory developments.
Second, the tradecraft is AI-community-specific. A fake “AI Policy Advisory Committee,” a spoofed Anthropic executive asking about “Military Integration of Claude,” a Senate export-controls report — these pretexts only work on someone deeply embedded in the AI policy conversation. As AI governance becomes geopolitical, its community becomes a espionage target in the classic sense, with spear phishing indistinguishable in quality from the campaigns that have long targeted defense and foreign-policy circles.
Third, MFA is not a defense here. The BitB relay defeats SMS codes, authenticator apps, and conditional-access checks by design, because the victim interacts with genuine Microsoft pages through the attacker’s proxy. Proofpoint’s recommendation — phishing-resistant, origin-bound authentication such as passkeys — is the only category of defense that actually breaks this chain. The second recommendation is behavioral: treat unsolicited subject-matter outreach as a potential pretext stage, and verify unexpected invitations through an independent medium before clicking anything.
Proofpoint assesses TA419 will continue targeting think tanks and policy experts working on technologies and in geographies of interest to Beijing, and will keep spoofing the identities of real subject-matter experts. For a community that communicates through email, calendars, and shared documents by professional necessity, the defense is not paranoia — it is verifying the committee exists before joining it.
Sources
- [1] https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy
- [2] https://www.reuters.com/technology/artificial-intelligence/
- [3] https://edition.cnn.com/2026/10/01/politics/china-linked-hackers-impersonated-us-ai-insiders
- [4] https://cyberscoop.com/china-cyber-espionage-ta419-phishing-us-ai-policy-experts/
- [5] https://therecord.media/china-linked-phishing-scheme-backdoor-taiwan