TA419 AI policy impersonation phishing campaign
Campaign
Updated: 01.10.2026 17:00
· First: 01.10.2026 17:00
· 📰 2 src / 2 articles
· H score: 36
TA419 is a China-nexus espionage campaign that used credential phishing against AI policy experts at U.S. think tanks, universities, and legal sector organizations, with additional targeting of defense contractors and Japan-linked institutions. The lures impersonated economists, AI policymakers, Lynne Parker, Heidi Crebo-Rediker, and an Anthropic employee, including a February 2026 message with the subject “Request for Feedback on Military Integration of Claude.” Recipients who responded were pushed through shortened URLs and multi-stage redirects to a spoofed OneDrive sign-in page. The page used Frameless BitB and an adversary-in-the-middle (AitM) proxy to relay Microsoft 365 logins, capture passwords, MFA codes, and session cookies, and keep the sign-in appearing successful. Proofpoint says the activity has run since at least April 2025 and likely supports Chinese intelligence collection on U.S. AI policy and export-control issues.