TA419 AI policy impersonation phishing campaign
Campaign
Summary
Hide ▲
Show ▼
The TA419 phishing campaign is still active, using AI policy impersonation to target staff at think tanks, defense contractors, universities and law firms in the US and Japan. The operation has run since at least April 2025 and steers victims to spoofed Microsoft 365/OneDrive login pages that harvest credentials and session cookies. The access pattern supports espionage risk against people working on AI policy and export controls.
Related Happenings
CSuite phishing campaign stealing Microsoft 365 sessions and deploying remote-access tools
Campaign
H score30
First: 30.09.2026 13:45
Last: 30.09.2026 13:45
Sources 1
About this happening:
The CSuite phishing campaign is stealing Microsoft 365 sessions and deploying ScreenConnect or Action1, creating paths to account takeover, endpoint control, and b...
CSuite phishing campaign stealing Microsoft 365 sessions and deploying remote-access tools
CampaignAbout this happening: The CSuite phishing campaign is stealing Microsoft 365 sessions and deploying ScreenConnect or Action1, creating paths to account takeover, endpoint control, and b...
Global Profit PhaaS logistics-fraud platform
Threat Actor Meta
H score27
First: 24.09.2026 15:05
Last: 24.09.2026 15:05
Sources 1
About this happening:
Global Profit (aka MC Profit Always) is a PhaaS operation tied to a Russian-Armenian threat actor that sells logistics-focused credential theft to other operators. The...
Global Profit PhaaS logistics-fraud platform
Threat Actor MetaAbout this happening: Global Profit (aka MC Profit Always) is a PhaaS operation tied to a Russian-Armenian threat actor that sells logistics-focused credential theft to other operators. The...
ShinyHunters and Helix passkey-themed Microsoft 365 account compromise campaign
Campaign
H score34
First: 11.09.2026 20:26
Last: 11.09.2026 20:26
Sources 1
About this happening:
A ShinyHunters- and Helix-linked campaign is using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts, exposing Microsoft 3...
ShinyHunters and Helix passkey-themed Microsoft 365 account compromise campaign
CampaignAbout this happening: A ShinyHunters- and Helix-linked campaign is using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts, exposing Microsoft 3...
Anthropic Claude misuse analysis of multi-agent reconnaissance, exploitation, and exfiltration
Technical Analysis
H score59
First: 11.09.2026 17:29
Last: 11.09.2026 17:29
Sources 1
About this happening:
Anthropic says Claude AI was abused by multiple threat groups, including ShinyHunters, Midnight Blizzard, and GTG-10007, for credential harvesting, recon...
Anthropic Claude misuse analysis of multi-agent reconnaissance, exploitation, and exfiltration
Technical AnalysisAbout this happening: Anthropic says Claude AI was abused by multiple threat groups, including ShinyHunters, Midnight Blizzard, and GTG-10007, for credential harvesting, recon...
UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign
Campaign
H score16
First: 20.08.2026 22:59
Last: 20.08.2026 22:59
Sources 1
About this happening:
A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...
UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign
CampaignAbout this happening: A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...
Timeline
-
01.10.2026 17:00 1 articles · 2h ago
TA419 sent AI-policy phishing emails posing as Lynne Parker and Heidi Crebo-Rediker
Exploitation ObservedTA419 sent emails from July 8 while posing as Lynne Parker and later economist and foreign policy expert Heidi Crebo-Rediker to lure AI policy specialists with a made-up "AI Policy Advisory Committee" invitation and a request to help with a Senate Committee on Foreign Relations report on AI export controls; recipients who replied were pushed through shortened links and redirects to a spoofed OneDrive login page.
Show sources
- China-Linked Hackers Impersonate AI Experts to Target US Policy Insiders — www.infosecurity-magazine.com — 01.10.2026 17:00
-
01.10.2026 17:00 2 articles · 2h ago
Proofpoint details TA419 credential phishing against AI policy specialists at US and Japan institutions
Initial DisclosureProofpoint's October 1 research said TA419 has run credential phishing against staff at think tanks, defense contractors, universities and law firms in the US and Japan since at least April 2025, using a spoofed Microsoft 365/OneDrive login page built as an adversary-in-the-middle reverse proxy from Frameless BitB to forward Microsoft 365 logins in real time, capture passwords, MFA codes and session cookies, and bypass conditional access checks; Proofpoint assessed the activity as likely supporting Chinese intelligence gathering on US AI policy and advised phishing-resistant sign-in methods such as passkeys and verification through an independent channel.
Show sources
- China-Linked Hackers Impersonate AI Experts to Target US Policy Insiders — www.infosecurity-magazine.com — 01.10.2026 17:00
- China-Linked Hackers Impersonate AI Experts to Target US Policy Insiders — www.infosecurity-magazine.com — 01.10.2026 17:00