IT Brief US - Technology news for CIOs & IT decision-makers
United States
China-linked TA419 targets US AI policy experts in phishing

China-linked TA419 targets US AI policy experts in phishing

Tue, 6th Oct 2026 (Today)
Mara Sugue
MARA SUGUE News Editor

Proofpoint has identified a China-aligned cyber espionage group targeting US AI policy experts in phishing campaigns. The activity has not previously been reported publicly.

The group, tracked as TA419, impersonated prominent economists and AI policy figures in attacks on people at think tanks, universities and law firms. Researchers said the campaign fits a broader pattern of targeting organisations and experts linked to US and Japanese policy, defence and foreign affairs.

In July, the attackers posed as Lynne Edwards Parker, a former White House AI policy official, and Heidi Crebo-Rediker, an economist and foreign policy expert. In an earlier campaign, the group also impersonated a senior employee at Anthropic in an attempt to target an AI policy analyst at a US think tank.

The emails began as seemingly routine professional outreach. In one case, targets were invited to join an “AI Policy Advisory Committee”. In another, they were asked to contribute to a Senate Committee on Foreign Relations report on AI export controls and supply chains.

Once a recipient responded, the attacker sent a follow-up link presented as a file-sharing or document access request. The link passed through a chain of redirects before landing on a fake Microsoft OneDrive login page designed to collect credentials and session data.

How the attack worked

The campaign used an adversary-in-the-middle method that relayed a genuine Microsoft sign-in page in real time while overlaying a fake browser window. That allowed victims to enter their password and complete multi-factor authentication checks while the attacker captured the resulting session cookies.

The phishing chain used a customised version of an open-source browser-in-the-browser toolkit known as Frameless BitB. TA419 modified the tool with its own telemetry and automation functions to monitor a victim's progress through the sign-in process and help prolong access to compromised accounts.

Observed functions included scripts that tracked clicks on supposed OneDrive documents, triggered fake browser prompts and automatically accepted “Keep me signed in” prompts. Researchers also said the tooling could submit one-time authentication codes as soon as they were validated.

This means standard multi-factor authentication alone may not stop this type of attack. Instead, the method exploits trust in a familiar sign-in flow while the attacker sits between the victim and the real service.

Policy focus

The recent operations appear intended to gather insight into US thinking on AI regulation, export controls and related national security questions. The targeting comes amid broader strategic competition between the US and China over artificial intelligence, including disputes over supply chains, regulation and access to advanced technologies.

TA419 has shown a sustained interest in people and institutions working on defence, national security, energy, foreign policy and international relations since at least April 2025, according to the findings. The latest activity suggests AI policy has become part of that established focus rather than a separate line of work.

The group's regional interest extends beyond the US. TA419 has a strong focus on Asia-Pacific targets and has previously spoofed the identity of Japan's Defence Minister, Shinjirō Koizumi, as well as the Japan-Taiwan Exchange Association.

Other spoofed entities linked to the group included The Heritage Foundation. The domains used in these operations were often made to resemble file-sharing services, cloud platforms or the organisations being impersonated.

Infrastructure trail

TA419 commonly used Cloudflare to obscure the hosting location behind its phishing domains, which were often registered through NameSilo. In some cases, email headers pointed to virtual private servers likely controlled by the attackers. In others, the group appeared to send messages through residential proxy services.

A shared self-signed TLS certificate observed on several servers suggests a concealed network used to support the operation. This infrastructure probably served as anonymisation for TA419's campaigns.

The report places TA419 among a broader set of China-aligned groups that have recently turned their attention to sectors linked to AI and strategic technology. Researchers also observed activity targeting industries such as semiconductors and rare earths, both critical to AI supply chains.

Mark Kelly and the Proofpoint Threat Research Team said: “TA419 has consistently shown an interest in defence, national security, energy, international relations, and foreign policy targets, predominantly with a nexus to the US and Japan. The targeting of AI policy experts represents an extension of that remit rather than a departure from it.”