Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles

Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles
Proofpoint reports that China-aligned TA419 ran credential phishing campaigns in July 2026 by impersonating economists and AI policymakers to target AI experts at US think tanks, universities, and law firms. The operation used multi-stage redirects and a customized Frameless BitB AitM kit to steal Microsoft 365 / Entra ID credentials and session cookies while collecting intelligence on US AI policy and export controls. #TA419 #FramelessBitB #Microsoft365 #EntraID

Keypoints

  • TA419 conducted multiple credential phishing campaigns in July 2026 against AI policy experts in the US.
  • The group impersonated well-known economists and AI policy figures, including former White House OSTP leadership and Heidi Crebo-Rediker.
  • Initial outreach used benign emails about topics like an “AI Policy Advisory Committee” or AI export controls to build trust.
  • Replies triggered shortened links that led through a multi-stage redirect chain to an AitM phishing page.
  • The phishing infrastructure used a customized version of Frameless BitB to target Microsoft 365 / Entra ID and steal session cookies, passwords, and MFA codes.
  • Proofpoint links TA419’s activity to Chinese intelligence interests focused on US AI policy, regulation, and strategic competition.
  • The campaign also reused infrastructure and impersonation tactics seen in earlier 2026 activity, including a February 2026 attack posing as an Anthropic employee.

MITRE Techniques

  • [T1566.002 ] Spearphishing Link – TA419 sent benign emails and then followed up with shortened URLs that redirected victims to phishing pages (‘followed up with a shortened URL that purported to share additional information’).
  • [T1556.004 ] Web Session Cookie – The AitM proxy captured session cookies after relaying the victim’s Microsoft sign-in to real infrastructure (‘the attacker captures the resulting session cookies’).
  • [T1528 ] Steal Application Access Token – The phishing flow targeted Microsoft 365 / Entra ID session access by relaying authentication and capturing the resulting authenticated session (‘targets Microsoft 365 / Entra ID … the attacker captures the resulting session cookies’).
  • [T1056.001 ] Input Capture: Keylogging – The operation collected sensitive authentication inputs such as passwords and MFA codes during the fake sign-in flow (‘while the attacker captures the resulting session cookies’ and ‘the target’s password, MFA code’).
  • [T1190 ] Exploit Public-Facing Application – TA419 abused a fake OneDrive/Microsoft sign-in environment and proxying to interact with Microsoft authentication endpoints (‘the genuine Microsoft /common/oauth2/v2.0/authorize response, relayed in real time’).
  • [T1583.001 ] Acquire Infrastructure: Domains – The group registered and used multiple domains for redirect and phishing infrastructure (‘typically registered via NameSilo’ and ‘uses these to conduct phishing campaigns’).
  • [T1583.004 ] Acquire Infrastructure: Server – Proofpoint noted actor-controlled VPS servers used in email delivery (‘likely actor-controlled virtual private servers (VPS) used to send the email’).
  • [T1114.001 ] Email Collection – The campaign relied on email correspondence and response handling to progress the lure (‘If the target replied, TA419 followed up’).

Indicators of Compromise

  • [Email address ] attacker-controlled sender addresses – leparker@mail[.]com, hcrediker@mail[.]com, and other 1 item
  • [Domain ] first-stage redirect/phishing infrastructure – driftshare[.]co, quickfly[.]online, and other 5 items
  • [Domain ] second-stage AitM phishing infrastructure – globalfileshareplatform[.]com, smartsyncbox[.]com, and other 5 items
  • [Domain ] sender domains used to impersonate organizations – tw-koryu[.]org, heritiages[.]org, and other 2 items
  • [IP address ] actor-controlled VPS seen in email headers – 108.61.163[.]187, and other 0 items
  • [TLS certificate fingerprint ] self-signed certificate tied to covert infrastructure – b314a1499cd728ca3e54b7150661fd0c7d2279065fe3f570f0f66c395d744460, and other 0 items


Read more: https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy