[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f6kOCKJOenyZQZdoRtMatYT3B0AomCMmeSq_gF4FGeCU":3},{"article":4,"iocs":52},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":34,"category":35,"article_tags":39},"7b5d1e02-1530-4a04-9fd9-e9b9f3472759","China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing","china-aligned-ta419-targets-u-s-ai-policy-experts-with-microsoft-aitm-phishing-aac5cc","A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a","A China-aligned cyber espionage group, TA419, is conducting credential phishing campaigns against AI policy experts in US think tanks, universities, and legal organizations. The group impersonates prominent figures and uses a sophisticated Microsoft Adversary-in-the-Middle (AitM) phishing technique, leveraging a frameless browser-in-the-browser attack to steal credentials without raising suspicion.","China-aligned TA419 targets US AI policy experts with Microsoft AitM phishing.","China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing Ravie LakshmananOct 04, 2026Cyber Espionage \u002F Phishing A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a U.S. think tank in February 2026. The phishing email carried the subject line \"Request for Feedback on Military Integration of Claude.\" \"This activity likely supports wider Chinese intelligence objectives to better understand ongoing developments within the U.S. AI policy and regulatory landscape and occurs amid intense strategic competition, accusations of model distillation, and export controls involving the U.S. and China,\" Proofpoint said in an analysis published this week. The enterprise security company has described TA419 as a China-aligned and espionage-motivated threat actor that has a track record of orchestrating credential phishing campaigns against individuals working for U.S.- and Japan-based think tanks, defense contractors, universities, and law firms since at least April 2025. Around July 2026, the threat actor is said to have impersonated several individuals, including a former member of the White House Office of Science and Technology Policy leadership team, as part of credential phishing campaigns targeting AI policy experts in the U.S. The attack begins with harmless invitations that aim to establish trust with the target. It's only when the recipient responds to the outreach that the next stage kicks in, with the adversary following it up with a shortened URL that triggers a multi-stage redirection chain, which leads to an OneDrive adversary-in-the-middle (AitM) credential phishing page after completing a Cloudflare Turnstile check. The page employs a technique called Frameless BitB, a version of the browser-in-the-browser (BitB) attack that spoofs a trusted website or login page by crafting a fake browser window within a legitimate browser session using HTML, CSS, and JavaScript. While BitB works by serving the sign-in page inside an iframe, Frameless BitB, as the name implies, achieves the same goal without using the HTML element. \"This can be achieved by injecting scripts and HTML besides the original content using search and replace (aka substitutions), then relying completely on HTML\u002FCSS\u002FJS tricks to make the visual effect,\" security researcher Wael Masri noted back in January 2024. According to Proofpoint, TA419 has extended the open-source tool with a bespoke telemetry and automation module that tracks the target's Microsoft sign-in flow and captures the credential information using the AitM proxy, while relaying the details to the real Microsoft infrastructure in the background. The main advantage this method offers is that the victim doesn't notice anything is amiss, as the sign-in event is successful and there are no indications that the resulting session cookies have been stealthily captured by the attacker. To safeguard against this threat, organizations are recommended to enable phishing-resistant authentication methods like passkeys, and individual targets who are the focus of TA419 activity should treat unsolicited subject-matter outreach with caution, and verify their authenticity before proceeding further. \"TA419 has consistently shown an interest in defense, national security, energy, international relations, and foreign policy targets, predominantly with a nexus to the U.S. and Japan,\" Proofpoint said. \"The targeting of AI policy experts represents an extension of that remit rather than a departure from it.\" Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  artificial intelligence, cyber espionage, Identity Security, Microsoft, Phishing ⚡ Top Stories This Week Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access Beyond ISO 27001: Building a Risk Program That Can Keep Up With AI Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header","https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fchina-aligned-ta419-targets-us-ai.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEgR69JnEBkz8N6_Nd5K75adIWh8xVmxW8FB21gsKinx9HBzgXQSLWL5sYdKMe9d-cbTSrgc45ZtYhmvhLZJII1H-tPXKn4AiRvj4KrU8ayeZskmMCfiV-mUc2pz10MumKyXKH6ybJ2RsVj9ZZ67l-4u0Y2f5Dl3kX7PLEzCAqogMfHTSfD7gM7QypHi-yos\u002Fs1600\u002Fchina-ms.jpg","2026-10-04T07:20:32+00:00","2026-10-04T08:00:20.161654+00:00",8,[18,21,24,27,30,32],{"name":19,"type":20},"TA419","threat_actor",{"name":22,"type":23},"Microsoft AitM","product",{"name":25,"type":26},"AI","technology",{"name":28,"type":29},"Proofpoint","vendor",{"name":31,"type":23},"Claude",{"name":33,"type":23},"OneDrive","6cbdd207-aaa1-4176-9534-e156b125e917",{"id":34,"icon":36,"name":37,"slug":38},null,"Nation-state","nation-state",[40,42,47],{"category":41},{"id":34,"icon":36,"name":37,"slug":38},{"category":43},{"id":44,"icon":36,"name":45,"slug":46},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":48},{"id":49,"icon":36,"name":50,"slug":51},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[53],{"type":54,"value":19,"context":55},"malware","China-aligned cyber espionage group"]