A China-aligned espionage group has been impersonating senior figures from Washington's AI policy world, and from Anthropic itself, to break into the Microsoft 365 accounts of the experts who shape US AI regulation. In research published on 1 October 2026, Proofpoint details TA419, an actor it says has run regular targeted credential phishing against US- and Japan-based think tanks, defence contractors, universities and law firms since at least April 2025, and whose activity had not previously been reported publicly. Its latest campaigns use an adversary-in-the-middle (AitM) kit that relays the real Microsoft sign-in, so the victim's password, MFA prompt and conditional access checks all succeed while TA419 walks away with the session. Policy organisations that still rely on push or one-time-code MFA should treat this as a direct warning.

The lures: AI advisory committees, Senate reports and "Military Integration of Claude"

Beginning on 8 July 2026, TA419 impersonated Lynne Edwards Parker, the former Principal Deputy Director of the White House Office of Science and Technology Policy, and then Heidi Crebo-Rediker, an economist and foreign policy expert, in campaigns aimed at AI policy experts at US think tanks, universities and law firms. The opening emails were deliberately benign: invitations to join a fictitious "AI Policy Advisory Committee" or to contribute to a Senate Committee on Foreign Relations report on AI export controls and supply chains. Only when a target replied did TA419 send a shortened URL purporting to share more information.

Earlier, in February 2026, the group impersonated a senior employee of Anthropic to target an AI policy analyst at a US think tank, using the subject line "Request for Feedback on Military Integration of Claude", a reference to the debate over US military use of Anthropic's Claude models. That campaign led to a similar AitM chain.

TA419 also registered domains impersonating specific organisations during 2026:

Impersonated entityTA419 domain
Japan-Taiwan Exchange Associationtw-koryu[.]org
The Heritage Foundationheritiages[.]org, heritiage[.]org
Shinjiro Koizumi's official website (Japan's current Minister of Defense)shinjirou[.]info

Proofpoint assesses the AI-policy targeting is an extension of TA419's long-standing interest in defence, national security, energy, international relations and foreign policy targets with a US and Japan nexus, and that it likely supports wider Chinese intelligence objectives amid strategic competition, model-distillation accusations and export controls.

Attack mechanics: a relayed Microsoft sign-in behind a fake browser window

The chain Proofpoint documented works as follows:

  1. Redirect and filter. A URL shortener sends the target to a first actor-controlled domain that runs a Cloudflare Turnstile check behind a fake OneDrive loading screen. Both July campaigns used driftshare[.]co for this stage.
  2. AitM phishing page. The target is redirected to a second domain, in July globalfileshareplatform[.]com, hosting the AitM proxy.
  3. Relayed sign-in. The proxy targets Microsoft 365 / Entra ID through the first-party OfficeHome application (client_id=4765445b-32c6-49b0-83e6-1d93765276ca). The page the victim sees is the genuine Microsoft /common/oauth2/v2.0/authorize response relayed in real time.
  4. Injected scripts. The proxy injects /secondary/script.js, an adapted Frameless BitB driver that renders a fake OneDrive folder listing of lure documents in a Shadow DOM, and loads /primary/script.js, which raises a fake Chrome browser-in-the-browser overlay when the target clicks a document or Microsoft's own permission-denied banner appears.
  5. Telemetry and automation. A custom /secondary/observe.js reports the victim's position in the login flow to the operator, gives a live view of each session, auto-accepts "Keep me signed in" to extend the stolen session, and auto-submits one-time codes as soon as they validate.

Frameless BitB is an open-source kit that bundles the BitB overlay with an Evilginx phishlet for Microsoft 365 and server-side substitution rules. TA419's additions are the telemetry and automation module that drives the target through MFA. Because authentication happens against real Microsoft infrastructure, password strength, one-time codes and push approvals provide no protection: the attacker captures the resulting session cookies. Lure documents themselves were hosted in an attacker-controlled OneDrive account and reached through a proxy path that turns a 1drv.ms share link into an embeddable same-origin page.

Infrastructure

TA419 fronts its domains with Cloudflare's CDN to hide backend hosting and typically registers them through NameSilo, using file-sharing and cloud-service themes. First-hop Received headers in several 2026 emails exposed likely actor-controlled VPS senders, including 108.61.163[.]187. All observed servers shared a self-signed TLS certificate on a high ephemeral port with subject and issuer C=US, ST=Kansas, L=Millsstad, O=Castro Inc, CN=CI, which Proofpoint believes is associated with a covert anonymisation network. In other cases TA419 sent mail through residential proxy services.

Indicators of compromise

IndicatorTypeProofpoint descriptionFirst seen
leparker@mail[.]comEmailAttacker-controlled email addressJuly 2026
hcrediker@mail[.]comEmailAttacker-controlled email addressJuly 2026
hcrediker@outlook[.]comEmailAttacker-controlled email addressJuly 2026
driftshare[.]coDomainFirst stage redirect domainJuly 2026
globalfileshareplatform[.]comDomainSecond stage AitM phishing domainJuly 2026
quickfly[.]onlineDomainFirst stage redirect domainMay 2026
smartsyncbox[.]comDomainSecond stage AitM phishing domainMay 2026
cirrushare[.]coDomainFirst stage redirect domainApril 2026
mypublicshare[.]comDomainSecond stage AitM phishing domainMarch 2026
goshshare[.]onlineDomainFirst stage redirect domainMarch 2026
synchvault[.]coDomainFirst stage redirect domainMarch 2026
cloudsyncpulse[.]comDomainSecond stage AitM phishing domainMarch 2026
onecloudfilesync[.]comDomainSecond stage AitM phishing domainFebruary 2026
msfile[.]onlineDomainFirst stage redirect domainFebruary 2026
winsync[.]cloudDomainFirst stage redirect domainFebruary 2026
publicsharefile[.]cloudDomainSecond stage AitM phishing domainFebruary 2026
fileswiftonline[.]cloudDomainSecond stage AitM phishing domainDecember 2025
sharehub[.]spaceDomainFirst stage redirect domainDecember 2025
tw-koryu[.]orgDomainSender domainMay 2026
heritiages[.]orgDomainSender domainMarch 2026
heritiage[.]orgDomainSender domainMarch 2026
shinjirou[.]infoDomainSender domainFebruary 2026
b314a1499cd728ca3e54b7150661fd0c7d2279065fe3f570f0f66c395d744460TLS certificateO=Castro Inc certificate SHA-256 fingerprintFebruary 2026

The VPS address 108.61.163[.]187 appears in Proofpoint's example email headers rather than its indicator table.

Defensive playbook

  1. Move policy and research staff to phishing-resistant, origin-bound authentication. Proofpoint's primary recommendation is passkeys or equivalent. A FIDO2 credential bound to login.microsoftonline.com will not complete a sign-in proxied through globalfileshareplatform[.]com. Enforce it with a Conditional Access authentication strength rather than offering it as an option.
  2. Verify unsolicited expertise requests out-of-band. TA419 waits for a reply before sending any link. Train staff that an invitation from a well-known figure, especially via a free webmail address such as @mail.com or @outlook.com, should be confirmed through a known contact channel.
  3. Block the published domains and sender addresses at the mail gateway, DNS resolver and web proxy, and search mail logs for historical hits back to December 2025.
  4. Shorten the value of a stolen session. Revoke refresh tokens and sessions for any user who interacted with the lures, and review "Keep me signed in" behaviour for high-risk groups, since TA419's script auto-accepts it.
  5. Review mailbox and OAuth changes after any suspected compromise, including new inbox rules, forwarding and consent grants created after a suspicious OfficeHome sign-in.

Entra ID sign-in hunting starting point (KQL)

The query below uses only Proofpoint's published indicators: the OfficeHome client ID the kit targets and the actor VPS address. Because OfficeHome is a legitimate, heavily used first-party app, the first query looks for successful OfficeHome sign-ins from IP addresses a user has not used in the previous 30 days; expect noise and triage alongside email evidence of the lures.

// Starting point 1: OfficeHome sign-ins from IPs new to the user (AitM relay candidates)
let OfficeHome = "4765445b-32c6-49b0-83e6-1d93765276ca";
let KnownIPs = SigninLogs
    | where TimeGenerated between (ago(33d) .. ago(3d))
    | where ResultType == "0"
    | distinct UserPrincipalName, IPAddress;
SigninLogs
| where TimeGenerated > ago(3d)
| where AppId == OfficeHome and ResultType == "0"
| join kind=leftanti KnownIPs on UserPrincipalName, IPAddress
| project TimeGenerated, UserPrincipalName, IPAddress, Location, UserAgent,
          AuthenticationRequirement, ConditionalAccessStatus, CorrelationId

// Starting point 2: any sign-in activity from the published TA419 VPS address
union SigninLogs, AADNonInteractiveUserSignInLogs
| where TimeGenerated > ago(180d)
| where IPAddress == "108.61.163.187"
| project TimeGenerated, UserPrincipalName, AppDisplayName, AppId, IPAddress, ResultType

Why this matters

The people TA419 targets do not hold classified systems, but they hold early sight of policy thinking, draft reports and relationships with officials. Proofpoint expects the group to keep spoofing real subject-matter experts and to keep targeting think tanks and policy experts working on technologies and geographies of interest to Beijing. For those organisations, the practical takeaway is blunt: any MFA method that can be relayed will be relayed, and the only reliable control against this kit is authentication that is cryptographically bound to the real Microsoft origin.