A China-aligned espionage group has been impersonating senior figures from Washington's AI policy world, and from Anthropic itself, to break into the Microsoft 365 accounts of the experts who shape US AI regulation. In research published on 1 October 2026, Proofpoint details TA419, an actor it says has run regular targeted credential phishing against US- and Japan-based think tanks, defence contractors, universities and law firms since at least April 2025, and whose activity had not previously been reported publicly. Its latest campaigns use an adversary-in-the-middle (AitM) kit that relays the real Microsoft sign-in, so the victim's password, MFA prompt and conditional access checks all succeed while TA419 walks away with the session. Policy organisations that still rely on push or one-time-code MFA should treat this as a direct warning.
The lures: AI advisory committees, Senate reports and "Military Integration of Claude"
Beginning on 8 July 2026, TA419 impersonated Lynne Edwards Parker, the former Principal Deputy Director of the White House Office of Science and Technology Policy, and then Heidi Crebo-Rediker, an economist and foreign policy expert, in campaigns aimed at AI policy experts at US think tanks, universities and law firms. The opening emails were deliberately benign: invitations to join a fictitious "AI Policy Advisory Committee" or to contribute to a Senate Committee on Foreign Relations report on AI export controls and supply chains. Only when a target replied did TA419 send a shortened URL purporting to share more information.
Earlier, in February 2026, the group impersonated a senior employee of Anthropic to target an AI policy analyst at a US think tank, using the subject line "Request for Feedback on Military Integration of Claude", a reference to the debate over US military use of Anthropic's Claude models. That campaign led to a similar AitM chain.
TA419 also registered domains impersonating specific organisations during 2026:
| Impersonated entity | TA419 domain |
|---|---|
| Japan-Taiwan Exchange Association | tw-koryu[.]org |
| The Heritage Foundation | heritiages[.]org, heritiage[.]org |
| Shinjiro Koizumi's official website (Japan's current Minister of Defense) | shinjirou[.]info |
Proofpoint assesses the AI-policy targeting is an extension of TA419's long-standing interest in defence, national security, energy, international relations and foreign policy targets with a US and Japan nexus, and that it likely supports wider Chinese intelligence objectives amid strategic competition, model-distillation accusations and export controls.
Attack mechanics: a relayed Microsoft sign-in behind a fake browser window
The chain Proofpoint documented works as follows:
- Redirect and filter. A URL shortener sends the target to a first actor-controlled domain that runs a Cloudflare Turnstile check behind a fake OneDrive loading screen. Both July campaigns used
driftshare[.]cofor this stage. - AitM phishing page. The target is redirected to a second domain, in July
globalfileshareplatform[.]com, hosting the AitM proxy. - Relayed sign-in. The proxy targets Microsoft 365 / Entra ID through the first-party OfficeHome application (
client_id=4765445b-32c6-49b0-83e6-1d93765276ca). The page the victim sees is the genuine Microsoft/common/oauth2/v2.0/authorizeresponse relayed in real time. - Injected scripts. The proxy injects
/secondary/script.js, an adapted Frameless BitB driver that renders a fake OneDrive folder listing of lure documents in a Shadow DOM, and loads/primary/script.js, which raises a fake Chrome browser-in-the-browser overlay when the target clicks a document or Microsoft's own permission-denied banner appears. - Telemetry and automation. A custom
/secondary/observe.jsreports the victim's position in the login flow to the operator, gives a live view of each session, auto-accepts "Keep me signed in" to extend the stolen session, and auto-submits one-time codes as soon as they validate.
Frameless BitB is an open-source kit that bundles the BitB overlay with an Evilginx phishlet for Microsoft 365 and server-side substitution rules. TA419's additions are the telemetry and automation module that drives the target through MFA. Because authentication happens against real Microsoft infrastructure, password strength, one-time codes and push approvals provide no protection: the attacker captures the resulting session cookies. Lure documents themselves were hosted in an attacker-controlled OneDrive account and reached through a proxy path that turns a 1drv.ms share link into an embeddable same-origin page.
Infrastructure
TA419 fronts its domains with Cloudflare's CDN to hide backend hosting and typically registers them through NameSilo, using file-sharing and cloud-service themes. First-hop Received headers in several 2026 emails exposed likely actor-controlled VPS senders, including 108.61.163[.]187. All observed servers shared a self-signed TLS certificate on a high ephemeral port with subject and issuer C=US, ST=Kansas, L=Millsstad, O=Castro Inc, CN=CI, which Proofpoint believes is associated with a covert anonymisation network. In other cases TA419 sent mail through residential proxy services.
Indicators of compromise
| Indicator | Type | Proofpoint description | First seen |
|---|---|---|---|
leparker@mail[.]com | Attacker-controlled email address | July 2026 | |
hcrediker@mail[.]com | Attacker-controlled email address | July 2026 | |
hcrediker@outlook[.]com | Attacker-controlled email address | July 2026 | |
driftshare[.]co | Domain | First stage redirect domain | July 2026 |
globalfileshareplatform[.]com | Domain | Second stage AitM phishing domain | July 2026 |
quickfly[.]online | Domain | First stage redirect domain | May 2026 |
smartsyncbox[.]com | Domain | Second stage AitM phishing domain | May 2026 |
cirrushare[.]co | Domain | First stage redirect domain | April 2026 |
mypublicshare[.]com | Domain | Second stage AitM phishing domain | March 2026 |
goshshare[.]online | Domain | First stage redirect domain | March 2026 |
synchvault[.]co | Domain | First stage redirect domain | March 2026 |
cloudsyncpulse[.]com | Domain | Second stage AitM phishing domain | March 2026 |
onecloudfilesync[.]com | Domain | Second stage AitM phishing domain | February 2026 |
msfile[.]online | Domain | First stage redirect domain | February 2026 |
winsync[.]cloud | Domain | First stage redirect domain | February 2026 |
publicsharefile[.]cloud | Domain | Second stage AitM phishing domain | February 2026 |
fileswiftonline[.]cloud | Domain | Second stage AitM phishing domain | December 2025 |
sharehub[.]space | Domain | First stage redirect domain | December 2025 |
tw-koryu[.]org | Domain | Sender domain | May 2026 |
heritiages[.]org | Domain | Sender domain | March 2026 |
heritiage[.]org | Domain | Sender domain | March 2026 |
shinjirou[.]info | Domain | Sender domain | February 2026 |
b314a1499cd728ca3e54b7150661fd0c7d2279065fe3f570f0f66c395d744460 | TLS certificate | O=Castro Inc certificate SHA-256 fingerprint | February 2026 |
The VPS address 108.61.163[.]187 appears in Proofpoint's example email headers rather than its indicator table.
Defensive playbook
- Move policy and research staff to phishing-resistant, origin-bound authentication. Proofpoint's primary recommendation is passkeys or equivalent. A FIDO2 credential bound to
login.microsoftonline.comwill not complete a sign-in proxied throughglobalfileshareplatform[.]com. Enforce it with a Conditional Access authentication strength rather than offering it as an option. - Verify unsolicited expertise requests out-of-band. TA419 waits for a reply before sending any link. Train staff that an invitation from a well-known figure, especially via a free webmail address such as
@mail.comor@outlook.com, should be confirmed through a known contact channel. - Block the published domains and sender addresses at the mail gateway, DNS resolver and web proxy, and search mail logs for historical hits back to December 2025.
- Shorten the value of a stolen session. Revoke refresh tokens and sessions for any user who interacted with the lures, and review "Keep me signed in" behaviour for high-risk groups, since TA419's script auto-accepts it.
- Review mailbox and OAuth changes after any suspected compromise, including new inbox rules, forwarding and consent grants created after a suspicious OfficeHome sign-in.
Entra ID sign-in hunting starting point (KQL)
The query below uses only Proofpoint's published indicators: the OfficeHome client ID the kit targets and the actor VPS address. Because OfficeHome is a legitimate, heavily used first-party app, the first query looks for successful OfficeHome sign-ins from IP addresses a user has not used in the previous 30 days; expect noise and triage alongside email evidence of the lures.
// Starting point 1: OfficeHome sign-ins from IPs new to the user (AitM relay candidates)
let OfficeHome = "4765445b-32c6-49b0-83e6-1d93765276ca";
let KnownIPs = SigninLogs
| where TimeGenerated between (ago(33d) .. ago(3d))
| where ResultType == "0"
| distinct UserPrincipalName, IPAddress;
SigninLogs
| where TimeGenerated > ago(3d)
| where AppId == OfficeHome and ResultType == "0"
| join kind=leftanti KnownIPs on UserPrincipalName, IPAddress
| project TimeGenerated, UserPrincipalName, IPAddress, Location, UserAgent,
AuthenticationRequirement, ConditionalAccessStatus, CorrelationId
// Starting point 2: any sign-in activity from the published TA419 VPS address
union SigninLogs, AADNonInteractiveUserSignInLogs
| where TimeGenerated > ago(180d)
| where IPAddress == "108.61.163.187"
| project TimeGenerated, UserPrincipalName, AppDisplayName, AppId, IPAddress, ResultType
Why this matters
The people TA419 targets do not hold classified systems, but they hold early sight of policy thinking, draft reports and relationships with officials. Proofpoint expects the group to keep spoofing real subject-matter experts and to keep targeting think tanks and policy experts working on technologies and geographies of interest to Beijing. For those organisations, the practical takeaway is blunt: any MFA method that can be relayed will be relayed, and the only reliable control against this kit is authentication that is cryptographically bound to the real Microsoft origin.


