- What: China-aligned TA419 is impersonating AI insiders and former White House staff to phish AI policy experts at U.S. think tanks, universities, and law firms.
- Impact: A Frameless BitB page in front of an AitM proxy captures Microsoft credentials and session cookies, which bypasses standard MFA and leaves the victim with a normal, successful sign-in.
- Fix / mitigation: Proofpoint recommends phishing-resistant authentication such as passkeys, plus out-of-band verification of unsolicited subject-matter outreach.
- Who's at risk: AI policy researchers, think tank fellows, academics, and legal staff with a U.S. or Japan nexus, especially those working on defense, export controls, or AI regulation.
Proofpoint tracks a China-aligned espionage group as TA419, and the group is running credential phishing against the people who shape U.S. artificial intelligence policy. In February 2026 it impersonated a prominent Anthropic employee to target an AI policy expert at a U.S. think tank. The email's subject line was "Request for Feedback on Military Integration of Claude." By July 2026 the group was impersonating a former member of the White House Office of Science and Technology Policy (OSTP) leadership team. Every campaign aims to capture a Microsoft account session through an adversary-in-the-middle (AitM) proxy. The victim gets a normal, successful sign-in and sees nothing wrong.
Who TA419 Is
Proofpoint describes TA419 as China-aligned and motivated by espionage. The group has run credential phishing since at least April 2025. Its targets are individuals at U.S.- and Japan-based think tanks, defense contractors, universities, and law firms. Its consistent interests are defense, national security, energy, international relations, and foreign policy. Proofpoint calls the move into AI policy "an extension of that remit rather than a departure from it."
The timing fits the target set. Proofpoint links the activity to Chinese intelligence efforts to understand the U.S. AI policy and regulatory landscape. That landscape currently includes intense strategic competition, accusations of model distillation, and export controls between the U.S. and China. The people TA419 is targeting brief lawmakers, draft frameworks, and advise on export policy. Their mailboxes hold draft positions before publication, correspondence with officials, and the contacts that show who is talking to whom.
The Lure: Trust First, Link Second
TA419 does not send a link in its first message. Its opening emails are harmless invitations that appear to come from prominent economists, AI policymakers, or, in the February case, an Anthropic employee. The goal is a conversation. The malicious stage starts only after the target replies. The operator then sends a shortened URL.
The opening message has no link, no attachment, and no credential request, so content filters have nothing to flag. When the target replies, the thread is established and the sender looks familiar. The malicious URL then arrives inside a conversation the recipient chose to join.
The pretexts are well chosen. A request for expert feedback on military use of a frontier model is exactly the kind of message an AI policy researcher expects and wants to answer. Impersonating a named Anthropic employee or a former OSTP leader gives the request credibility that a generic lure would lack.
Redirect Chain and Turnstile Gate
The shortened URL starts a redirection chain with several stages. A Cloudflare Turnstile check sits before the final page. Only after the check does the victim reach a OneDrive-themed AitM credential phishing page. This layering does two things. Turnstile blocks many automated scanners and sandbox detonation services, so URL analysis often records a challenge page instead of the phishing kit. The redirect hops also let the operator swap out infrastructure behind the short link without changing the lure.
Frameless BitB on Top of an AitM Proxy
The phishing page uses Frameless browser-in-the-browser (BitB). Classic BitB uses HTML, CSS, and JavaScript to draw a fake browser window inside a real browser session, with the fake sign-in page loaded in an iframe. Frameless BitB creates the same visual effect without the iframe element. Security researcher Wael Masri described the approach in January 2024: "injecting scripts and HTML besides the original content using search and replace (aka substitutions), then relying completely on HTML/CSS/JS tricks to make the visual effect." Removing the iframe also removes a common detection anchor.
Proofpoint reports that TA419 extended this open-source tool with its own telemetry and automation module. The module follows the target's progress through the Microsoft sign-in flow and captures the credentials through the AitM proxy. In the background, it relays everything to Microsoft's real infrastructure.
The proxy passes the full sign-in to Microsoft, so the victim completes their usual MFA prompt and Microsoft issues valid session cookies. TA419 captures those cookies in transit. Push approvals, SMS codes, and authenticator codes all pass through the proxy. The victim's sign-in succeeds and nothing on screen suggests the session has been copied.
What a Captured Session Exposes
A stolen Microsoft session cookie gives the operator authenticated access to the victim's account without a new MFA challenge until that session expires or is revoked. For an AI policy expert, that exposure plausibly includes:
- Mailbox contents, including drafts and correspondence with government staff, industry, and other researchers
- OneDrive and SharePoint documents such as unpublished papers, briefing materials, and comment drafts
- Contact lists and calendars that show who the target meets with and when
- A trusted sending identity that could be used to start the next benign lure against the victim's colleagues
Because the victim saw a successful sign-in, the compromise has no natural trigger for a report. Unless the organization's identity telemetry catches unusual session use, access can continue undetected.
Vendor Mitigation Guidance
Proofpoint recommends phishing-resistant authentication methods such as passkeys. Passkeys are bound to the legitimate origin, so a proxy domain cannot obtain a valid assertion and replay it to Microsoft. That defeats the core of this AitM technique. Proofpoint also advises people who fit TA419's targeting profile to treat unsolicited subject-matter outreach with caution and to verify that it is authentic before going further, even when it appears to come from a well-known name in their field.
The public reporting does not list indicators of compromise, the impersonated individuals by name, or the number of confirmed victims. Defenders looking for infrastructure details will need Proofpoint's full analysis.
RedEye Assessment
None of TA419's techniques is new by itself. Rapport-building lures, short-link redirect chains, Turnstile gating, BitB, and AitM proxies have all been documented before. The threat comes from combining them against a small, high-value group of targets. Each layer defeats a different control: the clean first email beats content filtering, Turnstile beats sandboxing, Frameless BitB beats iframe-based detection, and the AitM proxy beats push and code-based MFA. Organizations that employ AI policy, export control, or national security researchers should assume they are in scope. TA419 already targets the adjacent sectors where these experts work, and Proofpoint's reporting shows the group expanding into AI policy rather than changing course. For these organizations, phishing-resistant authentication is now a baseline requirement, and email filtering alone will not stop this threat.
Questions about your exposure?
RedEye Security provides assessments for organizations that need to understand their real risk.
Talk to us