Threat reportPhishingTL-2026-2884

China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)

highACTIVE

China-Aligned TA419 Targets U.S. AI Policy Experts With (TL-2026-2884) is a high-severity phishing campaign, first published 2026-10-04. It is attributed to TA419 (China) with medium confidence, affects Microsoft Microsoft 365 / Entra ID / OneDrive sign-in (OfficeHome, maps to 13 MITRE ATT&CK techniques (T1056.003, T1090, T1111), and is covered by 9 detection rules and 29 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
13MITRE ATT&CK
Actors
1TA419
Detection rules
9SPL · KQL · Sigma
IOCs
29Indicators of compromise

Key facts for TL-2026-2884

Threat ID
TL-2026-2884
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution
TA419
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
think tanks, education, legal, defense, government administration, foreign-policy, energy
Target regions
North America, japan, taiwan
Detection rules
9
Indicators of compromise
29

Malware and tooling in China-Aligned TA419 Targets U.S. AI Policy Experts With

Malware and tooling: Evilginx, Evilginx, Frameless BitB

How China-Aligned TA419 Targets U.S. AI Policy Experts With works

China-aligned, espionage-motivated actor TA419 is phishing U.S. AI policy experts at think tanks, universities, law firms and defense contractors, plus Japan-based organizations, by impersonating prominent AI figures and an Anthropic employee. Lures lead via shortened URLs and Cloudflare Turnstile-gated redirects to OneDrive-themed Microsoft sign-in pages that combine Evilginx-style AitM proxying with a modified Frameless BitB kit to capture credentials and live sessions.

Proofpoint reports that TA419, a China-aligned cyber-espionage actor active since at least April 2025, ran credential-phishing campaigns in February 2026 and July 2026 against people working on U.S. AI policy and regulation. In February 2026 the actor posed as a senior Anthropic employee and emailed an AI policy analyst at a U.S. think tank with the subject 'Request for Feedback on Military Integration of Claude'. In July 2026 (from July 8) it impersonated Lynne Edwards Parker, former Principal Deputy Director of the White House Office of Science and Technology Policy, and economist Heidi Crebo-Rediker, using mail.com and outlook.com sender addresses, inviting targets to a fictitious 'AI Policy Advisory Committee' or to contribute to a Senate Foreign Relations Committee report on AI export controls and supply chains.

The initial outreach is benign and builds trust. After a reply, the actor sends shortened URLs that pass through multi-stage redirection to first-stage domains (file-sharing themed), then a Cloudflare Turnstile check shown behind a fake OneDrive loading screen, and finally a second-stage adversary-in-the-middle (AitM) page. The kit uses a Microsoft 365 Evilginx-style phishlet with server-side substitution rules that inject scripts and HTML into proxied pages, relaying real Microsoft responses so the victim sees a genuine sign-in. A modified open-source Frameless BitB draws a fake browser window (HTML/CSS/JS, no iframe) over the OneDrive-styled page. A bespoke telemetry and automation module (/primary/script.js, /secondary/script.js, /secondary/observe.js) tracks and drives the victim through the Microsoft sign-in flow, including MFA, and auto-accepts the 'Keep me signed in' prompt. The target is Microsoft 365 / Entra ID via the OfficeHome client ID 4765445b-32c6-49b0-83e6-1d93765276ca. The result is capture of credentials, MFA codes and authenticated session cookies, enabling account takeover that passes conditional-access checks.

Infrastructure includes lookalike sender domains impersonating the Japan-Taiwan Exchange Association (tw-koryu.org), the Heritage Foundation (heritiages.org, heritiage.org) and a Japanese Minister of Defense site (shinjirou.info), eight first-stage and seven second-stage domains registered via NameSilo behind Cloudflare, an actor-controlled VPS at 108.61.163.187, and a TLS certificate with SHA256 b314a1499cd728ca3e54b7150661fd0c7d2279065fe3f570f0f66c395d744460 (subject C=US, ST=Kansas, L=Millsstad, O=Castro Inc, CN=CI). Targeting also covers defense contractors and Japan-based organizations. Proofpoint notes related AI-themed phishing previously reported as UNK_SweetSpecter. Coverage notes the report does not directly tie the activity to the Chinese government, which denies such allegations.

MITRE ATT&CK techniques used in TL-2026-2884

Credential Access

T1056.003 Input Capture: Web Portal Capture; T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle

Command and Control

T1090 Proxy

Execution

T1204.001 User Execution: Malicious Link

lateral-movement

T1550.004 Use Alternate Authentication Material: Web Session Cookie

Initial Access

T1566.002 Phishing: Spearphishing Link

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1583.003 Acquire Infrastructure: Virtual Private Server; T1585.002 Establish Accounts: Email Accounts

Reconnaissance

T1598.003 Phishing for Information: Spearphishing Link

Defense Evasion

T1684.001 Impersonation

Affected products and versions in China-Aligned TA419 Targets U.S. AI Policy Experts With

  • Microsoft — Microsoft 365 / Entra ID / OneDrive sign-in (OfficeHome client)
    Vulnerable versions: Accounts without phishing-resistant MFA

Remediation for China-Aligned TA419 Targets U.S. AI Policy Experts With

Immediate actions

  • Block and hunt for the listed first-stage, second-stage and sender-lookalike domains, the VPS IP 108.61.163.187 and the TLS certificate hash in mail, proxy, DNS and CT logs
  • Hunt Entra ID sign-in logs for OfficeHome client ID 4765445b-32c6-49b0-83e6-1d93765276ca with anomalous IP, user agent or session-reuse patterns
  • If compromise is suspected, revoke Entra ID sessions and refresh tokens, reset credentials and re-register MFA methods

Workarounds

  • Restrict sign-in pages to genuine Microsoft domains and treat in-page pop-up sign-in windows as suspicious (BitB)

Longer-term hardening

  • Require phishing-resistant authentication (FIDO2 passkeys) for critical resources
  • Enforce token binding / compliant-device conditional access so stolen session cookies are not replayable
  • Train AI-policy, think-tank, legal and defense staff to verify unsolicited subject-matter outreach out-of-band before opening links or entering MFA codes
  • Correlate email threads with URLs sent after the first reply, and alert on shortened URLs from free-mail senders

Timeline of China-Aligned TA419 Targets U.S. AI Policy Experts With

  • Earliest TA419 activity tracked by Proofpoint (April 2025)
  • First TA419 phishing domains registered (sharehub.space, fileswiftonline.cloud) per Proofpoint
  • TA419 poses as a senior Anthropic employee, emailing a U.S. think-tank AI policy analyst with the subject 'Request for Feedback on Military Integration of Claude'
  • Further domains registered (goshshare.online, synchvault.co, cloudsyncpulse.com) plus Heritage Foundation lookalikes heritiage.org and heritiages.org
  • quickfly.online and smartsyncbox.com registered; tw-koryu.org (Japan-Taiwan Exchange Association lookalike) used in outreach
  • Expanded campaigns begin, impersonating Lynne Edwards Parker (ex-OSTP) and economist Heidi Crebo-Rediker against AI policy experts at think tanks, universities and law firms
  • Proofpoint publishes 'Hallucinating Credibility' detailing TA419 infrastructure, Frameless BitB and AitM tradecraft
  • The Hacker News reports on the campaign; activity assessed as ongoing

Sources cited for China-Aligned TA419 Targets U.S. AI Policy Experts With

Detection coverage for TL-2026-2884

As of 2026-10-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2884 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
29 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats