← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

China-Aligned TA419 Group Targets U.S. AI Policy Experts with Microsoft AitM Phishing

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • TA419 is a China-aligned cyber espionage group.
  • Targets include U.S. AI policy experts in various sectors.
  • Phishing campaigns use Microsoft AitM and Frameless BitB techniques.
  • The goal is to understand U.S. AI policy and regulatory landscape.

TA419 Targets U.S. AI Policy Experts

A China-nexus cyber espionage group, identified as TA419, has been linked to multiple credential phishing campaigns. These campaigns specifically target artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The group has been active since at least April 2025, focusing on individuals in the U.S. and Japan.

Impersonation and Phishing Tactics

TA419's campaigns involve impersonating prominent economists, AI policymakers, and even an Anthropic employee. For example, in February 2026, an AI policy expert at a U.S. think tank received a phishing email with the subject line "Request for Feedback on Military Integration of Claude." Around July 2026, the group impersonated a former member of the White House Office of Science and Technology Policy leadership team in similar campaigns.

Sophisticated Attack Chain

The attacks begin with seemingly harmless invitations to build trust with the target. Once a response is received, the adversary sends a shortened URL that initiates a multi-stage redirection chain. This chain ultimately leads to a OneDrive adversary-in-the-middle (AitM) credential phishing page, after a Cloudflare Turnstile check. The phishing page utilizes a technique called Frameless BitB, which spoofs a trusted website login page by creating a fake browser window within a legitimate browser session using HTML, CSS, and JavaScript, without using an iframe.

Strategic Intelligence Gathering

According to an analysis by Proofpoint, this activity likely supports broader Chinese intelligence objectives. The aim is to gain a better understanding of ongoing developments within the U.S. AI policy and regulatory landscape. This occurs amidst intense strategic competition, accusations of model distillation, and export controls between the U.S. and China, highlighting the importance of AI policy intelligence.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~4 min · 3 stories · Oct 04

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A China-nexus cyber espionage group, TA419, is conducting credential phishing campaigns against U.S. AI policy experts in think tanks, universities, and legal organizations. The attacks use sophisticated adversary-in-the-middle (AitM) techniques to gather intelligence on U.S. AI policy and regulatory developments. This activity indicates ongoing strategic competition and intelligence gathering efforts related to AI between the U.S. and China.