A China-aligned espionage group known as TA419 has launched a campaign of Microsoft-based Adversary-in-the-Middle (AitM) phishing attacks aimed at American AI policy experts working in think tanks, universities, law firms, and other high-profile institutions. The operation, first observed in April 2025, has escalated in recent months with increasingly sophisticated impersonations and tools.
How the Attacks Work
TA419 begins with an innocuous initial contact—an email that appears to be from a respected economist, policymaker, or internal AI expert. Once the recipient engages, a follow-up message includes a shortened URL that leads through multiple redirects. After passing through a Cloudflare Turnstile check, the link takes the target to a credential phishing page hosted by OneDrive.
The phishing page uses a technique called Frameless BitB, an evolution of browser-in-the-browser (BitB) attacks. Unlike classic iframe-based spoofing, Frameless BitB mimics the layout and behavior of legitimate Microsoft login pages without using HTML iframes. Instead, attackers inject custom HTML, CSS, and JavaScript into the page to create a convincing fake login flow—one that surreptitiously captures credentials via the AitM proxy while relaying legitimate session information to Microsoft infrastructure. Because the login succeeds and session cookies appear valid, victims often don’t suspect anything unusual.
Target Profile and Strategic Context
The targets include U.S. AI policy experts spanning think tanks, legal advocacy groups, universities, and international relations bodies. In February 2026, one targeted individual received a phishing email titled “Request for Feedback on Military Integration of Claude,” impersonating an Anthropic employee. In mid-2026, TA419 also pretended to be leaders from the White House’s Science and Technology Policy Office to lure responses from potential targets.
This activity fits into broader objectives related to Chinese intelligence gathering—especially around U.S. AI regulation, export controls, model distillation practices, and the evolving policy landscape. Experts believe TA419’s operations deepen a trend in which tech policy is becoming a core arena in geopolitical competition.
Defensive Recommendations
Security leaders recommend that organizations enable authentication methods resistant to phishing, like passkeys, to prevent credential theft. Individuals who are likely targets should scrutinize unsolicited outreach, especially involving policy or AI expertise, and verify the sender’s identity before following any links or sharing sensitive information.
TA419 has clearly indicated a sustained interest in defense, national security, energy, and international relations—particularly among U.S. and Japanese institutions. The group’s recent shift to focus specifically on AI policy experts demonstrates an extension of its existing targeting rather than a change in mission.
What this reveals is a high-stakes intersection of cybersecurity and AI policy. As regulation and strategic competition around AI intensify globally, threat actors like TA419 are turning their gaze toward shaping—or at least surveilling—the decisionmakers. For institutions and individuals involved in AI governance, the signals are clear: operational security and awareness are no longer optional, they’re essential. Keep an eye on developments in phishing-resistant authentication, and how governments respond to these kinds of threats—not just with policy, but with action.