Skip to content
Security & Trust

China-aligned TA419 targeted AI policy experts with phishing that relays real Microsoft sign-ins

Proofpoint says the password and MFA both succeed. The proxy captures the session.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
China-aligned TA419 targeted AI policy experts with phishing that relays real Microsoft sign-ins

AI-generated image for WebPulse. About our images

In brief
  • Proofpoint says China-aligned TA419 targeted US AI policy experts with phishing that relays real Microsoft sign-ins, passing password and MFA checks while capturing session cookies.
  • A successful login does not prove the right person is in the account. The report does not say whether any target was compromised.
  • Proofpoint recommends passkeys or similar origin-bound sign-in, and checking unexpected outreach through another channel.

A login can pass every check and still give an attacker the session. That is the mechanism Proofpoint describes in its new report on a group it tracks as TA419. The password is accepted. The MFA code is accepted. Microsoft's conditional access checks pass. Meanwhile a proxy captures the session cookies, so the attacker ends up holding the session.

The report does not say whether any target was compromised. It describes how the method works and who was approached.

Proofpoint, the enterprise security firm, calls TA419 China-aligned and motivated by espionage. The lesson here is simple. A successful login is not proof that the right person is in the account.

Who was approached

From 8 July 2026, the group wrote to targets in the name of Lynne Edwards Parker. Her past post was Principal Deputy Director at the White House Office of Science and Technology Policy. The group then used the name of Heidi Crebo-Rediker, an economist and foreign policy expert.

The recipients worked on AI policy at American think tanks, universities and law firms.

The first message asked for nothing risky. One offered a seat on an "AI Policy Advisory Committee", which Proofpoint calls fictitious. A different lure asked for contributions to a Senate committee report on AI supply chains and export controls. Only a reply from the target moved things forward.

Since at least April 2025, Proofpoint has seen the group send targeted phishing to people at think tanks, defense contractors, universities and law firms. Most of them are based in the US or Japan. This activity had not been reported publicly before.

In February 2026, the group also posed as a senior Anthropic employee. The email was titled "Request for Feedback on Military Integration of Claude."

April 2025
TA419 activity observed since at least
Source: Proofpoint threat research blog

How the sign-in is relayed

After a reply, the attacker sends a shortened link. It passes through several redirects. The first stop shows a fake OneDrive loading screen and runs a Cloudflare Turnstile check, which filters visitors before the next page.

The second stop is an adversary-in-the-middle page. This is a proxy that sits between the victim and the real Microsoft sign-in. The page the target sees is Microsoft's own response, passed along in real time. The proxy adds two malicious scripts to it.

A fake browser window then appears on top. This is the open-source Browser-in-the-Browser technique, here through a kit called Frameless BitB. It draws a convincing Chrome window inside the real one.

The victim signs in as usual. The proxy forwards everything to Microsoft, so the password, MFA code and access checks all succeed. The attacker keeps the resulting session cookies. A session cookie is the token that tells a service you are already signed in.

2
Malicious scripts injected into the relayed Microsoft page
Source: Proofpoint threat research blog

TA419 added its own module to the open-source kit. One script reports how far the victim has got in the login. It also gives the attacker a live view of each session. It clicks "Keep me signed in", which extends the stolen session. It also submits one-time codes for the victim once they check out.

The Hacker News adds the practical effect. The victim sees nothing wrong, because the sign-in works and nothing shows that the cookies were copied.

Why MFA is the wrong question here

Many organizations treat MFA as the control that stops stolen passwords. This attack shows its limit. MFA checks that a person can finish the login. It does not check which site they finished it on.

Proofpoint advises organizations in scope to consider passkeys. These are origin-bound, which means the credential belongs to the real site's address. A look-alike page cannot use it.

The human side matters too. These targets do work that invites outreach. An analyst is expected to say yes to a committee seat or a request for feedback. The lure copies the normal habits of the job.

For individuals, Proofpoint suggests assuming that a cold message on their subject could be a setup. Its advice is to confirm it through a different channel.

8 July 2026
First campaign date impersonating a former OSTP leader
Source: Proofpoint threat research blog

What leaders should ask

Start with who in your organization is a likely target. Proofpoint says the group's long-running interests span defense, security, energy and diplomacy. It calls AI policy an extension of that interest, not a break from it. Researchers, policy staff and legal teams on these topics belong on the list.

Then put three questions to your security team. First, which accounts could move to passkeys or similar origin-bound sign-in first? Second, can we find and revoke a session that was stolen after a successful login? Third, can staff check an unexpected invitation outside email?

The second question matters because a relayed login looks like a normal one. Defenders have to protect where the login happens, not only who performs it.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Proofpoint.

Share this insight