China-Aligned TA419 Uses Impersonation and AiTM Phishing to Target U.S. AI Policy Experts

· Original article ↗

Summary

Proofpoint reports that China-aligned TA419 used impersonation and multi-stage adversary-in-the-middle phishing to target U.S. AI policy experts, stealing Microsoft 365 credentials and session cookies through a customized Browser-in-the-Browser tool.

Key points

  • In July 2026, TA419 impersonated prominent economists and AI policymakers in phishing campaigns targeting experts at U.S. think tanks, universities, and law firms; a similar campaign targeted a think-tank analyst in February.
  • The campaigns began with benign outreach about fictitious AI policy initiatives. After recipients replied, shortened links redirected them to fake OneDrive pages.
  • The phishing chain used a customized Frameless BitB tool to proxy Microsoft 365 / Entra ID sign-ins, capture passwords, MFA codes, and session cookies, and automate parts of the login flow.
  • The July campaigns used driftshare[.]co as a first-stage domain and globalfileshareplatform[.]com as a second-stage phishing domain.
  • Proofpoint assesses the targeting as consistent with Chinese intelligence interests in U.S. AI policy and recommends phishing-resistant, origin-bound authentication and independently verifying unexpected outreach.

Article Details

Attack Vectors
  • TA419 sent emails impersonating AI policy experts and other prominent individuals, using benign outreach to elicit a reply before sending a phishing link.
  • Shortened links redirected targets through an actor-controlled filtering domain and then to an adversary-in-the-middle credential phishing domain.
  • A fake OneDrive loading screen presented a Cloudflare Turnstile check before the phishing page.
  • A customized Frameless BitB overlay presented lure documents while a proxy relayed the Microsoft sign-in flow and captured session cookies.
Defensive Notes
  • Proofpoint recommends phishing-resistant, origin-bound authentication such as passkeys for organizations in scope.
  • Proofpoint recommends independently verifying unexpected subject-matter outreach through another medium.

Indicators of compromise

TypeIndicatorContext
DOMAINcirrushare[.]coTA419 phishing domain listed in the source's indicators.
DOMAINcloudsyncpulse[.]comTA419 phishing domain listed in the source's indicators.
DOMAINdriftshare[.]coFirst-stage redirect domain used in both July 2026 phishing campaigns.
DOMAINfileswiftonline[.]cloudTA419 phishing domain listed in the source's indicators.
DOMAINglobalfileshareplatform[.]comSecond-stage domain hosting the adversary-in-the-middle phishing page.
DOMAINgoshshare[.]onlineTA419 phishing domain listed in the source's indicators.
DOMAINheritiage[.]orgTA419 domain impersonating The Heritage Foundation.
DOMAINheritiages[.]orgTA419 domain impersonating The Heritage Foundation.
DOMAINmsfile[.]onlineTA419 phishing domain listed in the source's indicators.
DOMAINmypublicshare[.]comTA419 phishing domain listed in the source's indicators.
DOMAINonecloudfilesync[.]comTA419 phishing domain listed in the source's indicators.
DOMAINpublicsharefile[.]cloudTA419 phishing domain listed in the source's indicators.
DOMAINquickfly[.]onlineTA419 phishing domain listed in the source's indicators.
DOMAINsharehub[.]spaceTA419 phishing sender domain listed in the source's indicators.
DOMAINshinjirou[.]infoTA419 domain impersonating Shinjirō Koizumi’s official website.
DOMAINsmartsyncbox[.]comTA419 phishing domain listed in the source's indicators.
DOMAINsynchvault[.]coTA419 phishing domain listed in the source's indicators.
DOMAINtw-koryu[.]orgTA419 domain impersonating the Japan-Taiwan Exchange Association.
DOMAINwinsync[.]cloudTA419 phishing domain listed in the source's indicators.
EMAILhcrediker@mail[.]comAttacker-controlled email address listed for the July 2026 phishing activity.
EMAILhcrediker@outlook[.]comAttacker-controlled email address listed for the July 2026 phishing activity.
EMAILleparker@mail[.]comAttacker-controlled email address listed for the July 2026 phishing activity.
IPV4108[.]61[.]163[.]187VPS identified in an example TA419 phishing email header as actor-controlled.
SHA256b314a1499cd728ca3e54b7150661fd0c7d2279065fe3f570f0f66c395d744460SHA256 fingerprint of a TLS certificate associated with likely TA419 anonymization infrastructure.

MITRE ATT&CK

Threat Actors

Vendors

Products

Tools

Countries

Industries

Related Articles