Full Report
Your invite to a fake AI policy advisory committee has strings attached
Analysis Summary
# Threat Actor: TA419
## Attribution & Identity
* **Actor Name:** TA419
* **Attribution:** China-aligned / Suspected Chinese espionage group.
* **Known Associations:** Described as a Beijing-linked crew focused on technologies of strategic interest to the Chinese government.
## Activity Summary
In 2026, TA419 conducted high-profile espionage campaigns targeting AI policy experts.
* **February 2026:** Spoofed a senior Anthropic employee to target an AI policy analyst at a US think tank regarding "Military Integration of Claude."
* **July 2026:** Executed a two-stage phishing campaign impersonating a former White House Office of Science and Technology Policy (OSTP) official (Lynne Edwards Parker) and a prominent economist (Heidi Crebo-Rediker).
* **Theme:** The campaigns leveraged the lure of joining a fake AI policy advisory committee or contributing to Senate reports on AI export controls and supply chains.
## Tactics, Techniques & Procedures
* **Social Engineering:** Highly targeted impersonation of specific high-ranking individuals in the AI and policy sectors.
* **Credential Phishing:** Use of Browser-in-the-Browser (BitB) overlays to steal cloud account login information.
* **Adversary-in-the-Middle (AiTM):** Utilization of **Evilginx** phishlets to intercept usernames, passwords, and session cookies, specifically bypassing MFA for Microsoft 365/Entra ID.
* **Detection Evasion:**
* Use of Cloudflare Turnstile checks behind phony "OneDrive" loading screens to deter automated analysis.
* Hiding backend hosting IPs via Cloudflare’s Content Delivery Network (CDN).
* Use of shortened URLs to mask attacker-controlled domains.
* **MITRE ATT&CK IDs:**
* **T1566.002:** Phishing: Spearphishing Link
* **T1557:** Adversary-in-the-Middle
* **T1134:** Access Token Manipulation (Session cookie theft)
* **T1583.001:** Acquire Infrastructure: Domains
## Targeting
* **Sectors:** AI Policy, Think Tanks, Academia (Universities), Law Firms, and Government/Foreign Policy.
* **Geography:** Primarily United States; historical interest in Japan and Taiwan.
* **Victims:** US-based AI policy experts, university researchers, and specific organizations like The Heritage Foundation and the Japan-Taiwan Exchange Association.
## Tools & Infrastructure
* **Phishing Frameworks:**
* **Frameless BitB** (Open-source Browser-in-the-Browser)
* **Evilginx** (AiTM framework)
* **Client IDs:** Targets Microsoft 365 via the OfficeHome application (client_id=`4765445b-32c6-49b0-83e6-1d93765276ca`).
* **Domains (Defanged):**
* driftshare[.]co
* globalfileshareplatform[.]com
* msfile[.]online
* onecloudfilesync[.]com
* tw-koryu[.]org (Spoofing Japan-Taiwan Exchange Association)
* heritiages[.]org / heritiage[.]org (Spoofing The Heritage Foundation)
* shinjirou[.]info (Spoofing Japanese Minister of Defense)
## Implications
TA419 represents a sophisticated threat to the intellectual property and strategic policy-making of the United States. By targeting the "reasoning" and policy frameworks of AI development, the group aims to bridge technological gaps and influence or monitor international regulatory responses to AI. The use of AiTM techniques indicates a high level of technical competency capable of bypassing standard multi-factor authentication (MFA).
## Mitigations
* **Phishing-Resistant MFA:** Implement origin-bound authentication such as FIDO2-compliant security keys or Passkeys to prevent AiTM cookie theft.
* **Domain Monitoring:** Monitor for typosquatting and look-alike domains related to internal organizational names or relevant policy bodies.
* **Email Security:** Deploy advanced email protection systems capable of identifying shortened URLs and BitB frameworks.
* **User Awareness:** Train high-value targets (executives and policy researchers) on the specific social engineering lures used, such as fake committee invitations.