The Phish That Passes MFA: China-Aligned TA419 Targets AI Policy Experts

Estimated reading time: 5 minutes

Proofpoint says a China-aligned group posed as former White House staff and other AI policy figures to phish US experts. Its kit relays the genuine Microsoft sign-in, so the password and the MFA code both work. Proofpoint recommends phishing-resistant MFA such as passkeys.

The first email asks for nothing. It invites an AI policy expert to join an advisory committee. Another asks for input on a Senate report on AI export controls.

The link arrives only after the target replies.

Until 1 October, no one had publicly reported on the group behind those emails, according to Proofpoint. That day, Mark Kelly and the Proofpoint Threat Research Team published their findings. Their report details the lures, phishing kit, and infrastructure behind the campaign.

They track the actor as TA419. Proofpoint assesses it as China-aligned and espionage-motivated.

TA419 Impersonated AI Policy Figures

Beginning 8 July, TA419 posed as Lynne Edwards Parker. She is the former principal deputy director of the White House Office of Science and Technology Policy. It then impersonated Heidi Crebo-Rediker, an economist and foreign policy expert. The targets worked on AI policy at US think tanks, universities, and law firms.

Screenshot of a TA419 phishing email impersonating a former White House Office of Science and Technology Policy official, from Proofpoint research
A TA419 phishing page from July 2026. A fake Chrome sign-in window sits over a OneDrive file listing. Image: Proofpoint.

In February, the group posed as a senior Anthropic employee. That email’s subject line read “Request for Feedback on Military Integration of Claude.”

Proofpoint has tracked TA419 since at least April 2025. Its targets include think tanks, defense contractors, universities and law firms in the US and Japan. Proofpoint assesses that the AI policy campaigns likely serve wider Chinese intelligence interests in US AI policy and regulation.

See also  Upstream Report Flags Remote Attack Growth As HSB Adds Fleet Cyber Coverage

An MFA Bypass Built On Microsoft’s Own Sign-In

A shortened link sends the target through two actor-controlled domains. The first runs a Cloudflare Turnstile check behind a fake OneDrive loading screen. The second hosts the phishing page.

That page is adversary-in-the-middle phishing. The kit relays the target’s sign-in to Microsoft in real time. The target sees the genuine Microsoft 365 login. The password, the MFA code, and conditional access checks all succeed. TA419 captures the session cookies that result.

A browser-in-the-browser overlay frames the login as a normal Chrome window. The kit is built on two open-source tools, Frameless BitB and Evilginx.

Screenshot of a TA419 phishing page showing a fake browser sign-in window over a OneDrive file listing, from Proofpoint research
A TA419 phishing page from July 2026. A fake Chrome sign-in window sits over a OneDrive file listing. Image: Proofpoint.

TA419 added its own module. It reports each target’s position in the login flow and gives the attacker a live view of each session. It submits one-time codes as soon as they validate. And it also ticks “Keep me signed in” automatically to extend the stolen session.

Proofpoint does not say how many people TA419 targeted. It does not say whether the group compromised any accounts.

Phishing-Resistant MFA And The Application Question

MFA is a standard question on cyber insurance applications. This kit was built to pass it.

Proofpoint recommends phishing-resistant, origin-bound authentication such as passkeys. Passkeys are a form of phishing-resistant MFA. They only work on the legitimate site, so a relayed login does not complete.

For individuals in TA419’s sights, Proofpoint advises treating unsolicited subject-matter outreach as a possible pretext. Targets should verify unexpected contact through a separate channel.

Other recent access routes have skipped MFA entirely. Zscaler ThreatLabz documented ransomware crews calling staff on Microsoft Teams while posing as IT support. In that sequence, the employee grants access.

What Proofpoint Expects From TA419 Next

TA419 also registers domains that imitate specific organizations. Proofpoint listed lookalikes for the Heritage Foundation, the Japan-Taiwan Exchange Association, and the website of Japan’s defense minister.

Proofpoint expects TA419 to keep targeting think tanks and policy experts working on technologies of interest to the Chinese government. It also expects the group to keep spoofing real subject-matter experts.

FAQ – Phishing-Resistant MFA

Who is TA419?

A threat actor Proofpoint assesses as China-aligned and espionage-motivated. It has targeted think tanks, defense contractors, universities and law firms in the US and Japan since at least April 2025.

Who did TA419 impersonate?

A former principal deputy director of the White House Office of Science and Technology Policy, an economist and foreign policy expert, and, in February 2026, a senior Anthropic employee.

How does the phishing kit get past MFA?

It relays the target’s sign-in to the genuine Microsoft login in real time. The password and MFA code work as normal, and the attacker captures the session cookies that result.

What is phishing-resistant MFA?

Authentication bound to the legitimate site, such as passkeys. Because the credential only works on the real origin, a relayed login through a phishing proxy does not complete.

Were any accounts compromised?

Proofpoint does not say how many people TA419 targeted or whether the group compromised any accounts.

Why does this matter for cyber insurance?

MFA is a standard question on cyber insurance applications. Adversary-in-the-middle kits are built to pass standard MFA, which is why Proofpoint recommends phishing-resistant methods.

See also  Cyber Threat Complexity Surges: OPSWAT Uncovers the Hidden Malware Crisis

2 thoughts on “The Phish That Passes MFA: China-Aligned TA419 Targets AI Policy Experts”

Leave a Comment

×