TA419 Phishes AI Policy Experts With Microsoft AitM

The Hacker News · High sophistication
Last updated October 5, 2026

China-aligned threat actor TA419 ran real credential-phishing campaigns targeting U.S. AI policy experts at think tanks, universities, and law firms. The operation used trust-building outreach followed by a shortened link that redirected victims through checks to a fake Microsoft/OneDrive sign-in designed to steal credentials and session cookies without breaking the login.

How the Attack Worked

TA419, a China-aligned threat actor, ran a credential-phishing campaign against AI policy experts at U.S. think tanks, universities, and law firms. The operation relied on impersonation of prominent economists, AI policymakers, and an Anthropic employee to build credibility with targets. The email lure used the subject line "Request for Feedback on Military Integration of Claude" to draw in recipients working on AI policy issues.

The workflow was staged in two parts. First, attackers sent harmless outreach designed purely to establish trust and get a reply. Only after the target responded did the attacker send a shortened URL. That link triggered a multi-stage redirection chain, included a Cloudflare Turnstile bot check, and ultimately led to a fake OneDrive sign-in page built to look like a legitimate Microsoft login.

Why It Succeeded

The page used a frameless browser-in-the-browser technique combined with an adversary-in-the-middle proxy. This let the attacker capture both credentials and session cookies while still completing a real, successful sign-in to Microsoft services. Because the login worked as expected, victims had no visible indication that anything had gone wrong, since the usual signs of a failed or suspicious login were absent.

The layered approach, trust-building first, credential theft second, made the attack harder to spot than a typical one-shot phishing email. The bot check and multi-stage redirects also added a veneer of legitimacy that could make targets less suspicious before reaching the final page.

What to Watch For

  • Unsolicited messages from unfamiliar contacts requesting expert feedback or commentary, especially ones that pivot quickly toward a link
  • Shortened URLs that pass through several redirects before landing on a sign-in page
  • Unexpected verification steps, like a bot check, inserted before a Microsoft or OneDrive login
  • A sign-in flow that completes successfully but was reached through an unusual path

How to Build Resistance

Organizations and individuals who may be targeted by this kind of outreach, particularly those working on AI policy, defense, or regulatory issues, should treat unsolicited subject-matter requests with caution and verify the sender independently before replying or clicking any follow-up link.

Because AitM phishing can succeed even when the login appears normal, a successful sign-in should not be treated as proof that a page was legitimate. Adopting phishing-resistant authentication methods, such as passkeys, reduces the impact of stolen passwords and session cookies, since these methods are not vulnerable to the same credential-relay techniques used in this campaign.

Key findings

  • TA419 targeted AI policy experts at U.S. think tanks (and also universities and legal organizations) using credential phishing.
  • Attackers impersonated prominent economists/AI policymakers and an Anthropic employee to increase credibility.
  • The email lure included the subject line "Request for Feedback on Military Integration of Claude."
  • The workflow was two-stage: initial harmless invitations to build trust, then a shortened URL after the victim replied.
  • The shortened URL led through a multi-stage redirect chain and a Cloudflare Turnstile check to an OneDrive adversary-in-the-middle (AitM) phishing page.
  • The phishing page used a "Frameless BitB" (browser-in-the-browser) technique and an AitM proxy to capture credentials and session cookies while still logging the victim into real Microsoft services.
  • Because the sign-in succeeds, victims may not realize session cookies were captured.

Who’s being targeted

  • Commonly targeted roles: Executive leadership at think tanks, Policy and research staff, University faculty and research staff, Legal professionals handling AI policy/regulatory matters, Anyone using Microsoft/OneDrive for collaboration.
  • Affected industries: Think tanks / policy research organizations, Higher education (universities), Legal services (law firms), Defense and national security policy organizations.
  • Attack channels: email.
  • Impersonated: Prominent economists and AI policymakers; also a prominent Anthropic employee.

Red flags to watch for

  • Unsolicited policy/outreach message that quickly pivots to a login link
  • Shortened URL that redirects multiple times before landing on a Microsoft sign-in
  • Unexpected bot-check (Cloudflare Turnstile) before a login page
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

Who did TA419 target in this campaign?

TA419 targeted AI policy experts at U.S. think tanks, as well as university researchers and legal professionals working on AI policy and regulatory matters.

How did the TA419 phishing attack work?

The attackers sent trust-building outreach impersonating economists, AI policymakers and an Anthropic employee, then followed up with a shortened URL that redirected victims through a Cloudflare Turnstile check to a fake OneDrive sign-in page using an adversary-in-the-middle technique.

Why didn't victims notice their credentials were stolen?

The AitM proxy let the sign-in event succeed normally while stealthily capturing credentials and session cookies, so there were no visible signs anything was wrong.

How can organizations defend against this kind of attack?

Awareness guidance includes verifying unsolicited outreach independently, being cautious of shortened links and unexpected bot checks before a Microsoft login, and enabling phishing-resistant authentication such as passkeys.

Read the video transcript

You get an email: “Request for Feedback on Military Integration of Claude” from a big-name economist or even someone claiming to be from Anthropic. They start friendly, build trust, then after you reply, they send a shortened link. It bounces through redirects, shows a Cloudflare bot check, and lands on what looks like a normal Microsoft OneDrive sign-in. Behind that page is a frameless browser-in-the-browser, a Microsoft adversary-in-the-middle setup. Your login works, OneDrive opens, but they quietly steal your password and session cookies. If you get an unsolicited policy outreach that pivots to a shortened link and Microsoft login, stop and verify the person through a separate channel before you click or sign in.

Similar attacks

Chinese Spy Phish + Airmen BEC Sentenced

Chinese Spy Phish + Airmen BEC Sentenced

A China-aligned group (TA419) impersonated well-known U.S. figures to lure AI policy experts into a fake OneDrive/Microsoft 365 login that could steal session cookies even when MFA is enabled. Separately, two U.S. airmen were sentenced for a multi-year business email compromise scheme where they…

October 2, 2026
Fake AI Experts Lure Think Tanks Into M365 Phish

Fake AI Experts Lure Think Tanks Into M365 Phish

A China-aligned group (TA419) targeted US AI policy experts by impersonating well-known AI and policy figures and sending friendly “collaboration” emails. If the target engaged, the attackers redirected them through multiple URLs to a fake Microsoft login pop-up designed to steal Microsoft 365…

October 2, 2026
TA419 Poses as White House to Steal Cloud Logins

TA419 Poses as White House to Steal Cloud Logins

A China-aligned espionage group (TA419) targeted U.S. AI policy experts by impersonating well-known public figures and sending credible policy-related invitations. After victims replied, the attackers sent shortened links that led to a fake OneDrive login designed to capture passwords, MFA codes,…

October 2, 2026
Fake AI Advisory Invites Lure US Policy Targets

Fake AI Advisory Invites Lure US Policy Targets

A China-aligned group (tracked as TA419) impersonated real AI policy figures and sent benign-sounding outreach to people working on AI policy at US and Japanese organizations. Once targets replied, the attackers sent a shortened link that ultimately led to a fake OneDrive/Microsoft 365 login page…

October 1, 2026
ClickFix Trick Spreads ACR Stealer via Paste-Run

ClickFix Trick Spreads ACR Stealer via Paste-Run

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR (Amatera) Stealer. The malware steals saved browser passwords, live session tokens, and Microsoft 365/OneDrive/SharePoint files, meaning…

July 17, 2026
Fake AI Advisory Invites Steal M365 Logins

Fake AI Advisory Invites Steal M365 Logins

Researchers say a China-aligned group (TA419) impersonated well-known AI policy figures and an Anthropic executive to lure US AI policy experts into replying to emails about a fake advisory committee or Senate report. Once a target engaged, the attackers sent shortened links that led through a fake…

October 1, 2026