"In July 2026, TA419 impersonated multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team, in credential phishing campaigns targeting AI policy experts in the US," Proofpoint threat-intelligence analyst Mark Kelly said.
Targets and timeline
Proofpoint discovered and attributed a series of credential-phishing campaigns to a China-aligned group it tracks as TA419. The bulk of the efforts occurred in July 2026, with activity beginning July 8 that spoofed Lynne Edwards Parker, the former principal deputy director of the White House Office of Science and Technology Policy, and then Heidi Crebo-Rediker, described in the report as a prominent economist and foreign policy expert. The campaigns targeted AI policy experts at U.S. universities, think tanks, and law firms, inviting recipients to join a fake AI policy advisory committee or to contribute to a Senate foreign relations committee report on AI export controls and supply chains.
Proofpoint also reported an earlier February incident in which the group spoofed a senior Anthropic employee to phish an AI policy analyst at a U.S. think tank. That February email used the subject line: "Request for Feedback on Military Integration of Claude." Proofpoint’s alert followed an OpenAI allegation published a day earlier that China’s Moonshot AI had carried out distillation attacks beginning on July 1; the two publications appeared in close temporal proximity.
How the phishing chain worked
Proofpoint reconstructed the four-step phishing chain used by TA419. If a target replied to the spoofed email, the attacker returned a shortened URL that purported to give more details but actually pointed to an attacker-controlled domain. That domain performed a Cloudflare Turnstile check behind a fake OneDrive loading screen, then redirected the victim to an attacker-in-the-middle credential-phishing page that harvested cloud-account login credentials.
The campaigns specifically targeted Microsoft 365/Entra ID via the first-party OfficeHome application (client_id=4765445b-32c6-49b0-83e6-1d93765276ca). The kit used to stage the attacks is built on the open-source Frameless BitB framework, which contains a Browser-in-the-Browser (BitB) overlay, an Evilginx phishlet to intercept usernames, passwords, and session cookies for Microsoft 365, and server-side substitution rules that inject the kit into proxied pages.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleDomains, impersonations, and operational tradecraft
Proofpoint documented the domains and subdomains used in these campaigns. In July 2026 the actors used driftshare[.]co as the first-stage domain and globalfileshareplatform[.]com as the second-stage domain. The crew typically themes credential-phishing domains around file sharing and cloud services — examples Proofpoint cited include msfile[.]online and onecloudfilesync[.]com — and regularly leverages Cloudflare’s content delivery network to hide backend hosting IPs.
Beyond individuals, the group has impersonated organizations and public figures, including domains tied to the Japan-Taiwan Exchange Association (tw-koryu[.]org), The Heritage Foundation (heritiages[.]org and heritiage[.]org), and the official site for Japanese Minister of Defense Shinjirō Koizumi (shinjirou[.]info). Proofpoint said the crew uses dozens of phishing and spoofed-sender domains and provided a timeline of when each was registered or first observed in 2026.
What this means for technologists, policymakers, and AI policy experts
- Technologists and security teams: Proofpoint recommends adopting phishing-resistant, origin-bound authentication such as passkeys. Teams should also monitor for Browser-in-the-Browser (BitB) overlays and AitM (attacker-in-the-middle) frameworks like Evilginx that harvest session cookies and tokens.
- Policymakers and regulators: Invitations to advisory committees or requests to contribute to legislative reports were used as lures. Those working on AI export controls and supply chain policy should verify senders through out-of-band channels before sharing credentials or clicking shortened links.
- AI policy experts and academic researchers: The campaigns demonstrate a sustained targeting pattern against experts at universities, think tanks, and law firms; respondents who receive unsolicited project invitations or shortened URLs should treat them as high-risk and consult organizational security procedures.
Proofpoint concluded that TA419 and other Beijing-aligned crews will likely continue targeting AI and other policy experts working on technologies of interest to the Chinese government. The report includes a full set of indicators and a registration timeline for the discovered domains; Proofpoint’s concrete mitigation advice centers on moving to phishing-resistant, origin-bound authentication and watching for AitM techniques that bypass traditional credential protections.




