Proofpoint published details on 1 October 2026 of a China-aligned actor it tracks as TA419. In July the group impersonated AI policymakers and economists to phish AI policy experts at US think tanks, universities, and law firms. The follow-up link was an adversary-in-the-middle proxy of a real Microsoft 365 sign-in, built to steal the session even when MFA succeeded.
What happened
The first mail was benign. It invited the target to a fictional AI Policy Advisory Committee, or to contribute to a Senate report on AI export controls. Only after a reply did the actor send a shortened URL. That URL passed a Cloudflare Turnstile check, then landed on a fake OneDrive page backed by a customized Frameless BitB kit and an Evilginx phishlet for the OfficeHome application.
The page the victim sees is the genuine Microsoft authorize response, relayed live. A script auto-accepts "Keep me signed in" and auto-submits one-time codes once they validate. Password, MFA, and conditional access can all succeed while the attacker keeps the session cookies. In February the same actor impersonated an Anthropic employee with the subject "Request for Feedback on Military Integration of Claude."
Who is affected
- AI policy staff at think tanks, universities, and law firms, especially anyone working on export controls or national AI strategy
- Any Microsoft 365 tenant whose users answer unsolicited expert outreach with a click
- Proofpoint has also seen TA419 against Japan-linked policy and defense targets since at least April 2025
July infrastructure included driftshare[.]co as the first hop and globalfileshareplatform[.]com as the phishing host. Sender addresses included leparker@mail[.]com and hcrediker@mail[.]com.
What to do now
Require phishing-resistant, origin-bound sign-in such as passkeys for policy and executive mailboxes. Treat an unexpected collaboration invite as a pretext until it is confirmed on a separate channel. Hunt mail for the domains above and for short links that resolve to file-share themed hosts. Session-cookie theft bypasses a one-time code, so a successful MFA prompt is not proof the login was yours.
Source: Proofpoint Threat Insight, 1 October 2026.
Also on the blog
- CVE-2026-88779 crashes SAML NetScaler, patch by 7 October
- CVE-2026-105207 ZITADEL account takeover, upgrade to 4.17.3
- GitLab AI Gateway sandbox escape is a 9.9, patches are out
- ShinyHunters suspect Rey detained in Jordan, sources say
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.