Oct 02, 2026 · 8 min read
TA419 Phishing Fakes AI Policy Experts to Target Researchers
Proofpoint says the China aligned group posed as former White House official Lynne Edwards Parker and economist Heidi Crebo-Rediker from July 8, 2026, then sent repliers to a fake OneDrive login. Talos ties the Antino backdoor to a different group.
A former White House technology official would like you to join an AI Policy Advisory Committee. The email has no link and no attachment. Write back, and the next message carries a short link promising more detail that ends at a Microsoft sign in page feeding your session to a China aligned espionage group. Proofpoint's October 1 report describes a group it calls TA419 running this play against AI policy experts in July 2026. For analysts, academics and the reporters who quote them, it is a flattering ask from a familiar name.
Key Takeaways
- Proofpoint reported on October 1, 2026 that TA419 began impersonating former White House official Lynne Edwards Parker, then economist Heidi Crebo-Rediker, on July 8, 2026 to phish AI policy experts at US think tanks, universities and law firms.
- The opening emails were benign invitations to join a fictitious AI Policy Advisory Committee or to contribute to a Senate Committee on Foreign Relations report, and only targets who replied received a shortened link.
- That link led to a fake OneDrive page built on the open source Frameless BitB kit, which relays the password and MFA code to real Microsoft servers while TA419 captures the session cookies.
- Proofpoint does not link TA419 to the Antino backdoor: Cisco Talos attributes Antino to UAT-11587, a separate China nexus cluster it tied to 16 targeted or affected environments in eight Asian countries between September 2025 and July 2026.
Who Is TA419?
TA419 is Proofpoint's name for a China aligned, espionage motivated group that has run "regular targeted credential phishing campaigns" against people at US and Japan based think tanks, defense contractors, universities and law firms since at least April 2025. Proofpoint says its activity "has not been previously reported publicly" and maps TA419 to no other vendor's group name.
Its usual beats are defense, national security, energy and foreign policy. In 2026 it registered lookalike domains for the Japan-Taiwan Exchange Association (tw-koryu[.]org), The Heritage Foundation (heritiages[.]org, heritiage[.]org) and the official website of Japanese Defense Minister Shinjirō Koizumi (shinjirou[.]info). Proofpoint calls the move into AI policy "an extension of that remit rather than a departure from it."
What Did the Fake AI Policy Invitations Look Like?
They were polite, linkless conversation starters sent from consumer webmail accounts named after real experts. Proofpoint lists three July sender addresses, leparker@mail[.]com, hcrediker@mail[.]com and hcrediker@outlook[.]com, none of them on a government or institutional domain. The group impersonated Lynne Edwards Parker, whom Proofpoint identifies as "the former Principal Deputy Director of the White House Office of Science and Technology Policy," and then Heidi Crebo-Rediker, "a prominent economist and foreign policy expert."
The other pretext was a request to contribute to a Senate Committee on Foreign Relations report on AI export controls and supply chains. In Proofpoint's words, the group "first sent benign conversation starter emails, which included calls to action themed around AI policy such as joining an “AI Policy Advisory Committee”, to build rapport and solicit a response from the target."
In February 2026, TA419 posed as "a senior employee of the AI company Anthropic" to approach a US think tank analyst with the subject line "Request for Feedback on Military Integration of Claude." Anthropic was impersonated, not targeted.
Proofpoint did not say how many people were targeted or whether anyone was compromised, and CyberScoop's coverage reports no confirmation either way.
What Happens After You Reply?
You get a shortened URL that walks you through two attacker domains to a real Microsoft sign in page proxied by TA419. Both July campaigns used the same pair, according to Proofpoint:
- The filter.
driftshare[.]coshows a fake OneDrive loading screen and runs a Cloudflare Turnstile check before passing you on. - The bait folder.
globalfileshareplatform[.]comshows a OneDrive folder of real documents hosted in an attacker controlled account. - The fake window. Clicking a document, or hitting OneDrive's own permission denied banner, raises a fake Chrome window drawn inside the page, the Browser in the Browser trick.
- The relay. Inside that window sits the genuine Microsoft
/common/oauth2/v2.0/authorizeresponse, relayed in real time for the OfficeHome application. Your password, MFA code and conditional access checks "all succeed while the attacker captures the resulting session cookies."
TA419 added its own script, /secondary/observe.js, which gives the operators "a live view of each session," auto accepts "Keep me signed in" and submits one time codes the moment they validate. An authenticator code cannot help: you type it into Microsoft, and Microsoft issues the session the attacker keeps.
Is TA419 Behind the Antino Backdoor?
No: Antino belongs to a different cluster, and none of the three primary reports links the two. The Record covered both in one October 1 story, but Proofpoint's post never mentions Antino, and Cisco Talos' September 30 report never mentions TA419.
Talos calls the Antino operators UAT-11587, assesses "with high confidence" that they are China nexus, and between September 2025 and July 2026 found "at least 10 confirmed and five probable affected institutional environments, plus one additional intended target," and "approximately 350 compromised endpoints across eight countries": Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria.
Talos found overlaps with Symantec's Jewelbug research, published August 13, which names Antino as that group's Windows backdoor. Unable to verify Symantec's link between that espionage and Jewelbug's cryptocurrency fraud, Talos tracks UAT-11587 separately. We covered Symantec's findings in our Jewelbug webmail report.
UAT-11587's email tradecraft matters for policy researchers too. Talos first spotted it in a March 2026 spear phishing run against "Taiwan's academic, think tank, and civil society policy community." The message rebuilt Gmail's attachment card in the email body, "visually indistinguishable from a legitimate Gmail attachment preview," linked to a Cloudflare Pages URL carrying a per recipient identifier. Clicking starts a five stage chain ending with a Microsoft signed GatherOsState.exe sideloading Antino, a Rust backdoor that takes orders through the attackers' own Outlook mailbox and OneDrive.
What This Means for Your Inbox
Both campaigns began with one email a busy expert would answer or open. TA419's first message carries nothing for a mail filter to score, so your reply is what selects you for the phishing link.
The same shape surfaced three times in three days. On September 29, Microsoft described Russia's Star Blizzard sending closed door event invitations under IISS and Chatham House branding and waiting for a reply before sending malware. On September 30, Talos published a UAT-11587 decoy titled "CSIS Indo-Pacific Forecast 2026 (Event Details)." On October 1 came TA419's advisory committee invitations. Two countries, three groups, one approach: professional business in the name of a real institution or person, which a filter tuned to malicious attachments never sees.
A familiar sender name proves little: the Talos sample reached the inbox despite failing DMARC, because the impersonated organization's domain published a p=none policy, which asks receivers to monitor rather than reject. Reporters are direct targets as well, as the fake Google alerts sent to journalists we covered in July showed.
How Do You Verify an Invitation From a Named Expert?
Contact the person through a channel you found yourself before you reply to the email. Proofpoint advises targets to "treat unsolicited subject-matter outreach as a plausible pretext stage" and to verify it "via another independent medium."
- Read the domain after the @. All three July senders used mail.com or outlook.com. A former White House official recruiting for a Senate report from free webmail is your signal to stop.
- Verify out of band. Use the person's institutional page, a staff directory or a number you already had, never contact details from the email. If you accept, write fresh to the verified address instead of hitting reply.
- Never sign in from a shared document link. If a shortened link opens a OneDrive folder that wants a login, close it and type the OneDrive address yourself.
- Hover before you click "attachments." A card inside the message text that points to a
pages.devaddress is a link, not a file. - Move to passkeys. Proofpoint recommends "phishing-resistant, origin-bound authentication such as passkeys," which a lookalike domain cannot use. TA419's July kit targeted Microsoft 365, so ask your IT team to enforce passkeys there. For Google accounts, Google's Advanced Protection Program requires a passkey or security key to sign in.
- Report it, and if you signed in, end the session. Forward the message to your security team. A new password alone does not cover it: Microsoft's emergency revocation guide has admins block sign in and select Revoke sessions so the account cannot obtain new tokens. Civil society groups without a security team can contact Access Now's Digital Security Helpline.
Indicators and Detections for Security Teams
Highlights from both reports' indicator tables:
- TA419 (Proofpoint): OfficeHome client ID
4765445b-32c6-49b0-83e6-1d93765276casign ins that follow a click to a file sharing themed domain, typically registered through NameSilo and fronted by Cloudflare; July domainsdriftshare[.]coandglobalfileshareplatform[.]com; sending VPS108.61.163[.]187, exposed in first hopReceivedheaders; self signedO=Castro Inccertificate SHA256b314a1499cd728ca3e54b7150661fd0c7d2279065fe3f570f0f66c395d744460. - UAT-11587 (Talos): envelope sender domain
osc-cdn[.]comsent through Migadu;GatherOsState.exeloadingslc.dllfrom a writable folder; Outlook subjects beginningcommand_req_andcommand_res_; OneDrive paths under/antino/heartbeats/; TestAssembly GUIDb2b3adb0-1669-4b94-86cb-6dd682ddbea3; Snort SIDs 66880, 66881 and 66882. - Your own domain: a DMARC
p=nonepolicy lets receivers deliver mail that fails alignment, as happened with the Talos sample.
Looking Ahead
Proofpoint expects that TA419 "will likely continue targeting think tanks and policy experts working on technologies, and in geographies, of particular interest to the Chinese government," and that its campaigns "will likely also continue spoofing the identities of real subject-matter experts." Its indicator table lists redirect domains first seen in six separate months from December 2025 to July 2026, so these exact domains will not last.
The pattern is the durable part: a real name, a flattering ask, no link until you answer. If you work on AI policy, your best invitations this year deserve the same check as the suspicious ones.