China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
- ID
- 31577
- Status
- summarized
- Published
- 04 Oct 2026, 3:20 PM
- Fetched
- 04 Oct 2026, 4:53 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/10/china-aligned-ta419-targets-us-ai.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.5
- Created
- 04 Oct 2026, 4:54 PM
- Tags
- Audience
- developerssaas_founders
What happened
Proofpoint attributes a credential-phishing campaign to TA419, a China-aligned espionage group that has targeted U.S.- and Japan-based think tanks, defense contractors, universities, and law firms since at least April 2025. In February 2026 an AI policy expert at a U.S. think tank received a phishing email with the subject line 'Request for Feedback on Military Integration of Claude,' after the actor impersonated prominent economists, AI policymakers, and a prominent Anthropic employee; around July 2026 it also impersonated a former member of the White House Office of Science and Technology Policy leadership team. The chain starts with a benign-seeming invitation, then on reply sends a shortened URL through a multi-stage redirect and a Cloudflare Turnstile check to a fake OneDrive adversary-in-the-middle login page built with 'Frameless BitB,' a browser-in-the-browser variant that spoofs a login window without an iframe using injected HTML, CSS, and JavaScript.
Why it matters
This is not a spray-and-pray phish: the campaign defeats MFA by proxying a real Microsoft/OneDrive login (AitM), and the Cloudflare Turnstile gate plus Frameless BitB make the fake page hard to flag with URL-reputation checks alone. If your product lets users sign in with Microsoft/Entra ID or click OneDrive share links, assume an MFA prompt can be relayed by an attacker — phishing-resistant factors (passkey/FIDO2), conditional access, and token-binding are the only controls that hold. Malaysian builders are not the described targets here (the article names U.S. think tanks, universities, law firms, and a U.S. AI policy expert), so treat this as a technique warning for your own auth stack, not a threat aimed at you.
Discussion angle
Walk through why AitM plus a Turnstile-gated redirect chain survives MFA, and ask who in the group has actually enforced phishing-resistant auth (passkeys/FIDO2) on their Microsoft or Google SSO — that's the only control that reliably breaks this chain.