TA419 targets AI policy experts via OneDrive adversary-in-the-middle phishing
TA419 is a China-aligned espionage group targeting AI policy experts within the United States. The group employs impersonation of high-profile individuals to conduct phishing attacks against sectors including government, education, legal, and technology. By directing targets to fraudulent OneDrive pages, the actors utilize adversary-in-the-middle (AitM) proxies to capture session cookies and bypass multi-factor authentication.
- First seen
- 2026-02-01
- Last seen
- 2026-10-02
- Threat actors
- TA419
- Malware
- —
- Sectors
- Government, Education, Legal, Technology
- Countries
- United States
How it works
The attack begins with phishing emails where the actor impersonates high-profile individuals, such as former White House officials or employees, to engage targets. Once a target responds to the outreach, they are directed to a fraudulent OneDrive page. This page utilizes an adversary-in-the-middle (AitM) proxy to intercept the Microsoft 365 sign-in process, allowing the actor to capture session cookies and bypass multi-factor authentication.
Techniques (MITRE ATT&CK)
- T1566 · initial_accessPhishingThe group impersonated former White House OSTP Principal Deputy Director Lynne Edwards Parker and economist Heidi Crebo-Rediker in July 2026 to phish AI policy experts.
- T1557 · credential_accessAdversary-in-the-MiddleTargets are sent to a fake OneDrive page that passes the Microsoft 365 sign-in through an adversary-in-the-middle (AitM) proxy, capturing session cookies even when MFA is used.
What to do
- Monitor for anomalous Microsoft 365 sign-in locations and session cookie usage.
- Review authentication logs for successful logins following suspicious external email interactions.
- Educate high-value targets, such as policy experts, legal, and government staff, on advanced phishing and impersonation tactics.