OffPerimeter · Threat advisories
Campaign advisory
lowPublished 2026-10-04 · 0 indicators

TA419 targets AI policy experts via OneDrive adversary-in-the-middle phishing

TA419 is a China-aligned espionage group targeting AI policy experts within the United States. The group employs impersonation of high-profile individuals to conduct phishing attacks against sectors including government, education, legal, and technology. By directing targets to fraudulent OneDrive pages, the actors utilize adversary-in-the-middle (AitM) proxies to capture session cookies and bypass multi-factor authentication.

ShareXLinkedInWhatsApp
First seen
2026-02-01
Last seen
2026-10-02
Threat actors
TA419
Malware
—
Sectors
Government, Education, Legal, Technology
Countries
United States

How it works

The attack begins with phishing emails where the actor impersonates high-profile individuals, such as former White House officials or employees, to engage targets. Once a target responds to the outreach, they are directed to a fraudulent OneDrive page. This page utilizes an adversary-in-the-middle (AitM) proxy to intercept the Microsoft 365 sign-in process, allowing the actor to capture session cookies and bypass multi-factor authentication.

Techniques (MITRE ATT&CK)

What to do

References

ShareXLinkedInWhatsApp