Skip to content

Proofpoint: TA419 phishes US AI policy circles via BitB OneDrive

Proofpoint ties China-aligned TA419 to credential phishing against US AI policy experts, using Frameless BitB to spoof Microsoft OneDrive logins and steal MFA-backed sessions.

Published 3 min read

Proofpoint has detailed a credential-phishing campaign it attributes to TA419, a group it describes as China-aligned and espionage-motivated, targeting US AI policy experts at think tanks, universities, and legal-sector organizations. The operators impersonated real policy figures to open a conversation, then steered replies to a fake Microsoft OneDrive login built with a browser-in-the-browser kit that captured passwords, MFA codes, and live session cookies.

Attribution — as Proofpoint frames it

Proofpoint assesses the activity "likely supports wider Chinese intelligence objectives" around US AI policy. Keep that hedge: this is a vendor's confidence assessment of a tracked cluster, not an indictment, sanction, or court filing. No official attribution has been published.

The social-engineering chain

The lures leaned on credibility, not urgency. In July 2026 campaigns, TA419 wrote as Lynne Edwards Parker, former principal deputy director of the White House Office of Science and Technology Policy, and as Heidi Crebo-Rediker, an economist and foreign-policy expert, inviting targets onto a fictitious AI policy advisory committee or to contribute to a purported Senate Foreign Relations report on AI export controls. Earlier, in February 2026, the group impersonated an unnamed senior Anthropic employee; one email subject line Proofpoint quotes read "Request for Feedback on Military Integration of Claude."

The first message carried no link and no credential request — a benign rapport-builder designed to draw a reply. Only after a target responded did TA419 send a shortened URL. That link routed through an actor-controlled domain behind a Cloudflare Turnstile check and a fake OneDrive loading screen, then handed off to a second domain running the credential-capture page.

The BitB capture

Proofpoint identifies the phishing kit as Frameless BitB — a browser-in-the-browser technique that paints a convincing Microsoft sign-in window inside the page, with no real browser chrome for a careful user to inspect. Injected scripts intercepted document clicks, auto-accepted the "Keep me signed in" prompt, and auto-submitted one-time codes, relaying password, MFA code, and conditional-access checks against Microsoft's OfficeHome application (Microsoft 365 / Entra ID). The victim lands on a real resource and never sees that the session was proxied.

Indicators of compromise

Published by Proofpoint (verbatim):

# Sender addresses
leparker@mail[.]com
hcrediker@mail[.]com
hcrediker@outlook[.]com

# Phishing domains
driftshare[.]co
globalfileshareplatform[.]com
quickfly[.]online
smartsyncbox[.]com
cirrushare[.]co
mypublicshare[.]com
goshshare[.]online
synchvault[.]co
cloudsyncpulse[.]com
onecloudfilesync[.]com
msfile[.]online
winsync[.]cloud
publicsharefile[.]cloud
fileswiftonline[.]cloud
sharehub[.]space

# Spoofed organization domains
tw-koryu[.]org
heritiages[.]org
heritiage[.]org
shinjirou[.]info

# TLS certificate SHA-256
b314a1499cd728ca3e54b7150661fd0c7d2279065fe3f570f0f66c395d744460

Action checklist

  1. Block and hunt the IOCs above in mail gateways, proxy/DNS logs, and Entra ID sign-in logs. The sender addresses and phishing domains are the cheapest early catch.
  2. Move the targeted roles to phishing-resistant auth. Passkeys / FIDO2 defeat this chain; TOTP and push MFA do not, because BitB relays the code and the session cookie in real time.
  3. Review conditional access and session policies for AI-policy and research staff: shorter session lifetimes, token-protection / bound sessions, and alerting on new-device sign-ins blunt a stolen cookie.
  4. Brief high-value targets on the rapport pattern — a credible first email with no link, followed by a "shared document." The absence of a link in the opener is the tell, not a reassurance.

Context

This is the second China-nexus operation we've covered this week to treat trusted Microsoft cloud surfaces as the soft spot rather than the perimeter — UAT-11587's Antino backdoor used Outlook and OneDrive as C2 dead drops. TA419's twist is the front door: a frameless OneDrive clone that turns MFA into theater by relaying it. For the targeted sectors, the durable defense is phishing-resistant credentials, not a domain blocklist the actor rebuilds overnight — the IOC list above is already disposable infrastructure.

Related stories