China-Aligned TA419 Phishing US AI Policy Experts
Score: 8/10

China-Aligned TA419 Phishing US AI Policy Experts

China-aligned threat actor TA419 is conducting credential phishing campaigns against U.S. AI policy experts using Adversary-in-the-Middle (AitM) techniques and a customized Frameless BitB kit.

Executive Summary

Since at least April 2025, a China-aligned espionage group designated as TA419 has targeted individuals at U.S. and Japanese think tanks, universities, and law firms. Throughout 2026, the actor shifted focus toward AI policy experts, impersonating high-profile figures from the White House Office of Science and Technology Policy and AI safety organizations like Anthropic.

The attack chain involves social engineering via "benign" outreach regarding AI regulation, followed by multi-stage URL redirections. Victims are led to an Adversary-in-the-Middle (AitM) phishing page that utilizes "Frameless BitB," a sophisticated Browser-in-the-Browser technique that lacks traditional iframe markers. This kit captures credentials and MFA session cookies in real-time by relaying the authentication flow to legitimate Microsoft infrastructure.

This activity represents a strategic effort by Chinese intelligence to gain insights into U.S. AI policy, regulatory developments, and military integration of AI models. The technical sophistication of the AitM kit allows the actor to bypass standard multi-factor authentication, posing a significant risk to high-value targets in the AI research and policy space.

Key Details

Threat Name

TA419

Affects

—

Adversary

TA419 Other Adversaries and Aliases: UNK_SweetSpecter

Malware/Tools

Frameless BitB, Evilginx, SugarGh0st

Report Score

8out of 10
Quality Score
Good
IOC Quality8
TTP Details9
Detection Guidance6
Enterprise Relevance9
Clarity & Structure9
Technical Depth8

Sources