TA419 is a China-aligned, espionage-motivated threat actor tracked since at least April 2025. It conducts targeted credential-phishing operations against personnel at think tanks, defense contractors, universities, and law firms in the United States and Japan. Its intelligence interests include defense, national security, energy, international relations, foreign policy, and artificial-intelligence policy and regulation. Its targeting aligns with Chinese intelligence interests, although direct Chinese government control has not been established. TA419 uses tailored, conversation-based social engineering, impersonating trusted officials, economists, policymakers, and technology-company personnel. It initially sends apparently benign professional outreach and delivers phishing links only after recipients respond. In February 2026, it impersonated a senior Anthropic employee to approach a U.S. think-tank AI-policy analyst. July 2026 campaigns impersonated former White House science-policy official Lynne Parker and economist Heidi Crebo-Rediker, using fictitious advisory invitations and requests for contributions concerning AI export controls and supply chains. Its phishing chain uses shortened links, multiple redirects, Cloudflare Turnstile checks, and counterfeit Microsoft OneDrive document-sharing interfaces. TA419 combines adversary-in-the-middle authentication proxying with a customized Frameless BitB browser-in-the-browser toolkit to target Microsoft 365 and Entra ID accounts. Bespoke telemetry and automation monitor authentication progress, handle one-time codes, and accept prompts that extend session lifetime. The infrastructure relays legitimate password, multifactor-authentication, and conditional-access interactions while capturing credentials and authenticated session cookies for account access. TA419 also uses Cloudflare infrastructure and residential proxies to obscure its backend infrastructure and message origins. Successful account compromises or subsequent data theft have not been publicly established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
21 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-linked cyber-espionage group targeting Microsoft accounts belonging to policy and regulatory specialists, increasingly including U.S. AI policy experts. Its campaigns use tailored professional correspondence and impersonation to establish trust before delivering adversary-in-the-middle phishing links that capture credentials and authentication tokens. The reported activity supports Chinese intelligence interests in U.S. AI policy, regulation and export controls.
TA419 conducted credential-phishing campaigns against US AI policy experts in July 2026, impersonating prominent economists and AI policymakers. In February 2026, it also impersonated a senior Anthropic employee to target an AI policy expert at a US think tank. The report assesses that this activity likely supports Chinese intelligence monitoring of US AI policy and regulatory developments. China alignment is stated, but state sponsorship and the attackers' country of origin are not explicitly established.
TA419 conducts cyberespionage through targeted credential phishing. Its 2026 campaigns targeted U.S. AI policy experts, impersonating economists, policymakers, and an Anthropic employee. The actor establishes trust through initially harmless outreach before delivering links to adversary-in-the-middle phishing pages that capture Microsoft credentials and session cookies. Proofpoint assesses that this activity likely supports Chinese intelligence objectives concerning U.S. AI policy and regulation.
China-aligned espionage actor conducting targeted credential-phishing campaigns against AI-policy experts and, since at least April 2025, individuals at US- and Japan-based think tanks, defense contractors, universities, and law firms. The activity appears intended to collect intelligence concerning AI policy, regulation, export controls, critical technologies, defense, and foreign policy.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.