Proofpoint TA419 (1 Oct): China-aligned phishing spoofs Anthropic staff & US AI policymakers — AitM Microsoft 365
Proofpoint Threat Research (1 October 2026) publicly debuts TA419, a China-aligned espionage actor running credential phishing against US and Japan think tanks, defence contractors, universities and law firms since at least April 2025. July 2026 wave (from 8 Jul) impersonated Lynne Edwards Parker (former White House OSTP Principal Deputy Director) and economist Heidi Crebo-Rediker with benign “AI Policy Advisory Committee” / Senate Foreign Relations AI export-control report lures, then shortened links into Cloudflare Turnstile → Frameless BitB AitM against Microsoft 365 / Entra ID (OfficeHome client_id) capturing password, MFA and session cookies. February 2026: same actor impersonated a senior Anthropic employee (“Request for Feedback on Military Integration of Claude”) against a US think-tank AI policy analyst. Domains include driftshare[.]co → globalfileshareplatform[.]com (July) plus file-share themed infra; NameSilo + Cloudflare CDN; VPS TLS fingerprint O=Castro Inc. Assessed collection on US AI policy/regulatory landscape amid US–China competition. No product CVE. Primary: Proofpoint; wires: CyberScoop / Infosecurity / Nextgov 1 Oct. UPDATE (Reuters via iTnews, 2 Oct): Proofpoint says the July targeting involved fewer than 10 people at a handful of organisations, suggesting intelligence interest in US policymaking rather than technology theft alone; Reuters identified one recipient, former White House official Alex Engler, who received a fake invitation from “Parker” to join an AI policy project, and Parker said she knew of two such messages sent in her name in early July.
- Product
- Microsoft 365 / Entra ID accounts (AitM BitB phishing); TA419 China-aligned espionage
- Versions
- n/a (credential phishing TTPs; no product CVE). Sample IoCs: driftshare[.]co, globalfileshareplatform[.]com, leparker@mail[.]com, hcrediker@mail[.]com / @outlook[.]com; TLS SHA-256 b314a1499cd728ca3e54b7150661fd0c7d2279065fe3f570f0f66c395d744460 (O=Castro Inc)
- Exploited in Australia?
- unknown
- Patch to
- Prefer phishing-resistant / origin-bound auth (passkeys). Verify unsolicited AI-policy outreach out-of-band. Hunt Microsoft 365 sign-ins via unexpected file-share redirect domains; review Proofpoint IoCs (driftshare[.]co, globalfileshareplatform[.]com and related). Conditional Access + continuous access evaluation; revoke sessions on suspicious AitM.
Primary: Proofpoint — Hallucinating Credibility: TA419 US AI policy phishing (1 Oct 2026) · Vendor: Proofpoint Threat Research (primary) · CyberScoop — TA419 AI policy phishing (1 Oct 2026)
