hacker-news · Crawled Oct 4, 2026

China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing

Read original article ↗

AI Summary

China-aligned threat actor TA419 has conducted credential phishing campaigns targeting U.S. AI policy experts at think tanks, universities, and legal organizations since at least April 2025. The attacks involve impersonation of trusted individuals and use a multi-stage phishing flow featuring shortened URLs that redirect to a malicious OneDrive-based adversary-in-the-middle (AitM) page. This page employs a 'Frameless BitB' technique—using HTML, CSS, and JavaScript without iframes—to spoof Microsoft login pages and stealthily capture session cookies while relaying authentication to legitimate Microsoft infrastructure, making detection difficult.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.