SYMBOLCOMMON_NAMEaka. SYNONYMS

TA419  (Back to overview)


According to Proofpoint, TA419 is a China-aligned, espionage-motivated threat actor conducting regular targeted credential phishing campaigns against individuals at US- and Japan-based think tanks, defense contractors, universities and law firms since at least April 2025. In 2026 it impersonated real subject-matter experts, including a former White House OSTP official and a senior Anthropic employee, to target AI policy experts. Benign rapport-building emails are followed by multi-stage URL redirection to an adversary-in-the-middle phishing page against Microsoft 365 / Entra ID, built on a customised Frameless BitB kit embedding an Evilginx phishlet. Proofpoint states the group's activity had not been previously reported publicly.


Associated Families

There are currently no families associated with this actor.


References
2026-10-01 ⋅ Proofpoint ⋅ Mark Kelly, Proofpoint Threat Research Team
Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles
Evilginx TA419

Credits: MISP Project