| SYMBOL | COMMON_NAME | aka. SYNONYMS |
According to Proofpoint, TA419 is a China-aligned, espionage-motivated threat actor conducting regular targeted credential phishing campaigns against individuals at US- and Japan-based think tanks, defense contractors, universities and law firms since at least April 2025. In 2026 it impersonated real subject-matter experts, including a former White House OSTP official and a senior Anthropic employee, to target AI policy experts. Benign rapport-building emails are followed by multi-stage URL redirection to an adversary-in-the-middle phishing page against Microsoft 365 / Entra ID, built on a customised Frameless BitB kit embedding an Evilginx phishlet. Proofpoint states the group's activity had not been previously reported publicly.
There are currently no families associated with this actor.
| 2026-10-01
⋅
Proofpoint
⋅
Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles Evilginx TA419 |