<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>TA419 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/actors/ta419/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 10:33:30 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/actors/ta419/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>TA419 China-Aligned Credential Phishing Against US AI Policy Experts</title><link>https://feed.craftedsignal.io/briefs/2026-10-ta419-phishing/</link><pubDate>Thu, 01 Oct 2026 10:33:30 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-ta419-phishing/</guid><description>China-aligned actor TA419 is conducting targeted, long-tail credential phishing campaigns against US and Japanese AI policy and national security experts using AitM techniques and a custom Frameless BitB toolkit to capture MFA-protected Microsoft 365 sessions.</description><content:encoded><![CDATA[<p>TA419 is an espionage-motivated threat actor that has been targeting individuals in the defense, energy, and AI policy sectors since at least April 2025. In July 2026, the group launched targeted campaigns against US think tanks and academic experts, impersonating former government officials and subject matter experts. The threat actor employs a low-and-slow approach, beginning with benign social engineering to build rapport before introducing malicious links. Their infrastructure leverages Cloudflare for traffic obfuscation and NameSilo for domain registration. The actor has been observed using actor-controlled VPS infrastructure, identified by a common self-signed TLS certificate (O=Castro Inc), to send phishing emails. This campaign aligns with broader Chinese intelligence objectives concerning AI regulation, supply chain security, and export controls.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>TA419 sends a benign &quot;conversation starter&quot; email posing as a subject matter expert, inviting the target to join a fictitious advisory committee or contribute to a policy report.</li>
<li>Upon receiving a response, the attacker sends a shortened URL link that leads to a first-stage redirect domain (e.g., driftshare[.]co).</li>
<li>The first-stage domain performs a Cloudflare Turnstile verification hidden behind a fake OneDrive loading screen to filter automated security scanners.</li>
<li>The target is redirected to a second-stage, actor-controlled domain (e.g., globalfileshareplatform[.]com) hosting an Adversary-in-the-Middle (AitM) phishing page.</li>
<li>The AitM proxy relays the legitimate Microsoft /common/oauth2/v2.0/authorize request to Microsoft 365 servers in real time.</li>
<li>The proxy injects malicious scripts (/secondary/script.js and /secondary/observe.js) into the proxied page to facilitate the Frameless BitB overlay and capture telemetry.</li>
<li>The target completes the legitimate authentication process, including MFA, while the Frameless BitB toolkit captures the session token and auto-submits one-time codes.</li>
<li>The attacker uses the stolen session cookies for persistent access to the victim's cloud account.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The campaign targets sensitive US AI policy development, including reports on supply chains and export controls. Successful compromise allows TA419 to gain persistent, unauthorized access to cloud-based email and documents, potentially leading to the theft of internal strategy documents, communications with policy experts, and pre-publication research.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Enforce phishing-resistant, origin-bound authentication such as FIDO2/WebAuthn-based security keys (passkeys) for all Microsoft 365 and Entra ID accounts to render AitM session harvesting ineffective.</li>
<li>Review and audit Entra ID sign-in logs for anomalous user-agent strings or impossible travel patterns associated with successful logins that bypassed standard MFA.</li>
<li>Configure email gateways to flag or quarantine emails with links that redirect through known low-reputation domain registrars or temporary file-sharing domains.</li>
<li>Train high-value policy experts to verify the identity of unknown subject-matter outreach through independent, out-of-band communication channels.</li>
<li>Monitor egress traffic for connections to the identified redirect and phishing infrastructure listed in the IOC table.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>phishing</category><category>aitm</category><category>espionage</category><category>credential-theft</category></item></channel></rss>