IPS Signature
Oct 04, 2026
Severity: HIGH · Priority: P2 — China-nexus espionage targeting AI policy professionals, investigate on hit
These rules detect connections to infrastructure used by TA419, a China-aligned espionage group, in a sustained credential-phishing campaign against artificial intelligence policy experts at US think tanks, universities, and law firms. The campaign is assessed with high confidence to support Chinese intelligence objectives around understanding US AI policy, export controls, and national AI strategy — a strategic collection priority in the context of intense US-China competition over AI development and governance.
TA419's technique is unusually patient and convincing. Rather than opening with a malicious link, the actor sends an initial benign email that appears to come from a respected AI policy figure — in the July 2026 wave, the impersonated identities included a former director of the White House Office of Science and Technology Policy and a prominent foreign-policy economist; in February 2026, a named Anthropic employee. The initial message invites the target to join a fictitious AI Policy Advisory Committee, contribute to a Senate AI export-control report, or give input on AI supply chains — topics a genuine AI policy expert would reasonably discuss. Only after the target replies does TA419 send a follow-up with a shortened URL that triggers the multi-stage redirect chain. This reply-triggered design ensures the group invests only against confirmed interested targets, and the initial rapport-building makes the victim less suspicious of the follow-on link.
The infection chain separates across two domain tiers. The first-stage domains display a convincing fake OneDrive file-loading screen and run a Cloudflare Turnstile human-verification check before silently forwarding the victim's browser to the second-stage phishing domain. The second-stage domains present a fake OneDrive folder containing lure documents and host the adversary-in-the-middle (AitM) phishing kit — a combination of standard credential capture and a Browser-in-the-Browser component — to harvest both Microsoft 365 credentials and live session cookies, allowing the attacker to access the victim's Microsoft cloud account without needing to know the password or bypass multi-factor authentication separately.
A hit on any of these rules indicates a device on your network has contacted TA419 infrastructure. Given the highly targeted nature of this campaign, a hit strongly suggests the affected user is a research, policy, or legal professional working on AI-related topics, and should be investigated accordingly. If the connection reached a second-stage domain, treat Microsoft 365 credentials and active sessions as compromised: immediately revoke all active Microsoft sessions and reset passwords for the affected account from a known-clean device, paying particular attention to Microsoft Teams, SharePoint, and OneDrive contents which may have been accessed by the attacker after credential capture. Also audit Microsoft Entra ID sign-in logs and OAuth application grants for unexpected access. Review the user's recent email for the benign-looking first contact from an apparent AI policy figure — that conversation thread is evidence the user has been under active targeting.
Read the full update