负责起草出口管制判决的邮箱比一堆模型重量更安静的奖品,这就是一个与中国结盟的船员所追求的邮箱。 从2026年7月8日开始 后来报告的证据, a group it tracks as TA419 opened credential phishing by borrowing Lynne Edwards Parker, described there as the former principal deputy director of the White House Office of Science and Technology Policy. The same run then borrowed Heidi Crebo-Rediker, an economist whose career runs through the State Department and the Senate Foreign Relations Committee. The notes did not ask for source code. They asked policy people to join a conversation.
Proofpoint calls TA419 espionage-motivated and China-aligned, and says the 1 October 2026 writeup was the first public reporting on the group. It has watched TA419 phish people at United States and Japanese think tanks, defense contractors, universities, and law firms since at least April 2025. 路透社当天报道 that the July wave reached fewer than 10 people, including specialists on AI regulation, export controls, and national strategy. The China label is Proofpoint’s assessment from infrastructure and targeting. Reuters noted that the Chinese Embassy did not comment and that Beijing denies cyberespionage. It is not a court finding.
借来的传记为何要和问的相符
The July messages were written to sound like a favor between colleagues. One version invited the recipient onto a fictitious “AI Policy Advisory Committee.” Another asked for help with a Senate Committee on Foreign Relations report on AI export controls and supply chains. 帮助网安全 转发了Mark Kelly的账号 打开的邮件没有恶意链接 诱饵是回答 直到有人回信后,一个缩短的网络地址才到来,承诺提供更多材料并走过转机进入假云登录.
Crebo-Rediker’s record is why the second name fit. She was the State Department’s first chief economist in the Obama years, had been chief of international finance for the Senate Foreign Relations Committee, and is a senior fellow at the Council on Foreign Relations. A request to help with a Senate paper on export controls is a note that career would generate. Parker’s name did the parallel job for an advisory committee. She is a roboticist, founding director of the National Artificial Intelligence Initiative Office, and, in Proofpoint’s wording, a former principal deputy director of the science office.
The Trump administration had already advertised the persona. On 22 December 2024, Donald J. Trump named Parker executive director of the President’s Council of Advisors on Science and Technology and counselor to the director of the Office of Science and Technology Policy. Michael Kratsios was to run that office, and David Sacks, whom Trump called an “AI and Crypto Czar,” was to chair the council. The announcement, 政治处 和 科学说明, promised a “Golden Age of American Innovation” and “America’s technological dominance,” stapling a science panel to a cryptocurrency pitch. That branding handed a later impostor a committee title that already sounded official. The people drafting export-control language were still working in ordinary Microsoft 365 mail. The White House sold the names and left the inboxes easy to phish.

Heidi crebo-rediker的国务院和参议院的对外关系背景与AI出口管制报告的诱惑相吻合。
Reuters identified one recipient as Alex Engler, a former White House official who now heads the University of Pennsylvania’s Center on Media, Technology, and Democracy. Engler said the message, which invited him “to join a new AI policy project,” “felt slightly, nebulously off.” He realized it was an impostor after checking with other people. Parker told Reuters he was one of two people she knew of who had received mail purporting to come from her in early July. She also said, “The United States and China are in a competition around AI. Trying to get people in the AI policy space to reveal information about their AI policy plans — if that indeed was what the objective was — it’s not surprising.”
一个小清单是重点,不是安慰. 犯罪工具箱喷出数以万计的收件箱,仍作为企业运作. 2025年12月(农历正月). AEGIS联盟报告了与RaccoonO365有关的逮捕事件。,用于在卷中窃取微软365会话的服务。 TA419针对的是同一级别的盗窃行为,瞄准一个与一张桌子相匹配的房间. 目标不是一个模型文件。 出口规则仍在被措辞。
假的 OneDrive 页面取自微软 365 登录内容
Proofpoint’s account, written for defenders and not as a build guide, describes two stages. The first July domain, driftshare[.]co, showed a fake OneDrive screen behind a Cloudflare Turnstile check. A second domain, globalfileshareplatform[.]com, hosted the adversary-in-the-middle page, using a customized browser-in-the-browser kit known as Frameless BitB and an Evilginx phishlet for Microsoft 365. The page relayed the real Microsoft sign-in, including the one-time code, so the password and the second factor were typed where an operator could watch.
Scripts on the page drew a file listing and a fake browser window, accepted “Keep me signed in” without the user, and submitted a one-time code after it checked out. The login still succeeded at Microsoft. What the operator kept was the password, the multi-factor code, and the session cookies that mark a Microsoft 365 user as already signed in. 微软已经描述 多年来的这种模式。 复制的 cookie 表示第二个因子不再被询问 。

Proofpoint描述了一款假冒浏览器,该浏览器在OneDrive风格的股份上分层,转发了真正的微软登录.

Evilginx开发商Kuba Gretzky的2026年7月16日谈话覆盖了证书递补套件,并试图削弱防钓标志. 这不是关于TA419的通报。 它显示同一家族的工具 Proofpoint说这个船员定制。
Domains sat behind Cloudflare and were often registered through NameSilo as file-share brands such as quickfly[.]online, cirrushare[.]co, and winsync[.]cloud. Others impersonated institutions, including tw-koryu[.]org, the misspellings heritiages[.]org and heritiage[.]org, and shinjirou[.]info. Some 2026 messages used a self-signed certificate that named a fictitious Kansas town, Millsstad, and a firm called Castro Inc. Others went out through residential proxies.
2月 克劳德军事整编的诱惑
July was not the first AI impersonation from this group. In February 2026 TA419 posed as a senior Anthropic employee and wrote an AI policy analyst at a United States think tank. The subject line was “Request for Feedback on Military Integration of Claude,” aimed at the fight over military use of Anthropic’s models. The shape matches the summer mail: a believable name, a live dispute, and no login page until someone replies.
校对:Soup 先前关于SugarGh0st工具的报告 used against organizations that build generative AI. That work chased the labs. TA419’s 2026 mail chased the people who write the rules those labs live under, and Proofpoint also notes China-aligned interest in the semiconductor and rare-earth supply chains under the same models.
一个可疑的感觉不会保护下一个收件箱
Engler noticed something slightly off, then checked with other people. That worked once, for someone who already knew Parker’s world. It does not travel to a junior analyst flattered by a committee that sounds official. The first email was clean on purpose, so many gateways had nothing to detonate, and the malicious step waited until a real-looking conversation had started.
Selena Larson of Proofpoint, speaking on 22 September 2026 with SiliconANGLE’s theCUBE, discussed how generative tools change the look of social-engineering mail. That segment is not about TA419. It is the wider problem around this incident. A note can be grammatical, specific, and still be a lure, so broken spelling is a weak defense for a policy shop.

The 1 October writeup is direct. “TA419 has consistently shown an interest in defense, national security, energy, international relations, and foreign policy targets, predominantly with a nexus to the US and Japan,” it says. “The targeting of AI policy experts represents an extension of that remit rather than a departure from it.” Proofpoint assesses that TA419 “will likely continue targeting think tanks and policy experts working on technologies, and in geographies, of particular interest to the Chinese government,” and that “these campaigns will likely also continue spoofing the identities of real subject-matter experts.”
密码是符合这个phish的控件
A one-time code did not stop the July pages. The code was typed into a relay of Microsoft’s own prompt, and the resulting session stayed with the operator. Proofpoint tells organizations in this target set to use phishing-resistant, origin-bound sign-in such as passkeys, which are bound to the real site and do not hand a password-and-code pair to a lookalike. It also tells individuals to treat a surprise note from a famous specialist as a pretext and to check it on a channel the sender did not pick.
A passkey will not rescue a thread already copied. What it changes is the next reply. The papers worth taking here lived in ordinary cloud mail, not a classified enclave, written by people who draft AI export-control language. 黑客新闻 和 国际新闻. coverage has followed the high-volume version of the same theft, including a March 2026 Microsoft warning about impostor mail. TA419 is the boutique version: fewer than 10 inboxes, chosen for what those people were about to write. Crebo-Rediker’s biography is on the Council on Foreign Relations site, and more of this lane is filed under 新闻 在赞助联盟。









