TA419

MISP
Tipo:
Unknown
Paese:
Unknown
Prima attivita:
Unknown
Dettagli:

According to Proofpoint, TA419 is a China-aligned, espionage-motivated threat actor conducting regular targeted credential phishing campaigns against individuals at US- and Japan-based think tanks, defense contractors, universities and law firms since at least April 2025. In 2026 it impersonated real subject-matter experts, including a former White House OSTP official and a senior Anthropic employee, to target AI policy experts. Benign rapport-building emails are followed by multi-stage URL redirection to an adversary-in-the-middle phishing page against Microsoft 365 / Entra ID, built on a customised Frameless BitB kit embedding an Evilginx phishlet. Proofpoint states the group's activity had not been previously reported publicly.

Metadata
ID: 1131
Created: 05/10/2026 16:00
Updated: 05/10/2026 16:00