TA419TA419

Also known as: TA419

Known aliases
1

Profile

According to Proofpoint, TA419 is a China-aligned, espionage-motivated threat actor conducting regular targeted credential phishing campaigns against individuals at US- and Japan-based think tanks, defense contractors, universities and law firms since at least April 2025. In 2026 it impersonated real subject-matter experts, including a former White House OSTP official and a senior Anthropic employee, to target AI policy experts. Benign rapport-building emails are followed by multi-stage URL redirection to an adversary-in-the-middle phishing page against Microsoft 365 / Entra ID, built on a customised Frameless BitB kit embedding an Evilginx phishlet. Proofpoint states the group's activity had not been previously reported publicly.

Aliases· 1

TA419
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.