Yaamlabs
Identity

TA419 poses as AI policy figures to hijack M365 logins

Proofpoint says China-aligned TA419 impersonated AI policy figures to steal Microsoft 365 sessions. How the OfficeHome phishing works and how to check.

By Yaali. October 2, 2026, 6 min read, Identity, Phishing, Threat intel.

Cover illustration of a fake sign-in window nested inside a browser window, with the Yaamlabs logo and the text: TA419 fakes AI policy experts to hijack Microsoft 365, July 8, campaign start, sessions stolen live

On October 1, Proofpoint reported that TA419, a China-aligned espionage group, spent 2026 impersonating well-known names in US AI policy to phish the people who work on it. In July the group wrote as Lynne Parker, a former principal deputy director of the White House Office of Science and Technology Policy, and as economist Heidi Crebo-Rediker. In February it posed as a senior Anthropic employee. The targets were AI experts at US think tanks, universities and legal sector organizations.

The end goal was a working Microsoft 365 session. Victims who followed the link landed on a proxied Microsoft sign-in that captured their password, their one-time code and the session cookie that Microsoft issues afterwards. The kit submitted one-time codes on the victim's behalf, so code-based MFA did not stop it. If your staff work on policy, defense or foreign affairs and sign in to Microsoft 365 with a password and a code, this campaign is aimed at people like them.

Four stages of the TA419 campaign: a benign email from an impersonated AI policy figure, a shortened link after the target replies, a fake OneDrive page behind a Cloudflare Turnstile check, and a proxied Microsoft sign-in that captures the password, code and session cookie

How the lure works

The first email asked for nothing. Proofpoint describes the opening messages as benign conversation starters: an invitation to join a fictitious "AI Policy Advisory Committee", or a request to contribute to a purported Senate Foreign Relations Committee report on AI export controls and supply chains. The February message to a think tank AI policy analyst carried the subject line "Request for Feedback on Military Integration of Claude".

Only when a target replied did TA419 send a shortened link promising more detail. The emails came from attacker-controlled webmail addresses such as leparker@mail[.]com, hcrediker@mail[.]com and hcrediker@outlook[.]com. The group also registered lookalike domains for real organizations, including the Heritage Foundation, the Japan-Taiwan Exchange Association and the website of Japanese Defense Minister Shinjiro Koizumi.

How the session theft works

Adversary-in-the-middle (AiTM) phishing puts a proxy between the victim and the real login service. The victim talks to the real Microsoft sign-in through the attacker's server, so every page and every prompt is genuine, and the proxy copies what passes through it.

TA419 ran this in two stages. The first-stage domain, driftshare[.]co in the July campaign, showed a fake OneDrive loading screen and ran a Cloudflare Turnstile check, which filters out automated scanners before anything malicious is served. It then sent the visitor to the second-stage domain, globalfileshareplatform[.]com, which hosted the phishing flow.

That page was built on a customized version of Frameless BitB, an open-source browser-in-the-browser tool. It draws a fake browser window inside the web page, over what looks like a OneDrive file share, and uses Evilginx to proxy the Microsoft login inside it. The proxied chain targeted Microsoft 365 and Entra ID through Microsoft's own first-party OfficeHome application, client ID 4765445b-32c6-49b0-83e6-1d93765276ca.

TA419 added its own scripts on top. One tracked each victim's position in the login flow and gave the operators a live view of every session. It also accepted the "Keep me signed in" prompt automatically, to extend the stolen session, and submitted one-time codes as soon as they validated. The result was the password, the code and the session cookie, which lets the attacker use the account without signing in again.

What attackers are doing

Proofpoint has tracked TA419 since at least April 2025, running targeted credential phishing against think tanks, defense contractors, universities and law firms with a US or Japan nexus. Its interests are defense, national security, energy, international relations and foreign policy. The AI policy campaigns began on July 8, 2026, and the first-stage and second-stage domains it lists were registered between December 2025 and July 2026.

The report does not say how many people were targeted, how many accounts were compromised or what data was taken. CyberScoop notes that Proofpoint does not directly link the activity to the Chinese government. Proofpoint expects TA419 to keep targeting think tanks and policy experts on subjects of interest to Beijing, and to keep borrowing the identities of real experts.

What to do

Five steps for Microsoft 365 tenants: block the TA419 indicators, require phishing-resistant MFA through Conditional Access, hunt OfficeHome sign-ins, revoke sessions and reset passwords for anyone who entered credentials, and verify unsolicited outreach through another channel

  1. Block the published indicators. Add the sender addresses and the first-stage and second-stage domains from the Proofpoint report to your mail and web filters, and search mail logs for messages from them since December 2025.
  2. Require phishing-resistant MFA. This is Proofpoint's main recommendation: passkeys or other origin-bound methods, which are tied to the real Microsoft domain and do not work through a proxy on a lookalike domain. In the Microsoft Entra admin center, go to Entra ID, then Conditional Access, then Policies, create a policy for your highest-risk users, and under Grant select Require authentication strength with the built-in Phishing-resistant MFA strength. Start it in report-only mode to see who would be blocked.
  3. Hunt for OfficeHome session reuse. Microsoft's Defender XDR playbook for session cookie theft keys on the same OfficeHome application ID. Its advanced hunting query takes successful interactive browser sign-ins to OfficeHome in AADSignInEventsBeta, then looks for the same SessionId used later by another application from a different country. A second query lists the countries each account has signed in to OfficeHome from over seven days, which makes one-off locations stand out.
  4. Cut off anyone who entered credentials. Resetting the password alone does not end a stolen session. In the Entra admin center, open the user and select Revoke sessions, or run Revoke-MgUserSignInSession in Microsoft Graph PowerShell, then reset the password. Revocation stops new tokens, but existing access tokens stay valid until they expire, one hour by default. Afterwards check for new inbox rules, mail forwarding and app consents.
  5. Verify unexpected outreach. Proofpoint advises people in TA419's sights to treat unsolicited subject-matter outreach as a possible pretext and to confirm it through a separate channel before clicking anything.

Token protection in Conditional Access binds sign-in tokens to a device, but check the scope before relying on it here. Microsoft lists it as generally available for native apps on Windows, iOS and macOS, while browser support is a preview limited to selected web apps that access Azure Resource Manager. It does not cover a browser sign-in to the Microsoft 365 web portal, which is what TA419 targeted.

The wider lesson for identity teams

Every prompt the victims saw came from Microsoft through the proxy, and the one-time code was relayed as soon as it validated. Proofpoint's answer is sign-in that is bound to the real origin, such as passkeys. Until every account has one, detection has to look at what happens after sign-in, such as the same session ID showing up from a second country, and revoking a session has to be a step the help desk has already practiced.

We review Conditional Access and sign-in methods in our safeguarding and hardening work and hunt for AiTM session reuse in security operations. If you want to know whether your tenant would catch a campaign like this, open the chat and Yaali, our AI agent, will pass your question to an engineer.


Sources: Proofpoint, CyberScoop, The Register, Nextgov/FCW, Security Boulevard, Microsoft Defender XDR: session cookie theft alert, Microsoft Entra: revoke user access, Microsoft Entra: token protection, Microsoft Entra: authentication strength policy.

Read next

Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.