# China-Aligned TA419 Uses AitM Phishing Against U.S. AI Policy Experts

*Sunday, October 4, 2026 at 8:06 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-10-04T08:06:24.844Z (2h ago)
**Category**: cyber | **Region**: Global
**Importance**: 7/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/19648.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: The China-aligned hacking group TA419 is targeting U.S. artificial intelligence policy experts with adversary-in-the-middle phishing that uses shortened links and frameless BitB pages to capture credentials and session cookies.

A China-aligned threat group tracked as TA419 is running a phishing campaign against U.S.-based artificial intelligence policy experts, using techniques designed to steal both passwords and active login sessions.

According to reporting on the operation, TA419 initiates contact by email and waits for the target to reply. After that initial engagement, the group sends a shortened link that leads to a “frameless” browser-in-the-browser (BitB) page. The page is crafted to look like a legitimate login site but functions as an adversary-in-the-middle (AitM) trap, capturing credentials along with session cookies.

By harvesting session cookies, attackers can bypass some forms of multifactor authentication, logging in as the victim even without direct access to one-time codes.

The choice of U.S. AI policy experts as targets indicates an interest in accounts belonging to people involved in discussions about how artificial intelligence should be governed and regulated.

For the individuals and organisations involved, a successful compromise could expose emails, draft documents and contact networks, and give attackers a foothold to move into institutional systems.

Indicators to watch include any public attribution or advisories naming TA419 in connection with this campaign, changes by major email and identity providers to counter AitM techniques like frameless BitB pages, and any targeted guidance U.S. authorities issue to AI research and policy communities about this threat.
