- Proofpoint revealed that a China-linked group, TA419, impersonated former White House official Lynne Edwards Parker and economist Heidi Crebo-Rediker in July 2026, launching credential phishing attacks against US AI policy experts
- The attacks used a fabricated ‘AI Policy Advisory Committee’ and a fake Senate report on AI export controls as bait, ultimately leading to a fake OneDrive adversary-in-the-middle credential phishing page
- Cisco Talos separately discovered a backdoor called Antino, which attacked 16 organisations across eight Asian countries from September 2025 to July 2026, affecting around 350 infected endpoints
On this page
TA419 impersonates well-known figures to target AI policy circles
According to Proofpoint’s research report, the group tracked by Proofpoint as TA419 launched multiple rounds of credential phishing operations in July 2026, impersonating several well-known economists and AI policymakers. The targets were AI experts working at US think tanks, universities and legal institutions.
The campaign began on Jul 8, 2026. TA419 first impersonated Lynne Edwards Parker, former deputy director of the White House Office of Science and Technology Policy, before switching to impersonate renowned foreign policy expert Heidi Crebo-Rediker. The hackers first sent seemingly harmless emails inviting targets to join a fabricated ‘AI Policy Advisory Committee’ or contribute to a Senate Foreign Relations Committee report on AI export controls and supply chains, building trust to lure replies.
Once a target replied, TA419 sent a shortened URL with multiple redirects, ultimately leading to a fake OneDrive adversary-in-the-middle (AitM) credential phishing page. The page used a browser-in-the-browser (BitB) technique adapted from the open-source tool Frameless BitB, targeting Microsoft 365 and Entra ID accounts. The report notes the group also impersonated a senior Anthropic employee in February this year, targeting a think tank AI policy analyst.
Antino backdoor targets government agencies in eight Asian countries
According to a report by The Record citing Cisco Talos, another campaign run by a China state-backed group used a backdoor called Antino to breach government agencies in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria. Cisco’s incident response team found that between September 2025 and July 2026, 16 organisations across eight Asian countries were affected or targeted, with around 350 infected endpoints recorded.
The Antino backdoor allows hackers to conduct reconnaissance, transfer files and maintain access, aimed at intelligence gathering. Most victims were initially compromised through phishing emails and decoy documents, including news reports about the Trump administration, invitations impersonating real events, and legislative documents. Cisco Talos also noted overlap with Symantec’s Jewelbug research.
Jewelbug runs espionage operations alongside cryptocurrency fraud
Symantec’s threat hunter team report states that Jewelbug (also known as Earth Alux, REF7707, CL-STA-0049) is a China-based hacking-for-hire group that simultaneously runs espionage operations targeting governments and militaries in the Middle East, Southeast Asia and South Asia, as well as a cryptocurrency fraud business targeting Chinese-speaking users. Both operations are managed by the same small team on the same infrastructure, coordinated through a browser-based control panel called XG-Web.
The report says the group’s commercial activities are linked to a registered company in Hunan. Jewelbug’s victim database recorded over one million implant check-ins and more than 580,000 stolen browser cookies within an active period of less than three months. Its main implant is a malicious browser extension disguised as ‘PDF Viewer’, alongside Linux and router implants called ClientKing.
What to do now
- Review internal email systems’ detection rules for phishing emails that impersonate policy institutions or well-known figures
- Stay alert to unsolicited ‘committee invitations’ or ‘report contribution’ requests from unfamiliar sources, and avoid clicking follow-up links after replying
- Enable phishing-resistant multi-factor authentication methods, such as FIDO2 hardware keys, for Microsoft 365 and Entra ID accounts to prevent adversary-in-the-middle attacks from bypassing standard MFA
- Check the installation source and permissions of browser extensions, and remove unknown extensions that request excessive permissions, such as intercepting all website cookies and debug access
- Monitor corporate proxy servers and network traffic for unusual use of legitimate cloud services, such as the Microsoft Graph API, as a command-and-control channel
FAQ
What is TA419?
According to Proofpoint, TA419 is a hacking group linked to China that conducts espionage activities. Since April 2025, it has been observed launching targeted credential phishing attacks against personnel at think tanks, defence contractors, universities and law firms in the US and Japan.
Did this attack succeed?
The report does not specify how many targets’ accounts were compromised, but Proofpoint notes that the phishing page’s adversary-in-the-middle technique allowed the target’s password, multi-factor authentication code and conditional access checks to all ‘pass successfully’, while the attacker intercepted the post-login session cookie in the background.
What is an adversary-in-the-middle (AitM) credential phishing attack?
An adversary-in-the-middle credential phishing attack occurs when an attacker inserts a proxy page between the victim and the real login system, relaying the login request in real time. This allows the victim’s username, password and multi-factor authentication code to all pass verification on the real system, while the attacker simultaneously steals the session cookie generated after login, bypassing multi-factor authentication protection.
Are the Antino backdoor and Jewelbug the same group?
Cisco Talos’s report states that the Antino backdoor attacks it tracked overlap with the activity of the group tracked by Symantec as Jewelbug. However, neither report explicitly confirms the two are the same group, and the connection between them still requires further verification.
Which regions’ organisations were affected?
According to the Cisco Talos report, the affected or targeted government and security agencies are spread across eight Asian countries: Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria. According to the Proofpoint report, victims also include AI policy experts at US think tanks, universities and law firms.



