China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing

A Chinese-aligned threat group, TA419, has been targeting U.S. artificial intelligence (AI) policy experts with a sophisticated phishing campaign leveraging Microsoft’s Azure Information Protection (AIP) tool, also known as Microsoft AitM. The attackers are using this tactic to gain unauthorized access to sensitive information and potentially disrupt the development of AI policies in the United States.

TA419 has been identified as a China-aligned threat group that has been active since 2019, with a focus on cyber espionage and data theft. The group’s targets have included government agencies, think tanks, and private companies working in various sectors, including defense and technology. Microsoft AitM is a cloud-based email security tool designed to protect sensitive information by applying labels and encryption policies to emails.

The phishing campaign involves sending emails that appear to be from legitimate sources within the AI policy community. The emails contain attachments or links that, when clicked, prompt the victim’s email client to apply a label using Microsoft AitM. This allows the attackers to gain access to sensitive information stored on the victim’s email account. Once inside, the attackers can move laterally across the network, exploiting vulnerabilities in other systems and applications.

The use of Microsoft AitM in this phishing campaign is significant because it requires the attackers to have knowledge of the tool’s inner workings and how to manipulate its policies. This level of sophistication suggests that TA419 has been actively working with insiders or has developed extensive expertise through previous attacks. The group’s targets are likely chosen based on their access to sensitive information related to AI policy development, making this campaign a concern for U.S. national security.

The attack on AI policy experts is particularly worrying because it could disrupt the development of AI policies in the United States. AI technology has far-reaching implications, and decisions made about its development can have significant impacts on global politics and economies. If TA419 succeeds in gaining access to sensitive information or disrupting the work of these experts, it could give China an unfair advantage in this area.

The fact that TA419 is using a legitimate tool like Microsoft AitM to carry out their phishing campaign makes it even more challenging for victims to detect the attack. This tactic highlights the need for increased awareness and vigilance among AI policy experts and other targets of cyber espionage. Organizations should ensure they are taking robust security measures, including regular employee training on cybersecurity best practices.

In conclusion, the use of Microsoft AitM in this phishing campaign is a sophisticated and concerning development in the world of cyber espionage. It emphasizes the importance of ongoing education and awareness among AI policy experts about the threat posed by groups like TA419. By staying informed and vigilant, these individuals can better protect themselves from such attacks and ensure that sensitive information remains secure.


Source: The Hacker News — 2026-10-04