Threats & Adversaries · APT / Espionage

TA419 Steals Microsoft 365 Sessions With Fake Policy Outreach

Proofpoint said on October 1 that China-aligned TA419 has been running a credential-phishing campaign since at least April 2025 against AI policy specialists at think tanks, universities, law firms, defense contractors, and policy groups. The lures impersonated real policy figures and an Anthropic employee to pull targets into Microsoft 365 and OneDrive sign-ins.

The trap was an adversary-in-the-middle proxy built from Frameless BitB. It sat in front of a real Microsoft login, relayed the sign-in in real time, and captured the session cookies after the password, MFA prompt, and conditional-access checks all succeeded, so the attacker walked away with a live account session rather than just credentials.

For organizations that use Microsoft 365 for email, documents, or shared workspaces, the exposure sits in the session itself: once a target completes the login, ordinary password resets do not necessarily evict the attacker. The reporting does not say accounts were compromised in every case, but it does show why MFA alone does not close this pattern.

4 sources · 3h ago

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-10-01

Every edition of this story: TA419 Steals Microsoft 365 Sessions With Fake Policy Outreach

More from today