Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles

    Date: 10/05/2026

    Severity: High

    Summary

    In July 2026, China-aligned threat actor TA419 conducted multiple credential-phishing campaigns targeting AI experts. The campaigns impersonated prominent economists and AI policymakers to target experts at US think tanks, universities, and legal organizations. In February 2026, TA419 also impersonated a senior Anthropic employee to target an AI policy expert at a US think tank. The activity likely supports Chinese intelligence efforts to monitor US AI policy and regulatory developments. The campaigns occurred amid growing US-China strategic competition, model-distillation allegations, and AI-related export controls.

    Indicators of Compromise (IOC) List

    Domains/URLs

    driftshare.co

    globalfileshareplatform.com

    quickfly.online

    smartsyncbox.com

    cirrushare.co

    mypublicshare.com

    goshshare.online

    synchvault.co

    cloudsyncpulse.com

    onecloudfilesync.com

    msfile.online

    winsync.cloud

    publicsharefile.cloud

    fileswiftonline.cloud

    sharehub.space

    tw-koryu.org

    heritiages.org

    heritiage.org

    shinjirou.info

    Hash

    b314a1499cd728ca3e54b7150661fd0c7d2279065fe3f570f0f66c395d744460

    Email Address

    leparker@mail.com
    hcrediker@mail.com
    hcrediker@outlook.com
    driftshare.co

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "heritiages.org" or url like "heritiages.org" or siteurl like "heritiages.org" or domainname like "mypublicshare.com" or url like "mypublicshare.com" or siteurl like "mypublicshare.com" or domainname like "smartsyncbox.com" or url like "smartsyncbox.com" or siteurl like "smartsyncbox.com" or domainname like "tw-koryu.org" or url like "tw-koryu.org" or siteurl like "tw-koryu.org" or domainname like "cloudsyncpulse.com" or url like "cloudsyncpulse.com" or siteurl like "cloudsyncpulse.com" or domainname like "fileswiftonline.cloud" or url like "fileswiftonline.cloud" or siteurl like "fileswiftonline.cloud" or domainname like "winsync.cloud" or url like "winsync.cloud" or siteurl like "winsync.cloud" or domainname like "onecloudfilesync.com" or url like "onecloudfilesync.com" or siteurl like "onecloudfilesync.com" or domainname like "shinjirou.info" or url like "shinjirou.info" or siteurl like "shinjirou.info" or domainname like "publicsharefile.cloud" or url like "publicsharefile.cloud" or siteurl like "publicsharefile.cloud" or domainname like "globalfileshareplatform.com" or url like "globalfileshareplatform.com" or siteurl like "globalfileshareplatform.com" or domainname like "synchvault.co" or url like "synchvault.co" or siteurl like "synchvault.co" or domainname like "driftshare.co" or url like "driftshare.co" or siteurl like "driftshare.co" or domainname like "cirrushare.co" or url like "cirrushare.co" or siteurl like "cirrushare.co" or domainname like "goshshare.online" or url like "goshshare.online" or siteurl like "goshshare.online" or domainname like "quickfly.online" or url like "quickfly.online" or siteurl like "quickfly.online" or domainname like "sharehub.space" or url like "sharehub.space" or siteurl like "sharehub.space" or domainname like "msfile.online" or url like "msfile.online" or siteurl like "msfile.online" or domainname like "heritiage.org" or url like "heritiage.org" or siteurl like "heritiage.org"

    Detection Query 2 :

    Sha256hash IN (“b314a1499cd728ca3e54b7150661fd0c7d2279065fe3f570f0f66c395d744460”)

    Detection Query 3 :

    From In ("leparker@mail.com","hcrediker@mail.com","hcrediker@outlook.com","driftshare.co") or sender IN ("leparker@mail.com","hcrediker@mail.com","hcrediker@outlook.com","driftshare.co") or receiver IN ("leparker@mail.com","hcrediker@mail.com","hcrediker@outlook.com","driftshare.co")

    Reference: 

    https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy             


    Tags

    MalwareThreat ActorPhishingCredential HarvestingUnited StatesChinaEducation

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags