TA419: Microsoft 365 AitM and Browser-in-the-Browser Phishing Hunt

Threat Overview

Proofpoint disclosed on October 1, 2026 that the China-aligned espionage group TA419 has conducted targeted credential-phishing operations against U.S.- and Japan-based think tanks, defense contractors, universities, and law firms since at least April 2025. In July 2026, the actor impersonated prominent economists and AI policymakers, began with benign rapport-building messages, and only sent a malicious link after the target replied. The redirect chain used a fake OneDrive loading page, Cloudflare Turnstile, and a customized Frameless Browser-in-the-Browser kit backed by an Evilginx Microsoft 365 phishlet.

The proxy relayed the genuine Microsoft /common/oauth2/v2.0/authorize flow for the first-party OfficeHome application (4765445b-32c6-49b0-83e6-1d93765276ca). TA419’s injected scripts tracked the victim through password, MFA, and Conditional Access, auto-submitted validated one-time codes, auto-accepted “Keep me signed in,” and captured resulting session cookies. This is confirmed campaign reporting by Proofpoint. Proofpoint’s China alignment and continued-targeting forecast are researcher assessments. Public reporting confirms phishing infrastructure and technique, but does not document a universally reliable post-compromise sign-in pattern or every victim outcome.

References

Impacted Systems

  • Identity/platform: Microsoft 365 and Microsoft Entra ID user accounts accessed through web browsers; no vulnerable Microsoft version is required.
  • Target population: AI-policy experts, think tanks, universities, law firms, defense contractors, and people working in national security, energy, international relations, foreign policy, semiconductors, or strategic technology.
  • Prerequisite: A target engages with an impersonation email and follows the later shortened/redirected link; successful token theft requires completion of the proxied sign-in and MFA flow.
  • Exposure: Internet email and browser access to attacker-controlled domains, Cloudflare-fronted redirects, and Microsoft sign-in. MFA that is not phishing-resistant can be relayed.
  • Observed cloud application: Microsoft first-party OfficeHome application ID 4765445b-32c6-49b0-83e6-1d93765276ca; the legitimate client ID alone is not malicious.
  • Fix status: Campaign/TTP, not a CVE. Phishing-resistant, origin-bound authentication is the relevant preventive control.

Why this matters

TA419 bypasses password-plus-OTP defenses by relaying a genuine sign-in and stealing the authenticated session. The benign-first-message pattern can evade link inspection, while selective follow-up to users who reply reduces volume and increases credibility. The technique is broadly applicable to Microsoft 365 customers and can lead directly to cloud-account takeover without endpoint malware.

Exploitation Status

Confirmed targeted phishing activity. Proofpoint observed campaigns from at least April 2025, including February, March, April, May, and July 2026 infrastructure. The July campaigns used driftshare.co followed by globalfileshareplatform.com. Public evidence confirms delivery and credential-phishing infrastructure; it does not prove compromise for every recipient or establish that all listed domains remain active.

What this hunt looks for

Published TA419 senders and domains, file-sharing redirect chains, first-contact-then-link conversations, IOC clicks, successful or newly characterized sign-ins after clicks, authentication-method changes, and inbox-rule creation.

Required logs

Microsoft 365 Defender EmailEvents, EmailUrlInfo, and UrlClickEvents; Microsoft Entra SigninLogs and AuditLogs; and OfficeActivity for Exchange mailbox-rule activity.

Hunt 1 — Published TA419 senders and phishing domains in email telemetry

let lookback = 180d;
let senders = dynamic(["leparker@mail.com", "hcrediker@mail.com", "hcrediker@outlook.com"]);
let domains = dynamic(["driftshare.co", "globalfileshareplatform.com", "quickfly.online", "smartsyncbox.com", "cirrushare.co", "mypublicshare.com", "goshshare.online", "synchvault.co", "cloudsyncpulse.com", "onecloudfilesync.com", "msfile.online", "winsync.cloud", "publicsharefile.cloud", "fileswiftonline.cloud", "sharehub.space", "tw-koryu.org", "heritiages.org", "heritiage.org", "shinjirou.info"]);
EmailEvents
| where Timestamp >= ago(lookback)
| where SenderFromAddress in~ (senders) or SenderMailFromDomain in~ (domains) or SenderFromDomain in~ (domains)
| project Timestamp, NetworkMessageId, SenderFromAddress, SenderFromDomain, RecipientEmailAddress, Subject, DeliveryAction, DeliveryLocation, ThreatTypes
| order by Timestamp desc

Hunt 2 — URLs from published TA419 infrastructure joined to message context

let lookback = 180d;
let domains = dynamic(["driftshare.co", "globalfileshareplatform.com", "quickfly.online", "smartsyncbox.com", "cirrushare.co", "mypublicshare.com", "goshshare.online", "synchvault.co", "cloudsyncpulse.com", "onecloudfilesync.com", "msfile.online", "winsync.cloud", "publicsharefile.cloud", "fileswiftonline.cloud", "sharehub.space"]);
EmailUrlInfo
| where Timestamp >= ago(lookback)
| where UrlDomain in~ (domains)
| join kind=inner (EmailEvents | where Timestamp >= ago(lookback) | project NetworkMessageId, MailTime=Timestamp, SenderFromAddress, RecipientEmailAddress, Subject, DeliveryAction, DeliveryLocation) on NetworkMessageId
| project MailTime, RecipientEmailAddress, SenderFromAddress, Subject, Url, UrlDomain, DeliveryAction, DeliveryLocation, NetworkMessageId
| order by MailTime desc

Hunt 3 — Clicks to published TA419 domains

let lookback = 180d;
let domains = dynamic(["driftshare.co", "globalfileshareplatform.com", "quickfly.online", "smartsyncbox.com", "cirrushare.co", "mypublicshare.com", "goshshare.online", "synchvault.co", "cloudsyncpulse.com", "onecloudfilesync.com", "msfile.online", "winsync.cloud", "publicsharefile.cloud", "fileswiftonline.cloud", "sharehub.space"]);
UrlClickEvents
| where Timestamp >= ago(lookback)
| extend ClickDomain = tostring(parse_url(Url).Host)
| where ClickDomain in~ (domains)
| project Timestamp, AccountUpn, Url, ClickDomain, ActionType, IsClickedThrough, IPAddress, Workload, NetworkMessageId
| order by Timestamp desc

Hunt 4 — IOC click followed by a successful Microsoft 365 sign-in

let lookback = 180d;
let domains = dynamic(["driftshare.co", "globalfileshareplatform.com", "quickfly.online", "smartsyncbox.com", "cirrushare.co", "mypublicshare.com", "goshshare.online", "synchvault.co", "cloudsyncpulse.com", "onecloudfilesync.com", "msfile.online", "winsync.cloud", "publicsharefile.cloud", "fileswiftonline.cloud", "sharehub.space"]);
let clicks = UrlClickEvents
| where Timestamp >= ago(lookback)
| extend ClickDomain=tostring(parse_url(Url).Host)
| where ClickDomain in~ (domains)
| project AccountUpn=tolower(AccountUpn), ClickTime=Timestamp, ClickDomain, ClickUrl=Url, ClickIP=IPAddress;
SigninLogs
| where TimeGenerated >= ago(lookback)
| where ResultType == 0
| extend AccountUpn=tolower(UserPrincipalName)
| join kind=inner clicks on AccountUpn
| where TimeGenerated between (ClickTime .. ClickTime + 2h)
| project TimeGenerated, UserPrincipalName, IPAddress, AppDisplayName, ClientAppUsed, ConditionalAccessStatus, UserAgent, ClickTime, ClickDomain, ClickUrl, ClickIP, CorrelationId
| order by TimeGenerated desc

Hunt 5 — New sign-in properties shortly after a TA419-domain click

let baseline = 30d;
let recent = 2d;
let domains = dynamic(["driftshare.co", "globalfileshareplatform.com", "quickfly.online", "smartsyncbox.com", "cirrushare.co", "mypublicshare.com", "goshshare.online", "synchvault.co", "cloudsyncpulse.com", "onecloudfilesync.com", "msfile.online", "winsync.cloud", "publicsharefile.cloud", "fileswiftonline.cloud", "sharehub.space"]);
let known = SigninLogs
| where TimeGenerated between (ago(baseline) .. ago(recent))
| where ResultType == 0
| summarize by UserPrincipalName=tolower(UserPrincipalName), IPAddress, UserAgent;
let clicks = UrlClickEvents
| where Timestamp >= ago(recent)
| extend ClickDomain=tostring(parse_url(Url).Host), UserPrincipalName=tolower(AccountUpn)
| where ClickDomain in~ (domains)
| project UserPrincipalName, ClickTime=Timestamp, ClickDomain;
SigninLogs
| where TimeGenerated >= ago(recent)
| where ResultType == 0
| extend UserPrincipalName=tolower(UserPrincipalName)
| join kind=inner clicks on UserPrincipalName
| where TimeGenerated between (ClickTime .. ClickTime + 2h)
| join kind=leftanti known on UserPrincipalName, IPAddress, UserAgent
| project TimeGenerated, UserPrincipalName, IPAddress, AppDisplayName, ClientAppUsed, ConditionalAccessStatus, UserAgent, ClickTime, ClickDomain
| order by TimeGenerated desc

Hunt 6 — First-contact conversation followed by a URL-bearing message

let lookback = 30d;
EmailEvents
| where Timestamp >= ago(lookback)
| where EmailDirection =~ "Inbound"
| summarize FirstSeen=min(Timestamp), LastSeen=max(Timestamp), MessageCount=count(), UrlMessages=countif(UrlCount > 0), Subjects=make_set(Subject, 10), MessageIds=make_set(NetworkMessageId, 20) by SenderFromAddress, RecipientEmailAddress
| where MessageCount >= 2 and UrlMessages >= 1 and FirstSeen < LastSeen
| order by LastSeen desc

Hunt 7 — Authentication-method or user-security changes after an IOC click

let lookback = 180d;
let domains = dynamic(["driftshare.co", "globalfileshareplatform.com", "quickfly.online", "smartsyncbox.com", "cirrushare.co", "mypublicshare.com", "goshshare.online", "synchvault.co", "cloudsyncpulse.com", "onecloudfilesync.com", "msfile.online", "winsync.cloud", "publicsharefile.cloud", "fileswiftonline.cloud", "sharehub.space"]);
let clickedUsers = UrlClickEvents
| where Timestamp >= ago(lookback)
| extend ClickDomain=tostring(parse_url(Url).Host)
| where ClickDomain in~ (domains)
| project UserKey=tolower(AccountUpn), ClickTime=Timestamp, ClickDomain;
AuditLogs
| where TimeGenerated >= ago(lookback)
| where OperationName has_any ("authentication method", "Update user", "Reset password", "Change password")
| mv-expand TargetResources
| extend UserKey=tolower(tostring(TargetResources.userPrincipalName))
| join kind=inner clickedUsers on UserKey
| where TimeGenerated between (ClickTime .. ClickTime + 24h)
| project TimeGenerated, OperationName, Result, InitiatedBy, TargetResources, ClickTime, ClickDomain, CorrelationId
| order by TimeGenerated desc

Hunt 8 — Inbox-rule creation after an IOC click

let lookback = 180d;
let domains = dynamic(["driftshare.co", "globalfileshareplatform.com", "quickfly.online", "smartsyncbox.com", "cirrushare.co", "mypublicshare.com", "goshshare.online", "synchvault.co", "cloudsyncpulse.com", "onecloudfilesync.com", "msfile.online", "winsync.cloud", "publicsharefile.cloud", "fileswiftonline.cloud", "sharehub.space"]);
let clickedUsers = UrlClickEvents
| where Timestamp >= ago(lookback)
| extend ClickDomain=tostring(parse_url(Url).Host)
| where ClickDomain in~ (domains)
| project UserKey=tolower(AccountUpn), ClickTime=Timestamp, ClickDomain;
OfficeActivity
| where TimeGenerated >= ago(lookback)
| where OfficeWorkload =~ "Exchange" and Operation in~ ("New-InboxRule", "Set-InboxRule", "UpdateInboxRules")
| extend UserKey=tolower(UserId)
| join kind=inner clickedUsers on UserKey
| where TimeGenerated between (ClickTime .. ClickTime + 24h)
| project TimeGenerated, UserId, Operation, ClientIP, Parameters, ClickTime, ClickDomain
| order by TimeGenerated desc

Detection Notes

  • Hunts 1–4 are highest confidence because they use Proofpoint-published indicators and preserve message/click/sign-in context. Domains are historical indicators; validate registration and event time before containment.
  • Hunt 6 is deliberately behavioral and will be noisy for recruiters, sales, media, and external collaboration. Prioritize external senders impersonating known experts, policy invitations, file-sharing themes, or a new relationship that quickly shifts to credentialed content.
  • The OfficeHome client ID is legitimate and broadly used; do not alert on it alone. AitM detection depends on session context, new IP/user-agent properties, risk signals, and activity after a relevant click.
  • Conditional Access success does not rule out AitM because the victim completes the real flow through the proxy. Phishing-resistant FIDO2/passkey authentication is resistant because it is origin-bound.
  • EmailUrlInfo, UrlClickEvents, and OfficeActivity availability depends on licensing and connectors. Shorteners or redirects may prevent the final domain from appearing until click detonation.
  • Some AuditLogs target-resource shapes vary. If TargetResources.userPrincipalName is absent, parse TargetResources.modifiedProperties or correlate by target ID using the tenant’s schema.