Threat Overview
Proofpoint disclosed on October 1, 2026 that the China-aligned espionage group TA419 has conducted targeted credential-phishing operations against U.S.- and Japan-based think tanks, defense contractors, universities, and law firms since at least April 2025. In July 2026, the actor impersonated prominent economists and AI policymakers, began with benign rapport-building messages, and only sent a malicious link after the target replied. The redirect chain used a fake OneDrive loading page, Cloudflare Turnstile, and a customized Frameless Browser-in-the-Browser kit backed by an Evilginx Microsoft 365 phishlet.
The proxy relayed the genuine Microsoft /common/oauth2/v2.0/authorize flow for the first-party OfficeHome application (4765445b-32c6-49b0-83e6-1d93765276ca). TA419’s injected scripts tracked the victim through password, MFA, and Conditional Access, auto-submitted validated one-time codes, auto-accepted “Keep me signed in,” and captured resulting session cookies. This is confirmed campaign reporting by Proofpoint. Proofpoint’s China alignment and continued-targeting forecast are researcher assessments. Public reporting confirms phishing infrastructure and technique, but does not document a universally reliable post-compromise sign-in pattern or every victim outcome.
References
- Proofpoint Threat Research, “Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles,” published October 1, 2026: https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy
Impacted Systems
- Identity/platform: Microsoft 365 and Microsoft Entra ID user accounts accessed through web browsers; no vulnerable Microsoft version is required.
- Target population: AI-policy experts, think tanks, universities, law firms, defense contractors, and people working in national security, energy, international relations, foreign policy, semiconductors, or strategic technology.
- Prerequisite: A target engages with an impersonation email and follows the later shortened/redirected link; successful token theft requires completion of the proxied sign-in and MFA flow.
- Exposure: Internet email and browser access to attacker-controlled domains, Cloudflare-fronted redirects, and Microsoft sign-in. MFA that is not phishing-resistant can be relayed.
- Observed cloud application: Microsoft first-party OfficeHome application ID
4765445b-32c6-49b0-83e6-1d93765276ca; the legitimate client ID alone is not malicious. - Fix status: Campaign/TTP, not a CVE. Phishing-resistant, origin-bound authentication is the relevant preventive control.
Why this matters
TA419 bypasses password-plus-OTP defenses by relaying a genuine sign-in and stealing the authenticated session. The benign-first-message pattern can evade link inspection, while selective follow-up to users who reply reduces volume and increases credibility. The technique is broadly applicable to Microsoft 365 customers and can lead directly to cloud-account takeover without endpoint malware.
Exploitation Status
Confirmed targeted phishing activity. Proofpoint observed campaigns from at least April 2025, including February, March, April, May, and July 2026 infrastructure. The July campaigns used driftshare.co followed by globalfileshareplatform.com. Public evidence confirms delivery and credential-phishing infrastructure; it does not prove compromise for every recipient or establish that all listed domains remain active.
What this hunt looks for
Published TA419 senders and domains, file-sharing redirect chains, first-contact-then-link conversations, IOC clicks, successful or newly characterized sign-ins after clicks, authentication-method changes, and inbox-rule creation.
Required logs
Microsoft 365 Defender EmailEvents, EmailUrlInfo, and UrlClickEvents; Microsoft Entra SigninLogs and AuditLogs; and OfficeActivity for Exchange mailbox-rule activity.
Hunt 1 — Published TA419 senders and phishing domains in email telemetry
let lookback = 180d;
let senders = dynamic(["leparker@mail.com", "hcrediker@mail.com", "hcrediker@outlook.com"]);
let domains = dynamic(["driftshare.co", "globalfileshareplatform.com", "quickfly.online", "smartsyncbox.com", "cirrushare.co", "mypublicshare.com", "goshshare.online", "synchvault.co", "cloudsyncpulse.com", "onecloudfilesync.com", "msfile.online", "winsync.cloud", "publicsharefile.cloud", "fileswiftonline.cloud", "sharehub.space", "tw-koryu.org", "heritiages.org", "heritiage.org", "shinjirou.info"]);
EmailEvents
| where Timestamp >= ago(lookback)
| where SenderFromAddress in~ (senders) or SenderMailFromDomain in~ (domains) or SenderFromDomain in~ (domains)
| project Timestamp, NetworkMessageId, SenderFromAddress, SenderFromDomain, RecipientEmailAddress, Subject, DeliveryAction, DeliveryLocation, ThreatTypes
| order by Timestamp desc
Hunt 2 — URLs from published TA419 infrastructure joined to message context
let lookback = 180d;
let domains = dynamic(["driftshare.co", "globalfileshareplatform.com", "quickfly.online", "smartsyncbox.com", "cirrushare.co", "mypublicshare.com", "goshshare.online", "synchvault.co", "cloudsyncpulse.com", "onecloudfilesync.com", "msfile.online", "winsync.cloud", "publicsharefile.cloud", "fileswiftonline.cloud", "sharehub.space"]);
EmailUrlInfo
| where Timestamp >= ago(lookback)
| where UrlDomain in~ (domains)
| join kind=inner (EmailEvents | where Timestamp >= ago(lookback) | project NetworkMessageId, MailTime=Timestamp, SenderFromAddress, RecipientEmailAddress, Subject, DeliveryAction, DeliveryLocation) on NetworkMessageId
| project MailTime, RecipientEmailAddress, SenderFromAddress, Subject, Url, UrlDomain, DeliveryAction, DeliveryLocation, NetworkMessageId
| order by MailTime desc
Hunt 3 — Clicks to published TA419 domains
let lookback = 180d;
let domains = dynamic(["driftshare.co", "globalfileshareplatform.com", "quickfly.online", "smartsyncbox.com", "cirrushare.co", "mypublicshare.com", "goshshare.online", "synchvault.co", "cloudsyncpulse.com", "onecloudfilesync.com", "msfile.online", "winsync.cloud", "publicsharefile.cloud", "fileswiftonline.cloud", "sharehub.space"]);
UrlClickEvents
| where Timestamp >= ago(lookback)
| extend ClickDomain = tostring(parse_url(Url).Host)
| where ClickDomain in~ (domains)
| project Timestamp, AccountUpn, Url, ClickDomain, ActionType, IsClickedThrough, IPAddress, Workload, NetworkMessageId
| order by Timestamp desc
Hunt 4 — IOC click followed by a successful Microsoft 365 sign-in
let lookback = 180d;
let domains = dynamic(["driftshare.co", "globalfileshareplatform.com", "quickfly.online", "smartsyncbox.com", "cirrushare.co", "mypublicshare.com", "goshshare.online", "synchvault.co", "cloudsyncpulse.com", "onecloudfilesync.com", "msfile.online", "winsync.cloud", "publicsharefile.cloud", "fileswiftonline.cloud", "sharehub.space"]);
let clicks = UrlClickEvents
| where Timestamp >= ago(lookback)
| extend ClickDomain=tostring(parse_url(Url).Host)
| where ClickDomain in~ (domains)
| project AccountUpn=tolower(AccountUpn), ClickTime=Timestamp, ClickDomain, ClickUrl=Url, ClickIP=IPAddress;
SigninLogs
| where TimeGenerated >= ago(lookback)
| where ResultType == 0
| extend AccountUpn=tolower(UserPrincipalName)
| join kind=inner clicks on AccountUpn
| where TimeGenerated between (ClickTime .. ClickTime + 2h)
| project TimeGenerated, UserPrincipalName, IPAddress, AppDisplayName, ClientAppUsed, ConditionalAccessStatus, UserAgent, ClickTime, ClickDomain, ClickUrl, ClickIP, CorrelationId
| order by TimeGenerated desc
Hunt 5 — New sign-in properties shortly after a TA419-domain click
let baseline = 30d;
let recent = 2d;
let domains = dynamic(["driftshare.co", "globalfileshareplatform.com", "quickfly.online", "smartsyncbox.com", "cirrushare.co", "mypublicshare.com", "goshshare.online", "synchvault.co", "cloudsyncpulse.com", "onecloudfilesync.com", "msfile.online", "winsync.cloud", "publicsharefile.cloud", "fileswiftonline.cloud", "sharehub.space"]);
let known = SigninLogs
| where TimeGenerated between (ago(baseline) .. ago(recent))
| where ResultType == 0
| summarize by UserPrincipalName=tolower(UserPrincipalName), IPAddress, UserAgent;
let clicks = UrlClickEvents
| where Timestamp >= ago(recent)
| extend ClickDomain=tostring(parse_url(Url).Host), UserPrincipalName=tolower(AccountUpn)
| where ClickDomain in~ (domains)
| project UserPrincipalName, ClickTime=Timestamp, ClickDomain;
SigninLogs
| where TimeGenerated >= ago(recent)
| where ResultType == 0
| extend UserPrincipalName=tolower(UserPrincipalName)
| join kind=inner clicks on UserPrincipalName
| where TimeGenerated between (ClickTime .. ClickTime + 2h)
| join kind=leftanti known on UserPrincipalName, IPAddress, UserAgent
| project TimeGenerated, UserPrincipalName, IPAddress, AppDisplayName, ClientAppUsed, ConditionalAccessStatus, UserAgent, ClickTime, ClickDomain
| order by TimeGenerated desc
Hunt 6 — First-contact conversation followed by a URL-bearing message
let lookback = 30d;
EmailEvents
| where Timestamp >= ago(lookback)
| where EmailDirection =~ "Inbound"
| summarize FirstSeen=min(Timestamp), LastSeen=max(Timestamp), MessageCount=count(), UrlMessages=countif(UrlCount > 0), Subjects=make_set(Subject, 10), MessageIds=make_set(NetworkMessageId, 20) by SenderFromAddress, RecipientEmailAddress
| where MessageCount >= 2 and UrlMessages >= 1 and FirstSeen < LastSeen
| order by LastSeen desc
Hunt 7 — Authentication-method or user-security changes after an IOC click
let lookback = 180d;
let domains = dynamic(["driftshare.co", "globalfileshareplatform.com", "quickfly.online", "smartsyncbox.com", "cirrushare.co", "mypublicshare.com", "goshshare.online", "synchvault.co", "cloudsyncpulse.com", "onecloudfilesync.com", "msfile.online", "winsync.cloud", "publicsharefile.cloud", "fileswiftonline.cloud", "sharehub.space"]);
let clickedUsers = UrlClickEvents
| where Timestamp >= ago(lookback)
| extend ClickDomain=tostring(parse_url(Url).Host)
| where ClickDomain in~ (domains)
| project UserKey=tolower(AccountUpn), ClickTime=Timestamp, ClickDomain;
AuditLogs
| where TimeGenerated >= ago(lookback)
| where OperationName has_any ("authentication method", "Update user", "Reset password", "Change password")
| mv-expand TargetResources
| extend UserKey=tolower(tostring(TargetResources.userPrincipalName))
| join kind=inner clickedUsers on UserKey
| where TimeGenerated between (ClickTime .. ClickTime + 24h)
| project TimeGenerated, OperationName, Result, InitiatedBy, TargetResources, ClickTime, ClickDomain, CorrelationId
| order by TimeGenerated desc
Hunt 8 — Inbox-rule creation after an IOC click
let lookback = 180d;
let domains = dynamic(["driftshare.co", "globalfileshareplatform.com", "quickfly.online", "smartsyncbox.com", "cirrushare.co", "mypublicshare.com", "goshshare.online", "synchvault.co", "cloudsyncpulse.com", "onecloudfilesync.com", "msfile.online", "winsync.cloud", "publicsharefile.cloud", "fileswiftonline.cloud", "sharehub.space"]);
let clickedUsers = UrlClickEvents
| where Timestamp >= ago(lookback)
| extend ClickDomain=tostring(parse_url(Url).Host)
| where ClickDomain in~ (domains)
| project UserKey=tolower(AccountUpn), ClickTime=Timestamp, ClickDomain;
OfficeActivity
| where TimeGenerated >= ago(lookback)
| where OfficeWorkload =~ "Exchange" and Operation in~ ("New-InboxRule", "Set-InboxRule", "UpdateInboxRules")
| extend UserKey=tolower(UserId)
| join kind=inner clickedUsers on UserKey
| where TimeGenerated between (ClickTime .. ClickTime + 24h)
| project TimeGenerated, UserId, Operation, ClientIP, Parameters, ClickTime, ClickDomain
| order by TimeGenerated desc
Detection Notes
- Hunts 1–4 are highest confidence because they use Proofpoint-published indicators and preserve message/click/sign-in context. Domains are historical indicators; validate registration and event time before containment.
- Hunt 6 is deliberately behavioral and will be noisy for recruiters, sales, media, and external collaboration. Prioritize external senders impersonating known experts, policy invitations, file-sharing themes, or a new relationship that quickly shifts to credentialed content.
- The OfficeHome client ID is legitimate and broadly used; do not alert on it alone. AitM detection depends on session context, new IP/user-agent properties, risk signals, and activity after a relevant click.
- Conditional Access success does not rule out AitM because the victim completes the real flow through the proxy. Phishing-resistant FIDO2/passkey authentication is resistant because it is origin-bound.
EmailUrlInfo,UrlClickEvents, andOfficeActivityavailability depends on licensing and connectors. Shorteners or redirects may prevent the final domain from appearing until click detonation.- Some
AuditLogstarget-resource shapes vary. IfTargetResources.userPrincipalNameis absent, parseTargetResources.modifiedPropertiesor correlate by target ID using the tenant’s schema.