Chinese Hackers Posing as Senior Anthropic Employee Targeting US AI Policy Experts
China-linked TA419 impersonated an Anthropic employee to phish US AI policy experts for Microsoft 365 sessions.
Proofpoint says China-aligned TA419 impersonated a senior Anthropic employee and former US policy figures to phish AI policy experts at think tanks, universities, law firms, and related organizations. After an initial email exchange, shortened links sent victims through attacker sites into a Frameless BitB and Evilginx-style proxy of Microsoft 365 and Entra ID sign-in. The flow captured session cookies and handled MFA so attackers could obtain a usable cloud session. Campaigns have been tracked since at least April 2025, but successful account compromise is not confirmed.