AI policy circles targeted in China-linked phishing operation
China-aligned TA419 ran adversary-in-the-middle phishing campaigns impersonating officials and an Anthropic staffer to steal credentials from U.S. AI policy experts.
Proofpoint attributed phishing campaigns to China-aligned group TA419 targeting U.S. AI policy experts at think tanks, universities, and law firms since at least April 2025. A July campaign impersonated former White House OSTP official Lynne Parker and economist Heidi Crebo-Rediker, using a modified open-source Frameless BitB tool to present fake Microsoft OneDrive sign-in pages that captured credentials and active browser sessions. A February campaign impersonated a senior Anthropic employee to solicit feedback on military use of Claude models. No victims or compromises were confirmed, and Proofpoint did not directly link the activity to the Chinese government.