Chinese Hackers Posing as Senior Anthropic Employee Targeting US AI Policy Experts
China-linked TA419 impersonated an Anthropic employee to phish US AI policy experts for Microsoft 365 sessions.
Proofpoint says China-aligned TA419 impersonated a senior Anthropic employee and former US policy figures to phish AI policy experts at think tanks, universities, law firms, and related organizations. After an initial email exchange, shortened links sent victims through attacker sites into a Frameless BitB and Evilginx-style proxy of Microsoft 365 and Entra ID sign-in. The flow captured session cookies and handled MFA so attackers could obtain a usable cloud session. Campaigns have been tracked since at least April 2025, but successful account compromise is not confirmed.
- TA419 impersonated an Anthropic employee and former White House officials in 2026.
- Lures targeted AI policy staff at US think tanks, universities, and law firms.
- Follow-up links used Evilginx-style adversary-in-the-middle phishing against Microsoft 365.
- The proxy captured session cookies and processed MFA, not just passwords.
- Proofpoint has not confirmed that targeted accounts were successfully compromised.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | driftshare.co | sed through attacker-controlled websites. The first domain, driftshare[.]co, displayed a fake OneDrive loading screen and ran a Cloud |
| domain | globalfileshareplatform.com | n a Cloudflare Turnstile check before directing visitors to globalfileshareplatform[.]com, which hosted the credential phishing flow. The attack co |
Full article607 words · extracted from cybersecuritynews.com · click to collapse
A China-aligned hacking group tracked as TA419 has impersonated a senior Anthropic employee and well-known policy figures to target US artificial intelligence experts.
Proofpoint linked the activity to credential-phishing campaigns aimed at researchers at think tanks, universities, and law firms, with lures designed to steal access to their cloud accounts.
The targeting likely supports Chinese intelligence efforts to understand US AI rules, export controls, and national strategy. Proofpoint has tracked TA419 since at least April 2025, observing campaigns against US and Japanese think tanks, defense contractors, universities, and legal organizations.
Chinese Hackers Posing as Anthropic Employee
In February 2026, TA419 posed as a senior Anthropic employee while contacting an AI policy analyst at a US think tank. The message carried the subject “Request for Feedback on Military Integration of Claude,” drawing on the public debate over military use of Anthropic’s AI models.
The campaign expanded in July. Beginning July 8, the attackers impersonated Lynne Edwards Parker, a former senior White House science and technology official, and economist Heidi Crebo-Rediker.
Messages invited recipients to join a fictitious “AI Policy Advisory Committee” or contribute to a Senate foreign relations report covering AI export controls and supply chains.

The first emails were conversation starters rather than immediate login requests. Once a recipient replied, TA419 sent a shortened link claiming to provide further information. This patient approach made the later document-sharing request appear connected to an established professional exchange.
According to the supplied Proofpoint findings, the shortened links passed through attacker-controlled websites. The first domain, driftshare[.]co, displayed a fake OneDrive loading screen and ran a Cloudflare Turnstile check before directing visitors to globalfileshareplatform[.]com, which hosted the credential phishing flow.
The attack combined adversary-in-the-middle, or AitM, phishing with a modified Frameless BitB toolkit. Browser-in-the-Browser creates a fake browser window inside a webpage, including a convincing address bar. Frameless BitB avoids iframes and supports Evilginx-based proxying of Microsoft login pages.
TA419 targeted Microsoft 365 and Entra ID through Microsoft’s OfficeHome application. Instead of merely copying a login screen, the proxy relayed the genuine Microsoft sign-in process while adding malicious scripts. This allowed supported password and MFA steps to complete while the attacker captured the resulting session cookies.
The script /secondary/script.js built a OneDrive-style document listing inside a Shadow DOM, a separate section of the page’s structure. Another script, /primary/script.js, watched document clicks and permission warnings, then displayed the fake Chrome login window.

A custom module, /secondary/observe.js, tracked each target’s progress through authentication. It also automatically accepted “Keep me signed in” and submitted validated one-time codes. The goal was a usable cloud session, not simply a stolen password.
TA419 used Cloudflare to hide backend hosting addresses and commonly registered cloud-sharing-themed domains through NameSilo. Email headers also exposed likely attacker-controlled servers, including 108.61.163[.]187. Shared self-signed certificates suggested a possible anonymization network, although that connection remains an assessment.
Related Cybersecurity News coverage of Browser-in-the-Browser phishing explains why familiar login windows cannot establish trust. Organizations should verify unexpected invitations independently, deploy phishing-resistant authentication, investigate unusual cloud sessions, and revoke suspicious tokens.
Earlier SugarGh0st attacks against AI researchers show that AI expertise remains an intelligence target. Public reporting does not establish whether TA419 successfully compromised these accounts.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.