AI policy circles targeted in China-linked phishing operation
China-aligned TA419 ran adversary-in-the-middle phishing campaigns impersonating officials and an Anthropic staffer to steal credentials from U.S. AI policy experts.
Proofpoint attributed phishing campaigns to China-aligned group TA419 targeting U.S. AI policy experts at think tanks, universities, and law firms since at least April 2025. A July campaign impersonated former White House OSTP official Lynne Parker and economist Heidi Crebo-Rediker, using a modified open-source Frameless BitB tool to present fake Microsoft OneDrive sign-in pages that captured credentials and active browser sessions. A February campaign impersonated a senior Anthropic employee to solicit feedback on military use of Claude models. No victims or compromises were confirmed, and Proofpoint did not directly link the activity to the Chinese government.
- TA419 targeted U.S. AI policy experts at think tanks, universities, and law firms
- AiTM phishing used modified Frameless BitB to steal credentials and sessions via fake OneDrive pages
- February campaign impersonated a senior Anthropic employee regarding Claude military use
- Group registered spoofed domains mimicking Heritage Foundation, WEF, and Japan-Taiwan Exchange Association
- Active since at least April 2025 against U.S. and Japanese institutions
Full article950 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Cybersecurity firm Proofpoint said TA419 impersonated officials and AI industry figures in an effort to gain access to cloud accounts held by U.S. think tank, university and legal-sector experts.
A China-aligned cyber espionage group targeted U.S. artificial intelligence policy experts through phishing emails that impersonated prominent officials, economists and an employee of AI company Anthropic, according to research released Thursday by Proofpoint.
The campaigns, which the cybersecurity company attributed to a group it calls TA419, sought access to cloud accounts held by people at think tanks, universities and law firms. The activity comes amid growing U.S.-China competition over AI development, export controls, semiconductor supply chains and military uses of the technology.
Proofpoint said the group began a campaign in July by impersonating Lynne Parker, a former principal deputy director of the White House Office of Science and Technology Policy, and economist and foreign policy expert Heidi Crebo-Rediker. The emails invited recipients to join a supposed AI policy advisory committee or contribute to a report on AI export controls and supply chains.
The initial messages did not immediately request passwords or direct recipients to a sign-in page. Instead, they appeared designed to begin a conversation and establish trust. After a target replied, the group sent a shortened link said to contain more information.
The link redirected recipients through several websites before leading to a false Microsoft OneDrive sign-in page. Proofpoint said the setup was intended to capture account credentials and active browser sessions.
The firm described the operation as an adversary-in-the-middle phishing attack. In such attacks, the victim interacts with genuine Microsoft infrastructure during part of the process, looking and behaving like a legitimate sign-in. The person may enter a password, complete a multifactor authentication prompt and pass access checks while the attacker captures the session information created by the login.
Proofpoint said TA419 used a modified version of an open-source phishing tool known as Frameless BitB. The tool creates a false browser window within a webpage, imitating a familiar sign-in prompt. In this case, it was used to present a fake Microsoft login window over a page that resembled a OneDrive document-sharing site.
Proofpoint also identified a February campaign in which the same group impersonated a senior Anthropic employee. That message asked an AI policy analyst at a U.S. think tank for feedback on the military’s use of Anthropic’s Claude AI models, which was a highly controversial topic at time.
The report did not identify victims or state whether any accounts were compromised.
Proofpoint said TA419 has targeted individuals connected to U.S. and Japanese think tanks, defense contractors, universities and law firms since at least April 2025. Its interest in AI policy, the firm said, appears to extend an existing focus on defense, national security, energy, international relations and foreign policy. The group also registered domains resembling real organizations, including the Heritage Foundation, the World Economic Forum and the Japan-Taiwan Exchange Association.
The report does not directly link the activity to the Chinese government. China has repeatedly denied conducting cyber espionage, while accusing the United States of cyber operations against Chinese interests.
The White House, along with several AI companies, have also accused China of distilling U.S. models in order to power open-weight models run by Chinese companies.
Indicators of compromise can be found on Proofpoint’s website.
More Scoops
Citing China, President Trump doubles down on hands-off approach to AI regulation
Following a series of chaotic agentic hacks, Trump and administration officials have consistently expressed fears of Chinese AI dominance in pushing for fewer regulations.
AI lets small actors run state-level hacking campaigns, Anthropic report finds
Feds accuse China of ‘systematic’ distillation of U.S. AI models
Latest Podcasts
Government
As AI world debates security, NVIDIA releases open source tools for agents
ShinyHunters trades financial extortion for a reckless war of ego with the FBI
Supreme Court permits states to use SAVE database for citizenship checks
House and Senate members propose legislation for CISA to step up cyber defenses for biotech
Technology
Threats
Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
Alleged ShinyHunters leader arrested in the Netherlands
Kiteworks lifts shutdown advisory after 'credible threat intelligence' from federal authorities
Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings
Policy
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks
Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack
The president has called for AI leadership. Here’s the mission.
After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program