China-Aligned TA419 Phished AI-Policy Experts for Cloud Sessions
Proofpoint says China-aligned TA419 has phished US and Japanese AI-policy circles since April 2025 using impersonation and Microsoft 365 session theft.
Proofpoint's first public report says China-aligned TA419 has conducted credential phishing since at least April 2025 against think tanks, universities, and law firms; Infosecurity also names defense contractors, and Infosecurity and CyberScoop include institutions in the United States and Japan. From July 8, which The Register places in 2026, lures impersonated former White House science or OSTP official Lynne Parker—named Lynne Edwards Parker by The Register—and economist Heidi Crebo-Rediker, while a February campaign impersonated a senior Anthropic employee. CyberScoop and The Register say that Anthropic lure concerned military use of Claude, and Cyber Security News dates the impersonations to 2026, alongside AI-policy and export-control pretexts. Shortened links led to spoofed OneDrive pages; sources describe the kit as Frameless BitB, a modified open-source Frameless BitB tool, or Frameless BitB plus Evilginx, capturing passwords, MFA codes, and session cookies, and The Register adds a Cloudflare Turnstile check and targeting of Microsoft 365 and Entra ID through OfficeHome. CyberScoop also reports spoofed domains mimicking the Heritage Foundation, WEF, and the Japan-Taiwan Exchange Association, and CyberScoop and Cyber Security News say no compromises were confirmed. On attribution, Infosecurity says Proofpoint assesses likely Chinese intelligence gathering, while CyberScoop says Proofpoint did not directly link the activity to the Chinese government; The Register's headline calls the operators suspected Chinese spies and reports advice to use phishing-resistant passkeys such as origin-bound authentication.
- Proofpoint's first public report attributes credential phishing to China-aligned TA419 since at least April 2025.
- Targets include think tanks, universities, and law firms; Infosecurity also names defense contractors, and Infosecurity and CyberScoop include the United States and Japan.
- From July 8, lures impersonated Lynne Parker (The Register: Lynne Edwards Parker), called a former White House science or OSTP official, and economist Heidi Crebo-Rediker; The Register dates that campaign to July 2026.
- A February campaign impersonated a senior Anthropic employee; CyberScoop and The Register say the lure concerned military use of Claude, and Cyber Security News places the impersonations in 2026.
- Spoofed OneDrive pages used Frameless BitB, which Cyber Security News and The Register also tie to Evilginx, to capture Microsoft 365 passwords, MFA codes, and session cookies; The Register adds a Cloudflare Turnstile check and Entra ID…
- CyberScoop says TA419 registered domains spoofing the Heritage Foundation, WEF, and the Japan-Taiwan Exchange Association.
- CyberScoop and Cyber Security News say compromises were not confirmed. Infosecurity says Proofpoint assesses likely Chinese intelligence collection on US AI policy and export controls; CyberScoop says Proofpoint did not directly link the…
- The Register says Proofpoint advises phishing-resistant passkeys such as origin-bound authentication.
Coverage timelineoldest first · each row is one article
- · 3h agoChina-Linked Hackers Impersonate AI Experts to Target US Policy Insiders
Infosecurity Magazine· 76
China-linked TA419 phishes US AI-policy staff using expert impersonation and a Microsoft 365 session-stealing proxy.
- · 3h agoAI policy circles targeted in China-linked phishing operation
CyberScoop· 64
China-aligned TA419 ran adversary-in-the-middle phishing campaigns impersonating officials and an Anthropic staffer to steal credentials from U.S. AI policy experts.
- · 2h agoChinese Hackers Posing as Senior Anthropic Employee Targeting US AI Policy Experts
Cyber Security News· 76