Breaking
Cyber CrimeDeveloping Story

China-Linked Group Poses as AI Policy Experts

Proofpoint says TA419 has impersonated AI policy figures and economists since at least April 2025 to steal credentials from US think tank staff.

··2 hours ago·5 min read
person using laptop computers
Photo by Jefferson Santos on Unsplash

For anyone working on AI policy inside a Washington think tank or university, an email from a famous economist or a White House science adviser should be routine. But according to new research from Proofpoint, a China-aligned hacking group has turned that routine into a trap. Since at least April 2025, the group tracked as TA419 has been impersonating real AI policy experts and economists to steal Microsoft 365 login credentials from staff at US think tanks, defense contractors, universities and law firms, the company said in research published October 1.

The report is the first public account of TA419, which Proofpoint has linked to Chinese intelligence-gathering interests. The victims are not random: they are people whose work touches AI regulation, export controls and national security policy — the exact subject areas where the US and China are competing.

Invented Committees, Real Names

TA419's approach starts with a low-friction invitation. According to Proofpoint, the group sent emails in the name of Lynne Parker, who served as principal deputy director of the White House Office of Science and Technology Policy, and later economist and foreign policy expert Heidi Crebo-Rediker. The messages invited targets to join a made-up "AI Policy Advisory Committee" or to help with a Senate Committee on Foreign Relations report on AI export controls. From July 8, those emails used Parker's and Crebo-Rediker's identities, the company said. Earlier, in February, TA419 had used the identity of a senior Anthropic employee to contact a think-tank analyst working on AI policy.

The pitches were designed to sound harmless — committee service and research assistance are normal asks among policy specialists. Only after a target replied did the attackers send a shortened link that bounced through several redirects to a spoofed OneDrive login page.

A Phishing Kit That Hijacks Live Sessions

That page is not a static fake login form. Proofpoint describes it as an adversary-in-the-middle reverse proxy assembled from Frameless BitB, an open-source kit that draws a fake browser window inside the page. Because the proxy forwards the victim's Microsoft 365 login to Microsoft in real time, the password, multifactor authentication (MFA) code and conditional access checks all pass — and TA419 walks away with the session cookies.

The group also customized the kit. Proofpoint said TA419 bolted on its own module to monitor where each victim is in the login process. It automatically ticks "Keep me signed in" so the stolen session lasts longer, and enters one-time codes the moment they are accepted. Those additions make the theft more reliable and extend how long an attacker can stay inside a compromised account.

"Individual targets in scope of TA419 activity should treat unsolicited subject-matter outreach as a plausible pretext stage, and seek to verify the legitimacy of such unexpected communications via another independent medium."

— Proofpoint, in research published October 1

Why AI Policy Is the Target

Proofpoint believes the campaigns likely feed Chinese intelligence gathering on how US AI policy and regulation are developing, amid US-China rivalry over export controls and model distillation. In that reading, the stolen credentials are less about financial gain and more about insight — access to the inboxes and documents of people shaping AI rules.

The company sees the AI targeting as an extension of TA419's focus on defense, national security, energy and foreign policy, and expects the group to continue impersonating real experts. The pattern is not unique to TA419: a House committee said Chinese state-linked actors used similar tactics in 2025, impersonating Congressman John Moolenaar.

What Proofpoint Is Telling Defenders

Proofpoint advised organizations to adopt phishing-resistant sign-in methods such as passkeys. That recommendation targets the core of the attack: an AitM proxy can relay passwords and MFA codes, but a passkey bound to a device is far harder to replay through a fake login page.

For individuals, the guidance is to slow down. Unsolicited subject-matter outreach — even from a name you recognize — should be treated as a possible pretext, and verified through a separate channel before any link is clicked. Proofpoint's wording on this point is unusually direct, describing individual targets as being in scope and urging them to confirm unexpected communications via another independent medium.

The Technical Details That Matter

Several elements of TA419's kit are worth noting for defenders reviewing their own exposure.

  • The campaign has been running since at least April 2025.
  • Proofpoint tracks the group as TA419.
  • Emails using Lynne Parker's and Heidi Crebo-Rediker's identities were sent from July 8.
  • In February, TA419 used the identity of a senior Anthropic employee to contact a think-tank analyst.
  • Targets included staff at think tanks, defense contractors, universities and law firms in the US and Japan.

The use of a shortened link that passes through multiple redirects is a common way to obscure the final destination from both the recipient and some email security tools. Once the victim lands on the spoofed OneDrive page, the Frameless BitB kit presents a browser-within-a-browser, which can make the fake login look more convincing.

MFA Is Not a Complete Answer

TA419's success depends on the fact that MFA codes can be relayed in real time. When the reverse proxy forwards the victim's credentials to Microsoft, the service sees a legitimate login and issues the expected prompts; the attacker's module captures the code as it is entered. Conditional access checks tied to device or location can also pass because the traffic originates from the victim's own browser session.

That is why Proofpoint's advice centers on phishing-resistant methods rather than simply adding another factor. Passkeys and similar approaches reduce the value of a relayed password or one-time code, because the authentication is tied to a key the attacker does not hold.

What Happens Next

Proofpoint said it expects TA419 to keep impersonating real experts. The group's playbook — borrow a credible name, offer a plausible policy task, then deliver a credential-stealing link — is cheap to run and scales across many targets.

For the think tanks, universities, defense contractors and law firms in the group's sights, the immediate question is whether their staff can recognize a well-crafted pretext when it arrives. The answer increasingly depends on whether the organization has moved past passwords and codes toward sign-in methods that cannot be relayed through a proxy.

According to the research, the AI policy community is now part of that target set — not as a side effect, but as a deliberate focus.

#ta419#china#phishing#aitm#ai policy#proofpoint

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories