China-Linked TA419 Hits US AI Policy Experts
Proofpoint attributes credential phishing targeting US AI policy experts to China-aligned TA419, which impersonated figures including an Anthropic employee.
A state-linked cyber espionage group has been caught impersonating prominent economists, former White House science officials and at least one Anthropic employee in a phishing operation aimed squarely at the people who shape US artificial intelligence policy. According to enterprise security firm Proofpoint, the activity is focused on AI experts at American think tanks, universities and legal organizations.
The campaign represents a direct bid to get inside the inboxes of the analysts and advisers who draft and debate the rules governing frontier AI. Proofpoint tied the work to a group it calls TA419, an actor it describes as China-aligned and espionage-motivated.
Impersonating the AI Policy World
The operation began with a simple, low-friction approach. TA419 made initial contact through seemingly harmless invitations meant to build rapport with the target, relying on professional courtesy rather than urgency to draw a response. Only after the recipient replied did the real attack machinery start.
One campaign singled out an AI policy expert at a US think tank in February 2026. The phishing email used the subject line "Request for Feedback on Military Integration of Claude." The message leaned on the target's professional interest in AI governance to appear legitimate.
Around July 2026, the group is said to have impersonated several people, including a former member of the White House Office of Science and Technology Policy leadership team, as part of credential phishing efforts aimed at US AI policy experts. The choice of personas suggests a deliberate effort to exploit the trust that flows within policy and research networks.
From Polite Invitation to AitM Trap
When a target responded, the adversary followed up with a shortened URL. That link triggered a multi-stage redirection chain, eventually landing on an OneDrive adversary-in-the-middle (AitM) credential phishing page. Before the page loaded, visitors had to clear a Cloudflare Turnstile check.
The page itself used Frameless BitB, a variant of the browser-in-the-browser attack that spoofs a trusted website or login screen inside a legitimate browser session. BitB works by serving the sign-in page inside an iframe, while Frameless BitB achieves the same effect without using the HTML element. The technique relies on HTML, CSS and JavaScript to make the fake window look real.
"This can be achieved by injecting scripts and HTML besides the original content using search and replace (aka substitutions), then relying completely on HTML/CSS/JS tricks to make the visual effect," security researcher Wael Masri noted back in January 2024.
— Wael Masri, security researcher
According to Proofpoint, TA419 extended this open-source tool with a bespoke telemetry and automation module that tracks the target's Microsoft sign-in flow and captures credential information through the AitM proxy. The stolen details are relayed to the real Microsoft infrastructure in the background, so the victim sees a successful sign-in and no obvious sign that session cookies have been captured.
The Illusion of a Successful Login
The advantage for the attacker is that nothing appears wrong. The sign-in succeeds, the session proceeds normally, and the target has little reason to suspect that their credentials and session cookies were quietly intercepted along the way. That makes follow-on access to email, documents and internal systems possible without tripping the usual user alarms.
That design choice means traditional warnings about "suspicious login pages" may not apply. The victim is not redirected to a broken or obviously fake site; they land on a convincing replica that behaves as expected, while their authentication data is captured in transit.
A Track Record Beyond AI
Proofpoint has described TA419 as a China-aligned and espionage-motivated threat actor with a history of credential phishing campaigns against individuals working for US- and Japan-based think tanks, defense contractors, universities and law firms dating back to at least April 2025.
The group's interests have centered on defense, national security, energy, international relations and foreign policy targets, predominantly with a nexus to the US and Japan. The focus on AI policy experts fits that pattern.
"TA419 has consistently shown an interest in defense, national security, energy, international relations, and foreign policy targets, predominantly with a nexus to the U.S. and Japan," Proofpoint said. "The targeting of AI policy experts represents an extension of that remit rather than a departure from it."
— Proofpoint
Proofpoint framed the broader objective bluntly. In its analysis, the company said the activity likely supports wider Chinese intelligence goals tied to understanding the direction of US AI policy and regulation. The firm noted the campaign is unfolding amid strategic competition, accusations of model distillation and export controls between the US and China.
"This activity likely supports wider Chinese intelligence objectives to better understand ongoing developments within the U.S. AI policy and regulatory landscape and occurs amid intense strategic competition, accusations of model distillation, and export controls involving the U.S. and China," Proofpoint said in an analysis published this week.
— Proofpoint
What TA419 Is After
The targeting pattern points to intelligence collection rather than financial crime. By going after people who study or advise on AI policy, the group appears positioned to gather insight into how Washington is thinking about frontier models, military applications and export rules. The February 2026 email subject line about "Military Integration of Claude" suggests an interest in how commercial AI systems might be used in defense contexts.
Think tanks, universities and legal organizations are attractive because they often hold early drafts, internal debate and unpolished analysis that never appears in public reports. Credential theft at that layer can open email threads, shared drives and calendars that reveal who is talking to whom about AI policy.
Defensive Steps for Targeted Organizations
Proofpoint recommended that organizations enable phishing-resistant authentication methods such as passkeys. It also advised that individuals targeted by TA419 activity should treat unsolicited subject-matter outreach with caution and verify its authenticity before proceeding.
- Organizations are recommended to enable phishing-resistant authentication methods like passkeys.
- Individual targets of TA419 activity should treat unsolicited subject-matter outreach with caution and verify authenticity before proceeding.
- The February 2026 campaign used the subject line "Request for Feedback on Military Integration of Claude."
- TA419 has targeted US- and Japan-based think tanks, defense contractors, universities and law firms since at least April 2025.
The AitM method makes passkeys and other phishing-resistant factors especially valuable, since stolen passwords and session cookies are the currency of this type of attack. Even a careful user can be fooled when the fake page passes a Turnstile check and the real login succeeds.
Why This Matters Beyond the Inbox
The targeting of AI policy experts sits at the intersection of espionage and technology governance. If the reported activity is confirmed, it suggests that foreign intelligence services view the people who shape AI rules as valuable sources of insight into US decision-making. That could mean more scrutiny for think tank staff, academic researchers and legal teams whose work touches AI policy.
For organizations in those spaces, the practical takeaway is that subject-matter outreach from unfamiliar contacts deserves verification, particularly when it arrives with a shortened link and a request to log in. The use of a convincing AitM page means that even a successful sign-in is not proof that nothing went wrong. This could push more institutions toward hardware-backed or passkey-based authentication, though such transitions take time and coordination.
Proofpoint's report attributes the activity to TA419, a group it tracks as China-aligned. As with any single-vendor attribution, independent corroboration may take time, and the full scope of the campaign may not yet be known. What is clear from the published analysis is that the group's methods rely on patience, impersonation and a fake login that looks exactly like the real thing.
For readers in policy, research and legal roles, the most immediate step is to treat unexpected requests for feedback or collaboration as a reason to slow down and confirm the sender through a separate channel. The techniques described by Proofpoint do not require a victim to ignore obvious warning signs; they are designed to remove those signs altogether.
Sources
- The Hacker News Original source
Continue Reading
Banking Scams Shift to Mobile Devices
A new BioCatch report claims 90% of scams now happen on phones, with banking scam attempts up 35% in the past year.
ShinyHunters suspect held in Jordan
A reported detention in Jordan and a week of digital silence are testing the extortion group's resilience.
DTU breach exposes 200k user records
Hackers accessed the Technical University of Denmark's identity system using compromised credentials, potentially exposing data of up to 200,000 people.