China-Linked TA419 Phishes U.S. AI Policy Experts — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- TA419 impersonated a prominent Anthropic employee and other AI policymakers with a February 2026 phishing email titled "Request for Feedback on Military Integration of Claude" aimed at a U.S. think tank AI policy expert.
- Proofpoint attributed the activity to TA419, a China-aligned espionage group that has targeted U.S. and Japan-based think tanks, defense contractors, universities, and law firms since at least April 2025.
- TA419 later impersonated a former White House Office of Science and Technology Policy leader around July 2026 in additional credential phishing campaigns targeting AI policy experts.
- The attack chain routes targets via shortened URLs through a Cloudflare Turnstile check to a OneDrive adversary-in-the-middle phishing page using a "Frameless BitB" technique that spoofs Microsoft sign-in without iframes.
- TA419 added bespoke telemetry and automation to the open-source Frameless BitB tool to capture session cookies while relaying credentials to legitimate Microsoft infrastructure, leaving victims unaware anything was amiss.
- Proofpoint recommended phishing-resistant methods like passkeys and warned that AI policy experts should verify unsolicited contacts before responding.
Why it matters: The impersonation of an Anthropic staffer and a former White House OSTP leader shows Chinese intelligence harvesting credentials of those shaping U.S. AI regulation amid export-control disputes and model-distillation accusations. Because sessions are stolen invisibly through real Microsoft infrastructure, affected experts at think tanks may have had inboxes accessed without any visible signs of compromise.
Ask SkimNews




