National Cyber Warfare Foundation (NCWF)

AI policy circles targeted in China-linked phishing operation


0 user ratings
2026-10-01 14:16:50
milo
Blue Team (CND)

Cybersecurity firm Proofpoint said TA419 impersonated officials and AI industry figures in an effort to gain access to cloud accounts held by U.S. think tank, university and legal-sector experts.


The post AI policy circles targeted in China-linked phishing operation appeared first on CyberScoop.



A China-aligned cyber espionage group targeted U.S. artificial intelligence policy experts through phishing emails that impersonated prominent officials, economists and an employee of AI company Anthropic, according to research released Thursday by Proofpoint.





The campaigns, which the cybersecurity company attributed to a group it calls TA419, sought access to cloud accounts held by people at think tanks, universities and law firms. The activity comes amid growing U.S.-China competition over AI development, export controls, semiconductor supply chains and military uses of the technology.





Proofpoint said the group began a campaign in July by impersonating Lynne Parker, a former principal deputy director of the White House Office of Science and Technology Policy, and economist and foreign policy expert Heidi Crebo-Rediker. The emails invited recipients to join a supposed AI policy advisory committee or contribute to a report on AI export controls and supply chains.





The initial messages did not immediately request passwords or direct recipients to a sign-in page. Instead, they appeared designed to begin a conversation and establish trust. After a target replied, the group sent a shortened link said to contain more information.





The link redirected recipients through several websites before leading to a false Microsoft OneDrive sign-in page. Proofpoint said the setup was intended to capture account credentials and active browser sessions.





The firm described the operation as an adversary-in-the-middle phishing attack. In such attacks, the victim interacts with genuine Microsoft infrastructure during part of the process, looking and behaving like a legitimate sign-in. The person may enter a password, complete a multifactor authentication prompt and pass access checks while the attacker captures the session information created by the login.





Proofpoint said TA419 used a modified version of an open-source phishing tool known as Frameless BitB. The tool creates a false browser window within a webpage, imitating a familiar sign-in prompt. In this case, it was used to present a fake Microsoft login window over a page that resembled a OneDrive document-sharing site.





Proofpoint also identified a February campaign in which the same group impersonated a senior Anthropic employee. That message asked an AI policy analyst at a U.S. think tank for feedback on the military’s use of Anthropic’s Claude AI models, which was a highly controversial topic at time.





The report did not identify victims or state whether any accounts were compromised.





Proofpoint said TA419 has targeted individuals connected to U.S. and Japanese think tanks, defense contractors, universities and law firms since at least April 2025. Its interest in AI policy, the firm said, appears to extend an existing focus on defense, national security, energy, international relations and foreign policy. The group also registered domains resembling real organizations, including the Heritage Foundation, the World Economic Forum and the Japan-Taiwan Exchange Association.





The report does not directly link the activity to the Chinese government. China has repeatedly denied conducting cyber espionage, while accusing the United States of cyber operations against Chinese interests.





The White House, along with several AI companies, have also accused China of distilling U.S. models in order to power open-weight models run by Chinese companies.

Indicators of compromise can be found on Proofpoint’s website.


The post AI policy circles targeted in China-linked phishing operation appeared first on CyberScoop.



Source: CyberScoop
Source Link: https://cyberscoop.com/china-cyber-espionage-ta419-phishing-us-ai-policy-experts/


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.