Security2 publishers2 min readPublished
TA419 courts AI policy experts before phishing their cloud accounts
Proofpoint says China-aligned TA419 has posed as a former White House official and an Anthropic employee to phish AI policy experts since at least April 2025. The first approach asks for nothing; the credential-stealing link follows only after a target replies.
The Watch · Security desk
What happened
- From July 8 the emails carried the names of Lynne Parker, a former White House science-office deputy director, and economist Heidi Crebo-Rediker, with invitations to a made-up AI Policy Advisory Committee or an export-controls report.
- A February campaign used the identity of a senior Anthropic employee to ask a US think-tank analyst for feedback on the military's use of Anthropic's Claude models.
- The spoofed Microsoft OneDrive sign-in page is an adversary-in-the-middle proxy built from Frameless BitB, an open-source kit that draws a fake browser window inside a webpage.
- Because the proxy forwards each login to Microsoft in real time, the password, MFA code and conditional-access checks all pass, and TA419 walks away with the session cookies.
- The group also registered web domains resembling the Heritage Foundation, the World Economic Forum and the Japan-Taiwan Exchange Association.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure The target set is the AI policy community itself: think tank, university and law firm staff whose cloud accounts hold export-control and national-security work.
- constraint A password plus an MFA prompt no longer protects these accounts against the proxy; Proofpoint says defenders need phishing-resistant sign-in such as passkeys.
- precedent Proofpoint expects TA419 to keep impersonating real experts, so a credible invitation from a known name is a standing attack vector in this field.
The kit does more than copy a login screen. Proofpoint says TA419 added a module that tracks where each victim sits in the login flow, ticks "Keep me signed in" automatically so the stolen session lasts longer, and enters one-time codes the moment Microsoft accepts them [12]. The shortened link bounces through several redirects before it reaches the fake OneDrive page [9].
October 1 was the first public account of TA419 [4]. The report does not identify a victim or say whether any account was taken [13]. It does not directly tie the group to the Chinese government, and China has repeatedly denied conducting cyber espionage while accusing the United States of the same [15]. Proofpoint says the campaigns likely feed Chinese intelligence collection on how US AI policy and export controls are developing [16], and it describes the AI targeting as an extension of the group's existing work on defense, national security and foreign policy [20]. The White House and several AI companies have separately accused China of distilling US models to power Chinese open-weight systems [21].
The tactic has a recent precedent. A House committee said Chinese state-linked actors used the same approach in 2025, impersonating Congressman John Moolenaar [17].
Proofpoint's guidance to the people being targeted is to treat the friendly first email as the attack. "Individual targets in scope of TA419 activity should treat unsolicited subject-matter outreach as a plausible pretext stage," the company wrote, "and seek to verify the legitimacy of such unexpected communications via another independent medium." [19]
What to watch
- Whether Proofpoint or others attribute TA419 to a specific Chinese agency, which the current report does not do.
- Whether any named victim or confirmed account takeover surfaces from this campaign.
- Whether the group rotates to new impersonated names or new lures beyond the advisory-committee and export-controls pretexts.