Skip to content

Build1 publisher2 min readPublished

China-aligned TA419 phishes US AI policy experts through a proxy that captures Microsoft session cookies

Proofpoint says China-aligned TA419 has phished US AI policy experts since April 2025 with a proxy that captures Microsoft session cookies and bypasses MFA. Its fix is passkeys plus out-of-band checks on unsolicited expert outreach.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • In February 2026 the group posed as a prominent Anthropic employee to reach a US think-tank AI policy expert, under the subject line 'Request for Feedback on Military Integration of Claude.'
  • By July 2026 it had moved to impersonating a former member of the White House Office of Science and Technology Policy leadership team.
  • No link appears in the opening email, and the malicious shortened URL arrives only after the target replies and the thread already looks familiar.
  • The shortened link runs a multi-stage redirection chain through a Cloudflare Turnstile check before reaching a OneDrive-themed credential page.
  • Proofpoint says the targets sit at US- and Japan-based think tanks, defense contractors, universities and law firms.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • decision For anyone with a US or Japan nexus working on defense, export controls or AI regulation, an unsolicited invitation from a named expert can no longer be trusted on sender identity alone.
  • exposure The payoff is the mailbox itself: pre-publication policy drafts, correspondence with officials, and the contacts that reveal who advises whom.
  • constraint Because Turnstile sits in front of the kit, URL scanners and sandbox detonation usually log the challenge page, not the phishing page, so automated analysis misses it.
  • capability The redirect chain lets the operator swap the hosting behind the short link, so taking down one phishing host does not disarm a lure already in someone's inbox.

Standard MFA fails here because of where the proxy sits. The adversary-in-the-middle page relays the victim's login to Microsoft as it happens. The victim types the password and clears the second factor against the real sign-in page, and the proxy keeps the session cookie Microsoft issues [4]. That cookie is a bearer token: whoever holds it is signed in, with no further challenge. A second factor entered during that login does not change the outcome, because it was spent on the genuine site at the moment the victim typed it. Proofpoint says the sign-in looks normal and successful, and the victim sees nothing wrong [4].

The fix Proofpoint names is a change of credential type: phishing-resistant authentication such as passkeys, with out-of-band verification of unsolicited subject-matter outreach [16]. That follows from the cookie. A credential that never produces a replayable secret gives the relay proxy nothing to carry to the real server.

The pretext is chosen to fit the reader. Proofpoint says an AI policy researcher both anticipates and wants to reply to a message seeking their expert input on how the military might use a frontier model, and impersonating a named Anthropic employee or a former OSTP leader lends it credibility a generic lure would lack [19].

The final page uses Frameless browser-in-the-browser. Classic BitB draws a fake browser window inside the real one with HTML, CSS and JavaScript and loads the fake sign-in page in an iframe; the frameless version produces the same picture without the iframe, so it drops a common detection anchor [13]. Security researcher Wael Masri described the technique in January 2024 as "injecting scripts and HTML besides the original content using search and replace (aka substitutions), then relying completely on HTML/CSS/JS tricks to make the visual effect" [14]. Proofpoint reports that TA419 extended this open-source tool [15].

TA419's standing interests are defense, national security, energy, international relations and foreign policy [17], and Proofpoint calls the move into AI policy "an extension of that remit rather than a departure from it" [6]. Proofpoint ties the activity to Chinese intelligence interest in how the US writes AI policy and regulation, a field that now runs through strategic competition, accusations of model distillation, and export controls between the two countries [7][18]. The targets brief lawmakers, draft frameworks, and advise on export policy [8].

What to watch

  • Whether the targeted think tanks and their email providers move the exposed identities to passkeys, and how quickly.
  • Whether TA419 drops the Anthropic and OSTP personas once they are burned and reaches for new named experts.
  • Whether the extended Frameless BitB kit shows up in campaigns run by other China-aligned groups.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories