China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
- Published
- Record updated
Summary
Proofpoint attributes a China-aligned, espionage-motivated group it calls TA419 to credential phishing campaigns against AI policy experts at U.S. think tanks, universities and legal organizations. The campaigns impersonate economists, AI policymakers and an Anthropic employee, and in February 2026 targeted a U.S. think tank expert with the subject line "Request for Feedback on Military Integration of Claude." The attackers use a Frameless BitB technique and an OneDrive adversary-in-the-middle page, with a custom module that captures credentials and session cookies while relaying the sign-in to real Microsoft infrastructure.
Mitigation
To safeguard against this threat, organizations are recommended to enable phishing-resistant authentication methods like passkeys, and individual targets who are the focus of TA419 activity should treat unsolicited subject-matter outreach with caution, and verify their authenticity before proceeding further.
Related items
- InfoAnthropic’s AI gave Philadelphia police a fake tip about an unsolved homicideSame vendor · The Verge (AI)
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSame vendor · BleepingComputer
- InfoAnthropic Launches Free AI Vulnerability Scanner for Open-Source ProjectsSame vendor · The Hacker News
- InfoAnthropic bans users from being 'cruel' to its AI systemsSame vendor · BBC Technology
- InfoThe Download: AI’s refusal problem and weight-loss drug side effectsSame vendor · MIT Technology Review