Overview
Proofpoint has attributed a sustained credential phishing campaign against U.S. AI policy professionals to TA419, a China-aligned espionage actor active since at least April 2025. The group has targeted individuals at think tanks, universities, defence contractors, and law firms in both the U.S. and Japan. Campaigns intensified in early 2026, with a notable February operation impersonating an Anthropic employee to reach an AI policy expert at a U.S. think tank — using the subject line “Request for Feedback on Military Integration of Claude” as a social engineering lure. The intelligence objective appears to be monitoring U.S. AI regulatory posture, export control developments, and policy positions amid escalating U.S.-China strategic competition.
Technical Analysis
TA419’s attack chain is multi-stage and operationally careful. Initial contact is a benign-seeming invitation email designed solely to establish trust. Only after the target responds does the actor deliver the payload: a shortened URL initiating a multi-stage redirect chain. The chain passes through a Cloudflare Turnstile CAPTCHA — likely to frustrate automated sandbox analysis — before landing on an OneDrive-hosted adversary-in-the-middle (AitM) phishing page.
The page implements Frameless BitB (Browser-in-the-Browser), a variant of the classic BitB technique that spoofs a legitimate Microsoft login window using only HTML, CSS, and JavaScript — critically, without relying on an <iframe> element. This evasion makes it harder for security tools that inspect iframe origins to detect the fake login surface. TA419 has extended an open-source Frameless BitB toolkit with a custom telemetry and automation module that:
- Tracks the victim’s Microsoft sign-in flow in real time.
- Captures submitted credentials via the AitM proxy.
- Relays the authentication to genuine Microsoft infrastructure, completing the login successfully.
- Silently exfiltrates the resulting authenticated session cookies.
Because sign-in succeeds from the victim’s perspective, no error messages or anomalies appear, dramatically reducing the chance of detection or reporting.
Framework Mapping
- AML.T0113 – Steal Web Session Cookie: The core objective is silent session token harvesting via AitM proxy to enable post-authentication access without re-authenticating.
- AML.T0012 – Valid Accounts: Harvested credentials and session cookies enable adversary access using legitimate account artefacts.
- AML.T0088 – Generate Deepfakes / Impersonation: Impersonating named Anthropic staff, economists, and former White House officials constitutes targeted social engineering consistent with identity fabrication at scale.
- LLM06 – Sensitive Information Disclosure: The ultimate intelligence target is sensitive AI policy deliberations, potentially including communications about AI model governance and export restrictions.
Impact Assessment
The targeting of AI policy professionals represents a direct intelligence threat to the integrity of U.S. AI governance processes. Compromised accounts at think tanks and universities could expose pre-publication research, internal policy positions, and communications with government officials. The impersonation of an Anthropic employee specifically suggests TA419 is tracking frontier AI lab activities and their intersection with national security policy — a high-value espionage target.
Mitigation & Recommendations
- Deploy FIDO2/hardware security keys for all Microsoft 365 accounts; these are resistant to AitM session cookie theft because authentication is bound to the origin domain.
- Enable Microsoft Entra ID Conditional Access policies requiring device compliance and continuous access evaluation to invalidate stolen session tokens.
- Educate high-risk personnel (policy researchers, legal staff) on multi-stage phishing chains that begin with innocuous outreach before delivering a malicious URL.
- Block or alert on URL shorteners arriving via email, particularly when followed by Cloudflare Turnstile challenges to external OneDrive links.
- Monitor for impossible travel or session anomalies in Microsoft 365 audit logs that may indicate cookie replay from attacker infrastructure.