LIVE FEED
FIRST LOOK Meta AI Agent Autonomously Emails Researchers, Explains Actions // HIGH OpenAI Safety Culture Failures Tied to Rogue Agent Swarm Attacks // HIGH TA419 AitM Phishing Targets US AI Policy Experts via Microsoft // MEDIUM Anthropic Reports Claude User to Police Over Diary Threat // FIRST LOOK Google Gemini Adds Full Mac File and App Access for Desktop Agents // FIRST LOOK doxx.net Launches ADN Platform to Govern AI Agents Online // FIRST LOOK AWS and Google Cloud Launch Hard Spend Caps for AI Agent Workloads // HIGH Microsoft: Attackers Gaining AI Edge in Vulnerability Exploitation // FIRST LOOK ServiceNow Releases AutoSynthData for Enterprise Agent Training // FIRST LOOK Apple Tightens macOS Full Disk Access Controls for AI Agents //
ATLAS OWASP HIGH Significant risk · Prioritise patching RELEVANCE ▲ 7.8

TA419 AitM Phishing Targets US AI Policy Experts via Microsoft

TL;DR HIGH
  • What happened: China-aligned TA419 uses AitM phishing to steal credentials from U.S. AI policy professionals.
  • Who's at risk: AI policy researchers, think tank staff, university academics, and legal professionals working on U.S. AI regulation and defence are primary targets.
  • Act now: Enforce phishing-resistant MFA (FIDO2/hardware keys) for all Microsoft 365 accounts to prevent session cookie reuse · Train AI policy staff to verify unsolicited collaboration requests via out-of-band channels before clicking any links · Deploy conditional access policies that bind session tokens to device compliance state to reduce AitM cookie replay risk
TA419 AitM Phishing Targets US AI Policy Experts via Microsoft

Overview

Proofpoint has attributed a sustained credential phishing campaign against U.S. AI policy professionals to TA419, a China-aligned espionage actor active since at least April 2025. The group has targeted individuals at think tanks, universities, defence contractors, and law firms in both the U.S. and Japan. Campaigns intensified in early 2026, with a notable February operation impersonating an Anthropic employee to reach an AI policy expert at a U.S. think tank — using the subject line “Request for Feedback on Military Integration of Claude” as a social engineering lure. The intelligence objective appears to be monitoring U.S. AI regulatory posture, export control developments, and policy positions amid escalating U.S.-China strategic competition.

Technical Analysis

TA419’s attack chain is multi-stage and operationally careful. Initial contact is a benign-seeming invitation email designed solely to establish trust. Only after the target responds does the actor deliver the payload: a shortened URL initiating a multi-stage redirect chain. The chain passes through a Cloudflare Turnstile CAPTCHA — likely to frustrate automated sandbox analysis — before landing on an OneDrive-hosted adversary-in-the-middle (AitM) phishing page.

The page implements Frameless BitB (Browser-in-the-Browser), a variant of the classic BitB technique that spoofs a legitimate Microsoft login window using only HTML, CSS, and JavaScript — critically, without relying on an <iframe> element. This evasion makes it harder for security tools that inspect iframe origins to detect the fake login surface. TA419 has extended an open-source Frameless BitB toolkit with a custom telemetry and automation module that:

  1. Tracks the victim’s Microsoft sign-in flow in real time.
  2. Captures submitted credentials via the AitM proxy.
  3. Relays the authentication to genuine Microsoft infrastructure, completing the login successfully.
  4. Silently exfiltrates the resulting authenticated session cookies.

Because sign-in succeeds from the victim’s perspective, no error messages or anomalies appear, dramatically reducing the chance of detection or reporting.

Framework Mapping

  • AML.T0113 – Steal Web Session Cookie: The core objective is silent session token harvesting via AitM proxy to enable post-authentication access without re-authenticating.
  • AML.T0012 – Valid Accounts: Harvested credentials and session cookies enable adversary access using legitimate account artefacts.
  • AML.T0088 – Generate Deepfakes / Impersonation: Impersonating named Anthropic staff, economists, and former White House officials constitutes targeted social engineering consistent with identity fabrication at scale.
  • LLM06 – Sensitive Information Disclosure: The ultimate intelligence target is sensitive AI policy deliberations, potentially including communications about AI model governance and export restrictions.

Impact Assessment

The targeting of AI policy professionals represents a direct intelligence threat to the integrity of U.S. AI governance processes. Compromised accounts at think tanks and universities could expose pre-publication research, internal policy positions, and communications with government officials. The impersonation of an Anthropic employee specifically suggests TA419 is tracking frontier AI lab activities and their intersection with national security policy — a high-value espionage target.

Mitigation & Recommendations

  • Deploy FIDO2/hardware security keys for all Microsoft 365 accounts; these are resistant to AitM session cookie theft because authentication is bound to the origin domain.
  • Enable Microsoft Entra ID Conditional Access policies requiring device compliance and continuous access evaluation to invalidate stolen session tokens.
  • Educate high-risk personnel (policy researchers, legal staff) on multi-stage phishing chains that begin with innocuous outreach before delivering a malicious URL.
  • Block or alert on URL shorteners arriving via email, particularly when followed by Cloudflare Turnstile challenges to external OneDrive links.
  • Monitor for impossible travel or session anomalies in Microsoft 365 audit logs that may indicate cookie replay from attacker infrastructure.

References

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.