China-Aligned TA419 Targets US AI Policy Experts by Impersonating Anthropic Staff and Policymakers
A China-aligned cyber espionage group tracked as TA419 has been linked to a series of credential phishing campaigns aimed at artificial intelligence (AI) experts at US think tanks, universities, and legal sector organizations, according to new research from Proofpoint.
Impersonating Trusted Names
The attackers have posed as well-known economists, AI policymakers, and even a prominent Anthropic employee. In one February 2026 campaign, an AI policy expert at a US think tank received a phishing email with the subject line "Request for Feedback on Military Integration of Claude."
Around July 2026, the group reportedly impersonated several more individuals, including a former member of the White House Office of Science and Technology Policy leadership team, to target AI policy professionals in the US.
Proofpoint believes the activity likely supports broader Chinese intelligence goals of understanding how US AI policy and regulation are developing. It comes at a time of intense US-China competition, export controls, and accusations of model distillation.
Who Is TA419
Proofpoint describes TA419 as an espionage-driven, China-aligned threat actor that has been running credential phishing operations since at least April 2025. Its past targets include think tanks, defense contractors, universities, and law firms based in the US and Japan.
How the Attack Works
The campaigns start with harmless-looking invitations designed to build trust. Only after the target replies does the attacker send a shortened URL. This link kicks off a multi-stage redirection chain that passes through a Cloudflare Turnstile check before landing on a fake OneDrive login page built for adversary-in-the-middle (AitM) credential theft.
The page uses a technique called Frameless BitB, a variation of the browser-in-the-browser (BitB) attack. Standard BitB creates a fake browser window inside a real browser session, typically by loading a spoofed login page inside an iframe. Frameless BitB achieves the same visual trick without an iframe, relying instead on injected HTML, CSS, and JavaScript. The technique was first published as an open-source tool by security researcher Wael Masri in January 2024.
According to Proofpoint, TA419 has extended this tool with a custom telemetry and automation module. The module follows the victim's Microsoft sign-in process, captures their credentials through the AitM proxy, and quietly passes the details on to Microsoft's real servers.
Why It Is Hard to Spot
Because the login actually succeeds, victims see nothing unusual. There is no visible sign that their session cookies have been stolen, giving attackers silent access to the account.
Recommendations
Proofpoint advises organizations to adopt phishing-resistant authentication such as passkeys. Individuals in fields targeted by TA419 should be cautious with unsolicited outreach on their area of expertise and verify the sender before engaging further.
Key Takeaway
Proofpoint notes that TA419 has long focused on defense, national security, energy, international relations, and foreign policy targets connected to the US and Japan. The company sees the group's move toward AI policy experts as a natural expansion of that focus rather than a change in direction.