Proofpoint said the group began a campaign in July by impersonating Lynne Parker, a former principal deputy director of the White House Office of Science and Technology Policy, and economist and foreign policy expert Heidi Crebo-Rediker.
How the campaign opened: trusted voices, slow build
According to research released by Proofpoint, the operation began with carefully worded phishing emails that impersonated prominent figures in U.S. AI policy circles. The initial messages invited recipients to join a supposed AI policy advisory committee or to contribute to a report on AI export controls and semiconductor supply chains. Crucially, those first messages did not ask for passwords or immediately direct recipients to a sign-in page; they appeared designed to start a conversation and build trust.
Adversary-in-the-middle technique and Frameless BitB
Proofpoint described the setup as an adversary-in-the-middle phishing attack. After a target replied to the initial message, the operator sent a shortened link said to contain more information. That link redirected recipients through several websites before landing on a false Microsoft OneDrive sign-in page. The firm said the configuration was intended to capture both account credentials and active browser sessions — meaning the victim could interact with genuine Microsoft infrastructure during part of the process while the attacker intercepted the resulting session information.
Proofpoint identified the use of a modified version of an open-source phishing tool known as Frameless BitB. The tool creates a false browser window within a webpage to imitate a familiar sign-in prompt; in this campaign it was used to present a fake Microsoft login window over a page that resembled a OneDrive document-sharing site.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageTargets and scope: AI policy experts, think tanks, law firms, defense-related contacts
The company attributed the campaigns to a group it calls TA419 and said the activity sought access to cloud accounts held by people at think tanks, universities and law firms. Proofpoint reported TA419 has targeted individuals connected to U.S. and Japanese think tanks, defense contractors, universities and law firms since at least April 2025. The report did not identify specific victims or state whether any accounts were successfully compromised.
Proofpoint also found that the group registered domains resembling real organizations, including the Heritage Foundation, the World Economic Forum and the Japan-Taiwan Exchange Association, consistent with an effort to appear legitimate to targets in policy networks.
February lure: impersonating an Anthropic employee and the military-use angle
Proofpoint said it identified an earlier campaign in February in which the same group impersonated a senior Anthropic employee. That message asked an AI policy analyst at a U.S. think tank for feedback on the military’s use of Anthropic’s Claude AI models — a topic the report notes was highly controversial at the time. The message pattern mirrors the July campaign: an initial outreach framed as a professional solicitation followed by a redirected sign-in to capture account access.
How policymakers, technologists, and think tanks should react
- Policymakers and regulators: Expect attempts to influence or infiltrate advisory and reporting channels. Proofpoint’s finding that messages were framed around advisory committees and export-control reporting indicates attackers are targeting policy-discussion vectors, not just technical accounts.
- Technologists and security teams: Watch for adversary-in-the-middle flows that use genuine Microsoft infrastructure during the login experience, and for modified open-source tooling such as Frameless BitB used to present fake sign-in prompts. Proofpoint posted indicators of compromise on its website.
- Think tanks, universities and law firms: Be cautious of incoming invitations to join committees or to comment on high-profile controversies. The campaign relied on initial, low-friction contact to build legitimacy before delivering a malicious link.
Proofpoint’s report stops short of a direct attribution to the Chinese government; the firm described the actor as China-aligned, and the report does not link the activity directly to state authorities. The company also noted the broader context in which the White House and several AI companies have accused China of distilling U.S. models to power open-weight models, and that China has repeatedly denied conducting cyber espionage while accusing the United States of cyber operations against Chinese interests.
Proofpoint did not name victims or confirm whether any accounts were taken. Indicators of compromise are posted on Proofpoint’s site for organizations seeking technical details and defensive steps. The immediate questions left by the report are concrete: which accounts, if any, were captured through these adversary-in-the-middle flows, and whether the conversations initiated by the fake solicitations produced actionable intelligence. For now, the evidence in Proofpoint’s report points to a patient, social-engineering-driven effort to reach into AI policy networks rather than a blunt mass-phishing blast.
Original reporting: https://cyberscoop.com/china-cyber-espionage-ta419-phishing-us-ai-policy-experts/




