Skip to main content
Emerging ThreatsMalware & Ransomware

China-Linked Hackers Impersonate AI Experts to Steal US Policy Insiders' Credentials

Cluttered desk with computer, papers, and books in a workspace, with an unseen person's arm reaching for the keyboard.
"Individual targets in scope of TA419 activity should treat unsolicited subject-matter outreach as a plausible pretext stage," Proofpoint wrote, "and seek to verify the legitimacy of such unexpected communications via another independent medium."

TA419’s impersonation campaign and targets

Proofpoint published research on October 1 that documents a China-aligned group tracked as TA419 conducting credential-phishing campaigns against staff at think tanks, defense contractors, universities and law firms in the United States and Japan. The activity has been ongoing since at least April 2025 and, according to Proofpoint, represents the first public report specifically attributing this set of campaigns to TA419.

From July 8, the adversary impersonated well-known AI policy figures — sending messages in the name of Lynne Parker, who served as principal deputy director of the White House Office of Science and Technology Policy, and later in the identity of economist and foreign policy expert Heidi Crebo-Rediker. In February of the same campaign window, TA419 used the identity of a senior Anthropic employee to contact a think-tank analyst working on AI policy. Initial messages were innocuous invitations — offers to sit on a fabricated "AI Policy Advisory Committee" or to assist with a Senate Committee on Foreign Relations report on AI export controls — designed to elicit a response and trigger the next step of the fraud.

How the phishing kit captures live Microsoft 365 sessions

Proofpoint describes the core technical mechanism as an adversary-in-the-middle (AitM) reverse proxy built from Frameless BitB, an open-source kit that draws a fake browser window inside the page. Victims who replied were given a shortened link that redirected through several hops to a spoofed OneDrive login page.

Because the page forwards the victim’s Microsoft 365 login to Microsoft in real time, the password, multifactor authentication (MFA) code, and conditional access checks all succeed on Microsoft’s side — while TA419 obtains the session cookies. Proofpoint said the group added its own module to track where each victim was in the login process, automatically checked the "Keep me signed in" box so stolen sessions would persist, and promptly entered one-time codes the moment they were accepted. In short: the kit captures fully authenticated sessions, not merely credentials as static text.

Why Proofpoint links the campaign to intelligence collection on AI policy

Proofpoint says the targeting pattern — focusing on AI policy specialists and institutions involved in national security, defense, energy and foreign policy — is consistent with intelligence collection on how U.S. AI policy and regulation are developing. The company explicitly tied the interest in AI policy to wider U.S.–China competition over export controls and model distillation, and characterized the AI-focused activity as an extension of TA419’s existing areas of interest.

The report also notes precedent: a House committee said Chinese state-linked actors used similar impersonation tactics in 2025, when attackers posed as Congressman John Moolenaar. Proofpoint expects TA419 to continue impersonating real experts in further operations.

What this means for technologists, policymakers, and think tanks

  • Technologists and security teams: Proofpoint advised organizations to adopt phishing‑resistant sign‑in methods such as passkeys. Teams should recognize that real-time session capture can defeat conventional MFA and should review protections that prevent session cookie theft and reuse.
  • Policymakers and regulators: Individuals and offices engaged in AI export controls and regulation should treat unexpected subject-matter outreach as a plausible pretext and require independent verification before clicking links or replying to invitations — consistent with Proofpoint’s recommendation to verify unexpected communications via another medium.
  • Think tanks, universities and law firms: Staff who receive unsolicited offers to join advisory committees or help with legislative or committee reports should assume impersonation is possible, especially when messages invoke known public figures — and route verification through institutional security channels.

Implications and next steps

The campaign combines social engineering against a deliberately chosen community with a technical approach that captures fully authenticated sessions from Microsoft 365. That fusion — targeting subject-matter experts with apparently credible pretexts, then using an AitM reverse proxy based on Frameless BitB to harvest session cookies — presents a clear operational playbook for adversaries seeking policy insights rather than immediate financial gain.

Proofpoint’s public disclosure functions as both a warning to potential targets and a technical road map for defenders: adopt phishing-resistant sign-in options, verify unexpected outreach through independent channels, and monitor for unusual session activity that could indicate stolen cookies in use. Whether TA419 continues to impersonate named experts or shifts tactics, Proofpoint judges the group likely to persist in seeking access to those shaping AI policy and regulation.

Original story