A cyber espionage group known as TA419, with connections to China, has launched a series of credential phishing attacks aimed at artificial intelligence experts in the United States. These experts are primarily affiliated with think tanks, universities, and legal institutions. The group has been active since April 2025 and has a history of targeting entities in the U.S. and Japan, particularly within sectors such as defense, national security, and international relations. In February 2026, TA419 impersonated well-known economists and AI policymakers, even targeting an AI policy expert with a phishing email titled 'Request for Feedback on Military Integration of Claude.' This attack is part of broader Chinese intelligence efforts to glean insights into U.S. AI policy and regulatory matters, amidst ongoing geopolitical tensions between the two nations. The attacks typically begin with innocuous invitations designed to build trust. Once a target engages, they are redirected through a series of links, eventually landing on a OneDrive phishing page. This page uses a tactic called Frameless BitB, a variation of the browser-in-the-browser attack. By leveraging HTML, CSS, and JavaScript, it creates a fake login interface that appears legitimate, capturing credentials without the victim's awareness. TA419 has enhanced this method with a custom telemetry and automation module to monitor and capture Microsoft sign-in credentials seamlessly. The stolen data is then relayed to Microsoft's real infrastructure, making detection nearly impossible for the victim. To combat this threat, organizations should adopt phishing-resistant authentication methods like passkeys. Individuals should verify the authenticity of any unsolicited requests related to sensitive subject matters before responding. This precaution is especially vital for those within the scope of TA419's activities. Proofpoint's analysis underscores TA419's continued focus on key geopolitical areas, with this latest campaign expanding their interest to AI policy experts.
TA419's Sophisticated Phishing Campaign Targets U.S. AI Policy Experts
TA419 is running Microsoft AitM-style phishing campaigns to steal credentials from U.S. AI policy experts at think tanks and universities.
Executive Summary
PremiumActionable Insights
PremiumOriginal source
thehackernews.com

