
Proofpoint has attributed a series of credential-phishing campaigns against artificial intelligence experts at U.S. think tanks, universities and legal-sector organizations to a China-aligned, espionage-motivated group it tracks as TA419. The lures impersonated prominent economists and AI policymakers, and in one February 2026 case a prominent Anthropic employee, who was used to approach an AI policy expert at a U.S. think tank with the subject line “Request for Feedback on Military Integration of Claude.” Around July 2026 the group also impersonated several individuals, including a former member of the White House Office of Science and Technology Policy leadership team. Proofpoint says the activity likely supports wider Chinese intelligence goals of understanding U.S. AI policy and regulation.
The attack starts with a harmless invitation meant to build trust. Only when the target replies does the attacker follow up with a shortened link that runs through a multi-stage redirect chain, a Cloudflare Turnstile check, and finally an OneDrive-themed adversary-in-the-middle (AitM) phishing page. That page uses “Frameless BitB,” a variant of the browser-in-the-browser trick that draws a fake browser window using HTML, CSS and JavaScript without an iframe. TA419 extended the open-source tool with a custom module that tracks the Microsoft sign-in flow and captures credentials through an AitM proxy while relaying them to the real Microsoft infrastructure, so the victim’s sign-in succeeds and nothing looks wrong, even though the session cookies have been captured. Proofpoint describes TA419 as active since at least April 2025 against U.S.- and Japan-based think tanks, defense contractors, universities and law firms, and says AI policy targeting extends that remit rather than departing from it.
How to check if you’re affected
Affected products are Microsoft sign-in flows (here, an OneDrive-themed login) reached through a link in an unsolicited email, most likely for people working in AI policy, think tanks, universities, law firms and defense or foreign-policy research. Proofpoint’s advice for organizations is to enable phishing-resistant authentication such as passkeys, and individuals who may be targets should treat unsolicited subject-matter outreach with caution and verify the sender’s identity through a separate channel before replying or clicking anything. If you replied to a request like this and then signed in through a shortened link, treat the account as compromised: sign out of all sessions and reset the password from a known-good device.
