A China-linked cyber-espionage group is targeting Microsoft credentials belonging to U.S. policy and regulatory specialists in artificial intelligence, using highly focused social engineering techniques.
TA419, the threat actor behind the campaign, has diversified its interest from defense, national security, energy, international relations and foreign policy to include those involved in the policy and regulation of AI, a Proofpoint analyst reported. The group has been targeting U.S. and Japan-based think tanks, defense contractors, universities and law firms through credential phishing since at least April 2025.
One technique, deployed in a February 2026 campaign, involved impersonating prominent figures in economic and AI policy, as well as an Anthropic employee, in an email titled “Request for Feedback on Military Integration of Claude” to influence an AI policymaker at a U.S. think tank. Similarly, around July, the group began targeting individuals including a former White House Office of Science and Technology Policy (OSTP) leadership team member with an impersonation campaign.
The attack chain is designed to appear to have come from a trusted source, not direct phishing.
First, the victim receives an innocuous request designed to gain the confidence of their target by referencing a shared professional interest. If it gets a response, it then replies with a shortened URL.
Once the link is clicked, the victim is directed to a Microsoft OneDrive-like adversarial in-the-middle phishing site after several redirections. The Cloudflare Turnstile Captcha is integrated into the attack chain, helping to lend credibility to the link.
The credential harvesting component of the attack uses a technique called Frameless BitB, which uses a browser-in-the-browser approach to create the illusion of a separate window using only HTML, CSS and JavaScript. This differs from previous use of Bitb by this threat actor, which used an iframe. Proofpoint noted that TA419 has been modifying an open-source iteration of the attack to incorporate its own telemetry and automation components.
The campaign uses an in-the-middle proxy to compromise Microsoft authentication by impersonating a legitimate login page.
It appears to be a legitimate login page; however, it is actually using the authentication token from the user’s Microsoft account to gain access to the account.
This technique can be challenging to detect because the Microsoft logon page can appear to be authentic while the attacker’s application window is using some of the user’s session information. This allows the attacker to use the credentials to access the Microsoft account.
Proofpoint noted that the activity supports Chinese intelligence interests by providing insight into the U.S. regulatory and policy environment around AI.
The intensifying U.S.-vs-China strategic competition over AI, including issues around model distillation and export controls, appears to be a catalyst for the campaign.
Entities should consider implementing phishing-resistant authentication factors such as passkeys, and individuals who received unexpected professional or professional correspondence should take steps to independently verify the request before responding or following any links.
While the shift to AI policy experts represents a new focus area for TA419, it is not a significant change in the group’s interests. According to Proofpoint, this is an evolution, rather than a revolution, of the group’s current targeting.
Read the original article:
