The China-aligned cyber threat group, identified by cybersecurity firm Proofpoint as TA419, is behind several phishing attacks against AI policy experts, including professionals at think tanks, universities, and legal sector organizations in the United States.

Cybercriminals have impersonated economists, foreign policy experts, and former administration officials to gain the trust of their targets, get them to respond to messages, and steal credentials.

According to Proofpoint researchers, these campaigns date back to July with seemingly legitimate emails and conversations related to AI policies. Among the decoys, motivated by cyberespionage, were invitations to belong to a supposed advisory committee on this matter or requests to contribute to a US Senate report on AI export controls and supply chains.

“If the recipient responded, the attackers sent a shortened URL that initially provided additional information, but led to a fake OneDrive page designed to steal cloud account credentials, using an adversary-in-the-middle technique,” ​​Proofpoint threat researchers say.

Previously, TA419 had impersonated a senior Anthropic employee in February to target an AI policy analyst at a think tank in the United States. The message referred to the debate on the military use of Anthropic’s Claude models, following the same tactic and the same objective of obtaining victim data.

Identity theft and credential phishing

The infrastructure used by these cybercriminals was specifically designed to attack Microsoft 365 and Entra ID accounts. TA419 also uses its own version of an open source tool to intercept authentication processes. This system could broadcast the legitimate Microsoft login page in real time and overlay a fake browser window, so the attacker could capture the password, multi-factor authentication codes, and session cookies. The kit incorporated telemetry mechanisms to track the victim’s progress during the authentication process.

The group has also automated certain parts of the process. Among other functions, the code used by TA419 can automatically accept the option to keep the session logged in and send one-time codes once they are validated, with the aim of prolonging and taking advantage of the compromised session.

TA419’s activity against AI policy experts could be part of broader intelligence objectives aimed at understanding the evolution of US policies and regulations around this technology. These operations occur in a context of growing strategic competition between the United States and China, marked by issues such as export controls and accusations about the distillation of AI models.

Adopting phishing-resistant and origin-linked authentication methods, such as passkeys, as well as verifying any unexpected communications, are key precautionary measures against possible attacks of this nature, according to Proofpoint experts.