Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
China-Linked TA419 Targets U.S. AI Experts with Phishing

China-Linked TA419 Targets U.S. AI Experts with Phishing

Posted on October 4, 2026 By CWS

A cyber espionage group identified as TA419, reportedly aligned with Chinese interests, has been linked to recent credential phishing campaigns aimed at U.S. experts in artificial intelligence (AI). These efforts have specifically targeted professionals at American think tanks, universities, and legal organizations.

The phishing schemes involved impersonating notable figures from the AI and economic sectors, including a high-profile employee from Anthropic. Notably, in February 2026, an AI policy expert from a U.S. think tank was targeted under the guise of a feedback request on military integration of AI technologies, particularly Claude.

Context and Objectives

According to Proofpoint’s analysis released this week, these attacks likely serve broader Chinese intelligence goals, aiming to gain insights into U.S. AI policies and regulations. This activity transpires amid heightened geopolitical tensions and debates over AI model distillation and export controls between the U.S. and China.

TA419 has been described as a China-aligned and espionage-driven entity, conducting credential phishing operations against personnel in U.S. and Japan-based think tanks, defense sectors, universities, and legal firms since April 2025. In July 2026, the group allegedly impersonated former U.S. government officials in their phishing attempts targeting AI policy experts.

Phishing Techniques and Threats

The phishing process starts with seemingly benign invitations designed to build trust. Once the target responds, a series of redirects, initiated by a shortened URL, culminate in a credential phishing page hosted on OneDrive. This page is delivered following a Cloudflare Turnstile verification.

A sophisticated method known as Frameless BitB, a variant of browser-in-the-browser attacks, is used. Unlike traditional BitB attacks, Frameless BitB achieves its deceptive appearance without an iframe, instead using HTML, CSS, and JavaScript to create a convincing fake browser window.

Countermeasures and Risks

Proofpoint highlights that TA419 has enhanced an open-source tool with a custom telemetry module, which monitors Microsoft’s login processes and captures credentials via an adversary-in-the-middle proxy, transparently relaying data to legitimate Microsoft servers.

This approach allows attackers to capture session cookies unnoticed, as the victim’s login appears normal. Organizations are urged to adopt phishing-resistant authentication techniques, such as passkeys, and individuals targeted by TA419 should scrutinize any unexpected outreach and verify its legitimacy.

Proofpoint emphasizes TA419’s ongoing focus on sectors related to defense, national security, energy, and international relations, particularly involving the U.S. and Japan. The targeting of AI policy specialists is viewed as an extension of these efforts.

The Hacker News Tags:AI policy, AitM attacks, China, Cloudflare Turnstile, credential theft, cyber espionage, Cybersecurity, Frameless BitB, military integration, OneDrive, passkey authentication, Phishing, Proofpoint, TA419, U.S. think tanks

Post navigation

Previous Post: Key Arrest in ShinyHunters Case Aids FBI Investigation

Related Posts

Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell The Hacker News
Nomani Investment Scam Surges 62% Using AI Deepfake Ads on Social Media Nomani Investment Scam Surges 62% Using AI Deepfake Ads on Social Media The Hacker News
Researchers Find Malicious VS Code, Go, npm, and Rust Packages Stealing Developer Data Researchers Find Malicious VS Code, Go, npm, and Rust Packages Stealing Developer Data The Hacker News
GitHub Account Compromise Led to Salesloft Drift Breach Affecting 22 Companies GitHub Account Compromise Led to Salesloft Drift Breach Affecting 22 Companies The Hacker News
Russian Hackers Breach 20+ NGOs Using Evilginx Phishing via Fake Microsoft Entra Pages Russian Hackers Breach 20+ NGOs Using Evilginx Phishing via Fake Microsoft Entra Pages The Hacker News
New Flaw in IDEs Like Visual Studio Code Lets Malicious Extensions Bypass Verified Status New Flaw in IDEs Like Visual Studio Code Lets Malicious Extensions Bypass Verified Status The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • China-Linked TA419 Targets U.S. AI Experts with Phishing
  • Key Arrest in ShinyHunters Case Aids FBI Investigation
  • Vercel Unveils KVM Zero-Day Flaw, Rewards Researcher $50K
  • ShinyHunters Suspect in Jordan Assists FBI in Hack Probe
  • Addressing Cybersecurity in an Era of Connected Vehicles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • China-Linked TA419 Targets U.S. AI Experts with Phishing
  • Key Arrest in ShinyHunters Case Aids FBI Investigation
  • Vercel Unveils KVM Zero-Day Flaw, Rewards Researcher $50K
  • ShinyHunters Suspect in Jordan Assists FBI in Hack Probe
  • Addressing Cybersecurity in an Era of Connected Vehicles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark