A cyber espionage group identified as TA419, reportedly aligned with Chinese interests, has been linked to recent credential phishing campaigns aimed at U.S. experts in artificial intelligence (AI). These efforts have specifically targeted professionals at American think tanks, universities, and legal organizations.
The phishing schemes involved impersonating notable figures from the AI and economic sectors, including a high-profile employee from Anthropic. Notably, in February 2026, an AI policy expert from a U.S. think tank was targeted under the guise of a feedback request on military integration of AI technologies, particularly Claude.
Context and Objectives
According to Proofpoint’s analysis released this week, these attacks likely serve broader Chinese intelligence goals, aiming to gain insights into U.S. AI policies and regulations. This activity transpires amid heightened geopolitical tensions and debates over AI model distillation and export controls between the U.S. and China.
TA419 has been described as a China-aligned and espionage-driven entity, conducting credential phishing operations against personnel in U.S. and Japan-based think tanks, defense sectors, universities, and legal firms since April 2025. In July 2026, the group allegedly impersonated former U.S. government officials in their phishing attempts targeting AI policy experts.
Phishing Techniques and Threats
The phishing process starts with seemingly benign invitations designed to build trust. Once the target responds, a series of redirects, initiated by a shortened URL, culminate in a credential phishing page hosted on OneDrive. This page is delivered following a Cloudflare Turnstile verification.
A sophisticated method known as Frameless BitB, a variant of browser-in-the-browser attacks, is used. Unlike traditional BitB attacks, Frameless BitB achieves its deceptive appearance without an iframe, instead using HTML, CSS, and JavaScript to create a convincing fake browser window.
Countermeasures and Risks
Proofpoint highlights that TA419 has enhanced an open-source tool with a custom telemetry module, which monitors Microsoft’s login processes and captures credentials via an adversary-in-the-middle proxy, transparently relaying data to legitimate Microsoft servers.
This approach allows attackers to capture session cookies unnoticed, as the victim’s login appears normal. Organizations are urged to adopt phishing-resistant authentication techniques, such as passkeys, and individuals targeted by TA419 should scrutinize any unexpected outreach and verify its legitimacy.
Proofpoint emphasizes TA419’s ongoing focus on sectors related to defense, national security, energy, and international relations, particularly involving the U.S. and Japan. The targeting of AI policy specialists is viewed as an extension of these efforts.
