Threats · 2h ago
Proofpoint said on October 1 that China-aligned TA419 has been running a credential-phishing campaign since at least April 2025 against AI policy specialists at think tanks, universities, law firms, defense contractors, and policy groups. The lures impersonated real policy figures and an Anthropic employee to pull targets into Microsoft 365 and OneDrive sign-ins.
The trap was an adversary-in-the-middle proxy built from Frameless BitB. It sat in front of a real Microsoft login, relayed the sign-in in real time, and captured the session cookies after the password, MFA prompt, and conditional-access checks all succeeded, so the attacker walked away with a live account session rather than just credentials.
For organizations that use Microsoft 365 for email, documents, or shared workspaces, the exposure sits in the session itself: once a target completes the login, ordinary password resets do not necessarily evict the attacker. The reporting does not say accounts were compromised in every case, but it does show why MFA alone does not close this pattern.
4 sources covering this story
The Record from Recorded Future
Researchers find Chinese hacking campaigns targeting AI firms, Asian governments
Two separate reports by cybersecurity companies highlight China-linked hacking operations, including a phishing campaign that impersonated Western experts.
Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing
Your invite to a fake AI policy advisory committee has strings attached
AI policy circles targeted in China-linked phishing operation
Proofpoint reports China-aligned cyber group TA419 targeted U.S.
China-Linked Hackers Impersonate AI Experts to Target US Policy
TA419 posed as AI policymakers and economists to phish US AI policy experts' Microsoft 365 accounts
Part of the PlainSec briefing for 2026-10-01