A China-nexus cyber espionage group, identified as TA419, has been linked to multiple credential phishing campaigns. These campaigns specifically target artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The group has been active since at least April 2025, focusing on individuals in the U.S. and Japan.
TA419's campaigns involve impersonating prominent economists, AI policymakers, and even an Anthropic employee. For example, in February 2026, an AI policy expert at a U.S. think tank received a phishing email with the subject line "Request for Feedback on Military Integration of Claude." Around July 2026, the group impersonated a former member of the White House Office of Science and Technology Policy leadership team in similar campaigns.
The attacks begin with seemingly harmless invitations to build trust with the target. Once a response is received, the adversary sends a shortened URL that initiates a multi-stage redirection chain. This chain ultimately leads to a OneDrive adversary-in-the-middle (AitM) credential phishing page, after a Cloudflare Turnstile check. The phishing page utilizes a technique called Frameless BitB, which spoofs a trusted website login page by creating a fake browser window within a legitimate browser session using HTML, CSS, and JavaScript, without using an iframe.
According to an analysis by Proofpoint, this activity likely supports broader Chinese intelligence objectives. The aim is to gain a better understanding of ongoing developments within the U.S. AI policy and regulatory landscape. This occurs amidst intense strategic competition, accusations of model distillation, and export controls between the U.S. and China, highlighting the importance of AI policy intelligence.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A China-nexus cyber espionage group, TA419, is conducting credential phishing campaigns against U.S. AI policy experts in think tanks, universities, and legal organizations. The attacks use sophisticated adversary-in-the-middle (AitM) techniques to gather intelligence on U.S. AI policy and regulatory developments. This activity indicates ongoing strategic competition and intelligence gathering efforts related to AI between the U.S. and China.