Chinese Hackers Impersonate US Officials for AI Cyber Espionage
An emerging threat group known as TA419 established seemingly legitimate professional relationships with AI policy experts working for US think tanks, universities, and legal organizations.
An emerging threat group known as TA419 established seemingly legitimate professional relationships with AI policy experts working for US think tanks, universities, and legal organizations.
Chinese hackers impersonated US policymakers in adversary-in-the-middle (AiTM) phishing campaigns aimed at stealing credentials from artificial intelligence (AI) experts working for US think tanks, universities, and legal organizations.
Researchers from Proofpoint discovered the campaign, which occurred in July, and attributed it to China-aligned threat actor TA419, according to a blog post published last week. The activity is believed to be part of a broader Chinese cyber espionage effort to gather intelligence on US AI policymaking and planning.
“Proofpoint has observed TA419 conducting regular targeted credential phishing campaigns against individuals working for US- and Japan-based think tanks, defense contractors, universities, and law firms since at least April 2025,” Proofpoint cyber threat intelligence analyst Mark Kelly and the Proofpoint Threat Research Team wrote in the post.
TA419 impersonated multiple individuals in the campaign, including a former member of the White House Office of Science and Technology Policy leadership team, and engaged with victims through a series of emails. The July campaign followed an earlier operation in February in which the same threat actor impersonated an Anthropic employee to target an AI policy expert at a US think tank, according to Proofpoint.
“This activity likely supports wider Chinese intelligence objectives to better understand ongoing developments within the US AI policy and regulatory landscape and occurs amid intense strategic competition, accusations of model distillation, and export controls involving the US and China,” the researchers wrote.
Social Engineering Before the Phish
The attack combines social engineering with extensive phishing infrastructure, but the technical attack comes later in the process. Rather than beginning with an obviously malicious email or attachment, TA419 first attempts to establish credibility with its targets.
The group impersonated people that appear to be legitimate contacts for AI policy experts at US think tanks, universities, and law firms. Once that relationship was established, the attackers introduced the phishing component.
On July 8, for example, the actor pretended to be Lynne Edwards Parker, the former principal deputy director of the White House Office of Science and Technology Policy, and later impersonated Heidi Crebo-Rediker, a prominent economist and foreign policy expert.
“In both cases, the group opened with benign outreach, inviting targets to join a fictitious ‘AI Policy Advisory Committee’ or to contribute to a Senate Committee on Foreign Relations report on AI export controls and supply chains,” the researchers wrote.
The approach allowed the attackers to start conversations around subjects that were particularly relevant to their targets, including AI policy, export controls, and technology regulation. The strategy is notable because the attackers were not simply trying to convince victims to click on a phishing link. They first attempted to make the eventual link appear to be a legitimate part of an ongoing professional relationship.
Technical Attack Begins With a Link
Once that credibility was established, the technical attack began with a link that appeared to lead to a legitimate Microsoft or OneDrive document or collaboration environment.
“If the target replied, TA419 followed up with a shortened URL that purported to share additional information,” the researchers wrote. “The link ultimately led to a fake OneDrive AiTM credential phishing page designed to gain access to the target’s cloud account.”
The URL used a multistage redirection chain before ultimately taking the victim to an AiTM credential-phishing page. Proofpoint said the infrastructure used a customized version of the open source browser-in-the-browser (BitB) phishing tool Frameless BitB.
Rather than simply collecting a username and password, an AiTM attack places the attacker between the victim and the legitimate authentication service. This can allow the attacker to capture authentication information and, critically, the authenticated session, even while the victim can still complete multifactor authentication (MFA) and believe the login was legitimate, according to Proofpoint. The stolen session can potentially then be reused to access the account without requiring the attacker to complete MFA again.
“It should be noted that the technique used is particularly common for all email compromise attacks,” observes Steven Swift, managing director of security firm Suzu Labs. “Most organizations are vulnerable to this attack, despite having confidence that their MFA will protect them.”
However, it will not, beacause “the point of the attack is to let the user both click on a link and approve the MFA for the link that they just clicked on,” Swift tells Dark Reading. “Because the users initiatives the activity, everything feels normal from the users perspective.”
And though this type of attack “feels a lot like an MFA bypass attack,” technically, the MFA happens, he says. “It just happens at a point in the attack where it doesn’t help,” Swift notes.
Recognizing Suspicious Relationship-Building
Proofpoint expects further attacks using similar impersonation and phishing techniques as TA419’s activity becomes more widely understood. Indeed, China is known for conducting cyber-espionage attacks against the US defense and energy industry, as well as foreign-policy makers, Swift observes. Going after AI policy makers appears to be “simply a logical extension of existing behavior,” he says.
“That they’re now also including AI policymakers is simply a reflection of where the industry is at. AI security overlaps meaningfully with national security, and it’s only logical that state sponsored groups are now including AI in the scope of their activities,” Swift says “We should expect this activity to continue if not escalate, as AI continues to further integrate and mature.”
The campaign also highlights why defending against targeted cyber espionage requires more than teaching employees how to recognize a phishing page or suspicious email. In this case, the phishing attempt came after the attackers spent time establishing what appeared to be a legitimate professional relationship.
“Individual targets in scope of TA419 activity should treat unsolicited subject-matter outreach as a plausible pretext stage and seek to verify the legitimacy of such unexpected communications via another independent medium,” the Proofpoint researchers wrote.
Organizations also should consider phishing-resistant, origin-bound authentication such as passkeys, Proofpoint recommended. The lesson for defenders is that the phishing link may be only the final stage of the attack, and the more difficult challenge may be recognizing that an apparently legitimate professional relationship is itself being used as the pretext for credential theft.