Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Alleged KillSec Ransomware Group Leader Arrested, Servers Dismantled
October 1, 2026
Fake Zoom Installer Delivers CloudSyncD Backdoor to macOS Users
October 1, 2026
Chinese Hackers Impersonate Anthropic Employee to Target US AI Policy Experts
October 1, 2026
Home/CyberSecurity News/Chinese Hackers Impersonate Anthropic Employee to Target US AI Policy Experts
CyberSecurity News

Chinese Hackers Impersonate Anthropic Employee to Target US AI Policy Experts

Key Takeaways A Chinese state-sponsored hacking group, TA419, is actively targeting U.S. AI policy experts. The group impersonates prominent figures, including a senior Anthropic employee and former...

Sarah simpson
Sarah simpson
October 1, 2026 4 Min Read
2 0

Key Takeaways

  • A Chinese state-sponsored hacking group, TA419, is actively targeting U.S. AI policy experts.
  • The group impersonates prominent figures, including a senior Anthropic employee and former White House officials, to establish credibility.
  • Attacks leverage sophisticated credential phishing, combining adversary-in-the-middle (AitM) techniques with a modified Frameless BitB toolkit.
  • The primary goal is to steal cloud account session cookies, likely to gather intelligence on U.S. AI policy, export controls, and strategic initiatives.

A sophisticated hacking collective, identified as TA419 and believed to be aligned with the Chinese state, has been observed impersonating high-profile individuals to target U.S. artificial intelligence policy experts. This campaign aims to compromise cloud accounts belonging to researchers at leading think tanks, universities, and law firms, according to findings from cybersecurity firm Proofpoint.

Table Of Content

  • Key Takeaways
  • Elaborate Impersonations Target AI Policy Analysts
  • Advanced Phishing Techniques Employed
  • What You Should Do

The intelligence gathering operation is likely designed to inform China’s understanding of American AI regulatory frameworks, export restrictions, and national strategy. Proofpoint has been tracking TA419 since at least April 2025, documenting its persistent campaigns against various organizations in the U.S. and Japan, including defense contractors and legal entities.

Elaborate Impersonations Target AI Policy Analysts

In a notable incident in February 2026, TA419 assumed the identity of a senior Anthropic employee to contact an AI policy analyst at a prominent U.S. think tank. The email, bearing the subject line “Request for Feedback on Military Integration of Claude,” strategically referenced ongoing public discussions surrounding the military applications of Anthropic’s AI models.

The scope of the campaign broadened significantly in July. Beginning on July 8, the attackers escalated their impersonation efforts, posing as Lynne Edwards Parker, a former senior science and technology official at the White House, and economist Heidi Crebo-Rediker. These deceptive communications invited recipients to join a fabricated “AI Policy Advisory Committee” or to contribute to a fictitious Senate foreign relations report focusing on critical topics such as AI export controls and supply chain vulnerabilities.

Initial emails served as conversation starters rather than direct requests for credentials. This patient approach involved TA419 engaging targets in dialogue, and only after a reply was received did the attackers send a shortened link. This link purported to offer additional information, making the subsequent request for document access appear as a natural progression of an established professional exchange.

Advanced Phishing Techniques Employed

As detailed in the supplied Proofpoint findings, the shortened links initially directed targets through attacker-controlled websites. One such domain, driftshare[.]co, presented a convincing fake OneDrive loading screen, complete with a Cloudflare Turnstile verification, before redirecting users to globalfileshareplatform[.]com, the actual host of the credential phishing flow.

The attack infrastructure ingeniously combined adversary-in-the-middle (AitM) phishing with a customized version of the Frameless BitB toolkit. Browser-in-the-Browser (BitB) attacks create a simulated browser window within a webpage, complete with a seemingly legitimate address bar. The Frameless BitB variant employed by TA419 bypasses traditional iframe limitations and supports Evilginx-based proxying, specifically targeting Microsoft login pages.

TA419’s focus was on compromising Microsoft 365 and Entra ID accounts via Microsoft’s OfficeHome application. Rather than simply presenting a static login screen, the sophisticated proxy architecture relayed the authentic Microsoft sign-in process. Crucially, while the legitimate authentication steps, including password entry and multi-factor authentication (MFA), were completed by the user, the malicious scripts embedded by the attackers simultaneously captured the resulting session cookies.

Technical analysis revealed that a script named /secondary/script.js constructed a OneDrive-like document listing within a Shadow DOM, a segregated part of the page’s structure. Concurrently, /primary/script.js monitored user interactions, specifically document clicks and permission prompts, before triggering the display of the fabricated Chrome login window.

A bespoke module, /secondary/observe.js, continuously tracked each target’s progress through the authentication sequence. This module was also designed to automatically accept “Keep me signed in” prompts and submit validated one-time codes. This intricate setup underscores TA419’s objective: to obtain a fully functional cloud session, not merely a stolen password.

To obscure their operational footprint, TA419 utilized Cloudflare services to conceal backend hosting IP addresses. The group frequently registered cloud-sharing-themed domain names through NameSilo. Analysis of email headers also revealed likely attacker-controlled servers, including 108.61.163[.]187. The presence of shared self-signed certificates suggests a potential anonymization network, although this remains an assessment.

While the success of these specific TA419 campaigns in compromising accounts has not been publicly confirmed, the targeting of AI researchers highlights the ongoing intelligence interest in artificial intelligence expertise, mirroring previous SugarGh0st attacks.

What You Should Do

  • Verify Unexpected Invitations: Always independently confirm the legitimacy of any unexpected invitations, especially those requesting sensitive information or access, by contacting the purported sender through an official, known channel (e.g., a phone number from their official website, not from the email).
  • Deploy Phishing-Resistant Authentication: Implement and enforce strong, phishing-resistant multi-factor authentication (MFA) methods, such as FIDO2 security keys or certificate-based authentication, across all cloud services.
  • Investigate Unusual Cloud Sessions: Monitor for and promptly investigate any unusual login attempts, session activities, or access patterns within cloud environments.
  • Revoke Suspicious Tokens: If a compromise is suspected, immediately revoke all suspicious session tokens and force a password reset for affected accounts.
  • Educate Users: Conduct regular security awareness training to educate employees on sophisticated phishing techniques, including adversary-in-the-middle (AitM) and Browser-in-the-Browser (BitB) attacks.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCybersecurityHackerphishingSecurity

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical Microsoft Defender Flaw Lets Attackers Hide Malware

Next Post

Fake Zoom Installer Delivers CloudSyncD Backdoor to macOS Users

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Warlock Ransomware Exploits Critical SharePoint Flaws in Water, Telecom Attacks
October 1, 2026
Critical Axios HTTP/2 Vulnerabilities Allow SSRF and DoS Attacks
October 1, 2026
Critical Node.js Vulnerability CVE-2024-27983 Allows Remote Code Execution
October 1, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us