Proofpoint, which tracks the group as TA419, said the Beijing-aligned crew sent phishing emails beginning July 8 that impersonated Lynne Edwards Parker, former principal deputy director of the White House Office of Science and Technology Policy, and later Heidi Crebo-Rediker, a prominent economist and foreign policy expert. The emails invited targets to join a fake AI policy advisory committee or contribute to a Senate foreign relations committee report on AI export controls and supply chains.
If a target replied, the attackers sent a shortened URL that led to an attacker-controlled domain. The page displayed a Cloudflare Turnstile check behind a phony OneDrive loading screen before redirecting victims to an attacker-in-the-middle credential phishing page designed to steal cloud account login information. The July campaigns used the domains driftshare[.]co and globalfileshareplatform[.]com.
In February, before the July campaigns, TA419 spoofed a senior Anthropic employee to phish an AI policy analyst at a US think tank, using the subject line 'Request for Feedback on Military Integration of Claude.' This came as US military officials pressured Anthropic to remove safeguards from its Claude AI model.
The phishing chain targets Microsoft 365/Entra ID using open source Frameless BitB with a Browser-in-the-Browser overlay and an Evilginx phishlet to intercept credentials and session cookies for Microsoft 365. TA419 typically uses Cloudflare's CDN to hide backend hosting IP addresses and registers phishing domains themed around file sharing and cloud services, such as msfile[.]online and onecloudfilesync[.]com. The group also impersonates organizations including the Heritage Foundation and the Japan-Taiwan Exchange Association.
'Organizations in the scope of TA419 activity should consider phishing-resistant, origin-bound authentication such as passkeys,' Proofpoint threat hunters recommended.