Suspected Chinese Espionage Group Spoofs Anthropic Executive, White House Official in Phishing Campaign Targeting AI Policy Experts

Proofpoint attributes attacks to TA419, noting July 2026 campaigns aimed at US universities, think tanks, and law firms

By LineZotpaper
Published
Read Time2 min
A suspected Chinese espionage group impersonated a senior Anthropic employee and a former White House official in credential phishing campaigns targeting US AI policy experts at universities, think tanks, and law firms, according to security researchers at Proofpoint. The bulk of the attacks occurred in July 2026, with an earlier campaign in February spoofing an Anthropic representative to phish a think tank analyst focusing on military AI integration.

Proofpoint, which tracks the group as TA419, said the Beijing-aligned crew sent phishing emails beginning July 8 that impersonated Lynne Edwards Parker, former principal deputy director of the White House Office of Science and Technology Policy, and later Heidi Crebo-Rediker, a prominent economist and foreign policy expert. The emails invited targets to join a fake AI policy advisory committee or contribute to a Senate foreign relations committee report on AI export controls and supply chains.

If a target replied, the attackers sent a shortened URL that led to an attacker-controlled domain. The page displayed a Cloudflare Turnstile check behind a phony OneDrive loading screen before redirecting victims to an attacker-in-the-middle credential phishing page designed to steal cloud account login information. The July campaigns used the domains driftshare[.]co and globalfileshareplatform[.]com.

In February, before the July campaigns, TA419 spoofed a senior Anthropic employee to phish an AI policy analyst at a US think tank, using the subject line 'Request for Feedback on Military Integration of Claude.' This came as US military officials pressured Anthropic to remove safeguards from its Claude AI model.

The phishing chain targets Microsoft 365/Entra ID using open source Frameless BitB with a Browser-in-the-Browser overlay and an Evilginx phishlet to intercept credentials and session cookies for Microsoft 365. TA419 typically uses Cloudflare's CDN to hide backend hosting IP addresses and registers phishing domains themed around file sharing and cloud services, such as msfile[.]online and onecloudfilesync[.]com. The group also impersonates organizations including the Heritage Foundation and the Japan-Taiwan Exchange Association.

'Organizations in the scope of TA419 activity should consider phishing-resistant, origin-bound authentication such as passkeys,' Proofpoint threat hunters recommended.

§

Analysis

Why This Matters

  • The attacks directly target US AI policy experts, aiming to steal credentials and intelligence about American AI strategy and export controls.
  • The impersonation of a senior Anthropic employee shows adversaries are exploiting sensitive debates about military AI integration to gain access.
  • TA419's use of sophisticated attacker-in-the-middle techniques and Cloudflare evasion makes these campaigns harder to detect with standard security measures.

Background

Proofpoint identified the group as China-aligned based on infrastructure and targeting patterns. The attacks come amid heightened US-China tensions over AI technology, following OpenAI's recent accusation that Chinese firm Moonshot AI stole its model reasoning through distillation attacks beginning July 1. Chinese state-sponsored espionage groups have previously targeted technology sectors, but this campaign specifically focuses on individuals shaping AI policy rather than corporate R&D. The use of spoofed identities from well-known policy figures indicates careful reconnaissance.

Key Perspectives

Security Researchers (Proofpoint): The group poses a persistent threat to organizations involved in AI policy, and the sophistication of the phishing chain (Frameless BitB, Evilginx) demonstrates investment in evading detection. They recommend passkeys as a primary defense. Target Organizations (US universities, think tanks, law firms): These institutions face a difficult balance between open collaboration and security. A successful breach could expose sensitive policy discussions or intellectual property. Chinese Government (implied): Beijing has not commented, but the activity aligns with known priorities of monitoring and influencing US AI policy and export controls. The groups may seek to inform Chinese strategic decisions.

What to Watch

  • Whether US government agencies issue warnings or advisories targeting this specific phishing technique.
  • Adoption of phishing-resistant authentication (passkeys) among AI policy organizations.
  • Additional phishing campaigns leveraging current events, such as ongoing US-China AI export control negotiations.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.