Proofpoint: TA419 Impersonated Anthropic Exec to Phish AI Experts
TL;DR
- TA419 impersonated former White House OSTP deputy Lynne Edwards Parker and economist Heidi Crebo-Rediker to phish AI policy researchers starting July 8, 2026.
- A February 2026 campaign impersonated a senior Anthropic employee under the subject line 'Request for Feedback on Military Integration of Claude.'
- Fake OneDrive pages used Cloudflare Turnstile checks and Frameless BitB browser-in-browser pages to harvest credentials, MFA codes and session cookies.
China-aligned espionage group TA419 impersonated Lynne Edwards Parker, former Principal Deputy Director of the White House Office of Science and Technology Policy, and economist Heidi Crebo-Rediker to phish AI policy researchers at US think tanks, universities and law firms starting July 8, 2026, Proofpoint reported in research carried by Help Net Security. An earlier February 2026 campaign impersonated a senior Anthropic employee under the subject line "Request for Feedback on Military Integration of Claude."
The lures opened benignly, inviting targets to join a fictitious "AI Policy Advisory Committee" or to contribute to a Senate Committee on Foreign Relations report on AI export controls and supply chains. Once a target replied, the attackers sent a shortened URL that routed through Cloudflare Turnstile checks and fake OneDrive loading screens built with Frameless BitB, a browser-in-browser tool designed to capture credentials, MFA codes and session cookies. Domains were registered through NameSilo and sat behind Cloudflare CDN.
"This activity likely supports wider Chinese intelligence objectives to better understand ongoing developments within the US AI policy," Proofpoint said. The firm has tracked TA419 running credential phishing against US- and Japan-based think tanks, defense contractors, universities and law firms since at least April 2025.
The campaign lands in the middle of a steady run of China AI coverage and echoes Microsoft's 2026 Digital Defense Report, which argued AI has shifted the near-term advantage toward attackers.
Originally reported by helpnetsecurity.com
Read the original article →Original headline: Proofpoint: China-Aligned TA419 Impersonated an Anthropic Exec and Former White House OSTP Director to Phish AI Policy Experts