VYPR
advisoryPublished Oct 5, 2026· 1 source

Chinese Hackers Impersonate US Officials in AI Espionage Campaign

Chinese threat actor TA419 is targeting AI policy experts with sophisticated phishing campaigns, impersonating US officials to steal credentials and gather intelligence on AI policy.

A Chinese state-sponsored threat group, identified as TA419, has been actively engaged in sophisticated cyber espionage operations, specifically targeting individuals involved in artificial intelligence (AI) policy development. Researchers from Proofpoint uncovered a campaign conducted in July where the group impersonated US officials to conduct adversary-in-the-middle (AiTM) phishing attacks aimed at stealing credentials from AI experts working at US think tanks, universities, and legal organizations. This activity is believed to be part of a broader Chinese effort to gather intelligence on US AI policymaking and planning.

TA419 has a history of conducting targeted credential phishing campaigns against organizations in the US and Japan, including think tanks, defense contractors, universities, and law firms, since at least April 2025. The July campaign saw the threat actor impersonate multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team. This follows a similar operation in February where the same actor impersonated an Anthropic employee to target an AI policy expert.

The group's strategy is particularly noteworthy for its emphasis on social engineering before deploying technical attack vectors. Instead of initiating with overtly malicious emails, TA419 first focuses on establishing credibility with its targets. By impersonating legitimate contacts relevant to AI policy experts, the attackers build a professional rapport before introducing the phishing component. This approach aims to make the eventual phishing link appear as a natural part of an ongoing professional relationship, thereby increasing the likelihood of success.

In one instance observed on July 8, the attackers posed as Lynne Edwards Parker, former principal deputy director of the White House Office of Science and Technology Policy, and later as Heidi Crebo-Rediker, a prominent economist and foreign policy expert. They initiated contact by inviting targets to join a fictitious 'AI Policy Advisory Committee' or to contribute to a Senate Committee on Foreign Relations report on AI export controls and supply chains. These conversations were designed to be highly relevant to the targets' work, covering topics like AI policy, export controls, and technology regulation.

Once credibility was established, the technical phase of the attack commenced with a link that appeared to lead to a legitimate Microsoft or OneDrive document or collaboration environment. If the target responded, TA419 would follow up with a shortened URL, purportedly to share additional information. This link, however, led to a fake OneDrive AiTM credential phishing page meticulously designed to capture the target's cloud account credentials.

The phishing infrastructure employed a multistage redirection chain before presenting the victim with the AiTM credential-phishing page. Proofpoint noted that the infrastructure utilized a customized version of the open-source browser-in-the-browser (BitB) phishing tool, Frameless BitB. AiTM attacks are particularly insidious because they not only capture usernames and passwords but also the authenticated session. This allows attackers to potentially bypass multi-factor authentication (MFA) and maintain access to the compromised account, even after the user believes the login was legitimate and completed MFA.

Experts emphasize that this technique is common in email compromise attacks and can be effective even against organizations with MFA enabled. The attack's success hinges on the user initiating the activity, making the process feel normal from their perspective. While MFA technically occurs, it happens at a point in the attack chain where it offers no protection, as the user is approving the authentication for a link they have already clicked.

Proofpoint anticipates that TA419 and other threat actors will continue to employ similar impersonation and phishing techniques, especially as AI policy becomes an increasingly critical area of strategic competition. China's known history of cyber-espionage against US defense and energy sectors, as well as foreign policy makers, suggests that targeting AI policymakers is a logical extension of existing intelligence-gathering objectives. The overlap between AI security and national security makes this domain a prime target for state-sponsored groups.

Synthesized by Vypr AI