Full Report
A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a
Analysis Summary
# Threat Actor: TA419
## Attribution & Identity
* **Identification:** TA419 is a China-nexus cyber espionage group.
* **Alignment:** Described as China-aligned and espionage-motivated.
* **Associations:** Linked to Chinese intelligence objectives regarding U.S. policy and strategic competition.
## Activity Summary
* **Active Since:** At least April 2025.
* **February 2026 Campaign:** Targeted AI policy experts at U.S. think tanks by impersonating an Anthropic employee and using the subject line "Request for Feedback on Military Integration of Claude."
* **July 2026 Campaign:** Impersonated a former member of the White House Office of Science and Technology Policy (OSTP) leadership team to target AI policy experts.
* **Methodology:** Uses "benign" social engineering to establish trust before sending malicious phishing links.
## Tactics, Techniques & Procedures
* **Social Engineering:** Sends harmless initial invitations to establish rapport before deploying malicious lures.
* **Adversary-in-the-Middle (AitM):** Proxies Microsoft sign-in flows to capture credentials and session cookies in real-time.
* **Frameless Browser-in-the-Browser (BitB):** Uses HTML, CSS, and JavaScript to craft a fake browser window within a legitimate session without using traditional iframes.
* **Redirection Chains:** Employs shortened URLs and multi-stage redirects to bypass security filters.
* **Evasion:** Utilizes Cloudflare Turnstile checks to filter out automated analysis bots.
* **Telemetry:** Uses a bespoke telemetry and automation module to track victim sign-in progress.
## Targeting
* **Sectors:** Artificial Intelligence (AI) experts, think tanks, universities, legal sector, defense contractors, energy, international relations, and foreign policy.
* **Geography:** Primarily United States and Japan.
* **Victims:** AI policy experts, U.S. think tank personnel, and legal organizations.
## Tools & Infrastructure
* **Techniques:** Frameless BitB (based on open-source tools).
* **Infrastructure:**
* Microsoft OneDrive (abused for phishing hosting).
* Cloudflare Turnstile (for bot protection).
* Adversary-in-the-Middle (AitM) proxy infrastructure.
* **Defanged Links:** hxxps[://]github[.]com/waelmas/frameless-bitb
## Implications
* **Strategic Intelligence:** The actor seeks to understand the U.S. AI regulatory landscape, export controls, and policy developments.
* **Advanced Phishing:** The use of AitM and Frameless BitB bypasses traditional Multi-Factor Authentication (MFA) by capturing session cookies, allowing the actor to maintain access even if passwords are changed.
* **Geopolitical Context:** Activity is tied to U.S.-China strategic competition and accusations of AI model distillation.
## Mitigations
* **Authentication:** Enable phishing-resistant MFA, specifically **Passkeys** or FIDO2-compliant hardware keys, which are not susceptible to AitM proxying.
* **User Training:** Educate high-value targets (AI policy experts/researchers) to treat unsolicited subject-matter outreach with extreme caution.
* **Verification:** Verify the authenticity of invitations or document requests through secondary, out-of-band communication channels.
* **Technical Controls:** Monitor for suspicious session cookie usage and unusual redirection patterns involving Cloudflare Turnstile or shortened URLs in corporate email traffic.