TA419 Phishing Campaign Poses as Anthropic Staff

A Chinese Spy Group Targets Trust, Not Bugs
A Chinese cyber-espionage group has chosen a new way into the circle of American AI experts. It does not use a vulnerability. It uses trust.
The group, TA419, posed as Anthropic employees and as people close to the White House. It drew targets into believable conversations about AI policy. Then it slipped them a trap built to steal an active Microsoft 365 session.
Who Is TA419
Proofpoint links TA419 to Chinese interests. It has watched the group since at least April 2025. Earlier, the operators attacked staff at American and Japanese think tanks, universities, defense contractors, and law firms.
This time, TA419 focused on people who work on foreign policy, national security, and new technology.
The Impersonation Lure
In July 2026, the attackers posed as a former senior official of the White House Office of Science and Technology Policy. They also posed as a well-known specialist in international economics.
They invited victims to join a fictional advisory committee on AI policy. Alternatively, they asked for help with a US Senate report on export controls and supply chains.
The dangerous link appeared only after a reply. As a result, the first email looked like an ordinary professional introduction.
The Technical Trap
Then came the technical part. A shortened link led the user through several redirects and a fake OneDrive screen. It ended at a login page.
A Fake Window Inside the Browser
TA419 used the browser-in-the-browser technique, built on Frameless BitB. The kit draws a convincing sign-in window right inside the malicious page.
Evilginx as a Live Proxy
A fake visual was not the group’s only tool. The kit includes a phishlet for Evilginx. It turns the attackers’ infrastructure into a proxy between the victim and the real Microsoft 365 and Entra ID systems.
The user really does sign in. The victim types the password and approves the MFA prompt. Meanwhile, the proxy watches the process and collects the result of the successful login.
Why Session Cookies Matter
Session cookies are the main prize. With a valid token, the operator no longer needs the password. Nor must the operator pass multi-factor checks again.
Such session hijacking is especially dangerous. After all, the sign-in process can look completely normal from the outside.
An Intelligence Goal, Not Model Theft
The Proofpoint research treats the campaign as an intelligence operation. Its aim is to understand American AI policy and regulation, not to steal the models themselves.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.