A China-aligned threat group, TA419, has been impersonating prominent AI policy figures and economists to harvest login credentials from AI policy specialists at US think tanks, universities and law firms. Proofpoint notes the activity has been ongoing since at least April 2025, with public reporting beginning on 1 October 2026.
In July the attackers used the identity of Lynne Parker, formerly the White House OSTP principal deputy director, and in February posed as a senior Anthropic employee to contact a think-tank analyst. The outreach began with harmless invitations to join a fictitious “AI Policy Advisory Committee” or contribute to an AI export controls report; respondents were directed to a shortened link that redirected to a spoofed OneDrive login page.
The phishing kit used is described as an adversary-in-the-middle reverse proxy built with Frameless BitB, which presents a fake browser window to capture live Microsoft 365 sessions. Real-time forwarding of the victim’s login to Microsoft allows credentials, MFA codes and conditional access checks to pass, enabling TA419 to steal session cookies.
The group reportedly added its own module to monitor where victims are in the login flow and auto-selected “Keep me signed in,” extending session lifetimes, and entering one-time codes to complete authentication. The article urges organisations to adopt phishing-resistant sign-in methods such as passkeys and to verify unsolicited outreach through an independent channel.