A China-nexus actor is linked to multiple credential phishing campaigns targeting AI policy experts in the U.S., according to a report Thursday by Proofpoint.
The threat actor, tracked as TA419, impersonated leading economists and AI policymakers in a July credential-phishing campaign. In a February attack, the same actor impersonated an Anthropic employee in a campaign targeting an AI policy expert at a U.S. think tank.
Researchers believe the attacks are part of a wider effort by China to better understand U.S. policy objectives and the regulatory environment related to AI. The U.S. and China have been embroiled in a global race for dominance, amid growing security concerns about the technology.
Multiple experts have been impersonated by the hacker, including a former member of the White House Office of Science and Technology Policy. The lures began as routine emails requesting the target to join an advisory committee on AI policy. However, once the target replies to a request, the hacker begins an adversary-in-the-middle attack using a browser-in-the-browser phishing tool called Frameless BitB.
As part of the July campaign the actor impersonated Lynne Parker, a former principal deputy director at the White House office. The actor later impersonated Heidi Crebo-Rediker, a leading economist and foreign policy expert.
The adversary-in-the-middle attacks target Microsoft 365/Entra ID using a first-party OfficeHome application, according to Proofpoint.
Global AI race
The campaign comes at a time of fierce competition between the U.S. and China over AI dominance. Just last month, the Cybersecurity and Infrastructure Security Agency warned of China-based AI companies launching industrial-scale “knowledge distillation” campaigns against U.S. AI companies.
“Usually, when we see nation-state cyber actors targeting think tank and academic professionals, the goal is to collect information and insights into U.S. policymaking,” Annie Fixler, director of the Center on Cyber and Technology Innovation at the Foundation for Defense of Democracies, told Cybersecurity Dive. “These individuals often have regular conversations with government officials, and so gaining access to their email can provide the adversary — in this case, China — with behind-the-scenes details about future policy changes or the thinking behind previous decisions.”
During the February attack, the actor impersonated a senior-level executive at Anthropic to go after an AI policy analyst at a U.S. think tank. A lure email was sent asking for information on military use of Anthropic's Claude models.
TA419 is a China-nexus espionage actor linked to numerous credential phishing attacks since April 2025, according to Proofpoint. The hacker has targeted experts who work for think tanks in the U.S. and Japan and has also launched attacks against defense contractors, law firms and universities.
The actor used Cloudflare’s content delivery network to shield its backend hosting IP address, according to Proofpoint. The domains are typically registered through a web hosting provider called NameSilo.
Proofpoint in 2024 reported on a China-linked cluster called UNK_SweetSpecter, which used a remote access Trojan to target prominent AI experts in the U.S.