Proofpoint has attributed to the China-aligned, espionage-motivated group TA419 a credential-phishing campaign against US AI-policy experts that leads to an OneDrive adversary-in-the-middle (AitM) page through a multi-stage redirection chain gated by a Cloudflare Turnstile check. The campaign impersonated prominent economists, AI policymakers and a named Anthropic employee to single out an AI-policy expert at a US think tank in February 2026, with the lure headed "Request for Feedback on Military Integration of Claude". The page uses what researcher Wael Masri called "Frameless BitB" — a browser-in-the-browser spoof that achieves the effect without an iframe, by injecting scripts and HTML alongside legitimate content and relying on HTML/CSS/JS tricks for the visual spoof. Proofpoint frames the activity as supporting Chinese intelligence objectives around the US AI-policy and regulatory landscape amid strategic competition, model-distillation accusations and export controls, and describes TA419 as targeting US- and Japan-based think tanks, defence contractors, universities and law firms since at least April 2025. It escalates the TA419 activity carried on 3 October, which was static OneDrive phishing: both the tradecraft and the impersonation fidelity have moved.
| Attribute | Detail |
|---|---|
| Sector | Defence |
| Date | 2026-10-05 |
| Source | The Hacker News |
| Reliability | Tier 2 |