Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-05 · updated: 2026-10-05 · tags: [incident, defence, espionage, phishing] · confidence: medium · severity: low · affected_sectors: [defence] · au_impact: true

Proofpoint has attributed to the China-aligned, espionage-motivated group TA419 a credential-phishing campaign against US AI-policy experts that leads to an OneDrive adversary-in-the-middle (AitM) page through a multi-stage redirection chain gated by a Cloudflare Turnstile check. The campaign impersonated prominent economists, AI policymakers and a named Anthropic employee to single out an AI-policy expert at a US think tank in February 2026, with the lure headed "Request for Feedback on Military Integration of Claude". The page uses what researcher Wael Masri called "Frameless BitB" — a browser-in-the-browser spoof that achieves the effect without an iframe, by injecting scripts and HTML alongside legitimate content and relying on HTML/CSS/JS tricks for the visual spoof. Proofpoint frames the activity as supporting Chinese intelligence objectives around the US AI-policy and regulatory landscape amid strategic competition, model-distillation accusations and export controls, and describes TA419 as targeting US- and Japan-based think tanks, defence contractors, universities and law firms since at least April 2025. It escalates the TA419 activity carried on 3 October, which was static OneDrive phishing: both the tradecraft and the impersonation fidelity have moved.

Attribute Detail
Sector Defence
Date 2026-10-05
Source The Hacker News
Reliability Tier 2