Skip to content
Chinese espionage group TA419 spoofed Anthropic executive and former White House ...

Chinese espionage group TA419 spoofed Anthropic executive and former White House ...

News.Lavx.Hu • October 1, 2026

Proofpoint researchers attribute a July 2026 credential-phishing operation to China-aligned group TA419, which impersonated a senior Anthropic employee and former White House OSTP official to target AI policy experts at U.S. universities, think tanks, and law firms.

A suspected Chinese espionage group impersonated a senior Anthropic employee and a former White House science policy official in a phishing campaign that targeted American AI policy experts throughout July 2026, according to threat intelligence firm Proofpoint.

The group, tracked as TA419, sent emails spoofing Lynne Edwards Parker, who served as principal deputy director of the White House Office of Science and Technology Policy, and Heidi Crebo-Rediker, a prominent economist and foreign policy expert. The messages invited recipients to join a fake AI policy advisory committee or contribute to a fabricated Senate Foreign Relations Committee report on AI export controls and supply chains.

When targets replied, the attackers sent a shortened URL that led to a Cloudflare Turnstile check disguised as a OneDrive loading screen. That page then redirected victims to an attacker-in-the-middle credential phishing site designed to steal Microsoft 365 and Entra ID login credentials.

The campaign used driftshare[.]co as a first-stage domain and globalfileshareplatform[.]com as a second-stage domain. Proofpoint analyst Mark Kelly said the bulk of the activity occurred in July.

An earlier campaign in February spoofed a senior Anthropic employee with the subject line "Request for Feedback on Military Integration of Claude." That email targeted an AI policy analyst at a U.S. think tank while U.S. military officials were pressuring Anthropic to reduce Claude's safety guardrails.

TA419's phishing chain targets Microsoft 365 through the first-party OfficeHome application (client_id=4765445b-32c6-49b0-83e6-1d93765276ca). The infrastructure builds on the open-source Frameless BitB framework, which includes a browser-in-the-browser overlay, an Evilginx phishlet to capture usernames, passwords, and session cookies, and server-side substitution rules that inject the kit into proxied pages.

The group typically hides its backend hosting behind Cloudflare's content delivery network. Its phishing domains often mimic file-sharing and cloud services, such as msfile[.]online and onecloudfilesync[.]com. TA419 has also impersonated the Japan-Taiwan Exchange Association (tw-koryu[.]org), The Heritage Foundation (heritiages[.]org and heritiage[.]org), and the official website of Japanese Defense Minister Shinjirō Koizumi (shinjirou[.]info).

Proofpoint's report includes a full list of domains registered or first observed in 2026, along with a timeline of their appearance. The firm recommends that organizations in TA419's crosshairs adopt phishing-resistant, origin-bound authentication such as passkeys.

The disclosure comes one day after OpenAI accused China's Moonshot AI of stealing model reasoning and other data through distillation attacks that began July 1.

Source : theregister.com