China-Linked Phishers Target AI Policy Experts

The Record · High sophistication
Last updated October 1, 2026

Researchers reported two China-aligned campaigns that used phishing and impersonation to target AI policy experts and multiple Asian government organizations. One campaign built rapport with “AI policy” themed outreach before sending links to a OneDrive credential-harvesting page, while another used spear-phishing emails with decoy documents to deliver malware for espionage.

Key findings

  • Proofpoint described a July incident where a China-aligned actor ran phishing attacks by impersonating prominent economists and a former White House science/technology policy official.
  • Targets included AI experts in universities, think tanks, and law firms, with lures about joining a fake “AI Policy Advisory Committee” or contributing to a fictitious Senate report.
  • After victims responded, attackers sent a URL redirection chain leading to a OneDrive credential phishing page.
  • Cisco Talos reported a separate China-linked campaign targeting government organizations across multiple Asian countries, with initial access via phishing emails and decoy documents.
  • Talos observed ~350 compromised endpoints across eight countries and stated the campaign goal was intelligence gathering.

Who’s being targeted

  • Commonly targeted roles: Executive leadership, Government affairs / public policy, Researchers (AI/technology), Think tank staff, Legal (policy/regulatory), Administrative staff supporting policy teams.
  • Affected industries: Government, Higher education, Think tanks / policy organizations, Legal services, Artificial intelligence / technology.
  • Attack channels: email, website.
  • Impersonated: Former White House official Lynne Edwards Parker / foreign policy expert Heidi Crebo-Rediker (impersonation), Unspecified (campaign used decoy documents and spoofed invitations).

Awareness takeaways

  • Treat unsolicited ‘committee invitations’ and ‘policy collaboration’ requests as high-risk, even if they appear to come from credible experts.
  • Be cautious when an initial email seems harmless and relationship-building; attackers may be trying to get you to respond before sending the real payload.
  • Don’t enter credentials after clicking links from emails, especially if you are redirected and land on a cloud login page (e.g., OneDrive).
  • Assume “timely” topical attachments (news/legislative/event invites) can be weaponized; verify via known official channels before opening or downloading.

Red flags to watch for

  • Too-good-to-be-true policy invitation from an unexpected sender
  • Conversation-starter email designed to prompt a reply before any real details are provided
  • Link redirects and leads to a login page asking for credentials (OneDrive phishing)
  • Unexpected email with attachments/decoy documents
  • Pressure to review timely ‘news’ or ‘legislative’ material
  • Sender/event details don’t match known official channels
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get this email: “Invitation to join an AI Policy Advisory Committee,” supposedly from a former White House science official. Researchers say China-linked groups are doing this for real, impersonating economists and policy experts, asking you to join a fake AI committee or contribute to a Senate report, just to get you to reply. Here’s the trick: once you respond, they send a link that bounces through redirects into a OneDrive login page. It looks normal, but it’s a credential phish built to steal your username and password. If you get an unexpected policy invite or briefing, and it leads to a login page after a few redirects, stop. Don’t sign in there, go to the service directly and log in from a fresh browser tab.

Similar attacks

Device-Code Phishing and “ClickFix” Lures Spread

Device-Code Phishing and “ClickFix” Lures Spread

This weekly recap highlights multiple real-world campaigns where attackers trick users into taking actions that grant access, without needing to steal passwords directly. Notable examples include “device code” phishing (victims are instructed to enter a short code to approve an attacker session)…

September 28, 2026
Fake Gmail Attachment Lure Drops Antino Backdoor

Fake Gmail Attachment Lure Drops Antino Backdoor

A China-nexus threat group targeted government and policy organizations across Asia using spear-phishing emails tailored to the victim’s interests. The emails used spoofed trusted senders and a realistic fake Gmail attachment preview that linked to attacker-controlled pages, ultimately installing…

October 2, 2026
Fake Google Play Pages Push Spyware at Logistics

Fake Google Play Pages Push Spyware at Logistics

A real campaign is targeting logistics firms with fake Google Play pages impersonating well-known logistics brands to trick employees into installing an Android spyware app. Once installed, the spyware can steal newly received SMS messages (including one-time passcodes) and enable call forwarding,…

September 24, 2026
China-Linked Phish Uses Fake Gmail Preview

China-Linked Phish Uses Fake Gmail Preview

A China-linked espionage group (UAT-11587) targeted Asian government and policy organizations using highly tailored phishing emails and realistic decoy documents. After a click, malware ultimately installed the “Antino” backdoor, which then hid its command-and-control traffic inside normal…

October 3, 2026
Fake AI Advisory Invites Steal M365 Logins

Fake AI Advisory Invites Steal M365 Logins

Researchers say a China-aligned group (TA419) impersonated well-known AI policy figures and an Anthropic executive to lure US AI policy experts into replying to emails about a fake advisory committee or Senate report. Once a target engaged, the attackers sent shortened links that led through a fake…

October 1, 2026
EvilTokens Uses Device Codes to Bypass MFA

EvilTokens Uses Device Codes to Bypass MFA

Microsoft reports that the EvilTokens phishing-as-a-service platform helped criminals compromise thousands of organizations by tricking users into completing a legitimate Microsoft “device code” login. The lure drives victims to enter a short code at microsoft.com/devicelogin, which unknowingly…

September 22, 2026