Researchers reported two China-aligned campaigns that used phishing and impersonation to target AI policy experts and multiple Asian government organizations. One campaign built rapport with “AI policy” themed outreach before sending links to a OneDrive credential-harvesting page, while another used spear-phishing emails with decoy documents to deliver malware for espionage.
Key findings
- Proofpoint described a July incident where a China-aligned actor ran phishing attacks by impersonating prominent economists and a former White House science/technology policy official.
- Targets included AI experts in universities, think tanks, and law firms, with lures about joining a fake “AI Policy Advisory Committee” or contributing to a fictitious Senate report.
- After victims responded, attackers sent a URL redirection chain leading to a OneDrive credential phishing page.
- Cisco Talos reported a separate China-linked campaign targeting government organizations across multiple Asian countries, with initial access via phishing emails and decoy documents.
- Talos observed ~350 compromised endpoints across eight countries and stated the campaign goal was intelligence gathering.
Who’s being targeted
- Commonly targeted roles: Executive leadership, Government affairs / public policy, Researchers (AI/technology), Think tank staff, Legal (policy/regulatory), Administrative staff supporting policy teams.
- Affected industries: Government, Higher education, Think tanks / policy organizations, Legal services, Artificial intelligence / technology.
- Attack channels: email, website.
- Impersonated: Former White House official Lynne Edwards Parker / foreign policy expert Heidi Crebo-Rediker (impersonation), Unspecified (campaign used decoy documents and spoofed invitations).
Awareness takeaways
- Treat unsolicited ‘committee invitations’ and ‘policy collaboration’ requests as high-risk, even if they appear to come from credible experts.
- Be cautious when an initial email seems harmless and relationship-building; attackers may be trying to get you to respond before sending the real payload.
- Don’t enter credentials after clicking links from emails, especially if you are redirected and land on a cloud login page (e.g., OneDrive).
- Assume “timely” topical attachments (news/legislative/event invites) can be weaponized; verify via known official channels before opening or downloading.
Red flags to watch for
- Too-good-to-be-true policy invitation from an unexpected sender
- Conversation-starter email designed to prompt a reply before any real details are provided
- Link redirects and leads to a login page asking for credentials (OneDrive phishing)
- Unexpected email with attachments/decoy documents
- Pressure to review timely ‘news’ or ‘legislative’ material
- Sender/event details don’t match known official channels
Read the video transcript
You get this email: “Invitation to join an AI Policy Advisory Committee,” supposedly from a former White House science official. Researchers say China-linked groups are doing this for real, impersonating economists and policy experts, asking you to join a fake AI committee or contribute to a Senate report, just to get you to reply. Here’s the trick: once you respond, they send a link that bounces through redirects into a OneDrive login page. It looks normal, but it’s a credential phish built to steal your username and password. If you get an unexpected policy invite or briefing, and it leads to a login page after a few redirects, stop. Don’t sign in there, go to the service directly and log in from a fresh browser tab.