Proofpoint linked China-nexus actor TA419 to credential-phishing campaigns aimed at U.S. AI policy experts, including people at think tanks. The attacker impersonated well-known AI policymakers and an Anthropic executive, using believable “advisory committee” and “research questions” emails to draw victims into Microsoft 365 credential theft via an adversary-in-the-middle phishing setup.
How the Attack Worked
TA419, a China-nexus threat actor, ran credential-phishing campaigns aimed at U.S. AI policy experts, including staff at think tanks. The attacker impersonated recognized public figures, such as AI policymakers and economists, and in at least one case a senior-level executive at Anthropic. These impersonations were used to build credibility before the real attack began.
The lures started as routine, low-pressure professional outreach, such as an invitation to join an AI policy advisory committee or a request for information about military use of Anthropic's Claude models. Only after a target replied did the attacker move to the credential theft phase, using an adversary-in-the-middle technique powered by a browser-in-the-browser tool called Frameless BitB. This flow targeted Microsoft 365 and Entra ID logins through a first-party OfficeHome application, making the fake sign-in page appear more legitimate than a typical phishing link.
Why It Succeeded
This campaign worked because it exploited normal professional behavior rather than obvious red flags. An invitation to a committee or a research question from someone claiming AI policy or industry credibility is the kind of message policy experts and researchers receive regularly. By delaying the credential-harvesting step until after a reply, the attacker avoided triggering suspicion at the initial contact stage, when most people are more alert.
The use of a browser-in-the-browser technique also made the fake Microsoft sign-in page harder to distinguish from a real one, since it can visually mimic a legitimate login window within the browser itself.
What to Watch For
- Unsolicited emails inviting you to join a committee, panel, or advisory role, especially with urgency to respond
- Messages referencing sensitive topics, such as military use of AI systems, designed to prompt a quick reply
- A login prompt that appears only after you've replied to an email, rather than at first contact
- Sign-in windows that reference an app or context you did not initiate, such as OfficeHome
- Messages that claim to come from well-known policymakers, economists, or executives without any prior relationship
Building Resistance
Individuals in AI policy, research, and think tank roles should treat unsolicited professional opportunity emails as higher risk and verify the sender through a separate, known-good communication channel before replying or clicking any link. Because credential theft in this campaign happened after engagement rather than at first contact, staying alert through the entire conversation, not just the initial email, is important.
Organizations can reduce the impact of stolen passwords by adopting phishing-resistant authentication methods, such as passkeys, instead of relying solely on passwords. Proofpoint noted it was not aware of confirmed successful compromises from this campaign, but could not rule out activity outside its visibility, underscoring the value of proactive verification habits over reactive detection alone.
Key findings
- China-nexus actor TA419 ran multiple credential-phishing campaigns targeting U.S. AI policy experts and think tank staff.
- Attackers impersonated recognized public figures (AI policymakers/economists) and an Anthropic senior executive to build trust.
- The lure started as routine professional outreach (e.g., advisory committee invite), then shifted to an adversary-in-the-middle login theft flow using a browser-in-the-browser tool (“Frameless BitB”).
- The credential theft focused on Microsoft 365/Entra ID and used a first-party OfficeHome application.
- Infrastructure details noted by Proofpoint: Cloudflare CDN used to obscure hosting; domains commonly registered via NameSilo.
- Proofpoint said it was not aware of confirmed successful compromises, but could not rule out compromises outside its visibility.
Who’s being targeted
- Commonly targeted roles: Think tank leadership, AI policy teams, Researchers/analysts, Executive assistants and staff who handle external outreach, Anyone using Microsoft 365/Entra ID for email.
- Affected industries: Think tanks / policy research, Academia / universities, Defense contractors, Law firms.
- Attack channels: email, website.
- Impersonated: Former White House Office of Science and Technology Policy leader / AI policymaker, Anthropic senior-level executive.
Red flags to watch for
- Unexpected outreach asking you to join a committee with urgency or pressure to respond
- A login prompt appears in a web page context that doesn’t match Microsoft’s normal sign-in flow (browser-in-the-browser behavior)
- Sign-in flow references an app/context you didn’t initiate (e.g., OfficeHome)
- High-sensitivity topic used to prompt quick engagement (military use)
- Sender claims to be a senior executive but uses an unexpected process/link for follow-up
- Any Microsoft sign-in page that appears embedded or unusual (BitB)
Frequently asked questions
Who did TA419 target in this phishing campaign?
TA419 targeted U.S. AI policy experts, including think tank leadership, researchers, and policy analysts, often by impersonating well-known AI policymakers and an Anthropic executive.
How did the attackers steal credentials?
After a target replied to a lure email, attackers used an adversary-in-the-middle technique with a browser-in-the-browser tool called Frameless BitB to harvest Microsoft 365 and Entra ID credentials through a first-party OfficeHome application.
What made this phishing campaign convincing?
The lures began as routine professional outreach, such as invitations to join an AI policy advisory committee or questions about military use of AI models, which built trust before the credential theft stage began.
How can organizations defend against this type of attack?
Verify unsolicited professional outreach through a separate channel, watch for login prompts that appear after replying to an email, and adopt phishing-resistant authentication methods like passkeys.
Read the video transcript
You get an email: “Hello, I’m reaching out to request that you join an advisory committee on AI policy.” Looks legit, big-name sender, right? This is TA419, a China-linked group, impersonating AI policymakers and even an Anthropic executive. Once you reply, they send a Microsoft 365 link and launch an adversary-in-the-middle attack using a browser-in-the-browser tool called Frameless BitB. Here’s the trick: a fake Microsoft 365 login pops up inside the page. It looks like a normal sign-in, even shows 'OfficeHome', but it’s a BitB window, just a picture of a browser stealing your Entra ID credentials in the middle. If an invite or research request pushes you to a Microsoft sign-in that feels even slightly off, BitB popup, odd URL, 'OfficeHome' you didn’t start, stop and verify the person through a separate, known-good channel before you click anything.