China-aligned threat actor TA419 ran real credential-phishing campaigns targeting U.S. AI policy experts at think tanks, universities, and law firms. The operation used trust-building outreach followed by a shortened link that redirected victims through checks to a fake Microsoft/OneDrive sign-in designed to steal credentials and session cookies without breaking the login.
How the Attack Worked
TA419, a China-aligned threat actor, ran a credential-phishing campaign against AI policy experts at U.S. think tanks, universities, and law firms. The operation relied on impersonation of prominent economists, AI policymakers, and an Anthropic employee to build credibility with targets. The email lure used the subject line "Request for Feedback on Military Integration of Claude" to draw in recipients working on AI policy issues.
The workflow was staged in two parts. First, attackers sent harmless outreach designed purely to establish trust and get a reply. Only after the target responded did the attacker send a shortened URL. That link triggered a multi-stage redirection chain, included a Cloudflare Turnstile bot check, and ultimately led to a fake OneDrive sign-in page built to look like a legitimate Microsoft login.
Why It Succeeded
The page used a frameless browser-in-the-browser technique combined with an adversary-in-the-middle proxy. This let the attacker capture both credentials and session cookies while still completing a real, successful sign-in to Microsoft services. Because the login worked as expected, victims had no visible indication that anything had gone wrong, since the usual signs of a failed or suspicious login were absent.
The layered approach, trust-building first, credential theft second, made the attack harder to spot than a typical one-shot phishing email. The bot check and multi-stage redirects also added a veneer of legitimacy that could make targets less suspicious before reaching the final page.
What to Watch For
- Unsolicited messages from unfamiliar contacts requesting expert feedback or commentary, especially ones that pivot quickly toward a link
- Shortened URLs that pass through several redirects before landing on a sign-in page
- Unexpected verification steps, like a bot check, inserted before a Microsoft or OneDrive login
- A sign-in flow that completes successfully but was reached through an unusual path
How to Build Resistance
Organizations and individuals who may be targeted by this kind of outreach, particularly those working on AI policy, defense, or regulatory issues, should treat unsolicited subject-matter requests with caution and verify the sender independently before replying or clicking any follow-up link.
Because AitM phishing can succeed even when the login appears normal, a successful sign-in should not be treated as proof that a page was legitimate. Adopting phishing-resistant authentication methods, such as passkeys, reduces the impact of stolen passwords and session cookies, since these methods are not vulnerable to the same credential-relay techniques used in this campaign.
Key findings
- TA419 targeted AI policy experts at U.S. think tanks (and also universities and legal organizations) using credential phishing.
- Attackers impersonated prominent economists/AI policymakers and an Anthropic employee to increase credibility.
- The email lure included the subject line "Request for Feedback on Military Integration of Claude."
- The workflow was two-stage: initial harmless invitations to build trust, then a shortened URL after the victim replied.
- The shortened URL led through a multi-stage redirect chain and a Cloudflare Turnstile check to an OneDrive adversary-in-the-middle (AitM) phishing page.
- The phishing page used a "Frameless BitB" (browser-in-the-browser) technique and an AitM proxy to capture credentials and session cookies while still logging the victim into real Microsoft services.
- Because the sign-in succeeds, victims may not realize session cookies were captured.
Who’s being targeted
- Commonly targeted roles: Executive leadership at think tanks, Policy and research staff, University faculty and research staff, Legal professionals handling AI policy/regulatory matters, Anyone using Microsoft/OneDrive for collaboration.
- Affected industries: Think tanks / policy research organizations, Higher education (universities), Legal services (law firms), Defense and national security policy organizations.
- Attack channels: email.
- Impersonated: Prominent economists and AI policymakers; also a prominent Anthropic employee.
Red flags to watch for
- Unsolicited policy/outreach message that quickly pivots to a login link
- Shortened URL that redirects multiple times before landing on a Microsoft sign-in
- Unexpected bot-check (Cloudflare Turnstile) before a login page
Frequently asked questions
Who did TA419 target in this campaign?
TA419 targeted AI policy experts at U.S. think tanks, as well as university researchers and legal professionals working on AI policy and regulatory matters.
How did the TA419 phishing attack work?
The attackers sent trust-building outreach impersonating economists, AI policymakers and an Anthropic employee, then followed up with a shortened URL that redirected victims through a Cloudflare Turnstile check to a fake OneDrive sign-in page using an adversary-in-the-middle technique.
Why didn't victims notice their credentials were stolen?
The AitM proxy let the sign-in event succeed normally while stealthily capturing credentials and session cookies, so there were no visible signs anything was wrong.
How can organizations defend against this kind of attack?
Awareness guidance includes verifying unsolicited outreach independently, being cautious of shortened links and unexpected bot checks before a Microsoft login, and enabling phishing-resistant authentication such as passkeys.
Read the video transcript
You get an email: “Request for Feedback on Military Integration of Claude” from a big-name economist or even someone claiming to be from Anthropic. They start friendly, build trust, then after you reply, they send a shortened link. It bounces through redirects, shows a Cloudflare bot check, and lands on what looks like a normal Microsoft OneDrive sign-in. Behind that page is a frameless browser-in-the-browser, a Microsoft adversary-in-the-middle setup. Your login works, OneDrive opens, but they quietly steal your password and session cookies. If you get an unsolicited policy outreach that pivots to a shortened link and Microsoft login, stop and verify the person through a separate channel before you click or sign in.