Daily MaverickCOLLECTIVE WELLBEING: Renewable energy was promised as a path to prosperity — what happened?RTP DesportoDamsgaard empata para a DinamarcaESPN DeportesWNBA Playoffs 2026: Bracket, calendario, resultados y másESPNSteelers trade Porter to Cowboys, get pair of picks to end CB sagaThe Jerusalem PostIn their own voice: How Iran’s citizens documented January's massacres in Manoto documentaryBBC NewsPutin warns West that Russia is ready to use every weapon to protect KaliningradEl TiempoRevuelo en redes sociales: pasajeros de un vuelo de Avianca denunciaron que pasaron la noche en el piso tras demora en la ruta de Bucaramanga- BogotáLa PresseLes ministres de la Santé provinciaux demandent à Ottawa de renouveler du financementynet ספורטחי, מחצית: ישראל - קוסובו 0:0XatakaBenoit Pouffary, ingeniero de la ESA: “Almería podría ser el mejor lugar del mundo para simular lo que el rover estará enfrentando cuando llegue a Marte”NOSMislukte executie van Christa Pike was 'marteling', zegt haar advocaatIl Sole 24 OreAll’Ostello Caritas di Roma il concerto di Marco Arcieri dedicato a Chopin
The Daily Newsstand · Free, Always
Thursday, October 1, 2026

Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing

Translate

Your invite to a fake AI policy advisory committee has strings attached

A suspected Chinese espionage group impersonated AI policy figures, including a senior Anthropic employee and a former White House official, in phishing campaigns targeting AI policy experts at US universities, think tanks, and law firms, security researchers say.

The bulk of these campaigns occurred in July, according to Proofpoint, which discovered the espionage attempts and attributed them to a China-aligned group it tracks as TA419.

Proofpoint’s security alert comes a day after OpenAI accused China’s Moonshot AI of stealing the American models’ reasoning and other data in distillation attacks that began on July 1.

REG AD

“In July 2026, TA419 impersonated multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team, in credential phishing campaigns targeting AI policy experts in the US,” Proofpoint threat-intelligence analyst Mark Kelly said in a Thursday report.

REG AD

Beginning July 8, TA419 sent phishing emails spoofing Lynne Edwards Parker, the former principal deputy director of the White House Office of Science and Technology Policy, and then Heidi Crebo-Rediker, a prominent economist and foreign policy expert, to even more American AI policy experts at think tanks, universities, and law firms. The suspected spies’ emails invited their targets to join a fake AI policy advisory committee or contribute to a Senate foreign relations committee report on AI export controls and supply chains.

If the American AI expert replied, the Beijing-linked crew responded with a shortened URL promising to share additional details, but in reality pointing to an attacker-controlled domain. This page conducts a Cloudflare Turnstile check behind a phony OneDrive loading screen, and then redirects the victim to an attacker-in-the-middle (AitM) credential phishing page that steals the victim’s cloud account login information.

The July 2026 campaigns used driftshare[.]co as the first-stage domain and globalfileshareplatform[.]com as the second-stage domain.

In February - as US military officials pressured Anthropic to remove Claude’s safeguards - the Chinese spies spoofed a senior Anthropic employee to phish an AI policy analyst at a US think tank. This email used the subject line: “Request for Feedback on Military Integration of Claude.”

TA419’s phishing chain targets Microsoft 365/Entra ID through the first-party OfficeHome application (client_id=4765445b-32c6-49b0-83e6-1d93765276ca). It’s built on open source Frameless BitB, which contains a Browser-in-the-Browser (BitB) overlay, an Evilginx phishlet to intercept usernames, passwords, and session cookies for Microsoft 365, and server-side substitution rules that inject the kit into proxied pages.

TA419 typically uses Cloudflare’s content delivery network to hide the backend hosting IP address for its domains, and its credential phishing domains are usually themed around file sharing sites and cloud services - such as msfile[.]online and onecloudfilesync[.]com. 

It also impersonates specific organizations, including the Japan-Taiwan Exchange Association (tw-koryu[.]org), The Heritage Foundation (heritiages[.]org and heritiage[.]org), and Japanese Minister of Defense Shinjirō Koizumi’s official website (shinjirou[.]info).

In total, the crew uses dozens of phishing and spoofed-sender domains, and phony email addresses. Proofpoint includes all of the ones it discovered in 2026, plus the timeline of when they were registered or first seen, so check out those indicators, too.

REG AD

TA419 and other Beijing-aligned crews will likely continue targeting AI and other policy experts working on technologies of interest to the Chinese government, according to the threat hunters. “Organizations in the scope of TA419 activity should consider phishing-resistant, origin-bound authentication such as passkeys,” they recommend.®

View the original on The Register →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.