China-Nexus Group Targets US AI Experts
A sophisticated credential phishing campaign has targeted United States artificial intelligence policy experts, leveraging highly customized social engineering tactics and advanced browser-spoofing techniques.

A series of highly targeted cyber operations has emerged, focusing on individuals shaping artificial intelligence policy within the United States. Security researchers have identified a systematic campaign designed to harvest login credentials from specialized researchers and policy advisors. The threat actors utilize a multi-stage approach, initiating contact with benign, trust-building invitations before delivering shortened URLs that direct targets to sophisticated credential-harvesting pages. This methodology represents a shift toward highly personalized, patient social engineering designed to bypass standard digital defenses.
According to reports from the cybersecurity firm Proofpoint, these operations are attributed to TA419, a cyber espionage group with links to China. Proofpoint asserts that TA419 has targeted AI experts at U.S. think tanks, universities, and legal organizations since at least April 2025. Specifically, the group is accused of impersonating a prominent Anthropic employee in February 2026 to target an AI policy expert at a U.S. think tank, utilizing an email with the subject line "Request for Feedback on Military Integration of Claude." Furthermore, Proofpoint reported that around July 2026, the actors impersonated individuals including a former member of the White House Office of Science and Technology Policy leadership team. Alex Engler, a former White House official, confirmed to Reuters that he received a suspicious email from an impostor posing as Lynne Parker, inviting him to participate in an AI policy project.
These activities matter because they directly target the intellectual and regulatory framework of American artificial intelligence development. Security analysts point out that the attackers employed a technique known as Frameless BitB, which spoofs a trusted login page by crafting a fake browser window within a legitimate browser session using HTML, CSS, and JavaScript. TA419 allegedly extended this open-source tool with a custom telemetry and automation module to track Microsoft sign-in flows and capture credentials using an Adversary-in-the-Middle proxy. This method allows victims to successfully sign in without noticing any anomalies, while their session cookies are stealthily captured. Proofpoint stated that this activity likely supports wider Chinese intelligence objectives to understand U.S. AI policy and regulatory landscapes amid ongoing strategic competition.
In response to these allegations, the Chinese government has historically denied conducting cyberespionage operations. Additionally, the Chinese Embassy in Washington did not provide a response to Reuters' request for comment regarding this specific campaign.
Several key details regarding the scope and impact of the campaign remain undisclosed. Proofpoint did not reveal the success rate of these attacks, how many individuals were successfully compromised, or whether any sensitive data was actually exfiltrated. Furthermore, the specific identities of the senior Anthropic employee who was impersonated, as well as the identities of the other targeted policy experts, have not been publicly disclosed.
Sources
- The Hacker NewsChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
- GitHubwaelmas - Overview
- ProofpointHallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles
- GblockTA419 Phishing Fakes AI Policy Experts to Target Researchers
- InternazionaleChinese hackers impersonated ex-US official to steal emails from AI experts
Verified claims
Written by The Quiet Search. Method: /about.