China-Aligned Hackers Impersonate US Officials in AiTM Phishing Campaign Targeting AI Experts

· Original article ↗

Summary

Proofpoint says China-aligned actor TA419 impersonated US officials to build trust with AI experts before directing them to fake OneDrive pages designed to steal credentials and authenticated sessions.

Key points

  • Proofpoint attributed the July campaign to TA419 and said it targeted AI experts at US think tanks, universities, and legal organizations.
  • Attackers posed as prominent policy figures and used benign outreach about AI policy and export controls to establish trust.
  • After targets replied, the actor sent shortened links that redirected through multiple stages to fake OneDrive pages.
  • The phishing pages used a customized version of the open-source Frameless BitB tool for adversary-in-the-middle credential theft.
  • AiTM phishing can capture authenticated sessions even when victims complete MFA, potentially allowing account access without repeating MFA.
  • Proofpoint recommended verifying unexpected subject-matter outreach through an independent channel and considering phishing-resistant, origin-bound authentication such as passkeys.

Article Details

Event Type
Cyber-espionage campaign using impersonation and adversary-in-the-middle credential phishing
Impact
The campaign was designed to steal credentials and authenticated sessions from AI policy experts. A stolen session could potentially be reused to access an account without completing MFA again; the article does not confirm successful account compromise.

People

Threat Actors

Products

Tools

Countries

Industries

Related Articles