China-Aligned Hackers Impersonate US Officials in AiTM Phishing Campaign Targeting AI Experts

Summary
Proofpoint says China-aligned actor TA419 impersonated US officials to build trust with AI experts before directing them to fake OneDrive pages designed to steal credentials and authenticated sessions.
Key points
- Proofpoint attributed the July campaign to TA419 and said it targeted AI experts at US think tanks, universities, and legal organizations.
- Attackers posed as prominent policy figures and used benign outreach about AI policy and export controls to establish trust.
- After targets replied, the actor sent shortened links that redirected through multiple stages to fake OneDrive pages.
- The phishing pages used a customized version of the open-source Frameless BitB tool for adversary-in-the-middle credential theft.
- AiTM phishing can capture authenticated sessions even when victims complete MFA, potentially allowing account access without repeating MFA.
- Proofpoint recommended verifying unexpected subject-matter outreach through an independent channel and considering phishing-resistant, origin-bound authentication such as passkeys.
Article Details
- Event Type
- Cyber-espionage campaign using impersonation and adversary-in-the-middle credential phishing
- Impact
- The campaign was designed to steal credentials and authenticated sessions from AI policy experts. A stolen session could potentially be reused to access an account without completing MFA again; the article does not confirm successful account compromise.
People
Heidi Crebo-RedikerEconomist and foreign policy expert who was impersonated by TA419.Lynne Edwards ParkerFormer principal deputy director of the White House Office of Science and Technology Policy; impersonated by TA419 in the campaign.Mark KellyProofpoint cyber-threat intelligence analyst who co-authored the cited research.Steven SwiftManaging director of Suzu Labs who commented on the attack and MFA.
Threat Actors
Products
Tools
Countries
ChinaResearchers from Proofpoint discovered the campaign, which occurred in July, and attributed it to China-aligned threat actor TA419, according to a blog post published last week. The activity is believed to be part of aJapanTA419 conducting regular targeted credential phishing campaigns against individuals working for US- and Japan-based think tanks, defense contractors, universities, and law firms since at least April 2025," ProofpointUnited StatesChinese hackers impersonated US policymakers in adversary-in-the-middle (AitM) phishing campaigns aimed at stealing credentials from AI experts working for US think tanks, universities, and legal organizations.
Industries
Artificial intelligenceDefensetargeted credential phishing campaigns against individuals working for US- and Japan-based think tanks, defense contractors, universities, and law firms since at least April 2025," Proofpoint cyber-threat intelligenceEducationLegalChinese hackers impersonated US policymakers in adversary-in-the-middle (AitM) phishing campaigns aimed at stealing credentials from AI experts working for US think tanks, universities, and legal organizations.