HomeRisk ManagementsChina-Linked Hackers Impersonate AI Experts to Target U.S. Policy

China-Linked Hackers Impersonate AI Experts to Target U.S. Policy

Published on

spot_img

A China-aligned hacking group, identified as TA419 by cybersecurity firm Proofpoint, has been strategically posing as prominent figures in AI policy and economics to engage in credential theft. This sophisticated phishing campaign specifically targets professionals at U.S. think tanks, universities, and law firms focused on AI-related policies. The findings of Proofpoint’s research, released on October 1, mark the first public disclosure regarding the activities of TA419, indicating that these malicious operations have been ongoing since at least April 2025.

This campaign saw the attackers using the names of well-known individuals, including Lynne Parker, who previously held the position of principal deputy director of the White House Office of Science and Technology Policy. They also impersonated economist and foreign policy expert Heidi Crebo-Rediker. Notably, in February, TA419 had exploited the identity of a senior employee from Anthropic to reach out to an analyst at a think tank specializing in AI policy.

The initial communication from the attackers appeared innocuous, inviting recipients to join a fictitious “AI Policy Advisory Committee” or assist with a purported Senate Committee on Foreign Relations report concerning AI export controls. However, individuals who engaged with these messages were subsequently redirected to a fraudulent login page, cleverly disguised as a OneDrive sign-in interface. This cunning tactic allowed the attackers to lure unsuspecting victims into revealing their login credentials.

Proofpoint outlined that the fraudulent page is an “adversary-in-the-middle” (AitM) reverse proxy, created using an open-source kit known as Frameless BitB. This setup crafts a false browser window within the page, granting the perpetrators the capability to capture live login information. By routing the victim’s Microsoft 365 login credentials in real-time to Microsoft, the attackers could acquire not only passwords but also multifactor authentication (MFA) codes. Consequently, TA419 was able to secure session cookies that provided them extended access to the victims’ accounts.

In an alarming twist, Proofpoint reported that TA419 incorporated its own functionality to monitor the progression of victims throughout the login process. The malicious actors even manipulated the login screen to automatically check the “Keep me signed in” option and to input one-time security codes as soon as they were generated. This level of sophistication underscores an evolution in phishing tactics, shifting away from static web pages toward real-time credential interception.

The implications of TA419’s campaign extend beyond mere credential theft; Proofpoint speculates that these attacks serve the interests of Chinese intelligence agencies, feeding them critical information regarding the development of U.S. AI policy and regulations. This trend aligns with ongoing geopolitical tensions between the United States and China, especially concerning issues related to export controls and AI model refinement.

Additionally, such activities are viewed as a continuation of TA419’s established focus areas, which already include defense, national security, energy, and foreign policy. Given the increasing significance of AI policy in global affairs, it is likely that this group will persist in impersonating credible experts to further their espionage objectives.

In light of these risks, cybersecurity experts strongly advise organizations vulnerable to these forms of phishing to adopt more robust, phishing-resistant authentication methods, such as passkeys. Proofpoint also cautioned individuals who find themselves on the receiving end of unsolicited outreach from alleged experts to approach such communications with skepticism. They recommend that these targets verify the authenticity of unexpected messages through independent channels before engaging further.

As this landscape continues to evolve, stakeholders in AI policy and related fields must remain vigilant to combat these deceptive practices, ensuring the security of sensitive information and the integrity of their institutional knowledge amidst an increasingly hostile cyber environment. The emergence of such alarming tactics serves as a reminder of the critical need for organizations to bolster their cybersecurity measures, safeguarding against both individual and systemic vulnerabilities in a world where digital espionage is becoming prevalent.

Source link

Latest articles

Cisco SD-WAN Vulnerability Exploited

OpenAI Agents Attempt to Hack Canadian Government; ShinyHunters Suspect Arrested In recent developments shaking the...

Next.js ImageResponse Vulnerability Allows Remote Attackers to Execute Code via SVG Content

Next.js Faces Critical Vulnerability: A Threat to Server Security A recent discovery has revealed a...

Cryptohack Roundup – $387M Bitget Hack

Cybersecurity Weekly Roundup: Major Cryptocurrency Incidents In a detailed overview of recent cybersecurity incidents involving...

Cisco SD-WAN Manager Targeted in Zero-Day Admin Access Attack

Cisco Warns of Cybersecurity Risks Associated with SD-WAN Management Interfaces In an era where cyber...

More like this

Cisco SD-WAN Vulnerability Exploited

OpenAI Agents Attempt to Hack Canadian Government; ShinyHunters Suspect Arrested In recent developments shaking the...

Next.js ImageResponse Vulnerability Allows Remote Attackers to Execute Code via SVG Content

Next.js Faces Critical Vulnerability: A Threat to Server Security A recent discovery has revealed a...

Cryptohack Roundup – $387M Bitget Hack

Cybersecurity Weekly Roundup: Major Cryptocurrency Incidents In a detailed overview of recent cybersecurity incidents involving...