TA419, a China-nexus espionage group, has been using credential phishing campaigns to target AI experts at U.S. think tanks, universities, and legal organizations by impersonating economists, AI policymakers, and a prominent Anthropic employee. The group uses shortened URLs, multi-stage redirection, and a Frameless BitB adversary-in-the-middle setup to steal Microsoft credentials and session cookies while appearing legitimate. #TA419 #Anthropic #Microsoft #CloudflareTurnstile
Keypoints
- TA419 is a China-aligned espionage group targeting AI policy experts in the United States.
- The campaigns impersonate economists, policymakers, and an Anthropic employee to build trust.
- Attack chains use shortened URLs, redirection, and Cloudflare Turnstile checks.
- The group deploys a Frameless BitB technique with an adversary-in-the-middle proxy.
- Organizations are advised to use phishing-resistant authentication such as passkeys.
Read More: https://thehackernews.com/2026/10/china-aligned-ta419-targets-us-ai.html