Chinese Hackers Posing as Senior Anthropic Employee Targeting US AI Policy Experts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A China-aligned hacking group tracked as TA419 has impersonated a senior Anthropic employee and well-known policy figures to target US artificial intelligence experts.

Proofpoint linked the activity to credential-phishing campaigns aimed at researchers at think tanks, universities, and law firms, with lures designed to steal access to their cloud accounts.

The targeting likely supports Chinese intelligence efforts to understand US AI rules, export controls, and national strategy. Proofpoint has tracked TA419 since at least April 2025, observing campaigns against US and Japanese think tanks, defense contractors, universities, and legal organizations.

Chinese Hackers Posing as Anthropic Employee

In February 2026, TA419 posed as a senior Anthropic employee while contacting an AI policy analyst at a US think tank. The message carried the subject “Request for Feedback on Military Integration of Claude,” drawing on the public debate over military use of Anthropic’s AI models.

The campaign expanded in July. Beginning July 8, the attackers impersonated Lynne Edwards Parker, a former senior White House science and technology official, and economist Heidi Crebo-Rediker.

Messages invited recipients to join a fictitious “AI Policy Advisory Committee” or contribute to a Senate foreign relations report covering AI export controls and supply chains.

Spoofed Committee Invitation Email (Image Source: Proofpoint)

The first emails were conversation starters rather than immediate login requests. Once a recipient replied, TA419 sent a shortened link claiming to provide further information. This patient approach made the later document-sharing request appear connected to an established professional exchange.

According to the supplied Proofpoint findings, the shortened links passed through attacker-controlled websites. The first domain, driftshare[.]co, displayed a fake OneDrive loading screen and ran a Cloudflare Turnstile check before directing visitors to globalfileshareplatform[.]com, which hosted the credential phishing flow.

The attack combined adversary-in-the-middle, or AitM, phishing with a modified Frameless BitB toolkit. Browser-in-the-Browser creates a fake browser window inside a webpage, including a convincing address bar. Frameless BitB avoids iframes and supports Evilginx-based proxying of Microsoft login pages.

TA419 targeted Microsoft 365 and Entra ID through Microsoft’s OfficeHome application. Instead of merely copying a login screen, the proxy relayed the genuine Microsoft sign-in process while adding malicious scripts. This allowed supported password and MFA steps to complete while the attacker captured the resulting session cookies.

The script /secondary/script.js built a OneDrive-style document listing inside a Shadow DOM, a separate section of the page’s structure. Another script, /primary/script.js, watched document clicks and permission warnings, then displayed the fake Chrome login window.

Fake OneDrive Login Prompt (Image Source: Proofpoint)

A custom module, /secondary/observe.js, tracked each target’s progress through authentication. It also automatically accepted “Keep me signed in” and submitted validated one-time codes. The goal was a usable cloud session, not simply a stolen password.

TA419 used Cloudflare to hide backend hosting addresses and commonly registered cloud-sharing-themed domains through NameSilo. Email headers also exposed likely attacker-controlled servers, including 108.61.163[.]187. Shared self-signed certificates suggested a possible anonymization network, although that connection remains an assessment.

Related Cybersecurity News coverage of Browser-in-the-Browser phishing explains why familiar login windows cannot establish trust. Organizations should verify unexpected invitations independently, deploy phishing-resistant authentication, investigate unusual cloud sessions, and revoke suspicious tokens.

Earlier SugarGh0st attacks against AI researchers show that AI expertise remains an intelligence target. Public reporting does not establish whether TA419 successfully compromised these accounts.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

The post Chinese Hackers Posing as Senior Anthropic Employee Targeting US AI Policy Experts appeared first on Cyber Security News.