
Suspected Chinese spies spoofed an Anthropic exec and ex-White House official in AI phishing
Proofpoint says a China-aligned group it tracks as TA419 impersonated a senior Anthropic employee and former White House official Lynne Parker to phish AI policy experts at US think tanks, universities and law firms.
Security researchers at Proofpoint say a China-aligned espionage group it tracks as TA419 impersonated AI policy figures, including a senior Anthropic employee and a former White House official, in credential phishing campaigns targeting AI policy experts at US universities, think tanks and law firms. The bulk of the activity took place in July.
Borrowed identities
Proofpoint threat-intelligence analyst Mark Kelly said in the report that beginning on July 8, TA419 sent emails spoofing Lynne Edwards Parker, the former principal deputy director of the White House Office of Science and Technology Policy, and later Heidi Crebo-Rediker, an economist and foreign policy expert. The messages invited targets to join a fictitious "AI policy advisory committee" or contribute to a Senate foreign relations committee report on AI export controls and supply chains.
In February, as US military officials pressured Anthropic to remove safeguards from its Claude models, the group spoofed a senior Anthropic employee to phish an AI policy analyst at a US think tank. That email carried the subject line "Request for Feedback on Military Integration of Claude."
How the phishing chain worked
If a target replied, the attackers sent a shortened URL. The link led to an attacker-controlled domain that ran a Cloudflare Turnstile check behind a fake OneDrive loading screen, before redirecting to an adversary-in-the-middle (AitM) page built to steal cloud account logins.
The July campaigns used driftshare[.]co as the first-stage domain and globalfileshareplatform[.]com as the second stage. The phishing chain targets Microsoft 365 and Entra ID, and is built on the open-source Frameless BitB toolkit, which uses a Browser-in-the-Browser overlay to intercept usernames, passwords and session cookies.
TA419 typically hides the backend hosting IP behind Cloudflare's content delivery network, and its domains are themed around file-sharing and cloud services, such as msfile[.]online. The crew also impersonates organizations such as the Japan-Taiwan Exchange Association and The Heritage Foundation.
Why it matters
Proofpoint assesses that the campaigns likely feed Chinese intelligence interest in how US AI policy and regulation are developing, amid US-China competition over AI, export controls and semiconductor supply chains. The firm expects TA419 to keep targeting think tanks and policy experts working on technologies of interest to the Chinese government, and to keep spoofing the identities of real experts.
Organizations in the scope of TA419 activity should consider phishing-resistant, origin-bound authentication such as passkeys, the threat hunters recommend.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.