Chinese APT Group TA419 Impersonates Anthropic Staff to Phish US AI Policy Experts

China-aligned threat actor TA419 has been impersonating a senior employee at Anthropic and other AI policy figures in campaigns targeting United States-based AI policy researchers. According to recent findings, the group’s credential-phishing operations have focused on think tanks, universities, law firms, and defense contractors, with the goal of gaining access to cloud-based accounts.

Who’s Behind the Operation and What They’re After

Security researchers have been tracking TA419 since at least April 2025. Since then, the group has repeatedly gone after policy experts in the U.S. and Japan. Their targets include academics, analysts, legal counsel, and professionals working on export controls, AI governance, and supply chain strategy. These efforts are believed to be intelligence gathering on U.S. AI regulation, military integration, and export policies.

The Phishing Scheme: Lures, Impersonations, and Technique

In one campaign from February 2026, TA419 posed as a high-level Anthropic employee to reach out to a policy analyst at a U.S. think tank. The message used the subject “Request for Feedback on Military Integration of Claude,” referencing public discussions about using Anthropic models for defense work. By July, the group expanded, impersonating former White House science official Lynne Edwards Parker and economist Heidi Crebo-Rediker.

Recipients were invited to fake committees or asked to help with Senate foreign relations reports on AI export controls and supply chains. Initial emails were low-risk—just conversation starters. Only after a response would TA419 send shortened links to ostensibly professional resources. One such domain mimicked a OneDrive interface, complete with a Cloudflare Turnstile check, then redirected users to a site serving a credential phishing page.

The attack chain used a “Browser-in-the-Browser” framework (a variant of AitM phishing) and custom tools derived from the Frameless BitB toolkit. The aim was not only to steal credentials but to capture session cookies and bypass multi-factor authentication (MFA). Targeted services included Microsoft 365 and Entra ID via OfficeHome.

Technical & Infrastructure Details

The phishing infrastructure relied on domains registered via NameSilo with cloud-sharing themed names. The sites were hosted behind Cloudflare and used shared self-signed certificates, possibly pointing to anonymization tactics. Scripts embedded in fake login flows observed user interactions, automated “keep me signed in” prompts, and intercepted one-time codes. These allowed TA419 to hijack active cloud sessions rather than merely capture static credentials.

Researchers have not confirmed if any accounts were compromised in these specific campaigns. Past operations—like the SugarGh0st attacks—demonstrated that AI domain expertise remains a high priority target for sophisticated espionage groups.

What Organizations Should Do

Defensive strategies include verifying unexpected invitations via separate channels, deploying phishing-resistant authentication (e.g. hardware keys), monitoring for anomalous cloud session activity, and revoking suspicious access tokens. Familiar login popups—even those mimicking OneDrive—can’t be fully trusted. Rigorous SOC and threat intel work is essential to mitigating risk.

The modus operandi of TA419 underscores the increasing intensity of state-aligned cyber espionage aimed at shaping or anticipating AI regulation and policy. Artificial intelligence and its governance are now frontline targets.

Why this matters: As the U.S. moves to formalize export controls and regulation around AI, TA419’s targeting of policy experts represents a direct attempt to infiltrate the decision-making process. These campaigns threaten not just individual accounts, but also the confidentiality of policy formulation. Organizations working at this intersection of technology and governance must assume they are under threat and respond accordingly. Watch for domains resembling collaboration tools, insist on MFA that resists phishing, and build protocols for verifying research- or policy-oriented outreach.