安全
疑似中国间谍冒充Anthropic高管、前白宫官员进行AI钓鱼攻击
你受邀加入的虚假AI政策咨询委员会背后另有隐情
杰西卡·莱恩斯(Jessica Lyons)
网络安全编辑
发布于2026年10月1日 星期四 // 16:43 UTC
阅读更多
华为老板称国产AI芯片销量超越英伟达在中国市场
1天前
OpenAI效仿AWS Marketplace,而Anthropic依然坚持微软生态
1天前
特朗普政府促使大型科技公司签署软弱、无约束力的AI监管规定
1天前
泄露的IPO文件:Anthropic以生存风险警告吸引投资者
2天前
OpenAI暂停部分训练,因其 rogue agents(失控智能体)行为比最初认为的更恶劣
3天前
安全研究人员称,一个疑似中国间谍组织在针对美国大学、智库和律师事务所的AI政策专家的钓鱼活动中,冒充了包括Anthropic高级员工和前白宫官员在内的AI政策人物。
根据发现这些间谍活动并将其归因于其追踪的中国关联组织TA419的Proofpoint的说法,这些活动主要集中在7月进行。
Proofpoint的安全警报发布前一天,OpenAI指控中国的Moonshot AI在始于7月1日的蒸馏攻击中窃取了美国模型的推理能力及其他数据。
“在2026年7月,TA419冒充了多名个人,包括前白宫科技政策办公室领导团队成员,针对美国的AI政策专家开展凭证钓鱼活动,”Proofpoint威胁情报分析师Mark Kelly在周四的一份报告中表示。
从7月8日开始,TA419发送伪造的钓鱼邮件,冒充前白宫科技政策办公室首席副主管Lynne Edwards Parker,随后又冒充著名经济学家和外交政策专家Heidi Crebo-Rediker,向更多美国AI政策专家发出邀请,这些专家分布在智库、大学和律师事务所。疑似间谍的邮件邀请目标加入一个虚假的AI政策咨询委员会,或为参议院外交关系委员会关于AI出口管制和供应链的报告做出贡献。
如果美国AI专家回复,这个与北京有关联的团队会回复一个缩短的URL,承诺分享更多细节,但实际上指向攻击者控制的域名。该页面在虚假的OneDrive加载屏幕背后进行Cloudflare Turnstile检查,然后将受害者重定向到中间人(AitM)凭证钓鱼页面,窃取受害者的云账户登录信息。
2026年7月的活动使用driftshare[.]co作为第一阶段域名,globalfileshareplatform[.]com作为第二阶段域名。
在2月——当时美国军方官员施压Anthropic移除Claude的安全措施——中国间谍冒充了一名Anthropic高级员工,向美国智库的一名AI政策分析师发起钓鱼攻击。这封邮件的主题行是:“请求对Claude军事整合提供反馈。”
TA419的钓鱼链通过第一方OfficeHome应用程序(client_id=4765445b-32c6-49b0-83e6-1d93765276ca)针对Microsoft 365/Entra ID。它基于开源Frameless BitB构建,其中包含浏览器内(BitB)覆盖层、用于拦截Microsoft 365用户名、密码和会话cookie的Evilginx钓鱼配置,以及将工具包注入代理页面的服务器端替换规则。
TA419通常使用Cloudflare的内容分发网络来隐藏其域名的后端托管IP地址,其凭证钓鱼域名通常围绕文件共享站点和云服务主题——例如msfile[.]online和onecloudfilesync[.]com。
它还冒充特定组织,包括日本台湾交流协会(tw-koryu[.]org)、传统基金会(heritiages[.]org和heritiage[.]org),以及日本防卫大臣小泉进次郎的官方网站(shinjirou[.]info)。
总体而言,该团伙使用了数十个网络钓鱼和伪造发件人域名,以及虚假的电子邮件地址。Proofpoint 列出了其在2026年发现的所有此类域名,并附带了它们被注册或首次出现的时间线,因此请一并关注这些指标。
据威胁猎手称,TA419及其他与北京结盟的黑客组织可能会继续针对从事中国政府感兴趣的技术工作的AI专家及其他政策专家。“处于TA419活动范围内的组织应考虑采用防网络钓鱼、绑定源的身份验证方式,例如通行密钥(passkeys)。”他们建议道。®
SECURITY
Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing
Your invite to a fake AI policy advisory committee has strings attached
Jessica Lyons
CYBERSECURITY EDITOR
Published Thu 01 Oct 2026 // 16:43 UTC
READ MORE
Huawei boss claims homegrown AI chip sales top Nvidia in China
1 day ago
OpenAI apes AWS Marketplace while Anthropic remains stubbornly Microsoftian
1 day ago
Trump administration gets Big Tech to sign weak, non-binding, AI regulations
1 day ago
Leaked IPO docs: Anthropic tempts investors with existential risk warning
2 days ago
OpenAI pauses some training amid allegations its rogue agents behaved more badly than first thought
3 days ago
A suspected Chinese espionage group impersonated AI policy figures, including a senior Anthropic employee and a former White House official, in phishing campaigns targeting AI policy experts at US universities, think tanks, and law firms, security researchers say.
The bulk of these campaigns occurred in July, according to Proofpoint, which discovered the espionage attempts and attributed them to a China-aligned group it tracks as TA419.
Proofpoint’s security alert comes a day after OpenAI accused China’s Moonshot AI of stealing the American models’ reasoning and other data in distillation attacks that began on July 1.
“In July 2026, TA419 impersonated multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team, in credential phishing campaigns targeting AI policy experts in the US,” Proofpoint threat-intelligence analyst Mark Kelly said in a Thursday report.
Beginning July 8, TA419 sent phishing emails spoofing Lynne Edwards Parker, the former principal deputy director of the White House Office of Science and Technology Policy, and then Heidi Crebo-Rediker, a prominent economist and foreign policy expert, to even more American AI policy experts at think tanks, universities, and law firms. The suspected spies’ emails invited their targets to join a fake AI policy advisory committee or contribute to a Senate foreign relations committee report on AI export controls and supply chains.
If the American AI expert replied, the Beijing-linked crew responded with a shortened URL promising to share additional details, but in reality pointing to an attacker-controlled domain. This page conducts a Cloudflare Turnstile check behind a phony OneDrive loading screen, and then redirects the victim to an attacker-in-the-middle (AitM) credential phishing page that steals the victim’s cloud account login information.
The July 2026 campaigns used driftshare[.]co as the first-stage domain and globalfileshareplatform[.]com as the second-stage domain.
In February - as US military officials pressured Anthropic to remove Claude’s safeguards - the Chinese spies spoofed a senior Anthropic employee to phish an AI policy analyst at a US think tank. This email used the subject line: “Request for Feedback on Military Integration of Claude.”
TA419’s phishing chain targets Microsoft 365/Entra ID through the first-party OfficeHome application (client_id=4765445b-32c6-49b0-83e6-1d93765276ca). It’s built on open source Frameless BitB, which contains a Browser-in-the-Browser (BitB) overlay, an Evilginx phishlet to intercept usernames, passwords, and session cookies for Microsoft 365, and server-side substitution rules that inject the kit into proxied pages.
TA419 typically uses Cloudflare’s content delivery network to hide the backend hosting IP address for its domains, and its credential phishing domains are usually themed around file sharing sites and cloud services - such as msfile[.]online and onecloudfilesync[.]com.
It also impersonates specific organizations, including the Japan-Taiwan Exchange Association (tw-koryu[.]org), The Heritage Foundation (heritiages[.]org and heritiage[.]org), and Japanese Minister of Defense Shinjirō Koizumi’s official website (shinjirou[.]info).
In total, the crew uses dozens of phishing and spoofed-sender domains, and phony email addresses. Proofpoint includes all of the ones it discovered in 2026, plus the timeline of when they were registered or first seen, so check out those indicators, too.
TA419 and other Beijing-aligned crews will likely continue targeting AI and other policy experts working on technologies of interest to the Chinese government, according to the threat hunters. “Organizations in the scope of TA419 activity should consider phishing-resistant, origin-bound authentication such as passkeys,” they recommend.®
CREDENTIAL PHISHING ANTHROPIC SECURITY CHINA
首次收录 · 2026-10-02 · 8.68 分