一家与中国结盟的情报组织被Proofpoint发现,正伪装成前白宫官员和知名经济学家,以入侵美国AI政策专家的云端账户。
研究人员将该组织追踪为TA419,该组织在2026年7月发动了多起凭据钓鱼活动。
“2026年7月,TA419在针对美国AI政策专家的凭据钓鱼活动中冒充了多名个人,包括白宫科技政策办公室领导团队的前成员,”Proofpoint威胁情报分析师Mark Kelly写道。
自2026年7月8日起,TA419首先冒充了白宫科技政策办公室前常务副主任Lynne Edwards Parker,随后又冒充了经济学家兼外交政策专家Heidi Crebo-Rediker。
在2026年2月,该组织曾冒充Anthropic的一名高级员工,以针对美国智库的一名AI政策分析师。那封邮件的主题行是“关于Claude军事整合的反馈请求”,这指的是围绕美军使用Anthropic Claude模型的争论。
攻击过程详解
第一封电子邮件中不包含恶意链接。它们邀请目标加入一个虚构的“AI政策咨询委员会”,或为参议院外交关系委员会关于AI出口管制和供应链的报告做出贡献。
TA419活动邀请用户为AI供应链报告做出贡献(来源:Proofpoint)
“如果目标回复,TA419会跟进提供一个缩短的URL,声称分享额外信息。该链接最终指向一个伪造的OneDrive AitM凭据钓鱼页面,旨在获取对目标云端账户的访问权限,”Kelly指出。
该链接首先经过由该组织控制的域名,该域名在伪造的OneDrive加载屏幕后面运行Cloudflare Turnstile验证。
随后,目标被引导至托管钓鱼页面的第二个域名。该页面显示带有诱饵文档的OneDrive文件夹列表。点击文档或OneDrive自带的登录提示,会在页面内通过Frameless BitB(一个开源的浏览器内浏览器工具)打开一个伪造的Chrome登录窗口。
在该窗口中输入的凭据会被中继到Microsoft的服务器,因此密码、MFA代码以及条件访问检查都会顺利通过。该套件内置的自定义脚本会将受害者的进度报告给攻击者,提供会话的实时视图,接受“保持登录状态”提示,并在一次性代码验证后立即提交。
该套件旨在捕获登录结束时创建的会话Cookie,这将使攻击者能够访问目标的账户。
基础设施与动机
“TA419一贯使用Cloudflare的内容分发网络(CDN)来隐藏其域名背后的托管IP地址,这些域名通常通过NameSilo注册。该组织的凭据钓鱼域名通常以文件共享站点和云服务为主题,”Kelly补充道。
该组织偶尔会注册冒充特定组织的域名,例如用于 Heritage Foundation 的 heritiages[.]org 和 heritiage[.]org,用于日本-台湾交流协会的 tw-koryu[.]org,以及模仿日本防卫大臣小泉进次郎官方网站的 shinjirou[.]info。
“这些活动可能支持更广泛的中国情报目标,以更好地了解美国AI政策和监管格局中的最新发展,并且发生在美中之间激烈的战略竞争、模型蒸馏指控以及涉及出口管制的背景下,”Proofpoint总结道。
A China-aligned espionage group has been posing as a former White House official and a prominent economist to get into the cloud accounts of AI policy experts in the US, Proofpoint have found.
The group, which the researchers track as TA419, ran several credential phishing campaigns in July 2026.
“In July 2026, TA419 impersonated multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team, in credential phishing campaigns targeting AI policy experts in the US,” wrote Proofpoint threat intelligence analyst Mark Kelly .
Beginning 8 July 2026, TA419 first impersonated Lynne Edwards Parker, former Principal Deputy Director of the White House Office of Science and Technology Policy, and then Heidi Crebo-Rediker, an economist and foreign policy expert.
In February 2026, the group impersonated a senior Anthropic employee to target an AI policy analyst at a US think tank. That email carried the subject line “Request for Feedback on Military Integration of Claude”, a reference to the debate over the US military’s use of Anthropic’s Claude models.
How the attack unfolds
The first emails contained no malicious links. They invited targets to join a fictitious “AI Policy Advisory Committee” or to contribute to a Senate Committee on Foreign Relations report on AI export controls and supply chains.
TA419 campaign inviting users to contribute to AI supply chain report (Source: Proofpoint)
“If the target replied, TA419 followed up with a shortened URL that purported to share additional information. The link ultimately led to a fake OneDrive AitM credential phishing page designed to gain access to the target’s cloud account,” noted Kelly.
The link first passes through a domain controlled by the group, which runs a Cloudflare Turnstile check behind a fake OneDrive loading screen.
From there, the target is sent to a second domain hosting the phishing page. It shows a OneDrive folder listing with lure documents. Clicking a document, or OneDrive’s own prompt to sign in, opens a fake Chrome login window drawn inside the page with Frameless BitB, an open-source browser-in-the-browser tool.
Credentials entered in that window are relayed to Microsoft’s servers, so the password, the MFA code and conditional access checks would all go through. A custom script built into the kit reports the victim’s progress to the attackers, gives them a live view of the session, accepts the “Keep me signed in” prompt and submits one-time codes as soon as they validate.
The kit is designed to capture the session cookies created at the end of the login, which would give the attackers access to the target’s account.
Infrastructure and motive
“TA419 consistently uses Cloudflare’s content delivery network (CDN) to obscure the backend hosting IP address for its domains, which are typically registered via NameSilo. The group’s credential phishing domains are typically themed around file sharing sites and cloud services,” added Kelly.
The group occasionally registers domains that impersonate specific organizations like heritiages[.]org and heritiage[.]org for the Heritage Foundation, tw-koryu[.]org for the Japan-Taiwan Exchange Association, and shinjirou[.]info, which mimics the official website of Japanese Defense Minister Shinjirō Koizumi.
“This activity likely supports wider Chinese intelligence objectives to better understand ongoing developments within the US AI policy and regulatory landscape and occurs amid intense strategic competition, accusations of model distillation , and export controls involving the US and China,” Proofpoint concluded .
首次收录 · 2026-10-03 · 7.37 分