Ravie Lakshmanan 2026年10月4日 网络间谍活动 / 钓鱼攻击
一个名为 TA419 的新兴与中国有关联的网络间谍组织被归因于多起针对在美国智库、大学和法律部门工作的 AI(人工智能)专家的凭证钓鱼活动。
这些活动冒充了著名的经济学家和 AI 政策制定者,以及一位知名的 Anthropic 员工,以便在 2026 年 2 月锁定一名美国智库的 AI 政策专家。该钓鱼邮件的主题行是“关于 Claude 军事集成的反馈请求”。
Proofpoint 在本周发布的一份分析中表示:“此类活动可能支持更广泛的中国情报目标,以更好地了解美国 AI 政策和监管格局中的最新发展,并且这一行动发生在美中之间激烈的战略竞争、模型蒸馏指控以及出口管制措施不断升级的背景下。”
这家企业安全公司将 TA419 描述为一个与中国结盟且以间谍活动为动机的威胁行为者,自 2025 年 4 月以来,该组织一直有针对在美国和日本智库、国防承包商、大学和法律机构工作的个人策划凭证钓鱼活动的记录。
据报道,在 2026 年 7 月左右,该威胁行为者冒充了多个人物,包括前白宫科技政策办公室领导团队的一名成员,作为针对美国 AI 政策专家的凭证钓鱼活动的一部分。
攻击始于旨在与目标建立信任的无害邀请。只有当收件人回复此次联络后,下一阶段才会启动,对手随后会发送一个缩短的 URL,触发多级重定向链,在完成 Cloudflare Turnstile 验证后,最终导向 OneDrive 中间人(AitM)凭证钓鱼页面。
该页面采用了一种称为 Frameless BitB 的技术,这是浏览器内浏览器(BitB)攻击的一个版本,它通过在合法浏览器会话中使用 HTML、CSS 和 JavaScript 伪造一个假浏览器窗口,从而欺骗受信任的网站或登录页面。
BitB 通过在 iframe 内提供登录页面来工作,而 Frameless BitB 顾名思义,在不使用 iframe HTML 元素的情况下实现了相同的目标。“这可以通过在原始内容之外注入脚本和 HTML(使用搜索和替换,即替换),然后完全依赖 HTML/CSS/JS 技巧来实现视觉效果,”安全研究员 Wael Masri 早在 2024 年 1 月时就曾指出。
根据 Proofpoint 的说法,TA419 对该开源工具进行了扩展,添加了定制的遥测和自动化模块,用于跟踪目标的 Microsoft 登录流程,并使用 AitM 代理捕获凭证信息,同时在后台将详细信息转发给真实的 Microsoft 基础设施。
这种方法的主要优势在于受害者不会察觉任何异常,因为登录事件成功完成,且没有任何迹象表明生成的会话 cookie 已被攻击者悄无声息地捕获。
为了防范这一威胁,建议组织启用防钓鱼的身份验证方法,如通行密钥(passkeys);而成为 TA419 活动目标的个人应谨慎对待未经请求的主题相关联络,并在进一步行动之前验证其真实性。
Proofpoint 表示:“TA419 一直对国防、国家安全、能源、国际关系和外交政策目标表现出浓厚兴趣,主要与美国和日本有关联。”“针对 AI 政策专家的定向攻击是该组织职责范围的延伸,而非偏离。”
Ravie Lakshmanan Oct 04, 2026 Cyber Espionage / Phishing
A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations.
The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a U.S. think tank in February 2026. The phishing email carried the subject line "Request for Feedback on Military Integration of Claude."
"This activity likely supports wider Chinese intelligence objectives to better understand ongoing developments within the U.S. AI policy and regulatory landscape and occurs amid intense strategic competition, accusations of model distillation, and export controls involving the U.S. and China," Proofpoint said in an analysis published this week.
The enterprise security company has described TA419 as a China-aligned and espionage-motivated threat actor that has a track record of orchestrating credential phishing campaigns against individuals working for U.S.- and Japan-based think tanks, defense contractors, universities, and law firms since at least April 2025.
Around July 2026, the threat actor is said to have impersonated several individuals, including a former member of the White House Office of Science and Technology Policy leadership team, as part of credential phishing campaigns targeting AI policy experts in the U.S.
The attack begins with harmless invitations that aim to establish trust with the target. It's only when the recipient responds to the outreach that the next stage kicks in, with the adversary following it up with a shortened URL that triggers a multi-stage redirection chain, which leads to an OneDrive adversary-in-the-middle (AitM) credential phishing page after completing a Cloudflare Turnstile check.
The page employs a technique called Frameless BitB , a version of the browser-in-the-browser ( BitB ) attack that spoofs a trusted website or login page by crafting a fake browser window within a legitimate browser session using HTML, CSS, and JavaScript.
While BitB works by serving the sign-in page inside an iframe , Frameless BitB , as the name implies, achieves the same goal without using the HTML element. "This can be achieved by injecting scripts and HTML besides the original content using search and replace (aka substitutions), then relying completely on HTML/CSS/JS tricks to make the visual effect," security researcher Wael Masri noted back in January 2024.
According to Proofpoint, TA419 has extended the open-source tool with a bespoke telemetry and automation module that tracks the target's Microsoft sign-in flow and captures the credential information using the AitM proxy, while relaying the details to the real Microsoft infrastructure in the background.
The main advantage this method offers is that the victim doesn't notice anything is amiss, as the sign-in event is successful and there are no indications that the resulting session cookies have been stealthily captured by the attacker.
To safeguard against this threat, organizations are recommended to enable phishing-resistant authentication methods like passkeys, and individual targets who are the focus of TA419 activity should treat unsolicited subject-matter outreach with caution, and verify their authenticity before proceeding further.
"TA419 has consistently shown an interest in defense, national security, energy, international relations, and foreign policy targets, predominantly with a nexus to the U.S. and Japan," Proofpoint said. "The targeting of AI policy experts represents an extension of that remit rather than a departure from it."
首次收录 · 2026-10-05 · 9.24 分