Chinese Hackers Use Deceptive Tactics to Steal AI Experts’ Credentials
A sophisticated cyber espionage campaign has been uncovered, targeting artificial intelligence (AI) experts working for US think tanks, universities, and law firms. Chinese hackers impersonated US officials in a series of phishing attacks designed to steal sensitive credentials, highlighting the increasing sophistication of state-sponsored hacking efforts.
The campaign, attributed to China-aligned threat actor TA419, was discovered by researchers at Proofpoint, who detailed the tactics used to deceive AI policy experts into divulging their login information. The attackers created seemingly legitimate professional relationships with their targets, often using fake emails from high-ranking officials, including a former White House Office of Science and Technology Policy leader.
The approach employed by TA419 is characteristic of “adversary-in-the-middle” (AiTM) phishing campaigns. Rather than immediately sending malicious links or attachments, the attackers first established credibility with their targets through benign outreach. They invited experts to join fictitious committees or contribute to reports on AI export controls and supply chains – topics of particular interest to their targets.
Once a relationship was built, the technical attack began with a link that appeared to lead to a legitimate Microsoft or OneDrive document or collaboration environment. However, this link ultimately led to an AiTM credential-phishing page designed to gain access to the target’s cloud account. The URL used a customized version of the open source “browser-in-the-browser” (BitB) phishing tool Frameless BitB.
The campaign is part of a broader Chinese cyber espionage effort to gather intelligence on US AI policymaking and planning. This activity supports China’s wider objectives, including understanding ongoing developments within the US AI policy and regulatory landscape. The tactics employed by TA419 demonstrate an increasing level of sophistication in state-sponsored hacking efforts, making it essential for organizations handling sensitive information to be vigilant.
For individuals and organizations working with sensitive data, this campaign serves as a stark reminder of the importance of verifying identities before engaging in online interactions. Establishing relationships through seemingly legitimate channels can be a precursor to phishing attacks. It is crucial to remain cautious when receiving unsolicited emails or invitations from unknown parties, even if they appear to come from reputable sources.
To mitigate these risks, it’s essential to educate users on the dangers of AiTM phishing campaigns and to implement robust security measures, such as multi-factor authentication and regular software updates. By staying informed and vigilant, we can better protect ourselves against these sophisticated cyber threats.
Source: Dark Reading — 2026-10-05