Proofpoint has published research on TA419, a China-aligned espionage group it has tracked running targeted credential phishing since at least April 2025 against think tanks, defence contractors, universities and law firms in the United States and Japan.

The campaigns it describes this year went after one community in particular: the people who shape US AI policy.

Borrowed credibility

The group's method is to be someone the target would be pleased to hear from.

From 8 July 2026 it impersonated Lynne Edwards Parker, former Principal Deputy Director of the White House Office of Science and Technology Policy, and then Heidi Crebo-Rediker, an economist and foreign policy expert. Both were impersonated; neither had anything to do with the campaign.

In a separate campaign in February, the group posed as a senior employee of Anthropic and asked an AI policy analyst at a US think tank for feedback on the military's use of Anthropic's Claude models.

Read that last one as a piece of social engineering rather than as a detail. A policy analyst is asked, by someone from the company itself, for their view on the most contested question in their field. The message is not asking the target to do anything unusual. It is offering them exactly the thing their job consists of.

The first message has nothing in it

The mechanical innovation is restraint.

The opening email carries no link and no attachment. It is a note asking for an opinion, and it survives every control that exists to catch a malicious link, because there is not one. Mail filtering sees correspondence.

Only after the target replies does the URL arrive, and by then it is arriving inside a conversation the target is already part of — one they chose to join, from a person they believe they know, on a subject they volunteered to discuss. Every instinct about unsolicited mail has been disarmed by the target's own participation.

This is the same patience the China-nexus campaign Talos documented last week showed in a different form, where the delivery was dressed as a native Gmail attachment. Spear-phishing against this class of target is no longer about the lure looking plausible. It is about the lure arriving after trust exists.

A browser window that is a drawing

The link runs through a shortened URL, a multi-stage redirection chain and a Cloudflare Turnstile check — which looks like a bot test and functions as a filter against automated analysis — before landing on a fake loading screen for a familiar file-sharing service.

What appears next is a sign-in window. It has a title bar, an address bar, a padlock, and a URL that reads correctly.

The window is not a window at all. Browser-in-the-Browser is HTML drawn inside the page to look like a separate browser window, built here with a customised version of the open-source tool Frameless BitB. The address bar is a picture of an address bar. You cannot click into it, you cannot read the certificate, and dragging it outside the page is impossible because there is nothing to drag.

The advice everyone has been given for twenty years — check the URL before you type your password — is answered by the attack, because the URL being checked is part of the attack.

What the page collects is the password, the multifactor code and the session cookie, in real time. The cookie is the serious part: it is proof of a completed login, and replaying it needs no password and no second factor at all.

Why MFA did not help

It is worth being precise, because the lesson gets mangled.

Nothing here broke multifactor authentication. The code was real, the user typed it, and the service accepted it. An adversary-in-the-middle page simply stands between the two and passes everything through, keeping what comes back.

The defence that does hold is the one that binds the credential to the site. A passkey or a hardware security key will not authenticate to a domain it was not registered for, so the relay has nothing to relay. That is a different control from an app that shows you a six-digit number, and the distinction is the whole thing.

What to do

  • Move the people who are targeted to phishing-resistant authentication. Passkeys or hardware keys for policy researchers, executives and anyone whose opinion is publicly valuable. Codes in an app do not survive this.
  • Treat an unexpected request for your professional opinion as an approach, not a compliment. The flattery is the payload, and the link comes in the second message.
  • Expect the conversation. Train people that a clean first email followed by a link is a pattern, not a reassurance.
  • Alert on session cookie reuse from new locations. When the credential is replayed rather than re-entered, that anomaly is often the only signal left.

What is not established

  • Whether anyone was successfully compromised. Proofpoint does not identify victims or say whether accounts fell.
  • Who TA419 works for. Proofpoint describes it as China-aligned and espionage-motivated, and names no sponsor.
  • What the group did with any access it obtained.
  • Whether the February campaign impersonating an Anthropic employee and the July ones are the same operators or a shared toolkit.