The first email carried no link at all, and the browser window the target checked was drawn inside the page
2026-10-06Security
Proofpoint has tied a China-aligned group to credential phishing against US AI policy researchers. The approach opens as an ordinary conversation with no link in it, and only once the target replies does a URL arrive — ending at a fake sign-in window rendered inside the real browser, which collects the password, the MFA code and the session cookie.