字号 ·· | 护眼
海峡时报

中国黑客冒充美国前官员窃取人工智能专家电子邮件Chinese hackers impersonated ex-US official to steal e-mails from AI experts

点「原文对照」整页切到原文,或双击某段只看那段的原文。

华盛顿——网络安全公司Proofpoint于10月1日表示,中国黑客一直在冒充美国的人工智能专家(包括一名前政府官员),试图从智库、大学及其他机构的人工智能专家手中窃取电子邮件。

WASHINGTON – Chinese hackers have been impersonating US AI experts, including a former government official, to try to steal e-mails from experts in AI at think-tanks, universities and other organisations, the cybersecurity company Proofpoint said on Oct 1.

Proofpoint在报告中指出,这些黑客(被该公司称为“TA419”)自2025年以来就一直在试图窃取为美国或日本智库、国防承包商、大学及律师事务所工作的人员的密码。

In a report, Proofpoint said that it had watched the hackers – which it dubs “TA419” – regularly try to steal passwords from people working for US or Japanese think-tanks, defence contractors, universities and law firms since as far back as 2025.

该公司根据黑客使用的恶意软件类型、实施攻击所使用的互联网基础设施,以及他们所针对的目标,判断这些黑客属于中国势力。这些目标与中国情报收集的重点高度吻合。

Proofpoint attributed the hacking efforts to the Chinese group based on the types of malware the group used, the internet infrastructure used to carry out the attacks, and the targets it observed the group focusing on, which align with Chinese intelligence collection priorities.

Proofpoint称,这些黑客最近的攻击手段包括发送伪装成人工智能或外交政策专家发来的电子邮件;其中一位被冒充的专家是林恩·帕克(Lynne Parker),她曾担任白宫科技政策办公室的首席副主任。这些邮件通常会提议开展与人工智能相关的合作项目,随后将受害者引导至用于窃取密码的网站。

Proofpoint said the hackers’ recent campaign involved writing e-mails purporting to come from experts in AI or statecraft, including Lynne Parker, who previously worked as the principal deputy director of the White House's Office of Science and Technology Policy. Proofpoint said the e-mails would typically propose AI-themed collaborations or initiatives before steering targets towards password-stealing websites.

中国驻华盛顿大使馆并未立即回复记者的置评请求。北京方面长期以来一直否认从事网络间谍活动。

The Chinese Embassy in Washington did not immediately return a message seeking comment. Beijing has long denied carrying out cyberespionage operations.

Proofpoint拒绝公开这些黑客的具体攻击目标,仅表示攻击对象包括“从事人工智能监管、出口控制及国家人工智能战略研究的专家”。

Proofpoint declined to name the hackers’ targets, saying only that the latter included “experts working on AI regulation, export controls and national AI strategy”.

路透社独立核实后发现,其中一名受害者是亚历克斯·恩格勒(Alex Engler)——他曾任白宫官员,现任宾夕法尼亚大学媒体、技术与民主研究中心的负责人。恩格勒在9月30日告诉路透社,他曾收到一封看似来自帕克的电子邮件,邀请他参与一个“新的人工智能政策项目”;但他觉得这封邮件有些可疑,经过进一步核实后确认对方是骗子。

Reuters was independently able to identify one of them: Alex Engler, a former White House official who now heads the Penn Center on Media, Technology, and Democracy. Engler told Reuters on Sept 30 that he had received an e-mail appearing to come from Parker inviting him “to join a new AI policy project”. But he said the e-mail “felt slightly, nebulously off” and, after he checked with others in the field, he realised he was dealing with an impostor.

恩格勒表示,他无法揣测为何有人试图对他发动黑客攻击,但Proofpoint公司称,从此次针对行动来看,受影响者包括为少数几个组织工作的不到10人,这表明“相关人士的动机是获取美国政策制定方面的情报,而不只是窃取技术”。

Engler said he could not speculate about why someone would try to hack him, but Proofpoint said that its view of the targeting – which involved fewer than 10 individuals working for a handful of organisations – suggested “an intelligence interest in US policymaking rather than technology theft alone”.

帕克告诉路透社,恩格勒是7月初收到冒充她发送的可疑信息的两人之一。她还表示,有关中国牵涉其中的说法并非不合常理。

Parker told Reuters that Engler was one of two people who received suspicious messages purporting to come from her in early July. She added that the allegation of Chinese involvement made sense.

帕克说:“美国和中国正在人工智能领域展开竞争。试图让人工智能政策领域的人士透露其人工智能政策规划——如果这确实是目标的话——并不令人意外。”路透社

“The United States and China are in a competition around AI,” Parker said. “Trying to get people in the AI policy space to reveal information about their AI policy plans – if that indeed was what the objective was – it’s not surprising.”REUTERS