安全研究人员称,一个疑似中国间谍组织冒充了人工智能政策领域的人物,包括一名Anthropic高级员工和一名前白宫官员,针对美国大学、智库和律师事务所的人工智能政策专家发动了钓鱼攻击。根据发现这些间谍活动并将其归因于其追踪的中国关联组织TA419的Proofpoint公司数据,这些攻击活动的大部分发生在7月。
A suspected Chinese espionage group impersonated AI policy figures, including a senior Anthropic employee and a former White House official, in phishing campaigns targeting AI policy experts at US universities, think tanks, and law firms, security researchers say. The bulk of these campaigns occurred in July, according to Proofpoint, which discovered the espionage attempts and attributed them to a China-aligned group it tracks as TA419.
Proofpoint的安全警报发布于OpenAI指控中国月之暗面(Moonshot AI)通过自7月1日开始的蒸馏攻击窃取美国模型的推理能力及其他数据之后一天。Proofpoint威胁情报分析师马克·凯利(Mark Kelly)在周四的报告中表示:“2026年7月,TA419冒充了多名人士,包括前白宫科技政策办公室领导团队成员,针对美国的人工智能政策专家实施了凭证钓鱼攻击。”
Proofpoint’s security alert comes a day after OpenAI accused China’s Moonshot AI of stealing the American models’ reasoning and other data in distillation attacks that began on July 1. “In July 2026, TA419 impersonated multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team, in credential phishing campaigns targeting AI policy experts in the US,” Proofpoint threat-intelligence analyst Mark Kelly said in a Thursday report.
自7月8日起,TA419发送了伪造前白宫科技政策办公室副主管林恩·爱德华兹·帕克(Lynne Edwards Parker)以及著名经济学家和外交政策专家海蒂·克雷博-雷迪克尔(Heidi Crebo-Rediker)身份的钓鱼邮件,目标指向更多位于智库、大学和律师事务所的美国人工智能政策专家。这些疑似间谍的邮件邀请目标加入一个虚假的人工智能政策咨询委员会,或为参议院外交关系委员会关于人工智能出口管制和供应链的报告做出贡献。
Beginning July 8, TA419 sent phishing emails spoofing Lynne Edwards Parker, the former principal deputy director of the White House Office of Science and Technology Policy, and then Heidi Crebo-Rediker, a prominent economist and foreign policy expert, to even more American AI policy experts at think tanks, universities, and law firms. The suspected spies’ emails invited their targets to join a fake AI policy advisory committee or contribute to a Senate foreign relations committee report on AI export controls and supply chains.
如果美国人工智能专家回复,这个与北京有关联的小组会回复一个缩短的URL,声称将分享更多细节,但实际上指向攻击者控制的域名。该页面在一个虚假的OneDrive加载屏幕背后进行Cloudflare Turnstile验证,随后将受害者重定向到一个中间人(AitM)凭证钓鱼页面,从而窃取受害者的云账户信息。
If the American AI expert replied, the Beijing-linked crew responded with a shortened URL promising to share additional details, but in reality pointing to an attacker-controlled domain. This page conducts a Cloudflare Turnstile check behind a phony OneDrive loading screen, and then redirects the victim to an attacker-in-the-middle (AitM) credential phishing page that steals the victim’s cloud account information.
2026年7月的攻击行动使用 driftshare[.]co 作为第一阶段域,并使用 globalfileshareplatform[.]com 作为第二阶段域。今年2月——正当美军官员施压 Anthropic 移除 Claude 的安全护栏之际——中国间谍假冒 Anthropic 的一名高级员工,对美国一家智库的AI政策分析师实施网络钓鱼。这封邮件的主题是:“关于Claude军事一体化的反馈请求”。
The July 2026 campaigns used driftshare[.]co as the first-stage domain and globalfileshareplatform[.]com as the second-stage domain. In February - as US military officials pressured Anthropic to remove Claude’s safeguards - the Chinese spies spoofed a senior Anthropic employee to phish an AI policy analyst at a US think tank. This email used the subject line: “Request for Feedback on Military Integration of Claude.”
TA419 的钓鱼攻击链通过第一方 OfficeHome 应用程序(client_id=4765445b-32c6-49b0-83e6-1d93765276ca)针对 Microsoft 365/Entra ID。它基于开源的 Frameless BitB 构建,其中包含浏览器内浏览器(BitB)悬浮窗、用于拦截 Microsoft 365 的用户名、密码和会话 Cookie 的 Evilginx 钓鱼脚本(phishlet),以及将攻击工具包注入代理页面的服务端替换规则。
TA419’s phishing chain targets Microsoft 365/Entra ID through the first-party OfficeHome application (client_id=4765445b-32c6-49b0-83e6-1d93765276ca). It’s built on open source Frameless BitB, which contains a Browser-in-the-Browser (BitB) overlay, an Evilginx phishlet to intercept usernames, passwords, and session cookies for Microsoft 365, and server-side substitution rules that inject the kit into proxied pages.
TA419 通常使用 Cloudflare 的内容分发网络来隐藏其域名的后端托管IP地址,其凭据钓鱼域名通常以文件共享网站和云服务为主题,例如 msfile[.]online 和 onecloudfilesync[.]com。它还假冒特定组织,包括日本台湾交流协会(tw-koryu[.]org)、传统基金会(heritiages[.]org 和 heritiage[.]org)以及日本防卫大臣小泉进次郎的官方网站(shinjirou[.]info)。
TA419 typically uses Cloudflare’s content delivery network to hide the backend hosting IP address for its domains, and its credential phishing domains are usually themed around file sharing sites and cloud services - such as msfile[.]online and onecloudfilesync[.]com. It also impersonates specific organizations, including the Japan-Taiwan Exchange Association (tw-koryu[.]org), The Heritage Foundation (heritiages[.]org and heritiage[.]org), and Japanese Minister of Defense Shinjirō Koizumi’s official website (shinjirou[.]info).
该团伙总共使用了数十个钓鱼域名、伪造发件人域名以及虚假的电子邮件地址。Proofpoint 收录了其在 2026 年发现的所有此类域名,以及它们的注册或首次出现的时间线,因此请同时查阅这些指标。威胁猎手表示,TA419 和其他亲北京的团伙可能会继续以人工智能以及从事中国政府感兴趣的技术研究的其他政策专家为目标。
In total, the crew uses dozens of phishing and spoofed-sender domains, and phony email addresses. Proofpoint includes all of the ones it discovered in 2026, plus the timeline of when they wereed or first seen, so check out those indicators, too. TA419 and other Beijing-aligned crews will likely continue targeting AI and other policy experts working on technologies of interest to the Chinese government, according to the threat hunters.
“处于 TA419 活动范围内的组织应考虑采用防钓鱼、绑定源站的身份验证方式,例如通行密钥(passkeys),”他们建议道。®
“Organizations in the scope of TA419 activity should consider phishing-resistant, origin-bound authentication such as passkeys,” they recommend.®