A China-aligned threat group tracked as TA419 has been linked to a string of credential phishing campaigns aimed at artificial intelligence (AI) policy experts across U.S. think tanks, universities, and legal sector organizations, according to new research.

The operation relies on adversary-in-the-middle (AitM) phishing, a technique that proxies login sessions through an attacker-controlled infrastructure to harvest credentials and session tokens in real time, allowing attackers to bypass multi-factor authentication protections that would normally stop simpler phishing attempts.

To lure victims, TA419 has impersonated well-known economists, AI policymakers, and at least one prominent employee of Anthropic. These spoofed personas were reportedly used to single out an AI policy expert at a prominent U.S. think tank, suggesting the group is conducting carefully tailored, individual-level targeting rather than broad spray-and-pray phishing.

Why This Matters

TA419’s focus on AI policy specialists, rather than purely technical AI researchers, points to an intelligence-gathering interest in how the United States is shaping AI governance, regulation, and national security strategy. Think tanks, universities, and legal organizations working on AI policy often hold early visibility into draft legislation, regulatory thinking, and industry lobbying positions, information that would be valuable to a nation-state actor tracking U.S. policy direction.

The use of impersonated, high-profile identities, including a named figure at a major AI company, also underscores how espionage actors are exploiting the credibility of recognizable names in the AI industry to improve the success rate of their phishing lures.

Recommendations

  • Treat unsolicited emails referencing AI policy discussions or invitations from well-known industry and academic figures with heightened scrutiny, especially those requesting login actions.
  • Deploy phishing-resistant authentication methods, such as FIDO2/WebAuthn hardware keys, which are far more resistant to AitM relay attacks than standard MFA codes.
  • Monitor for anomalous session token reuse and login patterns, since AitM attacks aim to hijack active sessions rather than just passwords.
  • Brief staff at think tanks, universities, and legal organizations involved in AI policy work on the elevated targeting risk highlighted by this campaign.

Further technical indicators and infrastructure details tied to TA419 were not fully disclosed in available reporting, but organizations in the AI policy space should treat this as an active and ongoing threat.