A China-linked espionage group known as TA419 has targeted AI experts at US think tanks, universities and law firms in a series of credential phishing campaigns, according to cybersecurity company Proofpoint.
The group has impersonated economists, AI policy experts and employees of major AI companies to gain the trust of the targets. The attacks often begin with harmless-looking invitations or messages. If the target responds, the attackers send a shortened link that eventually leads to a fake Microsoft login page hosted through OneDrive.
The phishing page uses a technique known as Frameless BitB, which creates a fake login window inside a real browser, making the page look like a legitimate Microsoft sign-in screen.
Proofpoint said TA419 has also modified an open-source tool to track Microsoft sign-in activity and steal login credentials through an adversary-in-the-middle attack. Researchers believe the campaigns are part of broader Chinese intelligence efforts to gather information about US AI policy and regulation.
In a separate report, Cisco Talos said it spotted a threat cluster it tracks as UAT-11587 targeting government and policy organizations across Asia. The group has used a previously unknown Windows backdoor called Antino, delivered mainly through spear-phishing emails and fake documents. Antino can collect information, execute commands, transfer files, and maintain access while using Microsoft 365 services for communication. Talos assesses with high confidence that UAT-11587 is linked to China.
British intelligence service MI5 has recently warned that more than 100 UK-linked academics have contributed to Chinese research projects allegedly funded through the China General Technology Research Institute (CGTRI), which it assesses as a front for China’s Ministry of State Security. The agency says CGTRI supports research in areas such as AI, cybersecurity, covert communications and steganography to enhance Chinese intelligence capabilities.