TA419 uses frameless browser spoofing to target US AI policy experts
China-aligned group TA419 targets US AI experts with sophisticated phishing using Frameless BitB techniques to steal Microsoft credentials.
A cyber espionage group known as TA419 has launched a series of credential phishing campaigns against artificial intelligence policy experts in the United States. Active since at least April 2025, this China-aligned actor recently targeted individuals at think tanks, universities, and legal firms using highly personalized lures and advanced technical deception methods.
What happened
The campaign specifically focuses on professionals involved in shaping U.S. AI policy and regulatory frameworks. In February 2026, attackers impersonated a prominent Anthropic employee to target an AI policy expert at a U.S. think tank. The phishing email used the subject line "Request for Feedback on Military Integration of Claude." Later, around July 2026, the group impersonated a former member of the White House Office of Science and Technology Policy leadership team to reach similar targets. Proofpoint, the enterprise security company that analyzed the activity, stated that these efforts likely support Chinese intelligence objectives to understand the U.S. AI landscape amid strategic competition and export controls.
TA419 has a history of targeting defense contractors, law firms, and academic institutions in both the U.S. and Japan. The group’s interest in AI policy experts is viewed as an extension of its existing remit rather than a new direction. The attacks begin with harmless-looking invitations designed to build trust. Only after the recipient responds does the attacker send a shortened URL. This link triggers a multi-stage redirection chain that includes a Cloudflare Turnstile check before landing the victim on a fake OneDrive login page.
How it works
The core of the attack relies on a technique called Frameless BitB, a sophisticated variation of the browser-in-the-browser (BitB) phishing method. Traditional BitB attacks use an HTML iframe to display a fake login window inside a legitimate browser session. Frameless BitB achieves the same visual spoofing without using iframes. Instead, it injects scripts and HTML into the original content using search-and-replace substitutions. By relying entirely on HTML, CSS, and JavaScript tricks, the attackers create a fake browser window that looks identical to a real one.
Once the victim lands on the phishing page, they encounter what appears to be a standard Microsoft sign-in flow. Behind the scenes, TA419 uses an adversary-in-the-middle (AitM) proxy enhanced with a bespoke telemetry and automation module. This tool tracks the user’s input, captures their credentials, and relays the information to the real Microsoft infrastructure in real time. Because the authentication request is forwarded to the actual service, the login succeeds normally. The victim sees no error messages or suspicious behavior, while the attacker silently steals the resulting session cookies.
Key details
- TA419 has been active since at least April 2025, targeting U.S. and Japan-based think tanks and defense sectors.
- Recent lures included impersonating an Anthropic employee and a former White House OSTP leader.
- The attack vector uses a shortened URL leading to a multi-stage redirect with a Cloudflare Turnstile check.
- Frameless BitB spoofs login pages using HTML/CSS/JS injections instead of traditional iframes.
- An AitM proxy with custom telemetry captures credentials and session cookies while relaying traffic to Microsoft.
- Proofpoint assesses the goal as gathering intelligence on U.S. AI policy and regulatory developments.
Why it matters
For software engineers and security leads, this campaign highlights the limitations of traditional multi-factor authentication (MFA) against AitM proxies. Since the attacker relays the login attempt to the real service, standard one-time passwords or push notifications may still approve the session, granting the adversary full access. The use of Frameless BitB further complicates detection because it bypasses some browser-based warnings that rely on iframe detection. This means that even vigilant users who check the URL bar might be deceived by the visual fidelity of the fake window.
The targeting of AI policy experts also signals a shift in espionage priorities toward intellectual property and regulatory strategy. As AI becomes central to national security and economic competition, adversaries are adapting their tactics to infiltrate the communities that define its governance. Organizations in the tech, legal, and academic sectors must recognize that their employees are high-value targets not just for code theft, but for strategic insight. Protecting these individuals requires moving beyond basic email filters to more robust identity security measures.
What you can do
- Enable phishing-resistant authentication methods such as passkeys or FIDO2 security keys for all high-value accounts.
- Train staff to treat unsolicited subject-matter outreach with caution, even if it appears to come from known contacts.
- Verify the authenticity of unexpected requests through secondary communication channels like phone calls or internal chat.
- Monitor for unusual sign-in locations or devices, although AitM attacks may mimic legitimate user behavior closely.
- Implement conditional access policies that restrict access based on device compliance and network location.
- Keep browser extensions and security tools updated to detect known malicious scripts and redirection patterns.



