Proofpoint, which tracks the China linked group behind the operation as TA419, says fewer than 10 US AI policy experts at think tanks, universities, and law firms received messages spoofing former White House science office (OSTP) deputy Lynne
A China-linked group tracked as TA419 by the cybersecurity firm Proofpoint sent fraudulent messages appearing to come from former White House science official Lynne Parker to fewer than ten US AI policy experts in July, Proofpoint said in a report published Wednesday.
The targets worked on AI regulation, export controls, and national AI strategy at think tanks, universities, and law firms, Reuters reported. Reuters independently identified Alex Engler of the Penn Center on Media, Technology, and Democracy as a recipient; Engler said he checked the approach with others before recognizing an impostor. Parker confirmed to Nextgov that two recipients contacted her through separate channels on July 9 about messages they had not requested.
Proofpoint's technical analysis describes a customized "Frameless BitB" adversary-in-the-middle kit targeting Microsoft 365 and Entra ID session cookies, including relayed multi-factor authentication. The firm linked the same group to a February campaign impersonating a senior Anthropic employee to approach a think-tank AI policy analyst. Proofpoint did not establish successful compromise of any individual or organization in either operation.
The firm characterizes TA419 as China-aligned based on malware, infrastructure, and target alignment, with assessed interest in US AI policy rather than direct technology theft. The Chinese Embassy in Washington did not immediately respond to a request for comment; Beijing publicly denies conducting cyberespionage.