Proofpoint reports that TA419, a China-aligned espionage actor, ran credential phishing campaigns in July 2026 in which it impersonated prominent economists and AI policymakers to target AI experts at US think tanks, universities and legal sector organisations [1]. Help Net Security summarised the findings on 2 October 2026 [2]. The campaign is relevant beyond its targets because the technique, a fake login window that relays passwords and MFA codes, works against anyone who signs in to a Microsoft account.
Background
Credential phishing sends a victim to a page that imitates a sign-in screen. A browser-in-the-browser attack draws a fake browser window inside a web page, including a convincing address bar, so that the sign-in window appears to come from the real service. Proofpoint names the open-source tool used here as Frameless BitB [1] [2].
Findings
Proofpoint names the impersonated people as Lynne Edwards Parker, a former Principal Deputy Director of the White House Office of Science and Technology Policy, and Heidi Crebo-Rediker, an economist and foreign policy expert [1]. In an earlier campaign in February 2026, the actor posed as a senior Anthropic employee [1] [2].
Help Net Security reports that the first messages were benign invitations to join a fictitious AI Policy Advisory Committee or to contribute to a Senate Committee report on AI export controls, and that follow-up emails to respondents contained shortened URLs leading to credential harvesting pages [2]. Proofpoint describes multi-stage redirects that end in pages capturing credentials and MFA codes through adversary-in-the-middle attacks on Microsoft 365 [1].
According to Help Net Security, domains controlled by TA419 hosted Cloudflare Turnstile checks and then redirected to fake OneDrive phishing pages, which used Frameless BitB to capture credentials [2]. It quotes Proofpoint analyst Mark Kelly as stating that credentials entered in that window are relayed to Microsoft's servers, so the password, the MFA code and conditional access checks would all go through [2].
Proofpoint assesses that the activity likely supports wider Chinese intelligence objectives and that TA419 will likely continue targeting think tanks and policy experts working on technologies, and in geographies, of particular interest to the Chinese government [1] [2].
Implications for Mac users
The sources describe a targeted campaign against a specific professional group, and they do not report attacks on the general public [1]. The method is not specific to an operating system: the fake window runs inside a web page, so it can appear in any browser on a Mac. The reported use of the names of a government official and of an AI company employee shows that a message can look credible because of who it claims to come from.
Recommendations
- Verify an unsolicited message about a committee, report or document through a separate channel before clicking, as Proofpoint advises [1].
- Use phishing-resistant authentication such as passkeys, which Proofpoint recommends for organisations [1].
- Be wary of shortened links in a follow-up message from a person met only by email.
- Open the document service by typing its address or using a saved bookmark, instead of following a link to sign in.
- If a password or an MFA code was entered on an unexpected page, change the password, revoke active sessions and report it to the organisation.
Relevance to FireAI
FireAI is a firewall for one Mac. When the optional threat lists are turned on, FireAI downloads public lists, which include Phishing Army and OpenPhish, once a day and can block a match that a list confirms; the traffic itself is never sent to the lists. It also reads the website name that an encrypted connection announces before encryption, as described in deep inspection without decrypting.
FireAI does not detect a phishing page that is not on a list, including a new domain used by a campaign like this one. It does not read the inside of an encrypted connection, does not see a fake window drawn within a page, and does not read email or judge whether a message is genuine. It cannot stop a user from typing a password into a page that is not blocked, and it does not replace passkeys or an MFA method that resists phishing.
Limitations
The campaign description comes from Proofpoint's research and Help Net Security's summary, and the sources do not state how many people were targeted or whether any credential was captured [1] [2]. The attribution to China-aligned interests is Proofpoint's assessment. The sources do not say whether the named people or the Anthropic employee were aware of the impersonation.
Try FireAI, by HisnLabs free for 17 days.