# Proofpoint 报告：TA419 在凭据钓鱼中冒充 AI 政策人物和一名 Anthropic 员工

> Proofpoint 报告称，与中国相关联的 TA419 在 2026 年 7 月以一个虚假的咨询委员会和一个转发 MFA 验证码的浏览器内浏览器页面，对 AI 政策专家实施钓鱼。

FireAI Security & Research Team (HisnLabs) · Published 2026-10-03
Canonical: https://hisnlabs.com/zh/news/ta419-impersonates-ai-policy-figures-credential-phishing-bitb

Proofpoint 报告称，与中国相关联的间谍行为体 TA419 在 2026 年 7 月实施了凭据钓鱼行动，冒充知名经济学家和 AI 政策制定者，以美国智库、大学和法律界机构的 AI 专家为目标 [[1]](https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy)。Help Net Security 于 2026 年 10 月 2 日对这些发现作了概述 [[2]](https://www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/)。这一行动的意义不限于其目标，因为这种手法，即转发密码和 MFA 验证码的虚假登录窗口，对任何登录 Microsoft 账号的人都有效。

## 背景

凭据钓鱼会把受害者引到一个冒充登录界面的页面。浏览器内浏览器（browser-in-the-browser）攻击会在网页内部绘制一个虚假的浏览器窗口，包括一个以假乱真的地址栏，使登录窗口看起来来自真实的服务。Proofpoint 指出，这里所用的开源工具是 Frameless BitB [[1]](https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy) [[2]](https://www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/)。

## 发现

Proofpoint 指出，被冒充的人是白宫科技政策办公室前首席副主任 Lynne Edwards Parker，以及经济学家和外交政策专家 Heidi Crebo-Rediker [[1]](https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy)。在 2026 年 2 月的一次更早的行动中，该行为体冒充了一名 Anthropic 的资深员工 [[1]](https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy) [[2]](https://www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/)。

Help Net Security 报道，最初的信息是无害的邀请，邀请对方加入一个虚构的 AI 政策咨询委员会，或为参议院委员会关于 AI 出口管制的报告提供意见，而发给回复者的后续邮件包含缩短的网址，通向凭据收集页面 [[2]](https://www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/)。Proofpoint 描述了多阶段重定向，最终进入通过对 Microsoft 365 的中间人攻击来获取凭据和 MFA 验证码的页面 [[1]](https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy)。

据 Help Net Security 称，TA419 控制的域名先托管 Cloudflare Turnstile 检查，然后重定向到虚假的 OneDrive 钓鱼页面，这些页面使用 Frameless BitB 来获取凭据 [[2]](https://www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/)。文章引述 Proofpoint 分析师 Mark Kelly 的话称，在该窗口中输入的凭据会被转发到 Microsoft 的服务器，因此密码、MFA 验证码和条件访问检查都会通过 [[2]](https://www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/)。

Proofpoint 评估认为，这一活动很可能服务于中国更广泛的情报目标，TA419 很可能会继续以智库和政策专家为目标，这些专家所从事的技术领域和所在地区是中国政府特别关注的 [[1]](https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy) [[2]](https://www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/)。

> FireAI 是 HisnLabs 开发的 macOS 本机防火墙，在开启可选的威胁列表后，可以把连接与公开的钓鱼网站列表进行比对。提供 17 天试用。 [Download FireAI for Mac](https://hisnlabs.com/en/download)

## 对 Mac 用户的影响

这些来源描述的是针对某个特定专业群体的定向行动，没有报告对公众的攻击 [[1]](https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy)。这种手法并不限于某个操作系统：虚假窗口运行在网页内部，因此可以出现在 Mac 上的任何浏览器中。据报道，冒用政府官员和 AI 公司员工的姓名说明，一条信息可能因其声称的来源而显得可信。

## 建议

1. 收到关于委员会、报告或文件的未经请求的信息时，先通过另一个渠道核实再点击，这也是 Proofpoint 的建议 [[1]](https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy)。
2. 使用通行密钥之类能抵御钓鱼的认证方式，Proofpoint 向各机构推荐这种方式 [[1]](https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy)。
3. 对一个仅通过邮件认识的人发来的后续信息中的缩短链接保持警惕。
4. 通过直接输入网址或使用已保存的书签打开文档服务，而不是点击链接去登录。
5. 如果在意料之外的页面上输入过密码或 MFA 验证码，请更换密码、撤销活动会话，并向所在机构报告。

## 与 FireAI 的关系

FireAI 是针对一台 Mac 的防火墙。开启可选的[威胁列表](https://hisnlabs.com/zh/docs/threat-intelligence-feeds)后，FireAI 每天下载一次公开列表（包括 Phishing Army 和 OpenPhish），并可拦截列表确认的匹配项；流量本身从不会被发送到这些列表。它还会读取加密连接在加密之前所声明的网站名称，详见[无需解密的深度检测](https://hisnlabs.com/zh/docs/protocol-inspection-without-decryption)。

FireAI 不会检测不在列表中的钓鱼页面，包括此类行动所使用的新域名。它不读取加密连接的内部，看不到在页面内绘制的虚假窗口，也不读取邮件，更不判断一条信息是否真实。它无法阻止用户在未被拦截的页面上输入密码，也不能替代通行密钥或能抵御钓鱼的 MFA 方式。

> 钓鱼页面是通过普通连接访问的。当某个 App 联系一个没有对应规则的目标时，FireAI 会先询问，其可选的威胁列表还可以拦截已确认的钓鱼地址。免费试用 17 天。 [Download FireAI for Mac](https://hisnlabs.com/en/download)

## 局限

对这一行动的描述来自 Proofpoint 的研究和 Help Net Security 的概述，这些来源没有说明有多少人成为目标，也没有说明是否有任何凭据被获取 [[1]](https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy) [[2]](https://www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/)。把此事归因于与中国相关联的利益方，是 Proofpoint 的评估。这些来源没有说明被点名的人或那名 Anthropic 员工是否知道自己被冒充。

免费试用 [HisnLabs 的 FireAI](https://hisnlabs.com/zh/download) 17 天。

## Sources

- [Proofpoint Threat Insight: Hallucinating credibility, China-aligned TA419 impersonates its way into US AI policy](https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy)
- [Help Net Security, 2 October 2026: Chinese spies impersonate White House, Anthropic figures to phish AI policy experts](https://www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/)
