Spoofed White House invitations seed a China-tied phishing run

A China-aligned crew posed as a White House adviser and an economist to phish US AI policy experts.

CSBadmin
2 Min Read

A China-aligned espionage crew spent July pretending to be a former White House science adviser and a well-known economist, aiming to crack the cloud accounts of US AI policy experts.

Proofpoint tracks the group as TA419. Starting July 8, it impersonated Lynne Edwards Parker, formerly a senior leader in the White House Office of Science and Technology Policy, and then Heidi Crebo-Rediker, an economist and foreign policy voice. Targets worked at think tanks, universities, and law firms.

The opening emails carried no links. They invited people to join a fictitious “AI Policy Advisory Committee” or to help draft a Senate report on AI export controls. Reply, and TA419 sent a shortened link that led to a fake OneDrive page.

That page runs a Cloudflare check behind a spoofed loading screen, then pushes victims to a credential-phishing site built to sit between them and Microsoft. A browser-in-the-browser window clones the Chrome login, and the kit relays entered credentials, one-time codes, and session cookies, defeating many forms of multi-factor authentication.

Earlier, in February, the group posed as a senior Anthropic employee with a lure about military use of Claude.

Proofpoint recommends phishing-resistant, origin-bound logins such as passkeys for anyone in range of the campaign.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.