China-linked hackers use fake logins to spy on US AI experts | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


A China-linked cyberespionage group, identified by cybersecurity researchers as TA419, has launched a sophisticated campaign targeting experts in artificial intelligence policy and industry in the United States.

The operation’s main objective was to intercept confidential strategic information on government regulations, technology export restrictions and the state of supply chains for key technological components.

The attackers’ strategy stands out for its careful planning and psychological manipulation. To gain the trust of their targets — think tank analysts, university researchers and specialist lawyers — they impersonated respected figures.

The identities they assumed included Lynne Parker, a former deputy director of the White House Office of Science and Technology Policy; economist Heidi Crebo-Rediker; and even employees of AI company Anthropic.

Through polished, professional-looking emails, they invited victims to join purported technology policy advisory committees or contribute to reports for the US Senate.

Rather than including suspicious links in their initial messages, the attackers first engaged their targets in seemingly legitimate professional conversations. Once they had established a relationship and received a response from the victim, they sent a shortened link that supposedly provided access to working documents in the cloud.

The link redirected users through several intermediate pages designed to evade automated security filters, before taking them to a fake platform imitating Microsoft OneDrive.

Stealing credentials through a fake browser window

To steal information, the group used a technique known as “browser-in-the-browser” (BitB). This method creates a pop-up within the web page itself that mimics a genuine browser window, complete with the usual address bar, security padlock and an exact replica of the Microsoft 365 login interface.

When victims entered their login credentials and the verification code sent to their phones, the attackers captured the information in real time.

Through this interception mechanism, the attackers obtained authenticated session cookies. This allowed them to retain access to victims’ corporate accounts and cloud services, bypassing even multi-factor authentication (MFA).

As these espionage operations become more common, security firms recommend adopting phishing-resistant authentication methods, such as passkeys and physical security keys, and independently verifying any invitation to collaborate before entering login credentials online.

A China-linked cyberespionage group, identified by cybersecurity researchers as TA419, has launched a sophisticated campaign targeting experts in artificial intelligence policy and industry in the United States.

The operation’s main objective was to intercept confidential strategic information on government regulations, technology export restrictions and the state of supply chains for key technological components.

The attackers’ strategy stands out for its careful planning and psychological manipulation. To gain the trust of their targets — think tank analysts, university researchers and specialist lawyers — they impersonated respected figures.

The identities they assumed included Lynne Parker, a former deputy director of the White House Office of Science and Technology Policy; economist Heidi Crebo-Rediker; and even employees of AI company Anthropic.

Through polished, professional-looking emails, they invited victims to join purported technology policy advisory committees or contribute to reports for the US Senate.

Rather than including suspicious links in their initial messages, the attackers first engaged their targets in seemingly legitimate professional conversations. Once they had established a relationship and received a response from the victim, they sent a shortened link that supposedly provided access to working documents in the cloud.

The link redirected users through several intermediate pages designed to evade automated security filters, before taking them to a fake platform imitating Microsoft OneDrive.

Stealing credentials through a fake browser window

To steal information, the group used a technique known as “browser-in-the-browser” (BitB). This method creates a pop-up within the web page itself that mimics a genuine browser window, complete with the usual address bar, security padlock and an exact replica of the Microsoft 365 login interface.

When victims entered their login credentials and the verification code sent to their phones, the attackers captured the information in real time.

Through this interception mechanism, the attackers obtained authenticated session cookies. This allowed them to retain access to victims’ corporate accounts and cloud services, bypassing even multi-factor authentication (MFA).

As these espionage operations become more common, security firms recommend adopting phishing-resistant authentication methods, such as passkeys and physical security keys, and independently verifying any invitation to collaborate before entering login credentials online.




Click Here For The Original Source.

——————————————————–

..........

.

.