TA419 faked an Anthropic exec to phish: MFA codes didn't help
Proofpoint says China-aligned TA419 impersonated an Anthropic employee and used browser-in-browser phishing to steal MFA codes and sessions. Move to passkeys.
Proofpoint reported on October 1 that a China-aligned group it tracks as TA419 ran browser-in-the-browser phishing against U.S. AI policy experts. One email came from a fake senior Anthropic employee with the subject "Request for Feedback on Military Integration of Claude." The targets were think tanks and universities, not online shops. But the toolkit steals passwords, MFA codes and live session cookies in one pass, and it works against any Microsoft 365 tenant, yours included.
What actually happened
Per Proofpoint and CyberScoop:
- Who was faked: a senior Anthropic employee (February 2026), plus former White House OSTP official Lynne Parker and economist Heidi Crebo-Rediker (July 2026).
- Step one, rapport: a harmless first email. An invite to an "AI Policy Advisory Committee," or a request for comments on a report. No link, nothing for a filter to catch.
- Step two, the link: after the target replied, a shortened URL. It went through a Cloudflare Turnstile check, then a fake OneDrive loading screen.
- Step three, the fake window: a modified copy of the open-source tool Frameless BitB drew a fake browser pop-up inside the page. Behind it, an adversary-in-the-middle relay passed everything to the real Microsoft login, live.
- What it took: passwords, MFA codes and session cookies. Custom scripts tracked each victim through the login steps.
CyberScoop notes the reports do not say whether any accounts were compromised.
Why browser-in-the-browser phishing matters for your business
SMS and app codes do not stop a relay. The victim types a real code into a fake window, and the attacker forwards it to Microsoft within seconds. The session cookie that comes back is the prize. It skips MFA until it expires. We covered the same weakness in the Apollo breach.
Passkeys do stop it. A passkey is bound to the real domain. On a fake page, the browser does not offer it. Proofpoint's first recommendation is exactly this: phishing-resistant, origin-bound sign-in. In Microsoft Entra, turn on passkeys and require them for admins first, then everyone with access to money or customer data.
The first email is the attack, too. Nobody clicked anything until they had answered a friendly note. Train staff on that pattern: an unsolicited, flattering request from a "known" name, followed by a link. Check the person through a channel you already have, not the reply-to address.
Fake pop-ups have a tell. A real browser window can be dragged outside the page. A BitB window is drawn inside the page, so it usually cannot. It is a small habit, and it works.
Key takeaways
- TA419 impersonated an Anthropic employee and U.S. policy figures to phish AI experts, per Proofpoint
- Benign rapport email first, then a shortened link to a fake OneDrive and BitB login window
- Adversary-in-the-middle relay captured passwords, MFA codes and session cookies
- Passkeys bound to the real domain defeat this chain; SMS and app codes do not
- Verify unexpected outreach through a channel you already trust
Not sure how your team signs in to Microsoft 365, Shopify or your bank? We audit login flows for small teams and move admins to passkeys without locking anyone out. Book an audit.
Sources: Proofpoint, CyberScoop.
- #phishing
- #passkeys
- #mfa
- #microsoft-365
- #browser-in-the-browser
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Supabase buys Turso: agents now make 70% of new databases
Supabase raised $150M and is acquiring Turso, the SQLite-based database for AI agents. 70% of its new databases come from agents. Who owns yours?
Read itOpenAI Decisions API: 150ms picks on Luna, price not yet public
OpenAI's Decisions API returns a fixed-option answer in about 150ms on GPT-6 Luna. It is in limited preview with no published price. Here is how to test it.
Read it