- Proofpoint says a Chinese threat actor began a July campaign against AI experts with harmless emails posing as AI policy panel invitations, sending malicious links only after a target replied.
- Links led to a fake OneDrive login page that stole passwords. That matters because defenses focused only on links can miss a friendly first message sent to staff whose job involves replying.
- Organizations should name staff likely to be courted for AI expertise, brief them, make verifying unexpected invitations a normal step, and ask whether a stolen password alone would give access.
A friendly first email can be the opening move of an attack. Proofpoint says one Chinese threat actor began its July campaign with harmless-looking conversation starters meant to draw a reply. The malicious links came only after a target answered.
That is the idea worth taking from Proofpoint's report. A polite message can be a tool. The question for security teams is not only whether a link is dangerous. It is also whether staff can tell a real invitation from a staged one.
What Proofpoint found
The Record reported two new studies this week. Both describe Chinese government-backed hacking groups, and both attributions are allegations from the researchers.
Only Proofpoint describes the rapport-first pattern. Talos, covered further down, describes a more standard approach based on lures.
Proofpoint studied a July campaign aimed at AI experts. The targets worked at universities, think tanks and law firms. The first emails went out on July 8.
The sender posed as Lynne Edwards Parker, a onetime leader in the White House science and technology office. Later emails used the name of Heidi Crebo-Rediker instead.
The bait was an offer to sit on an AI policy advisory panel. Another offer was a role in an invented Senate report on AI export controls.
Proofpoint says the first messages were benign conversation starters. Their purpose was to build rapport and draw out a response. Only after a target answered did the attackers send a chain of redirecting links. The chain ended at a fake OneDrive page that asked for login details.
How the credential theft works
A redirect chain sends a visitor through several web addresses before the final page. Each hop makes the real destination harder to see. The last page imitates a Microsoft sign-in screen. Anything typed there goes to the attacker.
The next points are our analysis, not findings in the report. In most organizations, a Microsoft login opens email and shared files. A stolen login can also let an attacker read a victim's contacts and past messages.
The reply matters too. It tells the attacker the address is live and the person is willing to engage. The follow-up then arrives inside a conversation the target started.
Here is one more inference. The report as covered does not say whether the first emails held links. If they did not, they would give filters little to flag.
Proofpoint adds some history. It has seen this group before, targeting people at think tanks, defense contractors and universities in the U.S. and Japan. The group has a habit of registering domains that pass as real institutions. Earlier mimicry covered the Heritage Foundation, a Japan-Taiwan exchange group and the Japanese defense chief's office. The report as covered does not say those domains were used in the July emails.
What Cisco Talos found
Talos describes a different kind of case. Its incident responders found 16 organizations affected or targeted. They span eight Asian countries, including Taiwan, India and the Philippines. The activity ran from September 2025 to July 2026.
Talos says the aim was intelligence gathering. The attackers used a backdoor called Antino. A backdoor is hidden software that lets an attacker keep coming back to a machine. Talos says Antino allowed reconnaissance, file transfers and ongoing access.
The entry method here was a more standard lure-based approach. Talos says most victims received phishing emails and decoy documents. Those lures pushed them to reply, click links or open malicious files. Talos does not describe a pattern of friendly conversation starters sent first. Themes included news about the Trump administration, spoofed event invitations and legislative papers.
Talos says its work began with a March 2026 phishing effort in Taiwan. It targeted people in academia, think tanks and civil society. Later work found affected or likely affected government and security systems in other countries. The campaign began in the Philippines. The latest wave, in June, targeted organizations in India.
Talos also found overlap with a Symantec campaign that used Antino.
Who carries the risk
Proofpoint says the targets were AI experts at universities, think tanks and law firms. They were not described as IT staff.
In our view, this matters for how companies spend. Security spending often centres on systems. This campaign, as Proofpoint describes it, aimed at a person's willingness to answer. For experts who handle outside invitations, replying may simply be part of the job.
Questions to put to your team
First, which staff are likely to be courted for AI expertise? Name them and brief them on this pattern.
Second, is there an easy way to verify an unexpected invitation? A call to a known number is one option. Make it a normal step.
Third, does your reporting rule cover a friendly first email that contains no links and only invites conversation? Will staff report it?
Fourth, who watches for lookalike domains that imitate your organization or partners?
Fifth, if a Microsoft password is typed into a fake page, what else stands between the attacker and the account? Ask whether a stolen password alone is enough. Ask how quickly your team can spot a sign-in from an unfamiliar place.
In our view, the lesson from Proofpoint's finding is that a defense focused only on links can miss a friendly first step. Check the person as well as the message.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: The Record.





