The sign-in window was not a window. The page had drawn it.
Check the address bar. It is the advice everyone gives about phishing, and in the campaign Proofpoint published on 1 October it would not have helped, because the window asking for the password was not a window at all. It was a picture of one, drawn on the page like any other box.
The group is TA419, assessed as China-aligned, and the people it went after were AI policy researchers at American think tanks, universities and law firms. The approach opened on 8 July with an email containing no link and no attachment, just a courteous note from someone who appeared to be Lynne Parker, until recently a senior figure at the White House Office of Science and Technology Policy, inviting the recipient onto an advisory committee. Only once a target replied did a shortened link turn up. It passed a Cloudflare check, landed on a page dressed as a OneDrive folder with convincing documents in it, and opened what looked like a Microsoft sign-in window floating on top. The kit that paints that window is open source and goes by Frameless BitB, short for browser-in-the-browser.
Behind the fake window sat a relay. Everything typed went on to the genuine Microsoft servers, so the password was accepted, the multi-factor prompt was accepted, and the sign-in really did succeed. What the attacker kept was the session cookie, the part that keeps you logged in afterwards without a password. A custom script in the kit ticked "Keep me signed in" on the victim's behalf and submitted the one-time code the second it validated.
One habit beats all of this: never sign in from a link somebody sent you. Open a new tab, type the address yourself, and the window you get belongs to the browser rather than to the page. Passkeys help too, because they simply refuse to work on the wrong domain. For the rest of the basics, encryption, Windows Update, what is actually switched on, Tendvane's health score puts them on one screen.