UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing
Description
Cisco Talos identified an advanced persistent threat (APT) spear-phishing campaign targeting Taiwan research organizations. The campaign used AI-assisted content generation to craft personalized phishing emails impersonating reputable academic and policy institutions. It combined traditional email phishing with QR code phishing (quishing) by modifying legitimate event posters with malicious QR codes. The phishing infrastructure included an advanced adversary-in-the-middle (AitM) framework impersonating Google authentication pages to intercept credentials and multi-factor authentication challenges in real time. The campaign leveraged legitimate event details as cover but redirected victims to actor-controlled phishing sites. The phishing kit's UI was originally developed in Simplified Chinese and adapted for Traditional Chinese and English, suggesting a developer with a Simplified Chinese primary language background.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This APT spear-phishing campaign targeted individuals affiliated with Taiwan research organizations by impersonating legitimate institutions and leveraging publicly available event information. The threat actor used AI-assisted content generation to produce highly consistent and personalized phishing emails with a common social engineering template. The campaign also employed quishing by embedding malicious QR codes in legitimate event posters, expanding the attack surface beyond email recipients. The phishing infrastructure used a hybrid HTTP and WebSocket architecture to implement a real-time adversary-in-the-middle (AitM) attack that intercepted Google credentials and MFA challenges. The phishing pages visually mimicked legitimate Google Forms and login pages, with deceptive hyperlinks concealing the true malicious destinations. Linguistic and localization analysis suggests the phishing kit was developed primarily in Simplified Chinese and later localized. The campaign demonstrates sophisticated multi-vector social engineering and technical phishing techniques.
Potential Impact
The campaign enables credential theft including multi-factor authentication tokens through a real-time adversary-in-the-middle phishing framework, potentially compromising user accounts and sensitive information. The use of AI-assisted content generation increases the scale and personalization of spear-phishing, raising the likelihood of successful victim engagement. The addition of quishing extends the attack vector to physical environments, potentially affecting secondary victims who scan malicious QR codes on printed materials. The impersonation of reputable institutions and use of legitimate event details increases the credibility of the phishing lures, making detection by recipients more difficult.
Defensive Guidance
No official patch or fix applies as this is a social engineering and phishing campaign. Organizations should educate users about the risks of spear-phishing and quishing, emphasizing verification of sender identities and caution with hyperlinks and QR codes in unsolicited communications. Users should verify event invitations directly with purported organizers through independent channels. Multi-factor authentication remains important but may be bypassed by this advanced AitM phishing technique, so additional monitoring and anomaly detection on accounts is recommended. Cisco Talos has not indicated that the phishing infrastructure is mitigated or taken down; vigilance and user awareness are key defenses.
Technical Details
- Classification
- {"confidence":0.73,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://blog.talosintelligence.com/uat-11985/","fetched":true,"fetchedAt":"2026-10-08T10:06:03.202Z","wordCount":2292}
Threat ID: 6ac76b0b2cdf04f656094f72
Added to database: 10/08/2026, 10:06:03 UTC
Last enriched: 10/08/2026, 10:06:08 UTC
Last updated: 10/08/2026, 16:03:38 UTC
Views: 20
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.