talos · Crawled Oct 8, 2026

UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing

1 IoCs
Read original article ↗

AI Summary

Cisco Talos identified an APT spear-phishing campaign, tracked as UAT-11985, targeting Taiwan-based research organizations using AI-assisted content generation to create highly personalized and credible phishing emails. The campaign leveraged legitimate event themes and impersonated reputable academic institutions, embedding malicious QR codes in posters (quishing) and using deceptive hyperlinks that mimic legitimate Google Forms URLs to redirect victims to phishing pages. The phishing infrastructure employs a real-time adversary-in-the-middle (AitM) framework with a hybrid HTTP and WebSocket architecture to intercept Google credentials and bypass MFA by dynamically mirroring authentication flows. Technical analysis suggests the phishing kit was developed primarily in Simplified Chinese, indicating a developer with mainland Chinese linguistic patterns.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
GitHub Repo talosintelligence/iocs Details →