UAT-11985 is a threat actor tracked in connection with a mid-2026 spear-phishing campaign targeting individuals affiliated with Taiwan-based research organizations. Its lures impersonated academic and policy institutions, including the Taiwan European Union Centre, NCCU Institute of International Relations, and Taiwan Research Institute. Invitations reused public event information and incorporated personalized praise, exclusive participation claims, and reserved VIP seating. The actor distributed deceptive registration hyperlinks and copied legitimate event posters while replacing their QR codes with malicious ones. The campaign used convincing Google Forms imitations that redirected victims to spoofed Google authentication pages. An operator-driven adversary-in-the-middle phishing framework relayed account identifiers, passwords, and multifactor authentication challenges between victims and legitimate Google services. HTTP POST requests carried submitted information, while persistent WebSocket connections delivered authentication-state updates and operator commands. This real-time relay enabled credential theft, authenticated-session token harvesting, and account takeover despite MFA. The interface supported Simplified Chinese, Traditional Chinese, and English, selecting localization according to browser preferences. Its JavaScript used encoded strings, control-flow obfuscation, and runtime array rotation to hinder analysis. The actor's country of origin and state affiliation have not been established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a targeted spear-phishing campaign against individuals affiliated with Taiwan research organizations in mid-2026. The actor impersonated academic and policy institutions using public event information and likely AI-assisted personalized invitations. Malicious registration links and altered poster QR codes led to an operator-driven Google adversary-in-the-middle phishing kit designed to intercept credentials, relay MFA challenges, and harvest authenticated session tokens. Talos assessed with moderate confidence that the kit's interface was originally authored in Simplified Chinese; this does not establish the actor's country of origin or state sponsorship.
Conducted a targeted spear-phishing campaign in mid-2026 against individuals affiliated with Taiwan-based research organizations. The actor impersonated academic and policy institutions, likely used AI-assisted invitation personalization, and distributed modified event posters containing malicious QR codes. An operator-driven adversary-in-the-middle phishing framework relayed Google authentication workflows in real time to steal credentials, intercept MFA challenges, and harvest authenticated session tokens. Simplified Chinese localization suggests the developer's primary working language, but does not establish attacker nationality or state sponsorship.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.