Cisco Talos identified a mid-2026 spear-phishing campaign by UAT-11985 targeting individuals affiliated with Taiwan-based research organizations. The actor impersonated academic and policy institutions, repurposed legitimate event information, and sent deceptive registration links and event posters containing malicious QR codes. Consistent email structures and personalized messaging suggested AI-assisted lure generation, but Talos could not conclusively establish large language model use.
The campaign used an operator-driven adversary-in-the-middle (AiTM) phishing kit that impersonated Google authentication, combining HTTP POST submissions with WebSocket updates to relay credentials and multifactor authentication challenges in real time. This enabled authenticated-session theft and account takeover, illustrating the credential and session interception risks covered by MITRE ATT&CK technique T1557. Talos assessed with moderate confidence that the kit’s interface was originally developed in Simplified Chinese, based on its localization architecture and terminology; this does not establish the operator’s origin. Organizations should prioritize phishing-resistant MFA, verify event invitations through independent channels, and revoke compromised sessions rather than relying on password resets alone.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
In mid-2026, Cisco Talos observed a spear-phishing campaign targeting individuals affiliated with Taiwan-based research organizations. The attackers impersonated academic and policy institutions, using deceptive registration links and copied event posters with malicious QR codes to direct recipients to Google-themed phishing pages.
Talos disclosed that the phishing kit combined HTTP POST submissions and WebSocket updates to relay credentials and MFA challenges in real time, enabling authenticated-session theft and account takeover. The report also documented evidence of AI-assisted lure generation, assessed a Simplified Chinese origin for the interface with moderate confidence, and provided detection coverage and indicators of compromise.
An email recipient contacted the institutions impersonated in the phishing invitations. None could confirm that the three purported senders were employees or representatives.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 10 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceblog.talosintelligence.com
Open sourcegithub.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.