AI-Written Lures, Operator-Driven Theft: Cisco Talos Tracks UAT-11985 Real-Time Google AitM Phishing Against Taiwan Researchers

Cisco Talos on 8 October 2026 (research by Joey Chen) attributed a spear-phishing campaign against individuals affiliated with Taiwan research organisations to a tracked activity set dubbed UAT-11985. The operation, observed in mid-2026, pairs two trends defenders keep treating separately: AI-assisted lure production at the front and a real-time, operator-driven adversary-in-the-middle (AitM) kit at the back that relays Google credentials and multi-factor challenges through a hybrid HTTP-plus-WebSocket architecture. The targets were people, the MFA was bypassed live, and the developer fingerprints point — with stated moderate confidence — at a native Simplified Chinese speaker.

Lures that read like a prompt template’s output

The actor impersonated legitimate Taiwanese institutions — the Taiwan European Union Centre, the NCCU Institute of International Relations, and the Taiwan Research Institute — reusing real public event information as cover. A recipient who checked with the named organisations confirmed none of the three purported senders worked there: fabricated identities, legitimate names, authentic event details. Talos calls the mechanism legitimacy laundering, and it is the part that should worry event organisers — the accuracy of the event details is the disguise, not a reason to trust the mail.

All three invitation emails share a near-identical three-part structure — grandiose geopolitical scene-setting (“reshaping the great-power order”, “high intensity professional dialogue”), interchangeable flattery with few verifiable details about the recipient’s actual work, then logistics copied from real announcements. Talos is careful about the AI claim: the syntactic consistency across different geopolitical topics suggests a reusable prompt template, but the team states explicitly it cannot conclusively determine whether the emails were fully LLM-generated. That caveat matters — “AI-assisted” here means template-driven personalisation at scale, which is threat enough without overstating it. The registration links complete the deception: visible text showing a benign Google Forms URL, with the underlying href pointing at actor-controlled phishing infrastructure.

Quishing jumps from inbox to bulletin board

The campaign did not stay inside email. Posters scraped from legitimate event sites were attached with maliciously altered QR codes — a calculated bet that recipients would print and display them on office bulletin boards, converting colleagues who never received the email into secondary victims. QR-code phishing turns every shared printer into a distribution channel, and it bypasses every email security control at once. Any awareness programme that teaches “hover the link” needs a poster-and-QR addendum: scan-to-register for an event you did not solicit is the physical-world equivalent of clicking the attachment.

The kit: HTTP exfiltrates, WebSocket orchestrates

Victims who clicked landed on a pixel-perfect Google sign-in replica that forcibly redirected from a spoofed Google Form, with locale selection (Simplified Chinese, Traditional Chinese, English) driven by the victim’s navigator.languages — targeting logic aimed at Chinese-speaking users. The kit’s split-channel design is the technically interesting part: stateless HTTP POST pushes exfiltration (browser fingerprints, credential and challenge submissions, heartbeat polls) while a persistent WebSocket streams operator instructions back, dictating exactly which MFA challenge screen to render next. Unlike fully automated kits, this one is built for a human operator orchestrating authentication step by step — relaying the victim’s session against real Google servers and harvesting complete, authenticated session tokens. The client JavaScript hides behind string-rotation obfuscation: a large Base64 string array resolved at runtime through a while(!![]){push/shift} shuffle loop that defeats naive static deobfuscation.

Attribution rests on the kit’s localisation architecture rather than infrastructure: the base translation object is written entirely in Simplified Chinese with Traditional Chinese and English derived at runtime, Simplified Chinese is consistently the default branch, and lexical choices (“账号” for account, “计算机” for computer, mainland-style terms for incognito and guest mode) match mainland conventions over Taiwanese or Hong Kong usage. Talos assesses moderate confidence — honest grading for a linguistic signal, and a reminder that developer-habit evidence constrains but does not close attribution.

What to do

  • Treat MFA as phishable by default unless it is FIDO2. Real-time AitM relay defeats one-time codes and push approvals; only phishing-resistant authentication (passkeys, hardware keys) breaks the relay. Prioritise it for the exact population targeted here — researchers and policy staff with institutional Google accounts.
  • Verify event invitations out of band. If the event details are real but the sender is not, the check that works is contacting the organiser through a known channel — which is precisely what exposed these lures.
  • Inspect the href, not the text — and extend the habit to QR codes on printed materials. Consider a policy that event QR codes get re-verified against the organiser’s site before display.
  • Detect the kit’s shape: newly observed hosts pairing rapid HTTP POST exfiltration with a persistent WebSocket to the same infrastructure, plus Google-login-themed pages serving heavily obfuscated shuffle-loop JavaScript, are high-fidelity hunting leads. Do not confuse this set with UAT-11587/Antino — a separate China-nexus Talos-tracked set running its own Taiwan-focused espionage campaign.

Verification note: the campaign timing (observed mid-2026, published 8 October 2026), the target set (Taiwan research organisations), the three impersonated institutions, the sender-verification failure, the three-part template structure and quoted jargon, the AI-assisted assessment with its explicit non-conclusive caveat, the Google-Forms-text versus hostile-href mismatch, the altered-QR poster mechanism and bulletin-board reasoning, the spoofed-Form-to-login redirect, the navigator.languages locale logic, the HTTP-POST-plus-WebSocket split architecture, the session-token objective, the string-rotation obfuscation mechanism, and the Simplified-Chinese-developer assessment with mainland-lexicon examples and moderate confidence were all read directly from Cisco Talos’s UAT-11985 analysis. The comparison with UAT-11587/Antino draws on Talos’s separate reporting as surfaced in secondary coverage; the two sets are distinct and should not be merged.

Sources: