malware
Published 2026-10-08
Verified 2026-10-11

Cisco Talos (8 Oct): UAT-11985 targets Taiwan research staff with AI-written event invitations and doctored QR-code posters that lead to a real-time Google sign-in relay able to defeat MFA

Cisco Talos reported on 8 October 2026 a spear-phishing campaign it tracks as UAT-11985, seen in mid-2026 against people linked to Taiwan research organisations. The emails invite targets to plausible public events, borrowing real event details and the names of institutions such as the Taiwan European Union Centre, the NCCU Institute of International Relations and Taiwan Research Institute, but the named senders could not be confirmed by any of those organisations. The three emails Talos studied share an almost identical three-part structure, flattery and policy jargon, which Talos says points strongly to AI-assisted templating, while noting that language alone cannot prove a large language model wrote them. Registration links display a legitimate-looking Google Forms address but point to a fake form hosted elsewhere, which forces a jump to a copy of the Google sign-in page. Some emails attached real event posters with the QR code swapped for a malicious one, so anyone who scans a printed copy on a noticeboard can also be phished. The sign-in kit is operator-driven: it sends browser details, the account name and the password to the attacker's server over HTTP POST, the server replays them to Google in real time, and a WebSocket channel tells the fake page which next screen to show, including password, passkey or the specific MFA challenge Google asks for, so the attacker ends up with a fully signed-in session. Talos assesses with moderate confidence that the kit's interface was first written in Simplified Chinese; it supports only Simplified Chinese, Traditional Chinese and English. Talos published ClamAV and Snort detections and indicators. No Australian targeting was reported. Primary: Cisco Talos.

Product
Google accounts (credential and MFA relay phishing); email and printed QR-code lures
Exploited in Australia?
unknown
Patch to
Move high-risk staff (research, policy, executive) to phishing-resistant sign-in such as passkeys or security keys, which a relay page cannot replay. Treat unsolicited event invitations as suspect even when the event is real: check the sender with the institution and type the registration address yourself. Hover links to compare the shown and real destination, and don't scan QR codes on posters that arrived by email. Load the Talos ClamAV/Snort detections and indicators, and in Google Workspace review sign-ins from unfamiliar devices and locations followed by new sessions

Primary: Cisco Talos — UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing (8 Oct 2026) · talkback.sh resources feed (listed 2 days before 11 Oct 2026)

ai identity