← Back to Daily Briefing

AI-Generated Lures and Quishing in a Google-Impersonating AitM Campaign Targeting Taiwan Research Sector

Published October 10, 2026

A China-linked APT group has launched a sophisticated, AI-assisted spearphishing campaign against Taiwanese research institutes and academic bodies. The operation utilizes AI-generated email lures and malicious QR codes (quishing) to drive victims to highly convincing, multi-locale Google login clones. By leveraging an Adversary-in-the-Middle (AitM) framework, attackers maintain a persistent WebSocket C2 channel to relay MFA challenges in real-time, enabling the theft of session tokens and bypassing multi-factor authentication. This campaign represents a significant escalation in autonomous, AI-driven cyber espionage targeting high-value intellectual property and policy research.

  • Attack Vector & AI Integration

    • Deployment of AI-generated email lures using reusable prompt templates to mimic reputable academic institutions.
    • Use of "quishing" (QR code phishing) via malicious codes embedded in replicated event posters.
    • Personalized social engineering content designed to increase engagement through flattery and event specificity.
  • Technical Exploitation & AitM Framework

    • Implementation of an Adversary-in-the-Middle (AitM) framework that clones Google login UIs in Simplified Chinese, Traditional Chinese, and English.
    • Real-time MFA bypass achieved via a persistent WebSocket C2 channel used to relay authentication challenges.
    • Credential exfiltration directed to google_login_start and google_login_check endpoints via HTTP POST.
    • Employment of hidden iframes to simulate successful Google authentication, masking the attack from the victim.
  • Malware Obfuscation & Attribution

    • Obfuscated JavaScript payloads utilizing Base64 string rotation and control-flow shuffling to evade endpoint detection.
    • Attribution to China-linked APT actors (likely TA419/APT15) based on infrastructure and linguistic markers.
    • Localization artifacts in Simplified Chinese indicate development originating from mainland Chinese entities.
  • Indicators of Compromise (IoCs) & Impact

    • Targeted entities include Taiwanese universities, policy think tanks, and technical research labs.
    • ClamAV Signature: Html.Phishing.UAT11985-10060614-0.
    • Snort2 SID: 1:67198; Snort3 SID: 7:31.
    • IoCs hosted at: https://github.com/Cisco-Talos/IOCs/blob/main/2026/10/uat-11985.txt.
  • Recommended Defensive Mitigations

    • Mandatory adoption of phishing-resistant MFA, specifically FIDO2/WebAuthn.
    • Inspection of WebSocket traffic for anomalous patterns indicative of real-time C2 relay.
    • Enhanced security awareness training focusing on the risks of scanning unverified QR codes.
    • Implementation of strict URL filtering for known phishing kit localization patterns.

Related posts

  1. Malware News — UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing
  2. Security Affairs — China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan
  3. The Record by Recorded Future — Researchers find Chinese hacking campaigns targeting AI firms, Asian governments
  4. thehackernews.com — China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
  5. Mallory
  6. Blog
  7. Threatintel
  8. Technadu
  9. D2233

LINK COPIED TO CLIPBOARD