AI-Generated Lures and Quishing in a Google-Impersonating AitM Campaign Targeting Taiwan Research Sector
A China-linked APT group has launched a sophisticated, AI-assisted spearphishing campaign against Taiwanese research institutes and academic bodies. The operation utilizes AI-generated email lures and malicious QR codes (quishing) to drive victims to highly convincing, multi-locale Google login clones. By leveraging an Adversary-in-the-Middle (AitM) framework, attackers maintain a persistent WebSocket C2 channel to relay MFA challenges in real-time, enabling the theft of session tokens and bypassing multi-factor authentication. This campaign represents a significant escalation in autonomous, AI-driven cyber espionage targeting high-value intellectual property and policy research.
-
Attack Vector & AI Integration
- Deployment of AI-generated email lures using reusable prompt templates to mimic reputable academic institutions.
- Use of "quishing" (QR code phishing) via malicious codes embedded in replicated event posters.
- Personalized social engineering content designed to increase engagement through flattery and event specificity.
-
Technical Exploitation & AitM Framework
- Implementation of an Adversary-in-the-Middle (AitM) framework that clones Google login UIs in Simplified Chinese, Traditional Chinese, and English.
- Real-time MFA bypass achieved via a persistent WebSocket C2 channel used to relay authentication challenges.
- Credential exfiltration directed to
google_login_startandgoogle_login_checkendpoints via HTTP POST. - Employment of hidden iframes to simulate successful Google authentication, masking the attack from the victim.
-
Malware Obfuscation & Attribution
- Obfuscated JavaScript payloads utilizing Base64 string rotation and control-flow shuffling to evade endpoint detection.
- Attribution to China-linked APT actors (likely TA419/APT15) based on infrastructure and linguistic markers.
- Localization artifacts in Simplified Chinese indicate development originating from mainland Chinese entities.
-
Indicators of Compromise (IoCs) & Impact
- Targeted entities include Taiwanese universities, policy think tanks, and technical research labs.
- ClamAV Signature:
Html.Phishing.UAT11985-10060614-0. - Snort2 SID:
1:67198; Snort3 SID:7:31. - IoCs hosted at:
https://github.com/Cisco-Talos/IOCs/blob/main/2026/10/uat-11985.txt.
-
Recommended Defensive Mitigations
- Mandatory adoption of phishing-resistant MFA, specifically FIDO2/WebAuthn.
- Inspection of WebSocket traffic for anomalous patterns indicative of real-time C2 relay.
- Enhanced security awareness training focusing on the risks of scanning unverified QR codes.
- Implementation of strict URL filtering for known phishing kit localization patterns.
Related posts
- Malware News — UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing
- Security Affairs — China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan
- The Record by Recorded Future — Researchers find Chinese hacking campaigns targeting AI firms, Asian governments
- thehackernews.com — China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
- Mallory
- Blog
- Threatintel
- Technadu
- D2233