Full Report
Cisco Talos identified an APT spear-phishing campaign against individuals affiliated with Taiwan research organizations. The operation leveraged legitimate public event themes and impersonated reputable academic and policy institutions.
Analysis Summary
# Threat Actor: UAT-11985
## Attribution & Identity
* **Actor Identification:** UAT-11985 (Temporary designation by Cisco Talos).
* **Origin/Affiliation:** Assessed with moderate confidence to be a developer whose primary working language is Simplified Chinese.
* **Evidence for Attribution:** Technical analysis of the phishing kit revealed the user interface was originally developed in Simplified Chinese before being adapted. The localization architecture and specific mainland-Chinese lexical usage support this assessment.
## Activity Summary
In mid-2026, Cisco Talos identified a sophisticated spear-phishing campaign targeting research organizations in Taiwan. The operation is notable for its use of AI-assisted content generation to create highly personalized lures and the deployment of a custom Adversary-in-the-Middle (AitM) framework capable of bypassing Multi-Factor Authentication (MFA) in real time.
## Tactics, Techniques & Procedures
* **AI-Assisted Social Engineering:** Use of reusable prompt templates and LLMs to generate professional, jargon-heavy invitation emails that include targeted flattery and academic context.
* **Legitimacy Laundering:** Impersonating reputable institutions and using authentic details from legitimate public events to establish credibility.
* **Quishing (QR Phishing):** Modifying legitimate event posters with malicious QR codes to target victims via physical or digital flyers.
* **Adversary-in-the-Middle (AitM):** Intercepting authentication flows in real time to capture credentials and MFA tokens.
* **Hybrid C2 Architecture:** Utilizing a combination of standard HTTP POST requests for credential harvesting and WebSockets for low-latency state synchronization between the victim and the real Google login service.
* **MITRE ATT&CK Mapping:**
* **T1566.001:** Phishing: Spear-phishing Attachment/Link
* **T1566.003:** Phishing: Spear-phishing via Service (QR Codes)
* **T1557:** Adversary-in-the-Middle
* **T1111:** Two-Factor Authentication Interception
* **T1071.001:** Application Layer Protocol: Web Protocols (HTTP/WebSockets)
## Targeting
* **Sectors:** Academia, Policy Research, Think Tanks, Geopolitical Research.
* **Geography:** Taiwan.
* **Victims:** Individuals affiliated with the Taiwan European Union Centre, NCCU Institute of International Relations, and Taiwan Research Institute.
## Tools & Infrastructure
* **Phishing Kit:** A custom-built Google AitM framework featuring a Simplified Chinese default language branch.
* **Infrastructure:**
* `google_input_identifier` and `google_login_check` endpoints used for real-time relay.
* Actor-controlled C2 servers mimicking Google authentication pages.
* **Defanged IOCs (Based on report):**
* hXXps[://]github[.]com/Cisco-Talos/IOCs/blob/main/2026/10/uat-11985[.]txt
* (Note: Specific C2 domains/IPs are maintained in the linked GitHub repository per the article).
## Implications
The use of AI-assisted lures marks a shift toward scalable, high-quality social engineering that can bypass traditional "suspicious language" filters. Furthermore, the reliance on AitM frameworks that synchronize via WebSockets demonstrates a high level of technical maturity, rendering standard MFA (like SMS or push notifications) ineffective against this actor.
## Mitigations
* **FIDO2/WebAuthn:** Implement hardware security keys (e.g., YubiKeys) which are inherently resistant to AitM phishing.
* **Email Security:** Deploy advanced email protection systems capable of identifying AI-generated syntactic patterns and analyzing embedded URLs for AitM infrastructure.
* **QR Code Awareness:** Educate staff on the risks of scanning QR codes on public posters or unsolicited digital documents.
* **Detection Signatures:**
* **ClamAV:** `Html.Phishing.UAT11985-10060614-0`
* **Snort:** `1:67198`, `7:31`