Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal. Detection, Dallas. Ava Okello: Report Finds Nearly Half of Deployed Detections Need Attention Before SOCs Can Trust Them.

SOCtember

Always First. Fast SOC News.

Cisco Talos Threat Spotlight branded graphic for the UAT-11985 AI-assisted phishing report.
Graphic: Cisco Talos, Threat Spotlight header art for the Oct 8, 2026 UAT-11985 post (fair use).

Threat Intel

Cisco Talos Tracks UAT-11985 Phishing Taiwan Researchers With AI-Assisted Invites and Real-Time Google Login Relays

Cisco Talos says the campaign reused real public event details, likely AI-assisted invitation templates, and an adversary-in-the-middle kit that relays Google authentication including MFA challenges over HTTP and WebSocket. ClamAV and Snort coverage plus IOCs are published.

Priya Shah, Threat IntelSingapore6 min read

SINGAPORE - Spear-phishing emails that looked like academic event invitations were, in fact, the front of a real-time Google login relay aimed at people tied to Taiwan research organizations, Cisco Talos reported on Oct. 8. Tracking the activity as UAT-11985, Talos said the operators reused legitimate public event themes, impersonated reputable Taiwanese academic and policy institutions, and deployed an adversary-in-the-middle framework that synchronized Google authentication workflows so credentials and multi-factor challenges could be intercepted live. Talos assesses with moderate confidence that the phishing kit's interface was originally written in Simplified Chinese and later adapted for Traditional Chinese and English.

In mid-2026, Talos said, the actor impersonated the Taiwan European Union Centre, the NCCU Institute of International Relations, and the Taiwan Research Institute. One recipient checked with those organizations. None could confirm that the named senders worked for them. Talos concluded the actor fabricated the sender identities while using real organizational names and publicly available event details as cover. The three invitation emails followed a highly consistent three-part structure: a polished geopolitical opening heavy on abstract policy jargon, personalized flattery with few verifiable details about the recipient's actual work, and logistics that copied authentic event information while burying a malicious registration link. In one example Talos documented, the visible link text resembled a Google Forms URL while the underlying destination pointed to actor-controlled infrastructure.

Side-by-side comparison of a legitimate Taiwan research event poster and a modified copy with a substituted QR code.
Figure: Cisco Talos, Figure 5, legitimate event poster (left) and modified poster with malicious QR code (right), Oct 8, 2026 (fair use).The right-hand poster keeps the event text and swaps the QR code.

Talos said the messages showed hallmarks of AI-assisted content generation, including formulaic prose, interchangeable praise, and rapid customization across different recipients and topics. The researchers stopped short of saying a large language model fully authored the emails. Several invitations also attached event posters scraped from legitimate sites with the embedded QR codes swapped for malicious ones, expanding the campaign beyond email into quishing if recipients printed and posted the materials. Fake Google Form pages then forced a redirect into spoofed Google sign-in panels that supported only zh-CN, zh-TW, and English locales, with region selection based on the browser's navigator.languages list.

Diagram of the UAT-11985 attack chain showing phishing delivery, spoofed Google login, and adversary-in-the-middle relay.
Figure: Cisco Talos, Figure 9, UAT-11985 attack chain from phishing URL through Google AitM relay, Oct 8, 2026 (fair use).The kit sits between the browser and Google's own sign-in service.

The credential-theft stage is what makes the kit operationally sharp for SOC desks. After the victim lands on a pixel-perfect Google sign-in replica, obfuscated JavaScript sits between the browser and real Google authentication servers. Talos described a dual-channel design: HTTP POST for outbound browser fingerprints, identifiers, passwords, and heartbeats, and a persistent WebSocket for inbound instructions that tell the page which MFA challenge screen to render next. When a victim submits an identifier, the actor's server checks whether the account exists and whether a passkey flow applies, then advances the fake UI accordingly. A password submission is relayed to Google; if Google demands more authentication, the kit mirrors that challenge in real time and ultimately aims to harvest full authenticated session tokens. Talos also flagged string-rotation and Base64 array obfuscation in the client script, plus localization architecture that treats Simplified Chinese as the base translation object from which Traditional Chinese and English variants are derived.

Diagram showing WebSocket inbound control used to stream Google MFA challenge screens to the phishing page.
Figure: Cisco Talos, Figure 13, inbound WebSocket command and control for MFA challenge screens, Oct 8, 2026 (fair use).Inbound WebSocket messages tell the page which challenge to show.

For defenders, Talos published ClamAV signature Html.Phishing.UAT11985-10060614-0 and Snort rules SID 1:67198 (Snort2) and 7:31 (Snort3), with indicators of compromise in its GitHub IOC repository under 2026/10/uat-11985.txt. Practical hunts include mismatches between displayed registration URLs and actual href destinations, unexpected Google-login lookalikes that speak only those three locales, outbound POSTs paired with long-lived WebSocket sessions to unfamiliar hosts during authentication, and QR codes on event posters that do not match the legitimate institutional originals. Talos sells network, web, and email security products that advertise coverage for this activity.

Sources:


Priya Shah covers threat intelligence, intrusion analysis, and adversary tradecraft for SOCtember from Singapore.

Related stories

Threat Intel desk