LIVE FEED
ATLAS OWASP HIGH Significant risk · Prioritise patching RELEVANCE ▲ 7.5

APT Uses AI-Generated Lures in Google AitM Phishing on Taiwan

TL;DR HIGH
  • What happened: APT used AI-generated phishing lures and Google AitM kit to steal credentials and bypass MFA.
  • Who's at risk: Taiwan-based research organisation staff are directly targeted via personalised invitation emails and QR code lures at public events.
  • Act now: Train staff to verify event invitations directly with named institutions before clicking links or scanning QR codes · Deploy phishing-resistant MFA (FIDO2/passkeys) to neutralise AitM credential interception · Implement email authentication controls (DMARC, DKIM, SPF) and flag mismatches from impersonated domains
APT Uses AI-Generated Lures in Google AitM Phishing on Taiwan

Overview

In mid-2026, Cisco Talos uncovered an APT spear-phishing campaign designated UAT-11985 targeting personnel affiliated with Taiwan research organisations. The operation is notable for two converging trends: the weaponisation of AI-assisted content generation to scale personalised lures, and the deployment of a real-time adversary-in-the-middle (AitM) phishing kit that intercepts Google authentication sessions including MFA challenges. The combination marks a meaningful escalation in the operational sophistication of state-aligned phishing campaigns.

Technical Analysis

AI-Assisted Lure Generation Phishing emails impersonated three Taiwanese institutions — the Taiwan European Union Centre, the NCCU Institute of International Relations, and the Taiwan Research Institute. Despite covering different geopolitical topics, the emails shared near-identical syntactic structure, rhetorical framing, and personalisation patterns. Talos assesses with moderate confidence that the content was produced from a reusable LLM prompt template, allowing the actor to rapidly customise invitations at scale without individually authoring each message.

QR Code Phishing (Quishing) Beyond email, the actor modified legitimate public event posters to embed malicious QR codes, extending the attack surface to individuals who encounter printed materials rather than the original email recipients. This is a deliberate expansion of the victim pool.

AitM Phishing Framework The campaign deployed a hybrid HTTP/WebSocket phishing kit that impersonated Google login pages. The WebSocket architecture enabled real-time synchronisation of authentication workflows: as a victim submitted credentials and MFA tokens on the fake page, the kit relayed them to Google’s actual infrastructure and proxied the session cookie back to the attacker. This renders standard TOTP-based MFA ineffective as a defence.

Developer Attribution Indicators Talos identified that the phishing kit’s user interface was originally developed in Simplified Chinese before being localised into Traditional Chinese and English. Mainland-Chinese lexical choices and the default language branch collectively suggest a developer whose primary working language is Simplified Chinese, indicating a probable China-nexus origin.

Framework Mapping

  • AML.T0065 (LLM Prompt Crafting): The reusable prompt template pattern strongly suggests deliberate engineering of LLM prompts to generate consistent, credible phishing content at volume.
  • AML.T0047 (AI-Enabled Product or Service): LLM tooling was leveraged as an operational capability within an offensive campaign infrastructure.
  • AML.T0113 (Steal Web Session Cookie): The AitM framework’s core objective is real-time session cookie interception post-authentication.
  • AML.T0088 (Generate Deepfakes): While not confirmed, the impersonation of institution identities via fabricated event materials shares the social-engineering intent of synthetic identity generation.

From an OWASP LLM perspective, LLM09 (Overreliance) is relevant: defenders and targets who over-trust AI-generated content as authentic are directly exploited by this technique.

Impact Assessment

Targeted individuals in Taiwan’s research and policy community face credential compromise and persistent access risk. The AitM design means MFA provides no protection unless phishing-resistant methods (FIDO2) are in place. The quishing vector extends risk beyond digitally cautious staff to anyone encountering printed event materials.

Mitigation & Recommendations

  • Adopt FIDO2/passkey authentication for Google Workspace and other sensitive services; these are cryptographically bound to the legitimate origin and cannot be relayed by an AitM proxy.
  • Verify event invitations out-of-band by contacting named institutions through official contact details before engaging with links or QR codes.
  • Enforce DMARC, DKIM, and SPF to reduce impersonation of institutional domains.
  • Educate staff on quishing — QR codes in physical materials are an emerging and under-appreciated phishing vector.
  • Monitor for adversary infrastructure using Talos IOCs associated with UAT-11985.

References

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.