Threat reportPhishingTL-2026-3205

UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing

highACTIVE

UAT-11985: AI-assisted event lures delivering real-time (TL-2026-3205) is a high-severity phishing campaign, first published 2026-10-10. It is attributed to UAT-11985 (China) with low confidence, affects Google Google Account sign-in (impersonated; no product vulnerability), maps to 9 MITRE ATT&CK techniques (T1027, T1071.001, T1111), and is covered by 9 detection rules and 15 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
9MITRE ATT&CK
Actors
1UAT-11985
Detection rules
9SPL · KQL · Sigma
IOCs
15Indicators of compromise

Key facts for TL-2026-3205

Threat ID
TL-2026-3205
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution
UAT-11985
Attribution confidence
LOW
Nation-state nexus
China
Motivation
UNKNOWN
Target sectors
research, academia, government administration, think-tank
Target regions
taiwan
Detection rules
9
Indicators of compromise
15

Malware and tooling in UAT-11985: AI-assisted event lures delivering real-time

Malware and tooling: Html.Phishing.UAT11985-10060614-0, WebSocket-based Google AitM phishing kit

How UAT-11985: AI-assisted event lures delivering real-time works

Cisco Talos reports UAT-11985 running a spear-phishing campaign impersonating Taiwanese academic institutions, using AI-assisted email lures and QR codes on modified event posters. Victims land on an adversary-in-the-middle Google sign-in replica that relays credentials and MFA challenges to the real Google service in real time over WebSockets.

Cisco Talos (blog published 2026-10-08) describes UAT-11985, a cluster observed in mid-2026 spear-phishing Taiwan-based research organizations. The lures impersonate legitimate events hosted by the Taiwan European Union Centre, the NCCU Institute of International Relations and the Taiwan Research Institute. Three analyzed emails shared a highly consistent structure, rhetoric and personalization pattern: a grandiose opening using abstract policy terminology (for example 'global strategic landscape' and 'reshaping the great-power order'), an interchangeable personalized-flattery section, and genuine event details combined with disguised hyperlinks that redirect to the malicious site. Talos assesses this is consistent with AI-assisted generation from reusable prompt templates, but notes the evidence is not conclusive proof of full LLM generation.

The actor also practiced quishing: legitimate event posters were modified so the genuine QR code was replaced with a malicious one, extending exposure to secondary victims who encounter printed posters, for example on office bulletin boards.

The landing infrastructure hosts a pixel-perfect Google sign-in replica in three locales (zh-CN, zh-TW, en), selected via navigator.languages. The page includes a hidden HTML section simulating successful authentication with an iframe (id google-success-frame). The JavaScript is obfuscated with Base64-encoded strings and a string-rotation routine (a while(!![]) push/shift shuffle loop) that decodes at runtime to defeat static analysis.

The kit works as a real-time adversary-in-the-middle relay with two channels. An HTTP POST channel carries event-driven, stateless telemetry and credentials: google_login_start (device fingerprint: locale, user agent, screen size, mobile flag), google_input_identifier (email or phone number) and google_login_check (password). A persistent WebSocket channel carries low-latency operator instructions that dictate which authentication challenge screen the victim sees, keeping MFA state synchronized with the genuine Google flow (including detection of whether a passkey-based flow is enabled). The relay lets the operator pass MFA challenges and harvest session material without the victim noticing.

Talos assesses with moderate confidence that the phishing UI was originally developed by a native Simplified Chinese speaker, based on localization architecture (the zh-CN base translation object, with zh-TW and en derived through an override function), mainland-Chinese terminology (e.g. 账号, 计算机, 邮箱, 无痕浏览窗口, 访客模式) and ternary-fallback ordering that defaults to Simplified Chinese. This assessment concerns the kit developer, not necessarily the operators; no named malware family, CVE or specific nation-state actor is reported. Motivation is not stated by the source; the targeting of policy and research staff and the focus on Google account takeover are consistent with credential theft but intent is unconfirmed.

Talos published IOCs at Cisco-Talos/IOCs (2026/10/uat-11985.txt) and detection coverage: ClamAV Html.Phishing.UAT11985-10060614-0, Snort 2 SID 1:67198 and Snort 3 SID 7:31. BeaconBeagle returned no matches for the phishing domain checked (morelessty.com).

MITRE ATT&CK techniques used in TL-2026-3205

Defense Evasion

T1027 Obfuscated Files or Information; T1684.001 Impersonation

Command and Control

T1071.001 Application Layer Protocol: Web Protocols

Credential Access

T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle

Execution

T1204.001 User Execution: Malicious Link

Initial Access

T1566.002 Phishing: Spearphishing Link

Resource Development

T1583.001 Acquire Infrastructure: Domains

Affected products and versions in UAT-11985: AI-assisted event lures delivering real-time

  • Google — Google Account sign-in (impersonated; no product vulnerability)

Remediation for UAT-11985: AI-assisted event lures delivering real-time

Immediate actions

  • Block the UAT-11985 domains and URLs at DNS, proxy and email gateway
  • Search proxy/DNS logs for visits to morelessty.com, centerhoti.com and natrlyi.com subdomains and reset credentials and revoke sessions for any Google accounts that interacted
  • Alert staff at Taiwan-based research and academic organizations to fake event invitations and tampered QR codes on printed posters

Workarounds

  • Open event registration links only by typing the organizer's known domain rather than following emailed links or scanning posted QR codes
  • Deploy Talos coverage: ClamAV Html.Phishing.UAT11985-10060614-0, Snort 2 SID 1:67198, Snort 3 SID 7:31

Longer-term hardening

  • Enroll high-risk users in phishing-resistant MFA (FIDO2 security keys or passkeys bound to the genuine origin) because OTP and push prompts can be relayed by AitM kits
  • Use conditional access / session-binding controls and review Google account sign-in and device activity for anomalous sessions
  • Train staff on QR-code phishing and on verifying posted event QR codes against the organizer's official site

Timeline of UAT-11985: AI-assisted event lures delivering real-time

  • Approximate date: Talos places the UAT-11985 spear-phishing campaign against Taiwan-based research organizations in mid-2026 (exact start date not published).
  • Approximate date (mid-2026): AI-assisted event-invitation emails impersonating the Taiwan European Union Centre, NCCU Institute of International Relations and Taiwan Research Institute carry disguised links to Google login AitM pages.
  • Approximate date (mid-2026): legitimate event posters modified with malicious QR codes, exposing secondary victims who scan printed posters.
  • Talos releases IOCs in Cisco-Talos/IOCs and detection coverage: ClamAV Html.Phishing.UAT11985-10060614-0, Snort 2 SID 1:67198, Snort 3 SID 7:31.
  • Cisco Talos publishes 'UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing', attributing the kit UI to a Simplified Chinese-speaking developer with moderate confidence.
  • Threadlinqs opens tracking of UAT-11985 as TL-2026-3205; BeaconBeagle check of morelessty.com returns no matches.

Sources cited for UAT-11985: AI-assisted event lures delivering real-time

Detection coverage for TL-2026-3205

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3205 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
15 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats