Threat reportPhishingTL-2026-3205
UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing
UAT-11985: AI-assisted event lures delivering real-time (TL-2026-3205) is a high-severity phishing campaign, first published 2026-10-10. It is attributed to UAT-11985 (China) with low confidence, affects Google Google Account sign-in (impersonated; no product vulnerability), maps to 9 MITRE ATT&CK techniques (T1027, T1071.001, T1111), and is covered by 9 detection rules and 15 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 9MITRE ATT&CK
- Actors
- 1UAT-11985
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-3205
- Threat ID
- TL-2026-3205
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution
- UAT-11985
- Attribution confidence
- LOW
- Nation-state nexus
- China
- Motivation
- UNKNOWN
- Target sectors
- research, academia, government administration, think-tank
- Target regions
- taiwan
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in UAT-11985: AI-assisted event lures delivering real-time
Malware and tooling: Html.Phishing.UAT11985-10060614-0, WebSocket-based Google AitM phishing kit
How UAT-11985: AI-assisted event lures delivering real-time works
Cisco Talos reports UAT-11985 running a spear-phishing campaign impersonating Taiwanese academic institutions, using AI-assisted email lures and QR codes on modified event posters. Victims land on an adversary-in-the-middle Google sign-in replica that relays credentials and MFA challenges to the real Google service in real time over WebSockets.
Cisco Talos (blog published 2026-10-08) describes UAT-11985, a cluster observed in mid-2026 spear-phishing Taiwan-based research organizations. The lures impersonate legitimate events hosted by the Taiwan European Union Centre, the NCCU Institute of International Relations and the Taiwan Research Institute. Three analyzed emails shared a highly consistent structure, rhetoric and personalization pattern: a grandiose opening using abstract policy terminology (for example 'global strategic landscape' and 'reshaping the great-power order'), an interchangeable personalized-flattery section, and genuine event details combined with disguised hyperlinks that redirect to the malicious site. Talos assesses this is consistent with AI-assisted generation from reusable prompt templates, but notes the evidence is not conclusive proof of full LLM generation.
The actor also practiced quishing: legitimate event posters were modified so the genuine QR code was replaced with a malicious one, extending exposure to secondary victims who encounter printed posters, for example on office bulletin boards.
The landing infrastructure hosts a pixel-perfect Google sign-in replica in three locales (zh-CN, zh-TW, en), selected via navigator.languages. The page includes a hidden HTML section simulating successful authentication with an iframe (id google-success-frame). The JavaScript is obfuscated with Base64-encoded strings and a string-rotation routine (a while(!![]) push/shift shuffle loop) that decodes at runtime to defeat static analysis.
The kit works as a real-time adversary-in-the-middle relay with two channels. An HTTP POST channel carries event-driven, stateless telemetry and credentials: google_login_start (device fingerprint: locale, user agent, screen size, mobile flag), google_input_identifier (email or phone number) and google_login_check (password). A persistent WebSocket channel carries low-latency operator instructions that dictate which authentication challenge screen the victim sees, keeping MFA state synchronized with the genuine Google flow (including detection of whether a passkey-based flow is enabled). The relay lets the operator pass MFA challenges and harvest session material without the victim noticing.
Talos assesses with moderate confidence that the phishing UI was originally developed by a native Simplified Chinese speaker, based on localization architecture (the zh-CN base translation object, with zh-TW and en derived through an override function), mainland-Chinese terminology (e.g. 账号, 计算机, 邮箱, 无痕浏览窗口, 访客模式) and ternary-fallback ordering that defaults to Simplified Chinese. This assessment concerns the kit developer, not necessarily the operators; no named malware family, CVE or specific nation-state actor is reported. Motivation is not stated by the source; the targeting of policy and research staff and the focus on Google account takeover are consistent with credential theft but intent is unconfirmed.
Talos published IOCs at Cisco-Talos/IOCs (2026/10/uat-11985.txt) and detection coverage: ClamAV Html.Phishing.UAT11985-10060614-0, Snort 2 SID 1:67198 and Snort 3 SID 7:31. BeaconBeagle returned no matches for the phishing domain checked (morelessty.com).
MITRE ATT&CK techniques used in TL-2026-3205
Defense Evasion
T1027 Obfuscated Files or Information; T1684.001 Impersonation
Command and Control
T1071.001 Application Layer Protocol: Web Protocols
Credential Access
T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle
Execution
T1204.001 User Execution: Malicious Link
Initial Access
T1566.002 Phishing: Spearphishing Link
Resource Development
Affected products and versions in UAT-11985: AI-assisted event lures delivering real-time
- Google — Google Account sign-in (impersonated; no product vulnerability)
Remediation for UAT-11985: AI-assisted event lures delivering real-time
Immediate actions
- Block the UAT-11985 domains and URLs at DNS, proxy and email gateway
- Search proxy/DNS logs for visits to morelessty.com, centerhoti.com and natrlyi.com subdomains and reset credentials and revoke sessions for any Google accounts that interacted
- Alert staff at Taiwan-based research and academic organizations to fake event invitations and tampered QR codes on printed posters
Workarounds
- Open event registration links only by typing the organizer's known domain rather than following emailed links or scanning posted QR codes
- Deploy Talos coverage: ClamAV Html.Phishing.UAT11985-10060614-0, Snort 2 SID 1:67198, Snort 3 SID 7:31
Longer-term hardening
- Enroll high-risk users in phishing-resistant MFA (FIDO2 security keys or passkeys bound to the genuine origin) because OTP and push prompts can be relayed by AitM kits
- Use conditional access / session-binding controls and review Google account sign-in and device activity for anomalous sessions
- Train staff on QR-code phishing and on verifying posted event QR codes against the organizer's official site
Timeline of UAT-11985: AI-assisted event lures delivering real-time
- Approximate date: Talos places the UAT-11985 spear-phishing campaign against Taiwan-based research organizations in mid-2026 (exact start date not published).
- Approximate date (mid-2026): AI-assisted event-invitation emails impersonating the Taiwan European Union Centre, NCCU Institute of International Relations and Taiwan Research Institute carry disguised links to Google login AitM pages.
- Approximate date (mid-2026): legitimate event posters modified with malicious QR codes, exposing secondary victims who scan printed posters.
- Talos releases IOCs in Cisco-Talos/IOCs and detection coverage: ClamAV Html.Phishing.UAT11985-10060614-0, Snort 2 SID 1:67198, Snort 3 SID 7:31.
- Cisco Talos publishes 'UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing', attributing the kit UI to a Simplified Chinese-speaking developer with moderate confidence.
- Threadlinqs opens tracking of UAT-11985 as TL-2026-3205; BeaconBeagle check of morelessty.com returns no matches.
Sources cited for UAT-11985: AI-assisted event lures delivering real-time
- UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing
- Cisco Talos IOCs: uat-11985.txt
- MITRE ATT&CK T1557 Adversary-in-the-Middle
- MITRE ATT&CK T1111 Multi-Factor Authentication Interception
- MITRE ATT&CK T1566.002 Phishing: Spearphishing Link
- MITRE ATT&CK T1539 Steal Web Session Cookie
Detection coverage for TL-2026-3205
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3205 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.