# UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing

> Cisco Talos reports UAT-11985 running a spear-phishing campaign impersonating Taiwanese academic institutions, using AI-assisted email lures and QR codes on modified event posters. Victims land on an adversary-in-the-middle Google sign-in replica that relays credentials and MFA challenges to the real Google service in real time over WebSockets.

- **Published:** 2026-10-10T00:00:00Z
- **Last reviewed:** 2026-10-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3205
- **ID:** TL-2026-3205
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Actor:** UAT-11985 (China)
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Cisco Talos (blog published 2026-10-08) describes UAT-11985, a cluster observed in mid-2026 spear-phishing Taiwan-based research organizations. The lures impersonate legitimate events hosted by the Taiwan European Union Centre, the NCCU Institute of International Relations and the Taiwan Research Institute. Three analyzed emails shared a highly consistent structure, rhetoric and personalization pattern: a grandiose opening using abstract policy terminology (for example 'global strategic landscape' and 'reshaping the great-power order'), an interchangeable personalized-flattery section, and genuine event details combined with disguised hyperlinks that redirect to the malicious site. Talos assesses this is consistent with AI-assisted generation from reusable prompt templates, but notes the evidence is not conclusive proof of full LLM generation.

The actor also practiced quishing: legitimate event posters were modified so the genuine QR code was replaced with a malicious one, extending exposure to secondary victims who encounter printed posters, for example on office bulletin boards.

The landing infrastructure hosts a pixel-perfect Google sign-in replica in three locales (zh-CN, zh-TW, en), selected via navigator.languages. The page includes a hidden HTML section simulating successful authentication with an iframe (id google-success-frame). The JavaScript is obfuscated with Base64-encoded strings and a string-rotation routine (a while(!![]) push/shift shuffle loop) that decodes at runtime to defeat static analysis.

The kit works as a real-time adversary-in-the-middle relay with two channels. An HTTP POST channel carries event-driven, stateless telemetry and credentials: google_login_start (device fingerprint: locale, user agent, screen size, mobile flag), google_input_identifier (email or phone number) and google_login_check (password). A persistent WebSocket channel carries low-latency operator instructions that dictate which authentication challenge screen the victim sees, keeping MFA state synchronized with the genuine Google flow (including detection of whether a passkey-based flow is enabled). The relay lets the operator pass MFA challenges and harvest session material without the victim noticing.

Talos assesses with moderate confidence that the phishing UI was originally developed by a native Simplified Chinese speaker, based on localization architecture (the zh-CN base translation object, with zh-TW and en derived through an override function), mainland-Chinese terminology (e.g. 账号, 计算机, 邮箱, 无痕浏览窗口, 访客模式) and ternary-fallback ordering that defaults to Simplified Chinese. This assessment concerns the kit developer, not necessarily the operators; no named malware family, CVE or specific nation-state actor is reported. Motivation is not stated by the source; the targeting of policy and research staff and the focus on Google account takeover are consistent with credential theft but intent is unconfirmed.

Talos published IOCs at Cisco-Talos/IOCs (2026/10/uat-11985.txt) and detection coverage: ClamAV Html.Phishing.UAT11985-10060614-0, Snort 2 SID 1:67198 and Snort 3 SID 7:31. BeaconBeagle returned no matches for the phishing domain checked (morelessty.com).

## MITRE ATT&CK

- T1566.002 Phishing: Spearphishing Link
- T1204.001 User Execution: Malicious Link
- T1557 Adversary-in-the-Middle
- T1111 Multi-Factor Authentication Interception
- T1539 Steal Web Session Cookie
- T1684.001 Impersonation
- T1027 Obfuscated Files or Information
- T1071.001 Application Layer Protocol: Web Protocols
- T1583.001 Acquire Infrastructure: Domains

## Sources

- [UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing](https://blog.talosintelligence.com/uat-11985/)
- [Cisco Talos IOCs: uat-11985.txt](https://github.com/Cisco-Talos/IOCs/blob/main/2026/10/uat-11985.txt)
- [MITRE ATT&CK T1557 Adversary-in-the-Middle](https://attack.mitre.org/techniques/T1557/)
- [MITRE ATT&CK T1111 Multi-Factor Authentication Interception](https://attack.mitre.org/techniques/T1111/)
- [MITRE ATT&CK T1566.002 Phishing: Spearphishing Link](https://attack.mitre.org/techniques/T1566/002/)
- [MITRE ATT&CK T1539 Steal Web Session Cookie](https://attack.mitre.org/techniques/T1539/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3205
