Security1 publisherNot yet confirmed elsewhere2 min readPublished
Templated event invites and doctored posters lure Taiwan researchers into a live Google login relay
Cisco Talos says UAT-11985 used fake event invitations to phish Taiwanese research staff through a kit that relays Google logins and MFA challenges live. For the people those invitations target, the useful control is a second factor the relay cannot pass along.
The Watch · Security desk

What happened
- A recipient checked with the institutions named in the invitations, and none could confirm that any of the three senders worked for them.
- The emails showed a harmless-looking URL while the hyperlink underneath pointed to infrastructure the actor controlled.
- The actor also altered legitimate event posters with malicious QR codes, reaching people who see the printed material without ever receiving an email.
- Invitations on different geopolitical topics shared nearly identical sentence structure; Talos says that points to a reusable prompt template.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint A code or push approval completed on the relayed page travels with the password, so code-based MFA does not close this path for targeted staff.
- exposure Anyone who scans a doctored poster becomes a target without appearing in mail logs, so email filtering and phishing reports cannot see that part of the campaign.
- decision Institutes have to choose which staff move to phishing-resistant sign-in first, and the lures were tailored from public professional profiles, so staff with visible expert profiles are the obvious first group.
- precedent A templated lure and a kit already built in English can be pointed at other policy audiences under new event names at little extra cost to the operator.
The fake page stays in step with Google's real sign-in. According to Talos, the kit pairs HTTP with WebSocket connections to synchronize the authentication workflow in real time [4]. That live sync lets the operator intercept the credentials and the MFA challenge together [4]. The write-up describes the MFA interception in general terms and does not break it down by factor type [4].
The victim types a one-time code or taps a push approval while looking at the relayed page. Either one goes to the operator along with the password [16]. In my view, the people these invitations were written for need a second factor that cannot be completed through a relayed page [16].
The invitations used the names of the Taiwan European Union Centre, the NCCU Institute of International Relations and the Taiwan Research Institute [7]. Each one had three parts: geopolitical context, flattery aimed at the recipient, then logistics with topic, date, venue and registration instructions [11]. Talos noted that the context sections leaned on phrases such as "reshaping the great-power order" and "high intensity professional dialogue" [14]. The flattery offered reserved VIP seating and exclusive participation. It said little that could be checked about the recipient's actual work [12].
Talos stops short on authorship. It says it cannot conclusively determine whether a large language model wrote the emails outright, but calls the evidence of AI-assisted production and personalization strong [10].
Talos tracks the operator as UAT-11985 and calls the activity APT spear-phishing [3][1]. The language evidence is about the kit's author. With moderate confidence, Talos assesses that the interface was first built in Simplified Chinese and later adapted for Traditional Chinese and English [13]. It cites the localization architecture, a Simplified Chinese default language branch and mainland-Chinese word choices, and says these suggest a developer whose primary working language is Simplified Chinese [13]. Talos observed the campaign in mid-2026 [2].
What to watch
- Any Talos or Google disclosure of compromised accounts, or of which second-factor types the UAT-11985 relay defeated.
- The kit's English build showing up against research or policy targets outside Taiwan.
- Warnings from the Taiwan European Union Centre, NCCU Institute of International Relations or Taiwan Research Institute about invitations sent in their names.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Cisco Talos identified an advanced persistent threat (APT) spear-phishing campaign against individuals affiliated with Taiwan research organizations, using legitimate public event themes and impersonating reputable academic and policy institutions.
- [2]
Talos observed the APT spear-phishing campaign targeting Taiwan-based research organizations in mid-2026.
- [4]
The campaign deployed an adversary-in-the-middle phishing framework that impersonated Google authentication pages and used a hybrid HTTP and WebSocket architecture to synchronize authentication workflows in real time, enabling the interception of credentials and multi-factor authentication (MFA) challenges.
- [5]
The emails embedded a hyperlink to actor-controlled infrastructure while the displayed URL appeared benign.
- [6]
The actor modified legitimate event posters with malicious QR codes, expanding the attack surface beyond email recipients to secondary victims who may encounter printed materials.
- [7]
The threat actor impersonated legitimate Taiwanese institutions including the Taiwan European Union Centre, the NCCU Institute of International Relations and the Taiwan Research Institute.
- [8]
An email recipient contacted the organizations concerned; none could confirm that the three senders were employees or representatives, suggesting the actor fabricated sender identities while using legitimate organizational names and public event information as cover.
- [9]
Several invitation emails exhibited nearly identical syntactic structures despite discussing different geopolitical topics, suggesting the content was generated from a reusable prompt template.
- [10]
Talos cannot conclusively determine whether the emails were fully generated by a large language model, but says the campaign demonstrates strong evidence of AI-assisted content production and personalization.
- [11]
All three emails followed a three-part structure: an opening on geopolitical or policy context, a section customized for the recipient using targeted flattery, and a final section with event logistics including topic, date, venue and registration instructions.
- [12]
The compliments were broadly applicable and contained few verifiable details about the recipient's actual work, suggesting the actor personalized a reusable template using publicly available professional information; references to exclusive participation, reserved VIP seating or the recipient's supposedly unique expertise exploited professional recognition to reduce suspicion.
- [13]
Talos assesses with moderate confidence that the phishing kit's user interface was originally developed in Simplified Chinese and later adapted for Traditional Chinese and English; the localization architecture, Simplified Chinese default language branch and mainland-Chinese lexical usage suggest a developer whose primary working language is Simplified Chinese.
- [14]
The opening sections relied on expressions such as "reshaping the great-power order" and "high intensity professional dialogue".
- [15]
Both halves of the operation were built for reuse: the lure text came from a reusable template across topics, and the kit was localized into three languages including English.
- [16]
Because the kit synchronizes the Google sign-in in real time and intercepts MFA challenges, a second factor the victim completes on the relayed page, such as a typed one-time code or a push approval, is passed to the operator with the password; the relevant control for targeted staff is a factor that cannot be completed through a relayed page.
Sources
1 independent publisher whose own reporting we read for this story.
- blog.talosintelligence.comUAT-11985: AI-assisted event lures delivering real-time Google AitM phishing
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.