Skip to content
UAT-11985: AI-Assisted Phishing Targets Taiwan Researchers

UAT-11985: AI-Assisted Phishing Targets Taiwan Researchers

Technadu • October 9, 2026

Taiwan Researchers Targeted: UAT-11985 delivers a spear-phishing campaign against individuals affiliated with Taiwan research organizations in mid-2026.

AI-Assisted Lures: Phishing emails showed strong evidence of AI-assisted content generation from a reusable prompt template.

Google AitM Kit: A real-time adversary-in-the-middle (AitM) kit intercepted Google credentials and multi-factor authentication (MFA) challenges.

UAT-11985, an advanced persistent threat (APT), deploys a spear-phishing campaign aimed at Taiwan-based research organizations. The operation used legitimate public event themes and impersonated reputable academic and policy institutions to build credibility, but altered the embedded QR codes.

Fake Invitations Impersonated Taiwan Academic and Policy Institutions

The threat actor posed as the Taiwan European Union Center, the NCCU Institute of International Relations, and the Taiwan Research Institute, a Cisco Talos report said . None of these organizations could confirm that the purported senders were employees or representatives.

Registration links displayed legitimate-looking Google Forms URLs, but the underlying hrefs redirected recipients to phishing sites.

Reusable Prompt Template Suggests AI-Generated Emails

Several invitation emails shared nearly identical syntactic structures, even though they covered different geopolitical topics. Talos said this pattern suggests the content came from a reusable prompt template. The researchers could not conclusively determine whether an AI agent fully generated the emails.

Quishing: Altered QR Codes Hidden in Event Posters

The actor attached event posters scraped from legitimate websites and altered the embedded QR codes. This QR code phishing (quishing) technique widens the attack surface to secondary victims who may encounter printed materials.

Google AitM Kit Intercepts Credentials and MFA Challenges

The AitM phishing kit impersonated Google sign-in pages. It used HTTP POST for data exfiltration and WebSocket for real-time command-and-control (C2). This hybrid design let operators synchronize authentication workflows and intercept both credentials and MFA challenges.

Simplified Chinese Interface Points to Developer’s Primary Language

Talos assessed with moderate confidence that the kit’s interface was first developed in Simplified Chinese, then adapted for Traditional Chinese and English. Mainland-Chinese lexical usage suggests a developer whose primary working language is Simplified Chinese.

Detection Coverage: ClamAV and SNORT Signatures

Defenders can already detect and block this threat via ClamAV signature Html.Phishing.UAT11985-10060614-0 and SNORT rules SID 1:67198 (Snort2) and 7:31 (Snort3).

A July Malwarebytes report warned that fake Google and Cloudflare verification delivered StealC, Amatera, CastleLoader, and the new ResiLoader in ClickFix campaigns.

QR code phishing made up one in nine detected phishing emails in ESET's telemetry in the first half of 2026, with Microsoft ranking QR codes as the fastest-growing email-based attack vector.

In April, traffic violation scams in the US were seen adopting quishing tactics, and the FBI warned in January that a Kimsuky campaign targeted the U.S. with quishing. In 2024, a Cyble report said a quishing campaign targeted Chinese citizens via fake official documents .