Technadu AI-Assisted Phishing Targets Taiwan Research Institutions
Article Content
- •APT campaign targets Taiwan research organizations using AI-assisted phishing.
- •Phishing emails impersonated legitimate institutions and employed QR code phishing techniques.
- •Adversary-in-the-middle framework intercepted Google credentials and MFA challenges.
An advanced persistent threat (APT) spear-phishing campaign has been identified targeting individuals affiliated with Taiwan research organizations. The campaign utilized AI-assisted content generation to create highly personalized phishing emails that impersonated reputable academic and policy institutions. Attack methods included traditional email phishing and QR code phishing (quishing), where malicious QR codes were embedded in legitimate event posters. The phishing framework employed an adversary-in-the-middle (AitM) technique, allowing real-time interception of Google credentials and multi-factor authentication (MFA) challenges. Cisco Talos reported that the emails exhibited nearly identical structures, suggesting the use of a reusable prompt template for content generation. None of the impersonated institutions could confirm the legitimacy of the senders, indicating that the identities were fabricated. The campaign highlights a significant threat to Taiwan's research community, with potential implications for sensitive information security.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Amatera and NCCU Institute Of International Relations in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Who is affected by this campaign?
What methods are used in the phishing attacks?
How can organizations protect themselves?
Continue Reading
Cisco Talos Reports ClickFix Attacks Targeting Cryptocurrency Traders Cisco Talos has identified two ClickFix attack campaigns that exploit trusted services to deceive victims into executing malicious code. The first campaign, active since October 2025, targets cryptocurrency traders with fake security reports, leading them to paste JavaScript into their browsers, which then retrieves…
Warden Stealer Malware Targets AI Agents for Data Theft Warden Stealer, a sophisticated malware-as-a-service, is actively targeting AI agents like Claude, Codex, Grok, and Cursor to steal sensitive developer data. This Rust-based infostealer collects configuration files, tokens, and conversation histories, posing a significant threat to organizations using AI tools. The…