WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH

UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing

Padlock on the floor of a server room beside cabled switchesAI illustration
WORLDTECH illustration · AI-generated (Canva)Google logo shown for identification only; no affiliation with or endorsement of WORLDTECH is implied.

What happened

Cisco Talos identified an APT spear-phishing (messages that impersonate someone to obtain passwords or money) campaign against individuals affiliated with Taiwan research organizations. UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing By Joey Chen Thursday, October 8, 2026 06:01 Threat Spotlight AI APT Cisco Talos identified an advanced persistent threat (APT) spear-phishing campaign against individuals affiliated with Taiwan research organizations. Google is an Internet and software company based in Mountain View.

The operation leveraged legitimate public event themes and impersonated reputable academic and policy institutions. The phishing emails exhibited highly consistent structure, rhetoric, and personalization patterns, suggesting the threat actor likely used AI-assisted content generation to rapidly customize invitation lures for different targets while maintaining a common social engineering framework.

The operation leveraged legitimate public event themes and impersonated reputable academic and policy institutions to establish credibility. Beyond traditional email phishing, the actor incorporated QR code phishing (quishing) techniques by modifying legitimate event posters with malicious QR codes, expanding the attack surface beyond email recipients to secondary victims who may encounter printed materials.

Sources & evidence