Cisco Talos has uncovered a sophisticated spear-phishing campaign by an unidentified Advanced Persistent Threat (APT) actor targeting research organizations in Taiwan. The operation, observed in mid-2026, combines several advanced techniques, including the suspected use of Artificial Intelligence (AI) to generate highly convincing email lures, QR code phishing (quishing) to expand the attack surface, and an adversary-in-the-middle (AitM) phishing framework to defeat multi-factor authentication (MFA). The campaign impersonates legitimate academic and policy institutions to gain the trust of targets. The primary goal is to steal credentials and session cookies by intercepting the authentication process in real-time, granting the attackers persistent access to victim accounts.
The campaign's lures are themed around legitimate public events and geopolitical topics relevant to the targets. The attackers impersonate reputable institutions such as the Taiwan European Union Centre and the NCCU Institute of International Relations. The phishing emails exhibit a consistent three-part structure and sophisticated rhetoric, leading researchers to assess that the content is generated using an AI model with a reusable prompt template. This allows the threat actor to rapidly produce personalized and credible lures at scale.
The attack is not limited to email. The actor has embedded malicious QR codes into legitimate-looking event posters. When scanned, these QR codes direct victims to the same malicious infrastructure, a technique known as quishing. This hybrid approach allows the campaign to bridge the digital and physical worlds, reaching victims who may not have received the initial email.
The core of the operation is an advanced adversary-in-the-middle (AitM) phishing kit that proxies the legitimate Google authentication flow. When a victim clicks the phishing link or scans the QR code, they are taken to a convincing replica of a Google login page. The AitM framework uses a combination of HTTP and WebSockets to pass the victim's credentials and MFA token (e.g., from an authenticator app) to the real Google service, while simultaneously capturing them for the attacker. This allows the attacker to hijack the authenticated session.
T1566.002 - Spearphishing Link: The primary delivery mechanism is through links in targeted emails.T1598.003 - Spearphishing via Service: The use of QR codes on posters is a form of physical-world phishing that leads to a malicious service.T1111 - Two-Factor Authentication Interception: The AitM framework is designed specifically to intercept and bypass MFA.T1539 - Steal Web Session Cookie: After a successful AitM attack, the actor gains the victim's session cookie, allowing them to access the account without needing to re-authenticate.T1589.002 - Email Addresses: The attackers gather email addresses of individuals at specific research organizations to conduct their spear-phishing campaign.A successful attack would grant the APT actor full access to the victim's Google account, including email, documents, and any other connected services. For individuals at research and policy organizations, this could lead to the theft of sensitive, pre-publication research, confidential government communications, and personal information. The stolen access could be used for further intelligence gathering, to launch subsequent attacks against the victim's contacts, or to maintain long-term persistence within the target organization's network. The use of AI to craft lures and AitM to bypass MFA makes this campaign particularly dangerous and effective against even security-conscious users.
No specific indicators of compromise were provided in the source articles.
Security teams can hunt for signs of AitM phishing activity with the following observables:
google.login.example.com).accounts.google.com. An AitM site will not.Web Proxy LogsDetection:
D3-UA: URL Analysis)D3-UGLPA: User Geolocation Logon Pattern Analysis)Response:
D3-MFA: Multi-factor Authentication)Deploy phishing-resistant MFA, such as FIDO2/WebAuthn, which is not vulnerable to AitM relay attacks.
Educate users to identify phishing lures, especially those involving QR codes and unexpected login prompts, and to verify URLs before entering credentials.
Use web filters to block access to known phishing sites and newly registered domains that are often used in these campaigns.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.