APT Targets Taiwan with AI-Powered Phishing

APT Uses AI and QR Codes in Phishing Attack on Taiwan Researchers

HIGH
October 8, 2026
6m read
PhishingThreat ActorData Breach

Related Entities

Organizations

Products & Tech

Other

Taiwan European Union CentreNCCU Institute of International RelationsTaiwan Research Institute

Full Report

Executive Summary

Cisco Talos has uncovered a sophisticated spear-phishing campaign by an unidentified Advanced Persistent Threat (APT) actor targeting research organizations in Taiwan. The operation, observed in mid-2026, combines several advanced techniques, including the suspected use of Artificial Intelligence (AI) to generate highly convincing email lures, QR code phishing (quishing) to expand the attack surface, and an adversary-in-the-middle (AitM) phishing framework to defeat multi-factor authentication (MFA). The campaign impersonates legitimate academic and policy institutions to gain the trust of targets. The primary goal is to steal credentials and session cookies by intercepting the authentication process in real-time, granting the attackers persistent access to victim accounts.

Threat Overview

The campaign's lures are themed around legitimate public events and geopolitical topics relevant to the targets. The attackers impersonate reputable institutions such as the Taiwan European Union Centre and the NCCU Institute of International Relations. The phishing emails exhibit a consistent three-part structure and sophisticated rhetoric, leading researchers to assess that the content is generated using an AI model with a reusable prompt template. This allows the threat actor to rapidly produce personalized and credible lures at scale.

The attack is not limited to email. The actor has embedded malicious QR codes into legitimate-looking event posters. When scanned, these QR codes direct victims to the same malicious infrastructure, a technique known as quishing. This hybrid approach allows the campaign to bridge the digital and physical worlds, reaching victims who may not have received the initial email.

The core of the operation is an advanced adversary-in-the-middle (AitM) phishing kit that proxies the legitimate Google authentication flow. When a victim clicks the phishing link or scans the QR code, they are taken to a convincing replica of a Google login page. The AitM framework uses a combination of HTTP and WebSockets to pass the victim's credentials and MFA token (e.g., from an authenticator app) to the real Google service, while simultaneously capturing them for the attacker. This allows the attacker to hijack the authenticated session.

Technical Analysis

  • AI-Generated Lures: The syntactic and structural consistency of the phishing emails across different campaigns and topics strongly suggests the use of a large language model (LLM) for content creation. This represents an evolution in phishing tactics, making lures harder to detect based on common grammatical errors or awkward phrasing.
  • QR Code Phishing (Quishing): By embedding QR codes in posters, the attackers bypass traditional email security gateways. Mobile devices that scan the code are taken directly to the malicious site, often in a browser with fewer security controls than a corporate desktop.
  • AitM Phishing Framework: The framework acts as a reverse proxy between the victim and the legitimate service (Google). Its hybrid HTTP/WebSocket architecture allows for real-time, interactive session hijacking. The WebSocket connection likely maintains a persistent channel to the attacker's server, enabling the immediate relay of stolen credentials and MFA tokens as the victim enters them.
  • Linguistic Analysis: Cisco Talos's analysis of the phishing kit suggests its user interface was originally developed in Simplified Chinese and later adapted for Traditional Chinese and English, providing a clue to the potential origin of the threat actor.

MITRE ATT&CK Techniques

Impact Assessment

A successful attack would grant the APT actor full access to the victim's Google account, including email, documents, and any other connected services. For individuals at research and policy organizations, this could lead to the theft of sensitive, pre-publication research, confidential government communications, and personal information. The stolen access could be used for further intelligence gathering, to launch subsequent attacks against the victim's contacts, or to maintain long-term persistence within the target organization's network. The use of AI to craft lures and AitM to bypass MFA makes this campaign particularly dangerous and effective against even security-conscious users.

IOCs — Directly from Articles

No specific indicators of compromise were provided in the source articles.

Cyber Observables — Hunting Hints

Security teams can hunt for signs of AitM phishing activity with the following observables:

Type
URL Pattern
Value
Look for URLs that use subdomains to impersonate a brand (e.g., google.login.example.com).
Description
AitM kits often use deceptive domain names to trick users.
Type
Certificate Subject
Value
Mismatched or generic certificate subjects for a login page.
Description
A legitimate Google login page will have a certificate issued to accounts.google.com. An AitM site will not.
Type
Network Traffic Pattern
Value
WebSocket connections initiated from a login page.
Description
While not always malicious, the use of WebSockets on a third-party login portal is suspicious and characteristic of some AitM kits.
Type
Log Source
Value
Web Proxy Logs
Description
Analyze logs for users visiting newly registered domains or domains with low reputation scores that are hosting login pages.

Detection & Response

Detection:

  1. URL Analysis: Deploy email security solutions that can analyze URLs for signs of impersonation and check them against threat intelligence feeds. (D3FEND: D3-UA: URL Analysis)
  2. Web Filtering: Block access to newly registered domains and domains categorized as phishing. This can prevent users from reaching the AitM landing page.
  3. Login Anomaly Detection: Monitor for impossible travel scenarios, logins from unusual locations or ASNs, and session creations that do not align with the user's typical behavior. (D3FEND: D3-UGLPA: User Geolocation Logon Pattern Analysis)

Response:

  1. Session Revocation: If a compromise is suspected, immediately revoke all active sessions for the user's account.
  2. Password Reset: Force a password reset for the compromised account.
  3. Account Audit: Review the user's account for any unauthorized activity, such as new email forwarding rules, OAuth application grants, or data access.

Mitigation

  • Phishing-Resistant MFA: The most effective mitigation against AitM attacks is to implement phishing-resistant MFA, such as FIDO2/WebAuthn security keys. These methods bind the authentication to the origin, preventing credentials from being relayed to a malicious site. (D3FEND: D3-MFA: Multi-factor Authentication)
  • User Training: Educate users about the threat of AitM phishing and QR code attacks. Train them to verify the URL in the address bar before entering credentials and to be suspicious of unsolicited QR codes. (M1017: User Training)
  • Mobile Device Management (MDM): Use MDM solutions to enforce web filtering and threat protection on mobile devices, which are often the target of quishing attacks.

Timeline of Events

1
October 8, 2026
This article was published

MITRE ATT&CK Mitigations

Deploy phishing-resistant MFA, such as FIDO2/WebAuthn, which is not vulnerable to AitM relay attacks.

Educate users to identify phishing lures, especially those involving QR codes and unexpected login prompts, and to verify URLs before entering credentials.

Use web filters to block access to known phishing sites and newly registered domains that are often used in these campaigns.

Sources & References

UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing
Cisco Talos (talosintelligence.com) •October 8, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

aptphishingquishingaimfaaitmtaiwancisco talos

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.