Threat

UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing

Page published

Earliest dated coverage: 8 Oct 2026 · First observed: 8 Oct 2026 · Latest dated coverage: 8 Oct 2026

Coverage timeline

8 Oct 2026talosintelligence.comprimary

Single-source incident — one report is available.

Why it matters

UAT-11985 shows nation-state actors weaponizing LLM-style content generation to scale convincing, personalized phishing lures alongside real-time MFA-intercepting AitM infrastructure, raising the credibility and volume of targeted social-engineering attacks.

Cisco Talos documented UAT-11985, an APT spear-phishing campaign against Taiwan research organizations that used AI-assisted content generation to rapidly customize event-invitation lures, combined with QR-code phishing (quishing) and a real-time adversary-in-the-middle (AitM) framework impersonating Google authentication pages. The AitM kit used a hybrid HTTP/WebSocket architecture to synchronize authentication in real time and intercept credentials and MFA challenges.