Cisco Talos’ UAT-11985 reporting is a useful warning because it connects three trends defenders are already seeing separately: AI-assisted social engineering, QR-code phishing, and real-time adversary-in-the-middle authentication theft. The campaign was not a broad spray-and-pray operation. It targeted people affiliated with Taiwan research organizations using polished event invitations that looked institutionally credible.

Cisco Talos reported that the actor reused legitimate public event themes, impersonated academic and policy organizations, and paired credible-looking invitation language with hidden malicious links. Talos also found modified event posters where the QR code had been swapped for a phishing destination, turning an ordinary poster into a second-stage credential-harvesting lure.

What Talos found

The lure content was highly consistent across different emails: polished geopolitical framing, recipient-specific flattery, and event logistics copied or adapted from legitimate public sources. Talos assessed that the writing patterns strongly suggest AI-assisted content generation, even though the use of a large language model cannot be proven from language alone.

The registration flow then moved victims into a phishing kit that impersonated Google authentication. Instead of simply collecting a password and stopping there, the kit used a real-time adversary-in-the-middle model. The victim saw a convincing sign-in experience while the operator-controlled infrastructure relayed authentication steps and synchronized the fake page with the real login process.

Talos’ technical analysis described a split communications design: HTTP POST requests carried victim-submitted data and browser details, while a WebSocket channel allowed the attacker to push real-time state changes back to the phishing page. That architecture lets the phishing page dynamically present the next prompt, including additional authentication challenges, without looking static or obviously broken.

Talos also assessed with moderate confidence that the phishing kit’s interface was originally authored in Simplified Chinese and later adapted for Traditional Chinese and English. The targeting, localization, and event themes make this campaign especially relevant to research, policy, government, nonprofit, and contractor environments working around China, Taiwan, defense, academia, or international affairs.

Why this matters

For SMBs and government contractors, the practical issue is not whether an email was written by AI. The issue is that AI makes targeted lures easier to scale while maintaining just enough polish, personalization, and institutional tone to pass casual inspection.

That matters because modern phishing is no longer limited to a fake login page asking for a password. Real-time AitM kits can walk a victim through multi-factor prompts, capture session material, and adapt the displayed flow based on the legitimate provider’s response. If defenders only train users to look for typos or low-quality graphics, they will miss the campaigns that are intentionally built around credibility.

The QR-code angle also deserves attention. A malicious QR code in a poster or PDF bypasses some of the normal email security surface. It can move the victim from a managed workstation to a personal phone, where browser isolation, endpoint logging, and phishing controls may be weaker. If the poster gets printed or forwarded internally, the attack becomes a lightweight physical-world propagation path.

Defensive takeaways

  • Treat event invitations as an identity risk. Research, policy, defense, legal, and government-contracting teams should verify unexpected invitations through known organizational channels, not through links in the invitation.
  • Inspect the real destination, not the visible text. Train staff and tune mail controls to look for mismatches between displayed URLs and underlying links, especially when the visible destination appears to be a common form or identity provider.
  • Do not exempt QR codes from review. Block or rewrite QR codes where possible, inspect attached posters and PDFs, and discourage scanning work-related codes with unmanaged personal devices.
  • Prioritize phishing-resistant MFA. Passkeys and hardware-backed FIDO2 reduce the value of credentials captured by AitM kits compared with push approvals, OTPs, or SMS codes.
  • Monitor for impossible or suspicious session behavior. Watch for new device fingerprints, unfamiliar geographies, suspicious OAuth grants, rapid session reuse, and login flows that begin immediately after a user clicks an invitation link.
  • Protect high-risk personas differently. Researchers, executives, proposal teams, legal staff, and anyone working around defense or foreign policy should have stricter identity controls and clearer verification paths.
  • Use network and detection coverage where available. Talos published ClamAV and Snort coverage for this activity, and defenders should ingest the related indicators into email, proxy, DNS, and SIEM workflows.

What to do this week

Start with identity controls. Confirm that administrator, executive, finance, proposal, and research accounts have phishing-resistant MFA where possible. If that is not fully deployed, tighten conditional access around new devices, foreign travel, impossible travel, and risky sign-in properties.

Next, review how your organization handles event invitations. If staff frequently attend conferences, webinars, policy briefings, or vendor events, create a simple verification habit: search for the event independently, use the organizer’s official site, and avoid scanning QR codes or clicking registration links from unsolicited messages.

Finally, test your logs. Pick a known training link or benign test registration page and confirm that your team can trace the click, destination, device, browser, identity event, MFA step, and resulting session. If those pieces live in separate consoles and nobody knows how to stitch them together, an AitM incident will be harder to contain quickly.

Bulwark Black assessment

UAT-11985 is not just another phishing-kit story. It shows how social engineering, AI-assisted writing, QR-code delivery, and real-time authentication relay are converging into a more operationally mature account-takeover workflow.

The defensive answer is not more generic awareness training. It is better identity architecture, stronger verification habits, phishing-resistant MFA, and telemetry that connects email clicks to authentication outcomes. The attacker is trying to make the login process feel normal. Defenders need enough visibility and friction to make that normal-looking process unsafe for the attacker.

Source: Cisco Talos — UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing.