Skip to content
Security & Trust

Fake invitations to Taiwan researchers relay Google logins live, Talos finds

Talos says the phishing kit passed each login step to the real Google, so MFA prompts reached the attacker too.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Fake invitations to Taiwan researchers relay Google logins live, Talos finds
In brief
  • Cisco Talos describes a campaign, tracked as UAT-11985, that targeted Taiwan-based research organizations with likely AI-assisted invitations and a phishing kit that relays Google logins in real time.
  • The kit passes each login step to the real Google, so multi-factor prompts can be intercepted. A polished, accurate-looking message does not prove the sender is real.
  • Staff should check unexpected senders outside the email. Security teams should review link checks, sign-in methods and QR-code awareness.

The invitation looked like it came from a known institute. It flattered the reader. It promised reserved VIP seating. The date and venue appeared to be copied from real public announcements. Yet the institution it named could not confirm the sender.

That is the picture in a new Cisco Talos report on a campaign it tracks as UAT-11985. The lesson here is simple. A convincing message no longer shows that anyone wrote it with care. Writing is cheap. The harder part to fake is the machinery behind the link.

What Talos saw

In mid-2026, Talos saw a spear-phishing campaign aimed at Taiwan-based research organizations. Spear-phishing means emails written for a small, chosen group. Talos labels the campaign an APT, a long-running targeted threat.

The senders used the names of three Taiwanese bodies. They were the Taiwan Research Institute, the NCCU Institute of International Relations and the Taiwan European Union Centre.

One recipient contacted those organizations to check the senders. None could confirm that the three senders were their staff or representatives. Talos concludes the actor invented the sender identities. The real names and public event details served as cover.

0 of 3
Impersonated institutions that could confirm the senders
Source: Cisco Talos (October 8, 2026)

The three emails shared one structure. First came a grand, vague view of world politics. Next came flattery aimed at the reader. Last came the event details and a registration link.

Talos says the flattery held few checkable facts about the reader's actual work. That suggests a reusable template.

Talos cannot say for certain that a large language model wrote the text. It does see strong evidence of AI-assisted writing. It says the actor likely used an AI-assisted template.

The accurate event details were part of the trick. Talos calls this "legitimacy laundering". True facts were used, but they do not prove the email is real.

How the trap works

Talos describes one link that showed a legitimate-looking Google Forms address. Its hidden destination was a phishing site on a third-party platform.

That site copied a Google Form. It then sent the victim to a fake Google sign-in page. The page offered Chinese (simplified and traditional) and English. It picked the language from the browser's settings.

The kit is an adversary-in-the-middle relay, or AitM. The attacker's server sits between the victim and the real Google. It does not just save the typed password. It uses the password at once, on the real Google.

To do this, the kit uses two channels. The first is HTTP POST. It sends one-off reports to the attacker. These include browser details, typed credentials and regular check-in signals.

The second is a WebSocket, which is a connection that stays open. Through it, the attacker's server tells the fake page which screen to show next.

The steps run like this. The victim types an email address or phone number. The attacker's server asks the real Google if the account exists. It also checks whether a passkey sign-in is turned on. It then tells the fake page to show a password screen or a passkey prompt.

Next, the victim types a password. The server forwards it to Google. Google may then ask for a second step. The server learns which step it is and has the fake page show the same one.

3 (zh-CN, zh-TW, en)
Languages the fake Google sign-in supports
Source: Cisco Talos (October 8, 2026)

Talos says this effectively bypasses multi-factor authentication (MFA). The attacker gets full, signed-in session tokens. A session token is the proof a site keeps that you are logged in.

It works because the victim completes the real checks. They simply do it through the attacker's window.

The report does not test whether passkeys resist this relay. It says only that the kit detects the passkey flow and shows a matching prompt.

From inbox to bulletin board

Some emails carried event posters. The designs were copied from real sites. The QR codes were changed.

Talos says the actor may have hoped staff would print the posters and pin them up. Then other people would scan the code. That would reach colleagues who never saw the email.

One more caveat. Talos assesses with moderate confidence that a native Simplified Chinese speaker first wrote the kit's interface. That describes the developer's working language. It does not say who is behind the campaign.

What leaders should ask

In this case, a recipient called the named organizations, and none could confirm the senders. Anyone can make that check outside the email. Do your staff know they may do the same for unexpected invitations? Who handles what they find?

Security teams should be able to answer three questions.

First, does your mail gateway flag links where the visible text differs from the real destination? Second, who holds sensitive research or policy access, and what sign-in method protects them? Third, does your training cover QR codes on printed posters and shared notice boards, not only email?

Talos lists ClamAV signatures and SNORT rules for this threat. It also points to indicators of compromise in its GitHub repository. Ask your team to confirm they are loaded.

Polished writing is now cheap to produce. The checks that still carry weight are the ones made outside the message.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Cisco Talos.

Share this insight