AI‑Assisted AitM Spear‑Phishing Targeting Taiwan
🛡️ Talos observed a mid‑2026 spear‑phishing campaign targeting Taiwan research institutions that used plausible event details and deceptive links. The emails used a reusable, formulaic template with personalized flattery and impersonated legitimate organizations while hiding actor‑controlled registration pages. Malicious posters included altered QR codes to expand the attack surface. The phishing kit replicated Google sign‑in pages across locales and used obfuscated JavaScript, HTTP POST exfiltration, and WebSocket C2 to perform real‑time AitM credential harvesting.
