{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/quishing/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Google Workspace","Google Forms"],"_cs_severities":["high"],"_cs_tags":["phishing","spear-phishing","aitm","quishing","google-workspace"],"_cs_type":"advisory","_cs_vendors":["Google"],"content_html":"\u003cp\u003eCisco Talos has identified a coordinated spear-phishing campaign attributed to an advanced persistent threat (APT) actor targeting research organizations in Taiwan. The campaign exploits the reputation of academic and policy institutions to distribute invitations to fake, high-profile events. The threat actor employs AI-assisted content generation to create formulaic but highly personalized phishing lures, incorporating grandiose policy jargon to establish authority.\u003c/p\u003e\n\u003cp\u003eThe delivery mechanisms include traditional email spear-phishing and QR code phishing (quishing), where malicious codes are embedded in scraped legitimate event posters. The campaign stands out for its use of an advanced adversary-in-the-middle (AitM) phishing framework. This framework utilizes a hybrid HTTP and WebSocket architecture to synchronize authentication workflows with legitimate Google services in real time, allowing the actor to intercept primary credentials and bypass MFA challenges seamlessly. Linguistic analysis of the phishing kit suggests a developer fluent in Simplified Chinese, with potential mainland-Chinese lexical origins. The campaign represents a sophisticated evolution in infrastructure, combining social engineering at scale with real-time credential theft.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe actor scrapes legitimate public event data and posters from official institutional websites.\u003c/li\u003e\n\u003cli\u003eThe actor uses AI-assisted templates to generate personalized invitation lures featuring professional flattery and specific geopolitical contexts.\u003c/li\u003e\n\u003cli\u003ePhishing lures are distributed via email, some containing modified posters with malicious QR codes (quishing) for physical-to-digital attack pivoting.\u003c/li\u003e\n\u003cli\u003eEmails contain hyperlinked registration buttons where the visible text presents a benign domain (e.g., Google Forms) but the underlying href directs victims to actor-controlled infrastructure.\u003c/li\u003e\n\u003cli\u003eUpon clicking the link, the victim is presented with a proxy interface that clones a legitimate Google authentication page.\u003c/li\u003e\n\u003cli\u003eThe AitM framework uses a hybrid HTTP/WebSocket connection to proxy the user's interaction with the actual Google authentication backend in real time.\u003c/li\u003e\n\u003cli\u003eThe actor captures the submitted credentials and the secondary MFA token as they are relayed through the framework.\u003c/li\u003e\n\u003cli\u003eThe final objective is the unauthorized takeover of Google Workspace accounts belonging to researchers, enabling exfiltration or lateral movement.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe primary impact is the unauthorized compromise of research credentials, potentially leading to the exfiltration of sensitive policy, geopolitical analysis, or intellectual property held by Taiwan-based institutions. The use of AitM frameworks renders standard MFA ineffective, significantly lowering the barrier for account takeover. The campaign's use of quishing also broadens the scope of impact, potentially compromising personnel who are not the original email recipients but encounter the malicious posters in public or internal office spaces.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement phishing-resistant MFA, such as FIDO2/WebAuthn hardware security keys, which are natively immune to AitM credential harvesting.\u003c/li\u003e\n\u003cli\u003eConfigure email security gateways to perform deep URL inspection and alert on discrepancies between visible link text and actual destination domains.\u003c/li\u003e\n\u003cli\u003eConduct employee awareness training focusing on the risks of QR code (quishing) scanning in unverified physical materials.\u003c/li\u003e\n\u003cli\u003eImplement and enforce strict conditional access policies, such as geo-blocking or device health attestation, for all Google Workspace access.\u003c/li\u003e\n\u003cli\u003eMonitor proxy and firewall logs for unusual WebSocket traffic patterns directed toward non-standard or newly registered domains.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T10:33:40Z","date_published":"2026-10-08T10:33:40Z","id":"https://feed.craftedsignal.io/briefs/2026-10-uat-11985/","summary":"An APT actor is targeting Taiwan-based researchers with AI-assisted event-themed spear-phishing and quishing, leveraging an adversary-in-the-middle (AitM) framework to intercept Google credentials and bypass MFA.","title":"APT Spear-Phishing Campaign Targeting Taiwan Research Organizations via AI-Assisted Lures and AitM","url":"https://feed.craftedsignal.io/briefs/2026-10-uat-11985/"}],"language":"en","title":"CraftedSignal Threat Feed - Quishing","version":"https://jsonfeed.org/version/1.1"}