<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Quishing - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/quishing/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 10:33:40 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/quishing/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>APT Spear-Phishing Campaign Targeting Taiwan Research Organizations via AI-Assisted Lures and AitM</title><link>https://feed.craftedsignal.io/briefs/2026-10-uat-11985/</link><pubDate>Thu, 08 Oct 2026 10:33:40 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-uat-11985/</guid><description>An APT actor is targeting Taiwan-based researchers with AI-assisted event-themed spear-phishing and quishing, leveraging an adversary-in-the-middle (AitM) framework to intercept Google credentials and bypass MFA.</description><content:encoded><![CDATA[<p>Cisco Talos has identified a coordinated spear-phishing campaign attributed to an advanced persistent threat (APT) actor targeting research organizations in Taiwan. The campaign exploits the reputation of academic and policy institutions to distribute invitations to fake, high-profile events. The threat actor employs AI-assisted content generation to create formulaic but highly personalized phishing lures, incorporating grandiose policy jargon to establish authority.</p>
<p>The delivery mechanisms include traditional email spear-phishing and QR code phishing (quishing), where malicious codes are embedded in scraped legitimate event posters. The campaign stands out for its use of an advanced adversary-in-the-middle (AitM) phishing framework. This framework utilizes a hybrid HTTP and WebSocket architecture to synchronize authentication workflows with legitimate Google services in real time, allowing the actor to intercept primary credentials and bypass MFA challenges seamlessly. Linguistic analysis of the phishing kit suggests a developer fluent in Simplified Chinese, with potential mainland-Chinese lexical origins. The campaign represents a sophisticated evolution in infrastructure, combining social engineering at scale with real-time credential theft.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The actor scrapes legitimate public event data and posters from official institutional websites.</li>
<li>The actor uses AI-assisted templates to generate personalized invitation lures featuring professional flattery and specific geopolitical contexts.</li>
<li>Phishing lures are distributed via email, some containing modified posters with malicious QR codes (quishing) for physical-to-digital attack pivoting.</li>
<li>Emails contain hyperlinked registration buttons where the visible text presents a benign domain (e.g., Google Forms) but the underlying href directs victims to actor-controlled infrastructure.</li>
<li>Upon clicking the link, the victim is presented with a proxy interface that clones a legitimate Google authentication page.</li>
<li>The AitM framework uses a hybrid HTTP/WebSocket connection to proxy the user's interaction with the actual Google authentication backend in real time.</li>
<li>The actor captures the submitted credentials and the secondary MFA token as they are relayed through the framework.</li>
<li>The final objective is the unauthorized takeover of Google Workspace accounts belonging to researchers, enabling exfiltration or lateral movement.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The primary impact is the unauthorized compromise of research credentials, potentially leading to the exfiltration of sensitive policy, geopolitical analysis, or intellectual property held by Taiwan-based institutions. The use of AitM frameworks renders standard MFA ineffective, significantly lowering the barrier for account takeover. The campaign's use of quishing also broadens the scope of impact, potentially compromising personnel who are not the original email recipients but encounter the malicious posters in public or internal office spaces.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Implement phishing-resistant MFA, such as FIDO2/WebAuthn hardware security keys, which are natively immune to AitM credential harvesting.</li>
<li>Configure email security gateways to perform deep URL inspection and alert on discrepancies between visible link text and actual destination domains.</li>
<li>Conduct employee awareness training focusing on the risks of QR code (quishing) scanning in unverified physical materials.</li>
<li>Implement and enforce strict conditional access policies, such as geo-blocking or device health attestation, for all Google Workspace access.</li>
<li>Monitor proxy and firewall logs for unusual WebSocket traffic patterns directed toward non-standard or newly registered domains.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>phishing</category><category>spear-phishing</category><category>aitm</category><category>quishing</category><category>google-workspace</category></item></channel></rss>