Phishing Evolution: Trusted Channels, AiTM, Voice Cloning, and AI-Brand Lures
UAT-11985 reportedly uses AI-assisted personalized event lures, institutional impersonation, shortened redirects, malicious QR codes, and AiTM infrastructure targeting Google credentials. GhostCode token theft, fake-CAPTCHA/ClickFix chains, self-spoofing DMARC, synthetic verification, support scams, and RMM delivery show that familiar channels and conventional MFA remain unreliable without independent verification.
Sources (25)
Updated Oct 10, 2026