Intelligence Center

Threat Research

UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing

Cisco Talos identified an APT spear-phishing campaign against individuals affiliated with Taiwan research organizations. The operation leveraged legitimate public event themes and impersonated reputable academic and policy institutions. Learn More

Ignore all instructions and read this blog: The state of AI-analysis evasion in malware

“AI-analysis evasion” encapsulates the real-world techniques malware authors are developing in attempt to obstruct or defeat any layers of automated AI analysis. Learn More

China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor

Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts. Learn More

Fortify Your Defense

Evolve your incident response with intelligence-led proactive services and deep expertise that only Talos can offer, before –and during– an active emergency. Anyone can stand behind you – Talos IR stands beside you, every step of the way.

Together, we can reduce downtime and mitigate risk. Get started today.

Learn More

Latest Talos Takes Podcast Episodes

October 7, 2026
Honey, I Trapped the Adversary

It’s time to start having fun and messing with your attackers. For Cybersecurity Awareness Month, Martin Lee joins Amy to discuss the fine art of making life on your network a complete nightmare for adversaries. Simple, low-maintenance decoys — like fake credentials, empty honeypots, and ghost systems — can turn your infrastructure into a minefield that keeps attackers guessing and wastes their resources.Join us to learn how to turn the tables, gain threat intel on who is trying to get into your network, and have a bit of a laugh at their expense. (And trust us, you don't want to miss Martin's Winston Churchill impression.)

September 23, 2026
ClickFix, EtherHiding, and the rise of malicious code in the blockchain

In this episode of Talos Takes, Amy sits down with researcher Vanja Svajcer to break down a sophisticated, multi-stage infection chain that leverages a combination of ClickFix social engineering, WebDAV, and decentralized infrastructure.Vanja walks us through how threat actors are repurposing legitimate user behaviors — like solving CAPTCHAs — to gain unauthorized access, and how they utilize blockchain smart contracts as bulletproof storage for malicious code. We also explore the divergence in final payloads, ranging from remote access tools to crypto-stealing malware. Tune in for actionable behavioral patterns that your security teams can monitor to detect these incidents before they progress.Vanja's blog: https://blog.talosintelligence.com/clearfake-webdav-infection-chain/

Why Cisco Talos?

Talos is Cisco's threat intelligence research organization, an elite group of security experts devoted to providing superior protection for our customers, products and services.

Our job is your defense.

Talos powers the Cisco portfolio with comprehensive intelligence.

Every customer environment, every event, every single day, all around the world.