UAT-11764 is a threat actor tracked for a persistent QR-code phishing operation focused on Microsoft 365 credential theft and follow-on mailbox abuse. The actor has been associated with campaigns that primarily targeted organizations in Australia and used victim-tailored PDF attachments containing QR codes that directed users to credential-harvesting pages impersonating Microsoft 365 login workflows. The operation relied on trusted cloud services and Microsoft-hosted infrastructure, including SharePoint and Microsoft 365, to reduce suspicion and bypass conventional email security controls. After obtaining credentials, UAT-11764 accessed victim mailboxes, created inbox rules to support defense evasion, and used compromised accounts to propagate additional phishing messages to internal and external contacts. This indicates a repeatable intrusion cycle centered on initial access through phishing, credential theft, post-compromise mailbox manipulation, and expansion through trusted business communications. The actor’s tradecraft emphasizes social engineering, abuse of legitimate cloud platforms, and stealthy use of compromised enterprise accounts rather than disruptive or destructive activity. UAT-11764 is currently known by this tracking name and is associated with credential-harvesting activity rather than ransomware or extortion operations. Its dominant objective is consistent with financially motivated phishing and account-compromise activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a persistent QR code phishing campaign against organizations to harvest Microsoft 365 credentials, evade email gateway detection, abuse trusted cloud platforms for credential harvesting, create inbox rules for defense evasion, and propagate further phishing from compromised accounts.
Conducting a persistent QR code phishing campaign primarily targeting Australian organizations, using compromised Microsoft 365 accounts, credential harvesting pages, inbox rule creation, SharePoint-hosted malicious documents, and internal/external phishing propagation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.