Cisco Talos Incident Response reported that phishing became the leading initial access vector in more than half of investigated incidents, with authentication abuse rising to 65% of cases. The firm highlighted an ongoing QR-code phishing campaign attributed to UAT-11764 that targeted mainly Australian organizations using compromised Microsoft 365 accounts, tailored PDF attachments, and SharePoint- or other trusted cloud-hosted credential harvesting pages. After stealing credentials, the attackers accessed victim inboxes, created inbox rules to evade detection, and used the compromised accounts to spread additional phishing internally and externally.
Talos also warned that phishing-as-a-service platforms such as ARToken are expanding attacker capabilities with device-code phishing, token abuse, OAuth device authorization flow abuse, persistent access via Primary Refresh Tokens, business email compromise, and SharePoint data exfiltration. In ransomware and pre-ransomware cases, including Sinobi and Warlock activity, operators maintained stealthy access by abusing legitimate remote management tools such as a trojanized MeshAgent binary and Zoho Assist. Healthcare was the most targeted sector, and Talos urged organizations to deploy phishing-resistant MFA, improve logging, patch exposed systems faster, and limit outbound email rates to reduce propagation.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
On July 28, 2026, Cisco Talos Incident Response published its Q2 2026 trends report covering incidents from March to June 2026. The report said phishing was the leading initial access vector in just over half of engagements, authentication abuse rose to 65 percent of cases, and ransomware/pre-ransomware made up over 20 percent of engagements.
Talos reported that the UAT-11764 QR-code phishing campaign was still ongoing as of late June 2026. After stealing credentials, the actor accessed victim inboxes, created inbox rules for evasion, and sent additional phishing messages from compromised accounts using trusted services such as SharePoint and Microsoft 365.
In an April engagement, Cisco Talos Incident Response observed Sinobi ransomware actors using a trojanized MeshAgent binary for command and control. The attackers maintained access for about three days, moved laterally via RDP and WinRM, staged exfiltration with rclone, and deployed ransomware domain-wide via a malicious Group Policy Object logon script.
Cisco Talos said a persistent QR-code phishing campaign began in April 2026, primarily targeting Australian organizations. The operation used compromised Microsoft 365 accounts and victim-tailored PDF attachments with QR codes leading to credential-harvesting pages.
During a Q2 2026 engagement, Talos uncovered the ARToken phishing-as-a-service platform and found it closely linked to EvilTokens. Talos said the platform exposed more than 80 API endpoints and supported device-code phishing, token abuse, business email compromise, SharePoint exfiltration, and other post-compromise functions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
blog.knowbe4.com
Open sourceinfosecurity-magazine.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.