Phishing attacks and the misuse of remote monitoring and management (RMM) tools were the most significant cyber threats observed in Q2 2026, according to Cisco Talos. Phishing remained the dominant initial access vector, now featuring in over half of all Talos Incident Response (IR) engagements. Attackers refined their methods, leveraging QR code PDFs, trusted cloud infrastructure, and advanced tactics to defeat multi-factor authentication (MFA). This quarter also saw a notable rise in ransomware operations that weaponise legitimate RMM tools, posing new challenges for defenders and businesses alike.
Phishing Surges as the Leading Initial Access Vector
Phishing was the primary entry point for attackers in Q2 2026, appearing in more than 50 percent of Talos IR cases, a sharp increase from roughly a third in the previous quarter. Attackers enhanced delivery mechanisms to bypass standard email defences. Notably, campaigns embedded malicious QR codes within PDF attachments, enabling them to sneak past traditional email security gateways. These QR codes often directed victims to credential harvesting sites hosted on legitimate cloud services, further complicating detection for security teams.
Authentication abuse was another major trend. In 65 percent of engagements, attackers targeted or circumvented MFA systems, compared to 35 percent last quarter. The most common techniques included:
- Adversary-in-the-middle (AitM) phishing proxies that intercept MFA tokens
- Session token theft, allowing persistent access after initial compromise
- MFA fatigue attacks, bombarding users with authentication prompts until they approve a malicious login
- Exploitation of self-enrolled devices to gain unauthorised access
These methods show an ongoing evolution in phishing tactics, highlighting the need for phishing-resistant MFA and vigilant monitoring of authentication anomalies.
QR Code Phishing Targets Australian Organisations Using Microsoft 365
One of the most impactful campaigns observed began in April 2026 and specifically targeted Australian organisations. This persistent phishing operation uses compromised Microsoft 365 accounts to harvest credentials and propagate further attacks. Attackers distributed auto-generated PDF documents tailored with QR codes, each leading to adversary-controlled login pages mimicking Microsoft 365.
Upon successful credential capture, the attackers:
- Accessed victims’ Microsoft accounts
- Created inbox rules to hide or reroute emails, evading detection
- Leveraged SharePoint to stage and distribute malicious documents
- Sent further phishing emails internally and externally, using compromised contact lists
This campaign remains active as of late June 2026. The threat actor, dubbed UAT-11764 by Talos, is expected to continue exploiting compromised mailboxes to scale their reach. By weaponising trusted platforms like SharePoint and Microsoft 365, the attackers successfully bypassed many standard security measures, relying on the inherent trust users and organisations place in these platforms.
Defenders are urged to:
- Block or flag emails with QR code PDF attachments
- Enforce phishing-resistant MFA on all Microsoft 365 accounts
- Monitor for suspicious inbox rule creation and unusual SharePoint activity
Weaponised RMM Tools Drive Ransomware Operations
Ransomware incidents accounted for over 20 percent of Talos IR engagements this quarter, consistent with previous periods. However, a growing trend is the use of legitimate RMM tools such as trojanised MeshAgent binaries and Zoho Assist for stealthy access. Attackers increasingly rely on these tools to maintain persistence and evade endpoint detection, mimicking routine IT operations to avoid suspicion.
Talos responded to incidents involving established ransomware variants like Nitrogen and Warlock, as well as debuting the Sinobi ransomware in their engagements for the first time. In many cases, these ransomware operators utilised the same phishing and authentication abuse techniques discussed earlier to establish initial access, followed by RMM tools for lateral movement and payload delivery.
- Trojanised MeshAgent and Zoho Assist enabled attackers to control endpoints remotely
- RMM activity blended in with legitimate IT support operations, delaying detection
- Behaviour-based monitoring and stringent controls over administrative binaries were recommended as countermeasures
Phishing-as-a-Service Platforms Expand Attack Capabilities
Another significant Q2 2026 finding was the exposure of the ARToken phishing-as-a-service (PhaaS) platform. Closely linked to EvilTokens, ARToken provides over 80 API endpoints for activities such as device code phishing, primary refresh token persistence, business email compromise (BEC), and SharePoint exfiltration. The platform’s React-based dashboard allows operators to automate and scale attacks, impersonate trusted vendors, and abuse OAuth device authorisation flows to bypass MFA protections.
This industrialisation of phishing, where sophisticated toolkits lower the barrier for attackers, has accelerated the volume and sophistication of Microsoft 365 account compromises. By leveraging legitimate Microsoft services and APIs, attackers evade detection and prolong unauthorised access, often leading to data theft and further internal compromise.
Why This Matters and Immediate Steps for Organisations
The Q2 2026 findings show a clear trajectory: phishing, MFA bypass, and weaponised RMM tools are converging to create more resilient and harder-to-detect attack chains. The focus on trusted platforms like Microsoft 365, combined with phishing lures like QR-in-PDFs, requires immediate attention from organisations.
- Review and restrict the use of RMM tools, monitoring for unauthorised binaries
- Deploy advanced phishing protections, including detection of QR codes in attachments
- Enforce phishing-resistant MFA and continuously monitor for abnormal authentication and SharePoint activity
Responding quickly to these evolving attack chains, with controls specific to the observed methods, reduces the risk of compromise and operational disruption.
Originally reported by blog.talosintelligence.com.





