Phishing and RMM Tools Shape Q2 2026 Cyber Attack Trends

Q2 2026 IR trends: phishing, MFA bypass and RMM abuse drive attacks

Phishing attacks and the misuse of remote monitoring and management (RMM) tools were the most significant cyber threats observed in Q2 2026, according to Cisco Talos. Phishing remained the dominant initial access vector, now featuring in over half of all Talos Incident Response (IR) engagements. Attackers refined their methods, leveraging QR code PDFs, trusted cloud infrastructure, and advanced tactics to defeat multi-factor authentication (MFA). This quarter also saw a notable rise in ransomware operations that weaponise legitimate RMM tools, posing new challenges for defenders and businesses alike.

Phishing Surges as the Leading Initial Access Vector

Phishing was the primary entry point for attackers in Q2 2026, appearing in more than 50 percent of Talos IR cases, a sharp increase from roughly a third in the previous quarter. Attackers enhanced delivery mechanisms to bypass standard email defences. Notably, campaigns embedded malicious QR codes within PDF attachments, enabling them to sneak past traditional email security gateways. These QR codes often directed victims to credential harvesting sites hosted on legitimate cloud services, further complicating detection for security teams.

Authentication abuse was another major trend. In 65 percent of engagements, attackers targeted or circumvented MFA systems, compared to 35 percent last quarter. The most common techniques included:

  • Adversary-in-the-middle (AitM) phishing proxies that intercept MFA tokens
  • Session token theft, allowing persistent access after initial compromise
  • MFA fatigue attacks, bombarding users with authentication prompts until they approve a malicious login
  • Exploitation of self-enrolled devices to gain unauthorised access

These methods show an ongoing evolution in phishing tactics, highlighting the need for phishing-resistant MFA and vigilant monitoring of authentication anomalies.

QR Code Phishing Targets Australian Organisations Using Microsoft 365

One of the most impactful campaigns observed began in April 2026 and specifically targeted Australian organisations. This persistent phishing operation uses compromised Microsoft 365 accounts to harvest credentials and propagate further attacks. Attackers distributed auto-generated PDF documents tailored with QR codes, each leading to adversary-controlled login pages mimicking Microsoft 365.

Upon successful credential capture, the attackers:

  • Accessed victims’ Microsoft accounts
  • Created inbox rules to hide or reroute emails, evading detection
  • Leveraged SharePoint to stage and distribute malicious documents
  • Sent further phishing emails internally and externally, using compromised contact lists

This campaign remains active as of late June 2026. The threat actor, dubbed UAT-11764 by Talos, is expected to continue exploiting compromised mailboxes to scale their reach. By weaponising trusted platforms like SharePoint and Microsoft 365, the attackers successfully bypassed many standard security measures, relying on the inherent trust users and organisations place in these platforms.

Defenders are urged to:

  • Block or flag emails with QR code PDF attachments
  • Enforce phishing-resistant MFA on all Microsoft 365 accounts
  • Monitor for suspicious inbox rule creation and unusual SharePoint activity

Weaponised RMM Tools Drive Ransomware Operations

Ransomware incidents accounted for over 20 percent of Talos IR engagements this quarter, consistent with previous periods. However, a growing trend is the use of legitimate RMM tools such as trojanised MeshAgent binaries and Zoho Assist for stealthy access. Attackers increasingly rely on these tools to maintain persistence and evade endpoint detection, mimicking routine IT operations to avoid suspicion.

Talos responded to incidents involving established ransomware variants like Nitrogen and Warlock, as well as debuting the Sinobi ransomware in their engagements for the first time. In many cases, these ransomware operators utilised the same phishing and authentication abuse techniques discussed earlier to establish initial access, followed by RMM tools for lateral movement and payload delivery.

  • Trojanised MeshAgent and Zoho Assist enabled attackers to control endpoints remotely
  • RMM activity blended in with legitimate IT support operations, delaying detection
  • Behaviour-based monitoring and stringent controls over administrative binaries were recommended as countermeasures

Phishing-as-a-Service Platforms Expand Attack Capabilities

Another significant Q2 2026 finding was the exposure of the ARToken phishing-as-a-service (PhaaS) platform. Closely linked to EvilTokens, ARToken provides over 80 API endpoints for activities such as device code phishing, primary refresh token persistence, business email compromise (BEC), and SharePoint exfiltration. The platform’s React-based dashboard allows operators to automate and scale attacks, impersonate trusted vendors, and abuse OAuth device authorisation flows to bypass MFA protections.

This industrialisation of phishing, where sophisticated toolkits lower the barrier for attackers, has accelerated the volume and sophistication of Microsoft 365 account compromises. By leveraging legitimate Microsoft services and APIs, attackers evade detection and prolong unauthorised access, often leading to data theft and further internal compromise.

Why This Matters and Immediate Steps for Organisations

The Q2 2026 findings show a clear trajectory: phishing, MFA bypass, and weaponised RMM tools are converging to create more resilient and harder-to-detect attack chains. The focus on trusted platforms like Microsoft 365, combined with phishing lures like QR-in-PDFs, requires immediate attention from organisations.

  • Review and restrict the use of RMM tools, monitoring for unauthorised binaries
  • Deploy advanced phishing protections, including detection of QR codes in attachments
  • Enforce phishing-resistant MFA and continuously monitor for abnormal authentication and SharePoint activity

Responding quickly to these evolving attack chains, with controls specific to the observed methods, reduces the risk of compromise and operational disruption.

Originally reported by blog.talosintelligence.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call