Talos Q2 2026 Incident Response Trends Overview
Cisco Talos Incident Response (Talos IR) data for Q2 2026 highlights a significant increase in phishing and authentication abuse as primary initial access vectors. Phishing was observed in over half of all engagements, up from approximately one-third in the previous quarter, indicating evolving attacker sophistication. Authentication abuse spiked to 65 percent of engagements, from 35 percent, often involving bypasses of multi-factor authentication (MFA). Ransomware incidents remained consistent, comprising over 20 percent of engagements, with new tactics observed for stealthy access, according to Cisco Talos Intelligence.
Evolving Phishing Tactics and MFA Bypass
Attackers are innovating phishing delivery to evade traditional defenses. A notable trend is the deployment of QR code-embedded PDFs to bypass email gateways, with links often hosted on trusted cloud platforms. Talos observed an ongoing QR code phishing campaign, attributed to a threat actor dubbed UAT-11764, primarily targeting Australian organizations. This campaign leverages compromised Microsoft 365 accounts to harvest credentials and then propagates via internal contact lists.
The UAT-11764 campaign generates victim-tailored PDF documents containing QR codes that direct to adversary-controlled M365 credential harvesting pages. Upon successful credential capture, the threat actor performs post-compromise actions such as creating email inbox rules for defense evasion, using SharePoint to host malicious documents, and sending additional phishing emails. The persistent use of trusted infrastructure like SharePoint and M365 helps UAT-11764 bypass many standard email security gateways, emphasizing the need for advanced detection strategies.
Multi-factor authentication bypass techniques are also prevalent, with attackers frequently defeating MFA using adversary-in-the-middle (AitM) proxies, session-token theft, MFA fatigue attacks, and self-enrolled devices. These methods highlight the importance of not relying solely on MFA as a complete defense but implementing a layered security approach.
ARToken: A Sophisticated Phishing-as-a-Service Platform
Talos uncovered the ARToken platform, a phishing-as-a-service (PhaaS) operation closely linked to the EvilTokens platform. ARToken offers a comprehensive toolkit for Microsoft 365 account compromise, exposing over 80 API endpoints for various malicious activities, including device code phishing, primary refresh token (PRT) persistence, email access, business email compromise (BEC) operations, and SharePoint exfiltration. This platform allows affiliates to bypass MFA through the OAuth device authorization flow rather than traditional password theft.
ARToken extends beyond typical phishing kits by providing capabilities such as automated token management, persistent access via PRTs, OneDrive and SharePoint administration, and advanced anti-analysis techniques. These features underscore the increasing sophistication of PhaaS platforms and the challenge they pose to organizations.
Ransomware Operators Leverage Remote Management Tools
Ransomware continues to be a significant threat. Talos IR responded to engagements involving Sinobi ransomware for the first time, alongside previously observed variants like Nitrogen and Warlock. A key development is the use of legitimate remote monitoring and management (RMM) tools, such as trojanized MeshAgent binaries and Zoho Assist, for covert access. For instance, Sinobi ransomware operators weaponized a MeshAgent binary as their primary command and control (C2) mechanism. This trojanized MeshAgent functions as a SYSTEM-level auto-start service, communicating via encrypted WebSocket (WSS) to an attacker-controlled server, facilitating a durable backdoor.
Actionable Recommendations and Mitigations
To effectively combat these evolving threats, security professionals must prioritize specific defensive measures:
- Enhance Phishing Defenses: Implement policies that block or flag emails containing QR codes within PDF attachments. Regularly train users on identifying sophisticated phishing attempts.
- Strengthen MFA and Authentication Security: Enforce phishing-resistant MFA on Microsoft 365 accounts. Monitor device code authentication attempts and enforce Conditional Access policies to restrict access based on user, device, and location.
- Detecting QR code phishing campaigns and MFA bypass is crucial. Monitor for suspicious inbox rule creation and anomalous SharePoint file staging, as these are common indicators of post-compromise activity by actors like UAT-11764.
- Monitor RMM Tool Usage: Prioritize behavior-based monitoring for all remote monitoring and management tools, and enforce strict control over administrative binaries like MeshAgent. This is vital to detect the presence of a Sinobi ransomware MeshAgent backdoor or similar covert access methods.
- Defend Against Token-Based Attacks: Implement strategies to strengthen defenses against session-token theft and PRT persistence, which platforms like ARToken Microsoft 365 account compromise toolkits utilize extensively. Regularly review and revoke stale or suspicious access tokens.
Related: ARToken PhaaS Exposes EvilTokens’ M365 Phishing Toolkit, Evilginx Operations Exposed: Misconfigured Server Leaks M365 Phishing Kits