# Q2 2026 IR Trends: Phishing, MFA Bypass, RMM Tool Abuse

> Talos Q2 2026 incident response data shows rising phishing and MFA bypass, with new actors like UAT-11764 and Sinobi ransomware leveraging RMM tools.

- Published: 2026-08-08T00:57:13.000Z
- Severity: high
- Category: Threat Intel
- Tags: Phishing, MFA Bypass, Ransomware, Microsoft 365, UAT 11764
- Author: Runtime Rebel Intel
- Primary source: https://blog.talosintelligence.com/ir-trends-q2-2026/
- Canonical: https://runtimerebel.com/blog/q2-2026-ir-trends-phishing-mfa-bypass-rmm-tool-abuse

## Key points

- Phishing and multi-factor authentication bypass are primary initial access vectors, enabling data compromise and ransomware attacks.
- Microsoft 365 environments, users susceptible to social engineering, and remote monitoring and management tools are key targets.
- Prioritize phishing-resistant MFA and behavior-based monitoring for RMM tools to mitigate current widespread threats.

## Talos Q2 2026 Incident Response Trends Overview

Cisco Talos Incident Response (Talos [IR](/glossary#incident-response-ir)) data for Q2 2026 highlights a significant increase in [phishing](/glossary#phishing) and authentication abuse as primary [initial access](/glossary#initial-access) vectors. Phishing was observed in over half of all engagements, up from approximately one-third in the previous quarter, indicating evolving attacker sophistication. Authentication abuse spiked to 65 percent of engagements, from 35 percent, often involving bypasses of multi-factor authentication ([MFA](/glossary#mfa)). [Ransomware](/glossary#ransomware) incidents remained consistent, comprising over 20 percent of engagements, with new tactics observed for stealthy access, according to [Cisco Talos Intelligence](https://blog.talosintelligence.com/ir-trends-q2-2026/).

### Evolving Phishing Tactics and MFA Bypass

Attackers are innovating phishing delivery to evade traditional defenses. A notable trend is the deployment of QR code-embedded PDFs to bypass email gateways, with links often hosted on trusted cloud platforms. Talos observed an ongoing QR code phishing campaign, attributed to a [threat actor](/glossary#threat-actor) dubbed UAT-11764, primarily targeting Australian organizations. This campaign leverages compromised Microsoft 365 accounts to harvest credentials and then propagates via internal contact lists.

The UAT-11764 campaign generates victim-tailored PDF documents containing QR codes that direct to adversary-controlled M365 [credential harvesting](/glossary#credential-harvesting) pages. Upon successful credential capture, the threat actor performs post-compromise actions such as creating email inbox rules for [defense evasion](/glossary#defense-evasion), using SharePoint to host malicious documents, and sending additional phishing emails. The persistent use of trusted infrastructure like SharePoint and M365 helps UAT-11764 bypass many standard email security gateways, emphasizing the need for advanced detection strategies.

Multi-factor authentication bypass techniques are also prevalent, with attackers frequently defeating MFA using adversary-in-the-middle (AitM) proxies, session-token theft, MFA fatigue attacks, and self-enrolled devices. These methods highlight the importance of not relying solely on MFA as a complete defense but implementing a layered security approach.

### ARToken: A Sophisticated [Phishing-as-a-Service](/glossary#phishing-as-a-service) Platform

Talos uncovered the ARToken platform, a phishing-as-a-service (PhaaS) operation closely linked to the EvilTokens platform. ARToken offers a comprehensive toolkit for Microsoft 365 account compromise, exposing over 80 [API](/glossary#api) endpoints for various malicious activities, including device code phishing, primary refresh token (PRT) [persistence](/glossary#persistence), email access, [business email compromise (BEC)](/glossary#business-email-compromise-bec) operations, and SharePoint exfiltration. This platform allows affiliates to bypass MFA through the OAuth device [authorization](/glossary#authorization) flow rather than traditional password theft.

ARToken extends beyond typical phishing kits by providing capabilities such as automated token management, persistent access via PRTs, OneDrive and SharePoint administration, and advanced anti-analysis techniques. These features underscore the increasing sophistication of PhaaS platforms and the challenge they pose to organizations.

### Ransomware Operators Leverage Remote Management Tools

Ransomware continues to be a significant threat. Talos IR responded to engagements involving Sinobi ransomware for the first time, alongside previously observed variants like Nitrogen and Warlock. A key development is the use of legitimate [remote monitoring and management (RMM)](/glossary#remote-monitoring-and-management-rmm) tools, such as trojanized MeshAgent binaries and Zoho Assist, for covert access. For instance, Sinobi ransomware operators weaponized a MeshAgent binary as their primary command and control ([C2](/glossary#c2)) mechanism. This trojanized MeshAgent functions as a SYSTEM-level auto-start service, communicating via encrypted WebSocket (WSS) to an attacker-controlled server, facilitating a durable [backdoor](/glossary#backdoor).

### Actionable Recommendations and Mitigations

To effectively combat these evolving threats, security professionals must prioritize specific defensive measures:

*   **Enhance Phishing Defenses:** Implement policies that block or flag emails containing QR codes within PDF attachments. Regularly train users on identifying sophisticated phishing attempts.
*   **Strengthen MFA and Authentication Security:** Enforce phishing-resistant MFA on Microsoft 365 accounts. Monitor device code authentication attempts and enforce Conditional Access policies to restrict access based on user, device, and location.
*   **Detecting QR code phishing campaigns and MFA bypass** is crucial. Monitor for suspicious inbox rule creation and anomalous SharePoint file staging, as these are common indicators of post-compromise activity by actors like UAT-11764.
*   **Monitor RMM Tool Usage:** Prioritize behavior-based monitoring for all remote monitoring and management tools, and enforce strict control over administrative binaries like MeshAgent. This is vital to detect the presence of a **Sinobi ransomware MeshAgent backdoor** or similar covert access methods.
*   **Defend Against Token-Based Attacks:** Implement strategies to strengthen defenses against session-token theft and PRT persistence, which platforms like **ARToken Microsoft 365 account compromise** toolkits utilize extensively. Regularly review and revoke stale or suspicious access tokens.

**Related:** [ARToken PhaaS Exposes EvilTokens' M365 Phishing Toolkit](/blog/artoken-phaas-exposes-eviltokens-m365-phishing-toolkit), [Evilginx Operations Exposed: Misconfigured Server Leaks M365 Phishing Kits](/blog/evilginx-operations-exposed-misconfigured-server-leaks-m365-phishing-kits)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/q2-2026-ir-trends-phishing-mfa-bypass-rmm-tool-abuse
