talos · Crawled Jul 28, 2026

IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains

4 IoCs 2 Actors 1 Malware
Read original article ↗

AI Summary

In Q2 2026, phishing remained the dominant initial access vector, accounting for over half of incident response engagements, with attackers increasingly leveraging QR code-embedded PDFs and trusted cloud platforms to bypass defenses. Threat actors, including the newly observed Sinobi ransomware group and Warlock (Storm-2603), weaponized legitimate remote management tools such as trojanized MeshAgent and Zoho Assist for stealthy persistence and lateral movement. Authentication abuse surged, with adversaries bypassing MFA using adversary-in-the-middle proxies, session token theft, and MFA fatigue attacks. The PhaaS platform ARToken was identified, offering a comprehensive toolkit for Microsoft 365 compromise via OAuth-based phishing, highlighting a growing trend in commoditized, sophisticated access-as-a-service operations.

AI-extracted · verify before operational use

Extracted Entities 3 found

Indicators of Compromise 4 extracted

Type Value Detail
Domain m365[.]credential[.]harvesting[.]page Details →
Filename rclone.exe Details →
Package MeshAgent Details →
Package Zoho Assist Unattended Agent Details →

MITRE ATT&CK TTPs 34 techniques

T1018 Remote System Discovery · Discovery T1021.001 Remote Desktop Protocol · Lateral Movement T1021.004 SSH · Lateral Movement T1048 Exfiltration Over Alternative Protocol · Exfiltration T1053 Scheduled Task/Job · Execution T1070 Indicator Removal · Defense Evasion T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1087 Account Discovery · Discovery T1102 Web Service · Command And Control T1110.003 Password Spraying · Credential Access T1111 Multi-Factor Authentication Interception · Credential Access T1133 External Remote Services · Persistence T1190 Exploit Public-Facing Application · Initial Access T1204.001 Malicious Link · Execution T1219 Remote Access Software · Command And Control T1484 Domain or Tenant Policy Modification · Defense Evasion T1486 Data Encrypted for Impact · Impact T1526 Cloud Service Discovery · Discovery T1534 Internal Spearphishing · Lateral Movement T1564.008 Email Hiding Rules · Defense Evasion T1566 Phishing · Initial Access T1567 Exfiltration Over Web Service · Exfiltration T1572 Protocol Tunneling · Command And Control T1621 Multi-Factor Authentication Request Generation · Credential Access T1663 T1663 T1687 T1687 T1003.001 LSASS Memory · Credential Access T1055.001 Dynamic-link Library Injection · Defense Evasion T1087.002 Domain Account · Discovery T1210 Exploitation of Remote Services · Lateral Movement T1558 Steal or Forge Kerberos Tickets · Credential Access