Infosecurity

Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques

Published

on

Phishing Surges as the Top Attack Vector

Phishing has reclaimed its spot as the number one way cyber-attacks begin. According to a new report from Cisco Talos, covering March through June 2026, phishing was the initial entry method in just over half of all incidents that required professional remediation.

That’s a sharp jump from the previous quarter, when phishing accounted for only a third of cases. The report, published July 28, makes clear: attackers are doubling down on social engineering — and they’re getting better at it.

Other common entry points included exploitation of public-facing applications and drive-by compromise attacks, where a user simply visits a booby-trapped website. But phishing was the clear leader.

The QR Code Twist: A New Kind of Bait

Why the spike? Attackers are experimenting with fresh tools and techniques designed to slip past defenses. One standout example: a QR code phishing campaign targeting organizations to steal Microsoft 365 credentials.

Here’s how it works. The attacker, tracked by Cisco Talos as UAT-11764, auto-generates PDF documents tailored to each victim. Inside the PDF: a QR code. Scan it, and you land on a credential harvesting page hosted on a trusted cloud platform like SharePoint or Microsoft 365.

Two things make this tricky to stop. First, traditional email gateways often don’t flag QR codes as malicious — they’re just images. Second, the phishing pages live on legitimate infrastructure, so they don’t trigger typical security alerts.

Once the attacker has the credentials, they don’t stop at inbox access. They create email inbox rules to hide their tracks, then use the compromised account to blast more phishing emails to the victim’s contacts. The campaign was still active as of late June 2026.

“By weaponizing existing, trusted infrastructure like SharePoint and Microsoft 365, UAT-11764 can bypass many standard email security gateways,” the report warns. Defenders are advised to block or flag emails containing QR codes inside PDF attachments, enforce phishing-resistant multi-factor authentication, and watch for suspicious inbox rule creation.

Phishing-as-a-Service: Crime Made Easy

The report also highlights the growing sophistication of phishing-as-a-service (PhaaS) kits. These are off-the-shelf toolkits that let almost anyone run a phishing campaign — no coding skills required.

Modern PhaaS platforms come with a full suite of post-compromise tools. Capabilities observed during the period include:

  • Automated token management
  • Persistent access through Primary Refresh Tokens (PRTs)
  • OneDrive and SharePoint administration
  • Geo-dynamic templates that change the phishing page based on the victim’s location
  • Inbox rule manipulation
  • Cross-account keyword monitoring
  • Collaborative token sharing among attackers

Some kits can even bypass MFA by abusing the OAuth device authorization flow — a technique that doesn’t steal passwords but tricks the authentication process itself.

Researchers also found advanced anti-analysis features, including layered evasion mechanisms and encrypted client-side payloads. The report calls this “the increasing sophistication of modern PhaaS platforms.”

How to Defend Against These Evolving Threats

Cisco Talos offers concrete steps for organizations trying to stay ahead. The advice is practical, not theoretical:

  • Deploy phishing-resistant MFA — and configure it properly. Not all multi-factor authentication is equal.
  • Centralize your logging with adequate retention. You can’t detect what you don’t record.
  • Patch aggressively and reduce your exposed infrastructure. Fewer doors mean fewer entry points.
  • Set strict outbound email thresholds to limit how many messages a single account can send. This can stop a compromised mailbox from becoming a spam cannon.

The takeaway? Phishing isn’t going away. But with the right defenses — and awareness that attackers are constantly refining their methods — organizations can make themselves a much harder target.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version