Cisco Talos Warns of M365 Token Theft and RMM-Disguised Ransomware in Q2 2026
Cisco Talos Incident Response released its Q2 2026 threat trends report on July 28, 2026, detailing two sophisticated attack chains observed in recent real-world incidents. The first chain leverages QR code phishing PDFs and OAuth device-code flows to steal Microsoft 365 access tokens without capturing passwords, effectively bypassing multi-factor authentication. Attackers then use a custom toolkit called ARToken to manage stolen tokens across more than 80 APIs, enabling inbox rule manipulation, internal phishing propagation, and data exfiltration via SharePoint and OneDrive. The second chain involves trojanized remote monitoring and management tools, specifically a modified MeshAgent, installed as a SYSTEM-level service to establish persistent access before conducting lateral movement via RDP and WinRM and deploying ransomware domain-wide through Group Policy Objects. Talos attributed related activity to threat actors including UAT-11764 and Warlock/Storm-2603, warning that both chains are designed to blend malicious actions within legitimate Microsoft and RMM infrastructure to evade detection.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in