
QR-PDF Phishing Hits M365, MFA Bypass Surges
Cisco Talos Incident Response reports that phishing drove initial access in over half of Q2 2026 cases, often using QR codes in PDF attachments and trusted…
Cisco Talos incident responders reported phishing as the most common initial entry method in recent real-world incidents, including an ongoing QR-code phishing campaign. The campaign uses victim-tailored PDF attachments with QR codes that lead to Microsoft 365 credential-harvesting pages hosted on trusted cloud infrastructure, then uses the compromised mailbox to spread more phishing.
Cisco Talos incident responders identified phishing as the initial access vector in just over half of incidents investigated between March and June 2026. A significant part of that activity was an ongoing, persistent campaign tracked as UAT-11764. The campaign uses auto-generated, victim-tailored PDF documents that contain QR codes. Instead of clicking a link, victims are prompted to scan a QR code with their phone, which routes them to an adversary-controlled Microsoft 365 credential harvesting page.
The phishing pages are hosted on trusted cloud platforms, which helps the campaign blend in with legitimate traffic. By weaponizing existing, trusted infrastructure like SharePoint and Microsoft 365, the operators can bypass many standard email security gateways that would otherwise flag suspicious links.
The core reason this technique evades detection is that the malicious destination is embedded inside an image, the QR code, rather than in text that gateways can scan. Because the lure looks like a normal document review request, and the destination login page appears to sit on familiar Microsoft infrastructure, victims have little visual reason for suspicion.
Once credentials are stolen, attackers do not stop at account access. They create email inbox rules for defense evasion, which can hide replies or alerts, and they use the compromised mailbox to send further phishing emails to the victim's contacts. This self-propagating step extends the campaign's reach without additional attacker infrastructure and increases the chance that recipients trust the message because it comes from someone they know.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Victims receive an auto-generated, victim-tailored PDF containing a QR code. Scanning it leads to an adversary-controlled Microsoft 365 credential harvesting page hosted on trusted cloud infrastructure.
Because the malicious link is embedded as an image inside a QR code rather than as plain text, it evades detections used by many traditional email gateways to identify potentially malicious behavior.
Attackers access the victim's inbox, create email inbox rules for defense evasion, and use the compromised account to send further phishing emails to the victim's contacts.
Enforce phishing-resistant multi-factor authentication on Microsoft 365 accounts and monitor for suspicious inbox rule creation and anomalous SharePoint file staging.
You get an email: “Action required, review the attached PDF and scan the QR code to sign in to Microsoft 365.” Looks routine, right? Behind that PDF is a QR code that jumps you to a fake Microsoft 365 login, hosted on trusted cloud platforms. Cisco Talos saw this QR-code campaign in real incidents, where stolen logins let the system email your contacts too. Here’s the twist: the next QR-code PDF might come from a real coworker, because their mailbox was already taken over. The only weird thing? You’re being pushed to scan a QR code and re-enter your password just to see a simple document. If a PDF tells you to scan a QR code to log in to Microsoft 365, stop. Don’t scan it, contact the sender or go to office.com yourself and open the file from there.

Cisco Talos Incident Response reports that phishing drove initial access in over half of Q2 2026 cases, often using QR codes in PDF attachments and trusted…

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…

Microsoft reports billions of phishing attempts in Q2 2026, with attackers increasingly using attachments (PDF/DOC/HTML) and new formats like calendar invites…

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…

Cisco Talos reports a remote access trojan (msaRAT) linked to the Chaos ransomware group that hides its command-and-control traffic inside legitimate…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…