UAT-11764 QR code phishing campaign against organizations
Campaign
Summary
Hide ▲
Show ▼
A persistent QR code phishing campaign attributed to UAT-11764 is stealing Microsoft 365 credentials from organizations and reusing compromised mailboxes for follow-on phishing. The operation relies on victim-tailored PDF attachments containing QR codes that point to adversary-controlled login pages. Because the lure is embedded in a document and the pages are hosted on trusted cloud services, common email and web controls are more likely to miss the activity. The campaign was still ongoing in late June 2026, signaling continued risk of account takeover and internal spread through victim inboxes.
Related Happenings
Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026
Trend
H score30
First: 28.07.2026 16:00
Last: 28.07.2026 16:00
Sources 1
How related:
According to the Cisco Talos Incident Response Trends report for March to June 2026, published on July 28, phishing accounted for the initial attack vector in just over half of incidents investigated.
About this happening:
Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...
Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026
TrendHow related: According to the Cisco Talos Incident Response Trends report for March to June 2026, published on July 28, phishing accounted for the initial attack vector in just over half of incidents investigated.
About this happening: Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...
LastPass and Bitwarden users targeted by fake-security-notice phishing campaign
Campaign
H score31
First: 14.07.2026 18:31
Last: 14.07.2026 18:31
Sources 1
About this happening:
An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...
LastPass and Bitwarden users targeted by fake-security-notice phishing campaign
CampaignAbout this happening: An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score37
First: 09.07.2026 17:39
Last: 09.07.2026 17:39
Sources 1
About this happening:
Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Kali365 Microsoft 365 device-code phishing campaign
Campaign
H score46
First: 25.05.2026 15:45
Last: 25.05.2026 15:45
Sources 1
About this happening:
A Kali365 phishing campaign is targeting Microsoft 365 environments worldwide with device-code login lures, putting accounts at risk of token theft and MFA bypas...
Kali365 Microsoft 365 device-code phishing campaign
CampaignAbout this happening: A Kali365 phishing campaign is targeting Microsoft 365 environments worldwide with device-code login lures, putting accounts at risk of token theft and MFA bypas...
CypherLoc phishing-led browser scareware campaign
Campaign
H score49
First: 20.05.2026 13:00
Last: 20.05.2026 13:00
Sources 1
About this happening:
The CypherLoc operation has driven around 2.8 million attacks since the start of 2026, using phishing emails to send users to malicious pages that lock browsers an...
CypherLoc phishing-led browser scareware campaign
CampaignAbout this happening: The CypherLoc operation has driven around 2.8 million attacks since the start of 2026, using phishing emails to send users to malicious pages that lock browsers an...
Timeline
-
28.07.2026 16:00 2 articles · 2h ago
UAT-11764 QR code phishing campaign against organizations
Initial DisclosureA QR code phishing campaign was underway by late June 2026, using tailored PDF attachments to direct victims to Microsoft 365 credential-harvesting pages. The operation targeted organizations and set up compromised accounts for follow-on phishing.
Show sources
- Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques — www.infosecurity-magazine.com — 28.07.2026 16:00
- Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques — www.infosecurity-magazine.com — 28.07.2026 16:00