Find notable cyber news and cases, enriched with sources, timelines, and signals.

UAT-11764 QR code phishing campaign against organizations

Campaign
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

A persistent QR code phishing campaign attributed to UAT-11764 is stealing Microsoft 365 credentials from organizations and reusing compromised mailboxes for follow-on phishing. The operation relies on victim-tailored PDF attachments containing QR codes that point to adversary-controlled login pages. Because the lure is embedded in a document and the pages are hosted on trusted cloud services, common email and web controls are more likely to miss the activity. The campaign was still ongoing in late June 2026, signaling continued risk of account takeover and internal spread through victim inboxes.

Related Happenings

Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026

Trend
H score30 First: 28.07.2026 16:00 Last: 28.07.2026 16:00 Sources 1

How related: According to the Cisco Talos Incident Response Trends report for March to June 2026, published on July 28, phishing accounted for the initial attack vector in just over half of incidents investigated.

About this happening: Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...

LastPass and Bitwarden users targeted by fake-security-notice phishing campaign

Campaign
H score31 First: 14.07.2026 18:31 Last: 14.07.2026 18:31 Sources 1

About this happening: An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...

Forg365-ForgCookie alliance reshapes ransomware ecosystem operations

Threat Actor Meta
H score37 First: 09.07.2026 17:39 Last: 09.07.2026 17:39 Sources 1

About this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...

Kali365 Microsoft 365 device-code phishing campaign

Campaign
H score46 First: 25.05.2026 15:45 Last: 25.05.2026 15:45 Sources 1

About this happening: A Kali365 phishing campaign is targeting Microsoft 365 environments worldwide with device-code login lures, putting accounts at risk of token theft and MFA bypas...

CypherLoc phishing-led browser scareware campaign

Campaign
H score49 First: 20.05.2026 13:00 Last: 20.05.2026 13:00 Sources 1

About this happening: The CypherLoc operation has driven around 2.8 million attacks since the start of 2026, using phishing emails to send users to malicious pages that lock browsers an...

Timeline

  1. 28.07.2026 16:00 2 articles · 2h ago

    UAT-11764 QR code phishing campaign against organizations

    Initial Disclosure

    A QR code phishing campaign was underway by late June 2026, using tailored PDF attachments to direct victims to Microsoft 365 credential-harvesting pages. The operation targeted organizations and set up compromised accounts for follow-on phishing.

    Show sources