ctipilot.ch

Microsoft Email Threat Landscape Q2 2026

report · report:microsoft-email-threat-landscape-q2-2026 single-source

Microsoft Threat Intelligence quarterly email-threat report (2026-07-23) covering Q2 2026: a roughly 10x surge in Microsoft Teams-based voice-phishing over the mid-2025 baseline, an attachment-delivery drift from PDF toward DOC/DOCX, credential theft as the objective of 94-96% of payload-based attacks, and the post-disruption decline of the Tycoon2FA adversary-in-the-middle kit.

Coverage timeline
1
first 2026-07-25 → last 2026-07-25
Peak priority
notable
1 notable
Sources cited
1
1 hosts
Sections touched
1
research
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
4
pinned v19.1 · see below

Hunting pivots

ATT&CK techniques
Affected products
Microsoft 365Microsoft Defender for Office 365Microsoft Teams

ATT&CK techniques

4 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1566Phishing×1

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

Evidence: 2026-07-25/microsoft-email-threat-landscape-q2-2026-teams-vishing-surge · ATT&CK page ↗

T1566.004Phishing: Spearphishing Voice×1

Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Spearphishing frequently involves social engineering techniques, such as posing as a trusted source (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.

Evidence: 2026-07-25/microsoft-email-threat-landscape-q2-2026-teams-vishing-surge · ATT&CK page ↗

Credential Access TA0006

T1528Steal Application Access Token×1

Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.

Evidence: 2026-07-25/microsoft-email-threat-landscape-q2-2026-teams-vishing-surge · ATT&CK page ↗

T1557Adversary-in-the-Middle×1

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Evidence: 2026-07-25/microsoft-email-threat-landscape-q2-2026-teams-vishing-surge · ATT&CK page ↗

Collection TA0009

T1557Adversary-in-the-Middle×1

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Evidence: 2026-07-25/microsoft-email-threat-landscape-q2-2026-teams-vishing-surge · ATT&CK page ↗

Story timeline

  1. 2026-07-25Microsoft Email Threat Landscape Q2 2026: phishing moves off email into Teams vishing, and attachment lures drift PDF → DOCX
    researchMicrosoft's quarterly email report flags a sustained shift of social engineering into Teams voice-phishing

Where this entity is cited

  • research1

Source distribution

  • microsoft.com1 (100%)

explore in graph

Entries about Microsoft Email Threat Landscape Q2 2026 (1)

2026-07-25 · view entry permalink →

NOTABLENATOB2

Microsoft Email Threat Landscape Q2 2026: phishing moves off email into Teams vishing, and attachment lures drift PDF → DOCX

Microsoft's quarterly email-threat report for Q2 2026 carries two findings that matter for any M365-heavy public-sector or enterprise tenant, and both are about where attacks land rather than raw volume. First, social engineering is migrating out of the inbox into trusted collaboration tooling: "weekly malicious call attempts reaching nearly ten times the mid-2025 baseline by the end of the quarter" in Microsoft Teams-based voice-phishing, concentrated in weekday business hours (roughly 14:00–20:00 UTC, near-zero at weekends) and trading on the implicit trust users place in an internal tool (Microsoft Threat Intelligence, 2026-07-23). Second, attachment-based phishing drifted from PDF toward DOC/DOCX delivery across the quarter and email-embedded QR codes collapsed to near-zero — a delivery-mechanism shift that is itself an evasion tell, following the disruption of the Tycoon2FA adversary-in-the-middle kit. Credential theft remained the dominant objective, "accounting for 94–96% of all payload-based attacks each month," with traditional malware delivery down to 4–6%.

Two illustrative campaigns show the current tradecraft. An automated business-email-compromise operation generated messages with Python's email-MIME library and dispatched them through the Amazon SES API from a DKIM-configured domain, reaching tens of thousands of role-based mailboxes (ar, payroll, hr) across many organizations in under three hours with open-tracking pixels for follow-up prioritization. A second campaign nested an EML attachment posing as a Teams voicemail; its action button ran a silent sign-in against an attacker-registered multi-tenant Entra application, and the OAuth redirect chain obscured the true destination from scanners and recipients before ultimately delivering a BAT dropper that pulled and ran a hidden second-stage payload (Microsoft Threat Intelligence, 2026-07-23).

Microsoft Threat Intelligence observed continued growth in Teams-based social engineering, particularly voice phishing (vishing), with weekly malicious call attempts reaching nearly ten times the mid-2025 baseline by the end of the quarter.

Credential phishing continued to dominate the malicious payload landscape throughout Q2, accounting for 94–96% of all payload-based attacks each month.

Microsoft Threat Intelligence 2026-07-23
annual-report25 Jul 04:38Zsingle-sourceOpen finding ↗