2026-07-25 · view entry permalink →
Microsoft Email Threat Landscape Q2 2026: phishing moves off email into Teams vishing, and attachment lures drift PDF → DOCX
Microsoft's quarterly email-threat report for Q2 2026 carries two findings that matter for any M365-heavy public-sector or enterprise tenant, and both are about where attacks land rather than raw volume. First, social engineering is migrating out of the inbox into trusted collaboration tooling: "weekly malicious call attempts reaching nearly ten times the mid-2025 baseline by the end of the quarter" in Microsoft Teams-based voice-phishing, concentrated in weekday business hours (roughly 14:00–20:00 UTC, near-zero at weekends) and trading on the implicit trust users place in an internal tool (Microsoft Threat Intelligence, 2026-07-23). Second, attachment-based phishing drifted from PDF toward DOC/DOCX delivery across the quarter and email-embedded QR codes collapsed to near-zero — a delivery-mechanism shift that is itself an evasion tell, following the disruption of the Tycoon2FA adversary-in-the-middle kit. Credential theft remained the dominant objective, "accounting for 94–96% of all payload-based attacks each month," with traditional malware delivery down to 4–6%.
Two illustrative campaigns show the current tradecraft. An automated business-email-compromise operation generated messages with Python's email-MIME library and dispatched them through the Amazon SES API from a DKIM-configured domain, reaching tens of thousands of role-based mailboxes (ar, payroll, hr) across many organizations in under three hours with open-tracking pixels for follow-up prioritization. A second campaign nested an EML attachment posing as a Teams voicemail; its action button ran a silent sign-in against an attacker-registered multi-tenant Entra application, and the OAuth redirect chain obscured the true destination from scanners and recipients before ultimately delivering a BAT dropper that pulled and ran a hidden second-stage payload (Microsoft Threat Intelligence, 2026-07-23).
Microsoft Threat Intelligence observed continued growth in Teams-based social engineering, particularly voice phishing (vishing), with weekly malicious call attempts reaching nearly ten times the mid-2025 baseline by the end of the quarter.
Credential phishing continued to dominate the malicious payload landscape throughout Q2, accounting for 94–96% of all payload-based attacks each month.