ctipilot.ch
← Back to the live brief
NOTABLENATOB2annual-report

Microsoft Email Threat Landscape Q2 2026: phishing moves off email into Teams vishing, and attachment lures drift PDF → DOCX

discovered 2026-07-25 04:38 UTCrun 2026-07-25T0409Z-intel1 sourcesingle-source

Microsoft's quarterly email-threat report for Q2 2026 carries two findings that matter for any M365-heavy public-sector or enterprise tenant, and both are about where attacks land rather than raw volume. First, social engineering is migrating out of the inbox into trusted collaboration tooling: "weekly malicious call attempts reaching nearly ten times the mid-2025 baseline by the end of the quarter" in Microsoft Teams-based voice-phishing, concentrated in weekday business hours (roughly 14:00–20:00 UTC, near-zero at weekends) and trading on the implicit trust users place in an internal tool (Microsoft Threat Intelligence, 2026-07-23). Second, attachment-based phishing drifted from PDF toward DOC/DOCX delivery across the quarter and email-embedded QR codes collapsed to near-zero — a delivery-mechanism shift that is itself an evasion tell, following the disruption of the Tycoon2FA adversary-in-the-middle kit. Credential theft remained the dominant objective, "accounting for 94–96% of all payload-based attacks each month," with traditional malware delivery down to 4–6%.

Two illustrative campaigns show the current tradecraft. An automated business-email-compromise operation generated messages with Python's email-MIME library and dispatched them through the Amazon SES API from a DKIM-configured domain, reaching tens of thousands of role-based mailboxes (ar, payroll, hr) across many organizations in under three hours with open-tracking pixels for follow-up prioritization. A second campaign nested an EML attachment posing as a Teams voicemail; its action button ran a silent sign-in against an attacker-registered multi-tenant Entra application, and the OAuth redirect chain obscured the true destination from scanners and recipients before ultimately delivering a BAT dropper that pulled and ran a hidden second-stage payload (Microsoft Threat Intelligence, 2026-07-23).

Microsoft Threat Intelligence observed continued growth in Teams-based social engineering, particularly voice phishing (vishing), with weekly malicious call attempts reaching nearly ten times the mid-2025 baseline by the end of the quarter.

Credential phishing continued to dominate the malicious payload landscape throughout Q2, accounting for 94–96% of all payload-based attacks each month.

Microsoft Threat Intelligence 2026-07-23

ATT&CK mapping

4 techniques mapped from the cited reporting · MITRE ATT&CK v19.1

Initial Access TA0001
T1566Phishing

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

overlap matrix · ATT&CK page ↗

T1566.004Phishing: Spearphishing Voice

Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Spearphishing frequently involves social engineering techniques, such as posing as a trusted source (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.

overlap matrix · ATT&CK page ↗

Credential Access TA0006
T1528Steal Application Access Token

Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.

overlap matrix · ATT&CK page ↗

T1557Adversary-in-the-Middle

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

overlap matrix · ATT&CK page ↗

Collection TA0009
T1557Adversary-in-the-Middle

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.