THREAT OPS › Threat News › IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains
<img alt="IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains" src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/07/TalosIR_quarterly_trends.jpg" /><p>Phishing was the primary means of gaining initial access this quarter, appearing in over half of all Cisco Talos Incident Response (Talos IR) engagements – an inc
MITRE ATT&CK techniques
- Scheduled TaskT1053.005
- Exploitation for Defense ImpairmentT1687
- Adversary-in-the-MiddleT1557
- SharepointT1213.002
- Email Hiding RulesT1564.008
- External Remote ServicesT1133
- Hide ArtifactsT1564
- VulnerabilitiesT1588.006
- SSHT1021.004
- System Information DiscoveryT1082
- Application Layer ProtocolT1071
- Scheduled Task/JobT1053
- Exploit Public-Facing ApplicationT1190
- Exfiltration Over Web ServiceT1567
- Remote Access ToolsT1219
- Social EngineeringT1684
- Protocol TunnelingT1572
- Gather Victim Identity InformationT1589
- Active ScanningT1595
- Password SprayingT1110.003
- Email AddressesT1589.002
- Account DiscoveryT1087
- Indicator RemovalT1070
- File and Directory DiscoveryT1083
- Web ServiceT1102
- Cloud ServicesT1021.007
- Multi-Factor Authentication Request GenerationT1621
- Internal SpearphishingT1534
- Search Open Websites/DomainsT1593
- Exfiltration Over Alternative ProtocolT1048
- PhishingT1566
- Valid AccountsT1078
- Multi-Factor AuthenticationT1556.006
- Data Encrypted for ImpactT1486
- CredentialsT1589.001
- Phishing for InformationT1598
- Conditional Access PoliciesT1556.009
- Drive-by CompromiseT1189
- Multi-Factor Authentication InterceptionT1111
- Web ProtocolsT1071.001
- Cloud Service DiscoveryT1526
- Remote System DiscoveryT1018
- Remote Desktop ProtocolT1021.001
- Domain or Tenant Policy ModificationT1484
- Malicious LinkT1204.001
- Active ScanningAML.T0006
- Malicious LinkAML.T0011.003
- Valid AccountsAML.T0012
- Exploit Public-Facing ApplicationAML.T0049
- Cloud Service DiscoveryAML.T0075
- Drive-by CompromiseAML.T0078
- Gather Victim Identity InformationAML.T0087
- Search Open Websites/DomainsAML.T0095
Indicators of compromise
- storage.ghost.iodomain
Original source: https://blog.talosintelligence.com/ir-trends-q2-2026/