Editor’s note: This report was authored by Daniel Wroblewski
This is external threat intelligence from the ReliaQuest Threat Research team. The findings describe threats, vulnerabilities, and attacker activity affecting third parties and the broader threat landscape—not ReliaQuest's own environment. Nothing in this report should be interpreted as a vulnerability in ReliaQuest's systems or data.
Key Points
This reporting period, we overwhelmingly observed attackers repeatedly turning phone calls and external Teams messages into persistent access to cloud accounts. Extortion groups "ShinyHunters" and "Helix" turned compromised identities into mass SharePoint data theft and extortion. And password resets alone didn't remove attacker-controlled devices, MFA methods, or refresh tokens.
Ransomware rankings changed, but the methods causing impact increasingly overlapped. Valid accounts, remote-support software, unmonitored virtual machines, and Server Message Block (SMB) helped attackers move from access to encryption with little warning.
Organizations should connect identity changes to the malicious activity that follows. When compromise is confirmed, revoke sessions and tokens, remove unauthorized authentication methods, and verify EDR coverage.
Identity-led intrusions were the clearest threat this quarter, extending a trend seen across several previous reporting periods. Between June 1 and August 31, 2026 ("the reporting period"), attackers refined social engineering into a persistent, adaptable weapon, making malicious access look legitimate and allowing them to return even after passwords and active sessions were reset.
Extortion groups "ShinyHunters" and "Helix" showed how quickly this access could become data theft and extortion. Attackers used compromised identities to run SharePoint site-enumeration searches and bulk file-download API calls. They also registered company-themed domains that impersonated help desks, HR departments, and identity portals such as Okta. Some domains were used on the day they were registered, allowing the actors to quickly replace blocked infrastructure.
These findings show why defenders need to connect activity across identity, endpoint, and software as a service (SaaS). Resetting a password or isolating one host isn't enough when attackers have registered another authentication method, established several persistence mechanisms, or already begun downloading data.
Read on to learn:
How vishing, device-code phishing, and external Teams impersonation led to double extortion.
How a company-branded domain can go from registration to active attack in a single day, making phishing harder for employees to question.
Why changing ransomware brands matters less than the valid accounts, remote-access tools, and visibility gaps that attackers repeatedly use.
Top Tactics Targeting Enterprise Environments
Attackers overwhelmingly targeted users and their unmanaged devices to gain access to accounts. Vishing, device-code phishing, external Teams impersonation, stolen tokens, and attacker-controlled authentication methods let threat actors operate through identities and services organizations already trusted. Once inside, they used legitimate software and over-privileged accounts to collect data, move laterally, and prepare for extortion or encryption.
Social Engineering Turns Cloud Accounts into Double Extortion
Organizations across multiple industries faced a sustained wave of help-desk impersonation that tricked users into allowing attackers into their networks. Attackers commonly posed as internal IT support and contacted employees through external Microsoft Teams accounts or voice calls, including calls to personal phones.
Because these interactions often occurred outside security monitoring, the first activity visible to defenders often resembled a legitimate sign-in, device registration, or MFA change.

These attacks remained prevalent because they’re simple to execute and repeatedly work. Attackers need only to persuade a user to complete a familiar action, such as opening remote-support software, approving an authentication request, or entering a device code. They can then replay stolen tokens, manipulate MFA, or register their own devices and authentication methods, turning one successful interaction into access that remains active after the original password is reset or its sessions terminated.
Device-code phishing made that persistence especially clear. In one campaign we observed, attackers registered several devices to compromised Microsoft Entra ID accounts. Each device received a Primary Refresh Token (PRT) that renewed while the device remained active. Routine password resets or session termination could leave those devices registered and able to renew access. Full containment required defenders to identify and remove every unauthorized registration.
ShinyHunters Scales Identity Compromise into Rapid Data Theft
This quarter showed how a single successful phone call can give attackers persistent cloud access, making this simple, repeatable path a foundation for major extortion campaigns. Attackers can change the message, impersonated brand, or domain while keeping the same core sequence: steal tokens, register attacker-controlled authentication methods, and bulk-download SharePoint data.
ShinyHunters stood out as one of the most prominent groups to exploit this path, turning compromised identities into mass SaaS data theft and extortion demands. Its campaigns replayed stolen refresh tokens, registered attacker-controlled devices, and used legitimate SaaS APIs to automate bulk data collection.
Helix has showed why this identity-led model is so dangerous. After using vishing and device-code phishing to gain legitimate account access, the actor turned that identity into a collection mechanism, running SharePoint site-enumeration searches and bulk file-download API calls through the compromised account. In one observed case, SharePoint access occurred only six minutes after a new MFA method was registered, leaving defenders little time to intervene before sensitive data was used for extortion.
Given this attack type’s repeated success, actors have invested in infrastructure tailored to each target. They’ve registered brand-impersonation and typosquatted domains designed to resemble target companies, internal help desks, HR portals, and identity services such as Okta. Directing users to pages that appear connected to their own organization makes the accompanying vishing calls more convincing.
Helix used target-specific subdomains under shared phishing infrastructure. ShinyHunters rotated through patterns such as {organization}[.]report, {organization}-report[.]com, and {organization}[.]myaccountoptions[.]com, while campaigns associated with the separate "BlackFile"/"Redact" ecosystem used similar target-specific infrastructure. Some domains were weaponized on the day they were registered, while others were used briefly in campaigns impersonating a company’s help desk, legal team, HR department, or document-sharing portal. Replacing the domain, impersonated brand, or claimed business purpose allowed the actors to adapt without redesigning the core attack.
Defenders should focus on detecting that sequence rather than relying on one domain, pretext, or payload. Alert when a password reset or authentication change is followed by a new device registration, MFA method, passkey enrollment, or unusual Microsoft Graph activity. Also detect rapid SharePoint enumeration or bulk downloads from an unfamiliar source. When compromise is confirmed, revoke active sessions and refresh tokens, remove unfamiliar devices and authentication methods, and review enrollment and SaaS activity across the full exposure window before releasing the account.
Obfuscation Leads Defense Evasion as Attackers Use Trusted Tools
Across incidents this reporting period, attackers repeatedly hid malicious activity inside software and processes that organizations already trusted. Signed applications, remote monitoring and management (RMM) tools, native persistence mechanisms, and familiar security states made malicious behavior appear routine while sometimes allowing access to survive the first containment attempt.
ReliaQuest observed this directly in Gryxa, a financially motivated toolkit that turned legitimate RMM software into persistent access. Gryxa distributed its persistence across at least seven scheduled tasks, a permanent Windows Management Instrumentation (WMI) event subscription, and a redundant copy of its files outside the main installation directory. Removing the visible RMM client or primary working folder left enough of the toolkit intact to rebuild the deleted components.

Partial containment could also trigger a more aggressive response. Gryxa checked every five minutes to determine whether it could still reach the actor’s infrastructure. After two consecutive failures, it attempted to disable Microsoft Defender and stop EDR products from a hardcoded list. After a third failure, it attempted to uninstall the security agent silently. Removing the visible remote-access service without eliminating the persistence mechanisms and file cache could leave endpoint protection disabled or uninstalled within roughly 10 to 13 minutes.
A later healthy antivirus status didn't prove that the host had remained protected. Gryxa re-enabled Defender after restoring its connection, but the exclusions it created remained in place. In one investigated environment, defenders removed the visible RMM implant, but another component remained operational, and the toolkit returned within seven days. The surviving component also collected Windows logs and host artifacts describing the response and uploaded them to actor-controlled infrastructure, potentially showing the attacker which tools and accounts defenders had used.
Signatures and reputation still provide useful context, but they shouldn't be the stopping point of an investigation. A signed binary, familiar application, or healthy antivirus status should prompt further questions: Where is the process running? What persistence remains? What security settings changed? Which identity launched it? Detecting those behaviors provides more durable coverage than relying on the name, hash, or apparent legitimacy of the tool.
SMB Remains the Top Lateral Movement Technique
Reused credentials and unmonitored internal hosts allowed attackers to move through SMB and other administrative protocols with little warning before encryption or domain compromise. One compromised credential or unmonitored host can cause widespread damage before defenders can intervene.
In a "Booba" ransomware incident, the operator staged the attack from an internal virtual machine that had no EDR sensor. A single previously compromised local administrator credential provided authenticated access to multiple hosts. Encryption began within seconds of authentication; several hosts were encrypted remotely over SMB, while the initial foothold was encrypted through the compromised user’s local session.

Available telemetry didn't show broad domain discovery or credential-dumping tools before encryption, and the actor limited its visible follow-on activity to basic process and network queries and a single privilege-confirmation command. Until files began changing, the intrusion largely resembled legitimate administration from an internal system.
A separate intrusion showed how social engineering could provide credentials for a broader administrative takeover. An attacker impersonated IT support through an external Microsoft Teams tenant and used Quick Assist to obtain remote access and steal credentials. After the malicious Quick Assist session ended, the actor reused those credentials through the organization’s VPN, then moved through RDP, SMB, and Impacket to achieve full domain compromise.
These incidents make the source host and identity as important as the protocol. Defenders should focus on who is using administrative access and where it originates. Investigate privileged accounts moving rapidly across several hosts or writing files to administrative shares and check for directory-replication activity from unexpected systems, especially virtual machines without endpoint coverage. Credential scoping should include every system and identity the attacker reached, not just the account or endpoint in the first alert.
Step Up Your Defenses
How ReliaQuest Helps You Stay Ahead
Protect against the initial-access, defense-evasion, and lateral-movement techniques covered in this report with tailored detection rules, which are complemented by the following GreyMatter Automated Response Playbooks. Together, they help organizations reduce their mean time to contain (MTTC) to five minutes or less.
Disable User + Terminate Sessions: Disables the compromised account and ends its active sessions across Microsoft 365 and connected applications.
Remove All Authentication Methods + Delete Device: Removes attacker-controlled authenticators, passkeys, security keys, and registered devices that can survive a password reset.
Isolate Host: Removes an affected host from the network to stop malware execution, suspicious SMB writes, and lateral movement.
Your Action Plan
Close every identity-persistence path: When an account is compromised, beyond resetting the password, revoke sessions and refresh tokens, remove unfamiliar devices and authentication methods, and require controlled MFA re-enrollment before returning the account to service.
Restrict external collaboration and remote support: Limit external Teams communication to approved partner tenants and require employees to verify unexpected IT requests through an established internal channel. Restrict Quick Assist and other remote-support tools to authorized support staff.
Connect identity changes to follow-on behavior: Alert when new device or authentication enrollment is followed by Microsoft Graph activity, SharePoint enumeration, bulk downloads, or remote-service authentication. Treat SMB, RDP, WinRM, and other administrative protocols as part of the same intrusion when they follow suspicious identity activity.
Ransomware Shifts, But Post-Access Tradecraft Converges

Ransomware brands changed positions during the reporting period, but the intrusions ReliaQuest investigated continued to follow many of the same post-access steps. Attackers used valid accounts, legitimate remote-access tools, and administrative protocols to reach data or deploy encryption. Because this activity often resembled legitimate administration, defenders couldn't rely on encryption as the first sign of impact or assume that stopping it meant data hadn't already been stolen.
The strength of the available evidence varied between incidents. In some cases, "Chaos" ransomware operators claimed they had stolen data, but available reporting didn't confirm exfiltration. In a separate intrusion that progressed to full domain compromise, access to internal shares and connections to cloud-storage infrastructure raised concern about data theft, but telemetry couldn't identify the files or volume transferred. Helix provided a clearer trail, with automated SharePoint enumeration and bulk downloads preceding the extortion demand.
Helix also showed how attackers could separate data theft from the extortion message. In observed activity, one compromised account quietly enumerated and downloaded SharePoint data over several days. A second account, compromised later, was used only to deliver the extortion demand through Microsoft Teams. Focusing only on the account that posted the demand could therefore leave the original data-theft activity undiscovered.
That uncertainty gives attackers leverage even when theft can't be proven. Security teams, legal counsel, and insurers may still need to make breach decisions without definitive evidence of what left the environment. Centralize SaaS audit logs, baseline approved file-transfer activity, and retain enough outbound visibility to distinguish a theft claim from confirmed exfiltration.
Professional, Scientific, and Technical Services Stays on Top
Professional, scientific, and technical services (PSTS) remained the most frequently named sector on data-leak sites. These organizations often hold client data, manage infrastructure, deliver software, or maintain privileged access to customer environments. So a compromise can spread beyond the named victim through shared identities, managed services, and software dependencies.

Manufacturing also remained a prominent target, and the “Clop”-linked PTC Windchill campaign illustrated the value attackers see in this sector. After exploiting CVE-2026-12569, the group deployed a custom web shell built specifically for Windchill, an industry-standard product lifecycle management (PLM) platform used by manufacturing enterprises worldwide to store engineering data and product designs. The implant could map engineering files stored in the application’s vault, decrypt administrative and directory credentials from its keystore, and load additional Java code directly into memory. One vulnerable application gave the attacker an inventory of sensitive intellectual property and credentials that could support access beyond the affected server.
The repeated targeting of PSTS and manufacturing reflects their structural value to extortion operators. PSTS providers can concentrate data and trusted access belonging to multiple clients, while manufacturing environments combine valuable intellectual property with low tolerance for operational downtime. One compromise can create several pressure points, including stolen client data, interrupted production, exposed product designs, and access to connected customers or suppliers.
The risk in both sectors extends beyond the initially compromised organization. Defenders should inventory the remote-administration paths, federated identity roles, service accounts, API tokens, and software integrations granted to third parties. Those connections should be segmented, monitored, and removable without disrupting the wider environment.
Step Up Your Defenses
How ReliaQuest Helps You Stay Ahead
Detect shared ransomware activity, including certificate abuse, suspicious file transfers, and remote share access, with ReliaQuest detection rules. Pair them with the following GreyMatter Automated Response Playbooks:
Isolate Host: Removes the affected host from the network to stop remote encryption and further lateral movement.
Disable User + Set Password + Terminate Sessions: Disables the compromised identity, replaces its password, and ends sessions used for VPN, RDP, or SMB access.
Block IP + Block Domain: Blocks confirmed attacker-controlled command-and-control (C2), staging, or exfiltration infrastructure.
Your Action Plan
Harden the routes attackers use to get in: Patch internet-facing VPN and remote-access systems on emergency timelines, remove dormant or local accounts, and require phishing-resistant MFA. Restrict external Teams communication and unauthorized remote-support tools.
Detect the shared post-access chain: Monitor for new administrator accounts, suspicious Active Directory Certificate Services (AD CS) certificate requests, directory replication from unexpected hosts, Impacket activity, rclone transfers, and bulk SMB access. These behaviors remain useful even when the ransomware group or payload changes.
Close visibility and third-party gaps: Confirm that virtual machines, backup systems, servers, and other critical assets have working EDR coverage. Treat PSTS providers and software suppliers as extensions of your environment and maintain enough SaaS and outbound logging to determine what data was accessed or removed.
Key Takeaways and What's Next
This reporting period reinforced a pattern that’s been building across recent reports. Attackers increasingly worked through access, tools, and services that organizations already trusted. Initial-access methods varied, but intrusions became hardest to identify once malicious activity blended into legitimate identities, software, and administrative functions.
Identity abuse is also becoming more modular. ShinyHunters, Helix, and campaigns associated with the separate BlackFile/Redact ecosystem changed domains, brands, and social-engineering infrastructure without changing the underlying sequence. Attackers used stolen tokens and attacker-controlled devices to run SharePoint site-enumeration queries and bulk file-download API calls. This repeatable model allowed extortion operations to scale without relying on endpoint malware or network encryption.
The same trust problem appeared inside enterprise networks. Gryxa used legitimate RMM software, scheduled tasks, a WMI event subscription, and backup copies of its files to restore access after partial removal. In one incident, a reused local administrator account and an unmonitored virtual machine enabled SMB encryption across several hosts within seconds of authentication. A familiar tool, valid account, or internal source host was therefore not enough to distinguish administration from an active intrusion.
For defenders, the challenge is connecting events that look legitimate on their own. A new MFA method, device registration, remote-support session, SharePoint search, or administrative-share write becomes more significant when it occurs in an unexpected sequence or at unusual scale. Security teams should correlate these unusual events to find and remove persistence mechanisms, verify endpoint coverage, and determine what data was accessed or transferred.
Three Forecasts for the Next Reporting Period
Social engineering will increasingly end in attacker-controlled accounts. Over the next two to three quarters, more campaigns will likely pair voice calls, SMS messages, or external collaboration contacts with attacker-controlled device, authenticator, passkey, or OAuth enrollment as these changes give attackers persistent access that can remain active after routine password resets or credential rotation. We assess this with moderate confidence, based on the device-code phishing, MFA manipulation, and device-registration activity observed during the reporting period.
More extortion groups will adopt identity-led SaaS theft. Prominent extortion group ShinyHunters and related campaigns already use stolen sessions and attacker-controlled devices to reach SharePoint and other SaaS data without deploying malware or encrypting a network. Over the next two to three quarters, we assess with moderate confidence that additional financially motivated groups will adopt this model because it reduces overhead and lets them use legitimate APIs for collection. Organizations should centralize SaaS audit logs, alert when new authentication methods are followed by enumeration or bulk downloads, and automate session revocation and device removal when compromise is confirmed.
Brand-abuse infrastructure will become more targeted and short-lived. Over the next quarter, we assess with high confidence that attackers will likely continue replacing generic phishing pages with domains tailored to a victim’s company, help desk, HR department, legal function, or identity provider. Patterns such as {organization}[.]report, {organization}-report[.]com, and {organization}[.]myaccountoptions[.]com can make a vishing call more convincing while remaining easy to replace after defenders block them.

