ReliaQuest Report Tracks Top Attacker Techniques in June–August 2026

Summary
ReliaQuest’s report finds identity-led intrusions drove persistent cloud access and SaaS data theft in June–August 2026, while attackers also relied on trusted tools, valid accounts, and SMB for evasion and lateral movement.
Key points
- From June 1 to August 31, attackers used vishing, device-code phishing, and external Teams impersonation to compromise accounts and register attacker-controlled devices or authentication methods.
- ShinyHunters and Helix used compromised identities and legitimate SaaS APIs to enumerate and bulk-download SharePoint data for extortion; in one observed case, SharePoint access began six minutes after a new MFA method was registered.
- Password resets or session termination alone may leave attacker access intact; the report recommends revoking sessions and refresh tokens, removing unauthorized devices and authentication methods, and reviewing SaaS activity.
- The Gryxa toolkit used legitimate remote-management software and multiple persistence mechanisms, and attempted to disable or remove security products when it lost contact with its infrastructure.
- In a Booba ransomware incident, a reused local administrator credential and an unmonitored virtual machine enabled remote SMB encryption across several hosts within seconds of authentication.
- The report identifies CVE-2026-12569 exploitation in a Clop-linked PTC Windchill campaign, where a custom web shell could map engineering files and extract stored credentials.
- ReliaQuest forecasts wider adoption of attacker-controlled identity enrollment, SaaS data theft, and short-lived, victim-specific phishing domains; it recommends correlating identity changes with follow-on activity and verifying endpoint and SaaS visibility.
Article Details
- Publisher
- ReliaQuest Threat Research
- Report Period
- 2026-06-01 to 2026-08-31
- Scope
- Enterprise intrusions, attacker techniques, ransomware activity, and organizations named on ransomware data-leak sites.
- Key Statistics
- In one observed Helix case, SharePoint access occurred six minutes after registration of a new MFA method.
- Gryxa used at least seven scheduled tasks as part of its persistence.
- Gryxa checked connectivity every five minutes; partial removal could leave endpoint protection disabled or uninstalled within roughly 10 to 13 minutes.
- In one investigated environment, Gryxa returned within seven days after defenders removed the visible RMM implant.
- Recommendations
- After confirming account compromise, revoke sessions and refresh tokens, remove unauthorized devices and authentication methods, and require controlled MFA re-enrollment.
- Restrict external Teams communication and remote-support tools; require verification of unexpected IT requests through an established internal channel.
- Correlate authentication changes and device enrollment with subsequent Microsoft Graph activity, SharePoint enumeration, bulk downloads, and remote-service authentication.
- Verify EDR coverage on virtual machines and other critical assets, and investigate privileged access and administrative-share activity from unexpected hosts.
- Centralize SaaS audit logs and retain outbound visibility to distinguish claims of data theft from confirmed exfiltration.
MITRE ATT&CK
T1021.002 · SMB/Windows Admin SharesAttackers moved between hosts and, in a Booba incident, encrypted hosts remotely over SMB.T1053.005 · Scheduled TaskGryxa maintained persistence through scheduled tasks.T1078 · Valid AccountsAttackers used compromised accounts and valid credentials for cloud access and lateral movement.T1098.005 · Device RegistrationAttackers registered their own devices to compromised Microsoft Entra ID accounts to maintain access.T1219 · Remote Access ToolsAttackers used remote-support and RMM software to obtain or maintain access.T1486 · Data Encrypted for ImpactThe Booba ransomware operator encrypted multiple hosts.T1546.003 · Windows Management Instrumentation Event SubscriptionGryxa maintained persistence through a permanent WMI event subscription.T1562.001 · Disable or Modify ToolsGryxa attempted to disable Microsoft Defender and stop or uninstall endpoint security agents.
CVE
Threat Actors
BlackFileNamed as part of a separate BlackFile/Redact campaign ecosystem using target-specific infrastructure; the source does not establish an alias relationship.ClopGroup linked by the report to a campaign exploiting CVE-2026-12569 in PTC Windchill.HelixExtortion actor described as using vishing and device-code phishing before SharePoint data collection.RedactNamed as part of a separate BlackFile/Redact campaign ecosystem using target-specific infrastructure; the source does not establish an alias relationship.ShinyHuntersExtortion group described as using compromised identities for bulk SaaS data theft and extortion.
Malware
BoobaIn a "Booba" ransomware incident, the operator staged the attack from an internal virtual machine that had no EDR sensor. A single previously compromised local administrator credential provided authenticated access toChaosThe strength of the available evidence varied between incidents. In some cases, "Chaos" ransomware operators claimed they had stolen data, but available reporting didn't confirm exfiltration. In a separate intrusionGryxaReliaQuest observed this directly in Gryxa, a financially motivated toolkit that turned legitimate RMM software into persistent access. Gryxa distributed its persistence across at least seven scheduled tasks, a
Vendors
Microsoftnetworks. Attackers commonly posed as internal IT support and contacted employees through external Microsoft Teams accounts or voice calls, including calls to personal phones.PTCreporting period vs. the previous oneManufacturing also remained a prominent target, and the “Clop”-linked PTC Windchill campaign illustrated the value attackers see in this sector. After exploiting CVE-2026-12569, theReliaQuestThis is external threat intelligence from the ReliaQuest Threat Research team. The findings describe threats, vulnerabilities, and attacker activity affecting third parties and the broader threat landscape—not
Products
GreyMattercovered in this report with tailored detection rules, which are complemented by the following GreyMatter Automated Response Playbooks. Together, they help organizations reduce their mean time to containMicrosoft 365Disable User + Terminate Sessions: Disables the compromised account and ends its active sessions across Microsoft 365 and connected applications.Microsoft Defenderstill reach the actor’s infrastructure. After two consecutive failures, it attempted to disable Microsoft Defender and stop EDR products from a hardcoded list. After a third failure, it attempted to uninstall theMicrosoft Entra IDespecially clear. In one campaign we observed, attackers registered several devices to compromised Microsoft Entra ID accounts. Each device received a Primary Refresh Token (PRT) that renewed while the device remainedMicrosoft Graphchange is followed by a new device registration, MFA method, passkey enrollment, or unusual Microsoft Graph activity. Also detect rapid SharePoint enumeration or bulk downloads from an unfamiliar source. WhenMicrosoft SharePointto cloud accounts. Extortion groups "ShinyHunters" and "Helix" turned compromised identities into mass SharePoint data theft and extortion. And password resets alone didn't remove attacker-controlled devices, MFAMicrosoft Teamsnetworks. Attackers commonly posed as internal IT support and contacted employees through external Microsoft Teams accounts or voice calls, including calls to personal phones.PTC Windchillperiod vs. the previous oneManufacturing also remained a prominent target, and the “Clop”-linked PTC Windchill campaign illustrated the value attackers see in this sector. After exploiting CVE-2026-12569, theQuick Assisttakeover. An attacker impersonated IT support through an external Microsoft Teams tenant and used Quick Assist to obtain remote access and steal credentials. After the malicious Quick Assist session ended, the
Tools
Industries
Manufacturingspecifically for Windchill, an industry-standard product lifecycle management (PLM) platform used by manufacturing enterprises worldwide to store engineering data and product designs. The implant could map engineeringProfessional, scientific, and technical servicesProfessional, Scientific, and Technical Services Stays on Top