Why Trust is the New Attack Surface: Mid-Year Threat Update 2026

Why Trust is the New Attack Surface: Mid-Year Threat Update 2026
Darktrace says the first half of 2026 was defined by attackers abusing trusted identities, SaaS, cloud entitlements, AI systems, and supply-chain relationships rather than relying on traditional exploitation, with one React2Shell honeypot compromised in under two hours. Campaigns involving StealC, AMOS, Phexia, Axios, Trivy, Hola VPN, BeyondTrust, and JadePuffer showed how quickly trust-based tradecraft, AI-generated malware, and supply-chain abuse are reshaping intrusion paths. #React2Shell #Darktrace #StealC #AMOS #Phexia #Axios #Trivy #HolaVPN #BeyondTrust #JadePuffer

Keypoints

  • Attackers shifted from traditional malware and vulnerability-centric attacks toward trusted identities, SaaS platforms, cloud entitlements, automation frameworks, and non-human identities.
  • A Darktrace-deployed React2Shell honeypot was compromised in less than two hours, underscoring the speed of exploitation in H1 2026.
  • Email and phishing remained highly effective, with 67% of phishing emails passing DMARC and 39% using novel social engineering techniques.
  • Infostealer activity was a major theme, especially StealC and AMOS campaigns, which often provided credentials for later intrusions.
  • Supply-chain trust was weaponized through compromises involving Axios, Trivy, Hola VPN, and legitimate blockchain infrastructure.
  • Cloud and SaaS environments increasingly served as attacker operating terrain, with compromised accounts enabling activity across email, SaaS, and network layers.
  • AI became both an accelerator and an attack surface, including AI-generated malware, compromised AI proxies, and sensitive data being entered into LLM prompts.

MITRE Techniques

  • [T1566 ] Phishing – Used to deliver trusted-looking malicious messages and social engineering, including high-volume text and novel techniques (‘phishing emails passed DMARC’ and ‘novel social engineering techniques’).
  • [T1204 ] User Execution – ClickFix tricks users into running malicious code themselves (‘tricks users into running malicious code themselves’).
  • [T1056.001 ] Input Capture: Keylogging – Infostealers harvested credentials and other identity material for later intrusion paths (‘Credentials harvested by infostealers often become the initial access vector’).
  • [T1078 ] Valid Accounts – Attackers inherited trust by abusing compromised SaaS accounts, delegated access, and legitimate administration tools (‘they inherit them through compromised identities, delegated access, and legitimate administration tools’).
  • [T1195 ] Supply Chain Compromise – Used against Axios, Trivy, and Hola VPN delivery paths to push malicious code or payloads (‘trusted CI/CD infrastructure’ and ‘issue within Hola’s own delivery pipeline’).
  • [T1105 ] Ingress Tool Transfer – Malicious payloads were downloaded through trusted services and delivery pipelines (‘devices downloaded malicious payloads’).
  • [T1219 ] Remote Access Software – RMM and remote administration tooling were repeatedly abused for control and persistence (‘remote management tooling’ and ‘RMM abuse’).
  • [T1027 ] Obfuscated Files or Information – The article notes stealthy intrusions and use of malicious code packages, including AI-generated malware and trojanized installers (‘AI-generated malware’ and ‘trojanized installers’).
  • [T1490 ] Inhibit System Recovery – Ransomware operations were part of the observed activity in multiple monthly clusters (‘ransomware’).
  • [T1059.001 ] Command and Scripting Interpreter: PowerShell – PowerShell was part of June activity tied to post-compromise operations (‘PowerShell’).
  • [T1486 ] Data Encrypted for Impact – Ransomware activity linked to automation and LLM-driven attacks points to encryption for impact (‘fully automated ransomware attack’).
  • [T1071.001 ] Application Layer Protocol: Web Protocols – WebSocket C2 was explicitly mentioned in January activity (‘WebSocket C2’).
  • [T1095 ] Non-Application Layer Protocol – C2 and infrastructure abuse included nonstandard channels and botnet activity (‘WebSocket C2’ and ‘botnet activity’).
  • [T1110 ] Brute Force – Account creation abuse, credential abuse, and authentication-focused attacks indicate repeated attempts to gain access (‘account creation abuse’ and ‘VPN credential abuse’).
  • [T1021.001 ] Remote Services: Remote Desktop Protocol – RDP abuse was specifically noted in June (‘RDP abuse’).
  • [T1041 ] Exfiltration Over C2 Channel – Data theft and exfiltration were part of the observed attacker behavior (‘data exfiltration’ and ‘cloud data theft’).
  • [T1068 ] Exploitation for Privilege Escalation – BeyondTrust and Fortinet exploitation show rapid use of vulnerabilities for access (‘BeyondTrust exploitation’ and ‘Fortinet exploitation’).
  • [T1053.005 ] Scheduled Task/Job: Scheduled Task – Automation frameworks and malicious workflows imply scheduled or automated execution at scale (‘automation frameworks’).
  • [T1090 ] Proxy – Legitimate services and proxies were used to mask attacker infrastructure and reach victims (‘legitimate command-and-control (C2) infrastructure’).

Indicators of Compromise

  • [Malware / Tool Names ] infostealer and payload families seen in campaigns – StealC, AMOS, and Phexia
  • [Campaign / Attack Names ] supply-chain and exploitation activity referenced in the article – React2Shell, JadePuffer, Axios, Trivy, and ClickFix
  • [Organizations / Services ] abused or targeted infrastructure and platforms – Hola VPN, BeyondTrust, Darktrace, and Fortinet
  • [Country / Region References ] campaign geography and targeting context – United States, Japan, United Kingdom, Zimbabwe
  • [Metrics / Detections ] scale indicators tied to detections and prompting – 16 million AI service detections, 2,945 sensitive prompts, and 67% DMARC-passing phishing emails
  • [File / Infrastructure Types ] examples of abused delivery and execution surfaces – malicious payloads, release artifacts, container images, and compromised LLM proxies


Read more: https://www.darktrace.com/blog/why-trust-is-the-new-attack-surface-darktraces-mid-year-threat-update-2026