NEW#0001
ANY.RUNabout 18 hours ago11 min▣LLM reporthigh Mirage2FA is a phishing-as-a-service toolkit that uses an Adversary-in-the-Middle (AiTM) architecture to steal Microsoft 365 credentials and authenticated session cookies. It bypasses conventional multi-factor authentication by relaying victim credentials and 2FA codes to Microsoft over WebSocket channels in real-time. The campaign primarily targets US organizations across technology, manufacturing, and education sectors using browser-executed attachments like .htm, .xhtml, and .svg.
#0002
ANY.RUN9 days ago10 min▣LLM reporthigh Researchers posed as founders of a fake DeFi startup (Ballena Azul LTD) and hired three suspected Famous Chollima operatives, observing their behavior inside controlled ANY.RUN sandbox environments. The operatives used AI-generated identity documents, proxy VPS infrastructure, AstrillVPN exit nodes, and remote desktop tools to access company systems. The investigation exposed operative infrastructure including DPRK-operated VPS servers, cryptocurrency wallets, and a shared 2FA platform (2fa.cn), along with the operatives' evolving toolset for coding, document forgery, and interview assistance.
#0003
ANY.RUN15 days ago11 min▣LLM reporthigh July 2026 saw coordinated phishing and malware campaigns targeting US, European, and Brazilian organizations through abuse of trusted business platforms and legitimate authentication flows. Key threats include Kratos and Kali365 phishing-as-a-service operations targeting Microsoft 365 accounts via credential theft and device code phishing, multiple stealer/RAT families (DestinyStealer, DARTHVADER, Banana RAT, OVERLORD RAT) collecting broad credential and session data, and PhantomEnigma's abuse of compromised Brazilian government infrastructure for malware delivery. Attackers consistently used legitimate tools and rotating infrastructure to evade indicator-based defenses.
#0004
ANY.RUN22 days ago10 min▣LLM reportmedium The article discusses how modern adversary-in-the-middle (AiTM) phishing attacks increasingly operate entirely within encrypted browser sessions, leaving little to no artifacts in files or processes, thereby evading traditional file-centric detection tools. It advocates for browser-level visibility, SSL/TLS decryption of session traffic, and threat-intelligence pivoting to detect and investigate such campaigns, illustrating the approach with screenshots of a live fake-CAPTCHA phishing chain and related infrastructure/hashes pulled from a threat intelligence feed.
#0005
ANY.RUN29 days ago15 min▣LLM reporthigh Kali365 is a device code phishing kit targeting US organizations by abusing legitimate Microsoft and Google device authentication flows. Instead of capturing passwords on fake login pages, the kit directs victims to authentic Microsoft/Google device login pages where they enter attacker-provided codes, granting attackers OAuth access and refresh tokens. The phishkit supports 34 lure templates across multiple brands and exposes identifiable API endpoints (/api/generate, /api/lure-config, /api/status) that can be used for detection.
#0006
ANY.RUNabout 1 month ago14 min▣LLM reporthigh PhantomEnigma is an active Brazil-focused crimeware campaign that compromises government infrastructure (.gov.br portals and police mailboxes) to deliver a modular Node.js backdoor embedded in patched Boostnote/Electron applications via Delphi-compiled Inno Setup installers. The operation uses at least two beacon generations (GET /laravel.php and POST /nbw/), rotates C2 domains weekly behind Cloudflare, and leverages trusted government email channels to bypass SPF/DKIM/DMARC checks. ANY.RUN analysts linked 231 sandbox analyses through a recurring build-chain fingerprint and connected a separate Ofício-PC QR-code phishing arm to the same operator via shared compromised government hosts.
#0007
ANY.RUNabout 1 month ago12 min▣LLM reporthigh Kratos is a mature Phishing-as-a-Service operation impersonating Microsoft 365 login pages to steal credentials across US and European organizations. The kit uses legitimate platforms (SharePoint, Canva, Tilda) as intermediary redirect pages, Cloudflare Turnstile to block automated analysis, and PHP endpoints for credential exfiltration. Researchers identified three generations (V0, V1, V2) with distinct asset fingerprints and exfiltration code, and uncovered the operator panel with automated deployment, Telegram-based data delivery, and geographic restriction capabilities.
#0008
ANY.RUNabout 1 month ago14 min▣LLM reporthigh ANY.RUN's Malware Trends Tracker data shows that phishing-as-a-service kits now dominate the US threat landscape, with five of the top ten threats being AiTM or device-code phishing platforms that defeat MFA by stealing session cookies or OAuth tokens. Commodity RATs and info stealers remain in constant high-volume circulation, while legacy threats like Emotet and WannaCry persist on unpatched systems. Several top-ranked threats (Cobalt Strike, Qbot, Emotet, DonutLoader, Smoke Loader) function as ransomware precursors, meaning their detection should trigger urgent escalation rather than routine handling.
#0009
ANY.RUNabout 1 month ago12 min▣LLM reporthigh An exposed public index on 198.245.53.26 revealed two evolutionary branches of Banana RAT, a Brazilian banking-oriented RAT. The older branch (May 2026) used static ETW-themed installation paths and a pseudo-Microsoft C2 domain (c.windowns-cdn.com), while the newer branch (June 2026) shifted to randomized install identifiers, VBS-assisted persistence via hidden SYSTEM scheduled tasks, and WebSocket C2 over host-specific testewin.com subdomains derived from the victim's MachineGuid. Exposed backend scripts (servidorcompletopool.py, ofuscador.py) indicate an automated polymorphic payload generation platform. A shared fallback IP (149.56.12.51) anchors both branches to the same operator.
#0010
ANY.RUNabout 2 months ago5 min▣LLM reporthigh The EvilTokens phishing kit utilizes browser-side AES-GCM decryption to conceal its malicious payload from static analysis tools. By abusing the Microsoft Device Code authentication flow, the kit tricks victims into authorizing attacker access to their Microsoft 365 accounts without directly harvesting credentials, creating a significant visibility gap for SOC teams.
#0011
ANY.RUN3 months ago4 min▣LLM reportmedium ANY.RUN's Q1 2026 Cyber Risk Report highlights a significant acceleration in attacker operational tempo, with the median time-to-persistence dropping to 21 seconds and LOTL execution occurring in 16 seconds. The data also shows a marked increase in loader-based attacks, credential theft, and the weaponization of trusted tools via JavaScript LOLBAS techniques, emphasizing the critical need for rapid, behavior-based detection capabilities.
#0012
ANY.RUN3 months ago6 min▣LLM reporthigh JS.MonoGlyphRAT is a newly identified, highly obfuscated JavaScript backdoor targeting US enterprises via phishing. It establishes persistence, communicates over HTTP using custom headers, and acts as a loader capable of executing AES-encrypted payloads, PowerShell commands, and in-memory .NET assemblies while bypassing AMSI.
#0013
ANY.RUN3 months ago6 min▣LLM reporthigh In May 2026, ANY.RUN observed a surge in sophisticated phishing and malware campaigns utilizing fileless execution, browser-based credential theft, and legitimate workflow abuse. Key threats included Agent Tesla credential harvesting, ClickFix fileless malware, BlobPhish in-memory page generation, and phishing-to-RMM chains bypassing traditional MFA via real-time OTP interception.
#0014
ANY.RUN3 months ago7 min▣LLM reporthigh Modern social engineering attacks have evolved to closely mimic legitimate business workflows, utilizing techniques like ClickFix, OAuth device code abuse, and in-browser blob phishing. These tactics bypass traditional security controls and create "gray-zone" alerts that require deep behavioral analysis to determine the true scope of compromise, such as credential theft, token abuse, or RMM deployment.
#0015
ANY.RUN3 months ago6 min▣LLM reporthigh An 18-month Agent Tesla campaign is targeting LATAM enterprises, particularly in Chile, using procurement-themed phishing lures. The attack chain employs a multi-stage loader protected by .NET Reactor 6.x, utilizing process hollowing into aspnet_compiler.exe to execute the credential-stealing payload entirely in memory. Stolen data is exfiltrated via cleartext FTP to compromised legitimate infrastructure.
#0016
ANY.RUN3 months ago6 min▣LLM reporthigh A large-scale phishing campaign is targeting U.S. organizations across multiple sectors using fake event invitations. The campaign employs a repeatable infrastructure to bypass initial defenses via CAPTCHA, subsequently leading to either credential and OTP interception or the deployment of legitimate Remote Monitoring and Management (RMM) tools for persistent access.
#0017
ANY.RUN3 months ago6 min▣LLM reporthigh Threat actors are increasingly leveraging phishing campaigns to deliver legitimate Remote Monitoring and Management (RMM) tools like ScreenConnect and LogMeIn Rescue, bypassing traditional malware defenses. These attacks often utilize compromised domains, SEO injection, and VBS scripts to weaken endpoint controls (e.g., SmartScreen, Defender) before silently installing the RMM payload, creating significant visibility gaps for SOC teams.
#0018
ANY.RUN3 months ago6 min▣LLM reportcritical A new phishing campaign targets Brazilian users with fake judicial summons to deliver agenteV2, a Nuitka-compiled interactive banking trojan. The malware establishes a persistent WebSocket backdoor for live screen streaming and remote shell access, enabling attackers to conduct real-time, operator-assisted financial fraud.
#0019
ANY.RUN3 months ago6 min▣LLM reporthigh Lazarus Group is conducting a new ClickFix campaign targeting macOS users in high-value sectors via Telegram. The attackers trick victims into executing a terminal command that deploys 'Mach-O Man,' a multi-stage Go-based malware kit designed to steal credentials, browser data, and macOS Keychain secrets, exfiltrating the data via Telegram.
#0020
ANY.RUN3 months ago5 min▣LLM reporthigh BlobPhish is an evasive credential-phishing campaign that generates fake authentication forms directly in the victim's browser memory using Blob objects. By avoiding traditional HTTP requests and disk writes, it bypasses standard network and file-based detection mechanisms to steal high-value financial and cloud service credentials.