Skip to content
.ca
sign in

Threat intelligence from ANY.RUN

27 reports on cyfar.ca summarizing ANY.RUN research. Visit ANY.RUN

ANY.RUNabout 18 hours ago11 minLLM reporthigh

Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US

Mirage2FA is a phishing-as-a-service toolkit that uses an Adversary-in-the-Middle (AiTM) architecture to steal Microsoft 365 credentials and authenticated session cookies. It bypasses conventional multi-factor authentication by relaying victim credentials and 2FA codes to Microsoft over WebSocket channels in real-time. The campaign primarily targets US organizations across technology, manufacturing, and education sectors using browser-executed attachments like .htm, .xhtml, and .svg.

ANY.RUN9 days ago10 minLLM reporthigh

Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup

Researchers posed as founders of a fake DeFi startup (Ballena Azul LTD) and hired three suspected Famous Chollima operatives, observing their behavior inside controlled ANY.RUN sandbox environments. The operatives used AI-generated identity documents, proxy VPS infrastructure, AstrillVPN exit nodes, and remote desktop tools to access company systems. The investigation exposed operative infrastructure including DPRK-operated VPS servers, cryptocurrency wallets, and a shared 2FA platform (2fa.cn), along with the operatives' evolving toolset for coding, document forgery, and interview assistance.

ANY.RUN15 days ago11 minLLM reporthigh

Major Cyber Attacks in July 2026: US and EU Organizations Hit by Phishing, RATs, and Stealers

July 2026 saw coordinated phishing and malware campaigns targeting US, European, and Brazilian organizations through abuse of trusted business platforms and legitimate authentication flows. Key threats include Kratos and Kali365 phishing-as-a-service operations targeting Microsoft 365 accounts via credential theft and device code phishing, multiple stealer/RAT families (DestinyStealer, DARTHVADER, Banana RAT, OVERLORD RAT) collecting broad credential and session data, and PhantomEnigma's abuse of compromised Brazilian government infrastructure for malware delivery. Attackers consistently used legitimate tools and rotating infrastructure to evade indicator-based defenses.

ANY.RUN22 days ago10 minLLM reportmedium

Building Resilience Against AiTM Phishing: What SOC Leaders Should Know

The article discusses how modern adversary-in-the-middle (AiTM) phishing attacks increasingly operate entirely within encrypted browser sessions, leaving little to no artifacts in files or processes, thereby evading traditional file-centric detection tools. It advocates for browser-level visibility, SSL/TLS decryption of session traffic, and threat-intelligence pivoting to detect and investigate such campaigns, illustrating the approach with screenshots of a live fake-CAPTCHA phishing chain and related infrastructure/hashes pulled from a threat intelligence feed.

ANY.RUN29 days ago15 minLLM reporthigh

Kali365 Targets US Organizations with Data Theft via Device Code Phishing

Kali365 is a device code phishing kit targeting US organizations by abusing legitimate Microsoft and Google device authentication flows. Instead of capturing passwords on fake login pages, the kit directs victims to authentic Microsoft/Google device login pages where they enter attacker-provided codes, granting attackers OAuth access and refresh tokens. The phishkit supports 34 lure templates across multiple brands and exposes identifiable API endpoints (/api/generate, /api/lure-config, /api/status) that can be used for detection.

ANY.RUNabout 1 month ago14 minLLM reporthigh

Hidden Infrastructure Exposed: ANY.RUN Reveals Hijacked Gov Websites Delivering Malware

PhantomEnigma is an active Brazil-focused crimeware campaign that compromises government infrastructure (.gov.br portals and police mailboxes) to deliver a modular Node.js backdoor embedded in patched Boostnote/Electron applications via Delphi-compiled Inno Setup installers. The operation uses at least two beacon generations (GET /laravel.php and POST /nbw/), rotates C2 domains weekly behind Cloudflare, and leverages trusted government email channels to bypass SPF/DKIM/DMARC checks. ANY.RUN analysts linked 231 sandbox analyses through a recurring build-chain fingerprint and connected a separate Ofício-PC QR-code phishing arm to the same operator via shared compromised government hosts.

ANY.RUNabout 1 month ago12 minLLM reporthigh

​​Kratos PhaaS Targets US and EU: How to Reduce Microsoft 365 Account Takeover Risk​

Kratos is a mature Phishing-as-a-Service operation impersonating Microsoft 365 login pages to steal credentials across US and European organizations. The kit uses legitimate platforms (SharePoint, Canva, Tilda) as intermediary redirect pages, Cloudflare Turnstile to block automated analysis, and PHP endpoints for credential exfiltration. Researchers identified three generations (V0, V1, V2) with distinct asset fingerprints and exfiltration code, and uncovered the operator panel with automated deployment, Telegram-based data delivery, and geographic restriction capabilities.

ANY.RUNabout 1 month ago14 minLLM reporthigh

US Threat Landscape Alert: 30 Active Malware Families Ranked by Real Sandbox Data

ANY.RUN's Malware Trends Tracker data shows that phishing-as-a-service kits now dominate the US threat landscape, with five of the top ten threats being AiTM or device-code phishing platforms that defeat MFA by stealing session cookies or OAuth tokens. Commodity RATs and info stealers remain in constant high-volume circulation, while legacy threats like Emotet and WannaCry persist on unpatched systems. Several top-ranked threats (Cobalt Strike, Qbot, Emotet, DonutLoader, Smoke Loader) function as ransomware precursors, meaning their detection should trigger urgent escalation rather than routine handling.

ANY.RUNabout 1 month ago12 minLLM reporthigh

Banana RAT Evolves: Comparing Two Recent Branches Through ANY.RUN

An exposed public index on 198.245.53.26 revealed two evolutionary branches of Banana RAT, a Brazilian banking-oriented RAT. The older branch (May 2026) used static ETW-themed installation paths and a pseudo-Microsoft C2 domain (c.windowns-cdn.com), while the newer branch (June 2026) shifted to randomized install identifiers, VBS-assisted persistence via hidden SYSTEM scheduled tasks, and WebSocket C2 over host-specific testewin.com subdomains derived from the victim's MachineGuid. Exposed backend scripts (servidorcompletopool.py, ofuscador.py) indicate an automated polymorphic payload generation platform. A shared fallback IP (149.56.12.51) anchors both branches to the same operator.

ANY.RUNabout 2 months ago5 minLLM reporthigh

EvilTokens: How “Ghost” Code Threatens US and European Businesses

The EvilTokens phishing kit utilizes browser-side AES-GCM decryption to conceal its malicious payload from static analysis tools. By abusing the Microsoft Device Code authentication flow, the kit tricks victims into authorizing attacker access to their Microsoft 365 accounts without directly harvesting credentials, creating a significant visibility gap for SOC teams.

ANY.RUN3 months ago4 minLLM reportmedium

Q1 2026 Cyber Risk Report: Insights from 2.1 Million Malware and Phishing Investigations

ANY.RUN's Q1 2026 Cyber Risk Report highlights a significant acceleration in attacker operational tempo, with the median time-to-persistence dropping to 21 seconds and LOTL execution occurring in 16 seconds. The data also shows a marked increase in loader-based attacks, credential theft, and the weaponization of trusted tools via JavaScript LOLBAS techniques, emphasizing the critical need for rapid, behavior-based detection capabilities.

ANY.RUN3 months ago6 minLLM reporthigh

From Fake Purchase Orders to Remote Access: Analyzing the JS.MonoGlyphRAT Threat to US Enterprises

JS.MonoGlyphRAT is a newly identified, highly obfuscated JavaScript backdoor targeting US enterprises via phishing. It establishes persistence, communicates over HTTP using custom headers, and acts as a loader capable of executing AES-encrypted payloads, PowerShell commands, and in-memory .NET assemblies while bypassing AMSI.

ANY.RUN3 months ago6 minLLM reporthigh

Major Cyber Attacks in May 2026: Fake Invitations, Agent Tesla, BlobPhish, and More

In May 2026, ANY.RUN observed a surge in sophisticated phishing and malware campaigns utilizing fileless execution, browser-based credential theft, and legitimate workflow abuse. Key threats included Agent Tesla credential harvesting, ClickFix fileless malware, BlobPhish in-memory page generation, and phishing-to-RMM chains bypassing traditional MFA via real-time OTP interception.

ANY.RUN3 months ago7 minLLM reporthigh

Top 5 Phishing-Driven Social Engineering Attacks on Companies in 2026

Modern social engineering attacks have evolved to closely mimic legitimate business workflows, utilizing techniques like ClickFix, OAuth device code abuse, and in-browser blob phishing. These tactics bypass traditional security controls and create "gray-zone" alerts that require deep behavioral analysis to determine the true scope of compromise, such as credential theft, token abuse, or RMM deployment.

ANY.RUN3 months ago6 minLLM reporthigh

LATAM Under Siege: Agent Tesla’s 18-Month Credential Theft Campaign Against Chilean Enterprises

An 18-month Agent Tesla campaign is targeting LATAM enterprises, particularly in Chile, using procurement-themed phishing lures. The attack chain employs a multi-stage loader protected by .NET Reactor 6.x, utilizing process hollowing into aspnet_compiler.exe to execute the credential-stealing payload entirely in memory. Stolen data is exfiltrated via cleartext FTP to compromised legitimate infrastructure.

ANY.RUN3 months ago6 minLLM reporthigh

New Phishing Campaign Targets US with Credential Theft: What CISOs Need to Know

A large-scale phishing campaign is targeting U.S. organizations across multiple sectors using fake event invitations. The campaign employs a repeatable infrastructure to bypass initial defenses via CAPTCHA, subsequently leading to either credential and OTP interception or the deployment of legitimate Remote Monitoring and Management (RMM) tools for persistent access.

ANY.RUN3 months ago6 minLLM reporthigh

Phishing-to-RMM Attacks: The Remote Access Blind Spot CISOs Can’t Ignore

Threat actors are increasingly leveraging phishing campaigns to deliver legitimate Remote Monitoring and Management (RMM) tools like ScreenConnect and LogMeIn Rescue, bypassing traditional malware defenses. These attacks often utilize compromised domains, SEO injection, and VBS scripts to weaken endpoint controls (e.g., SmartScreen, Defender) before silently installing the RMM payload, creating significant visibility gaps for SOC teams.

ANY.RUN3 months ago6 minLLM reportcritical

Inside agenteV2: How Brazilian Attackers Use Fake Court Summons to Steal Banking Credentials in Real Time

A new phishing campaign targets Brazilian users with fake judicial summons to deliver agenteV2, a Nuitka-compiled interactive banking trojan. The malware establishes a persistent WebSocket backdoor for live screen streaming and remote shell access, enabling attackers to conduct real-time, operator-assisted financial fraud.

ANY.RUN3 months ago6 minLLM reporthigh

New Lazarus APT Campaign: “Mach-O Man” macOS Malware Kit Hits Businesses

Lazarus Group is conducting a new ClickFix campaign targeting macOS users in high-value sectors via Telegram. The attackers trick victims into executing a terminal command that deploys 'Mach-O Man,' a multi-stage Go-based malware kit designed to steal credentials, browser data, and macOS Keychain secrets, exfiltrating the data via Telegram.

ANY.RUN3 months ago5 minLLM reporthigh

BlobPhish: The Phantom Phishing Campaign Hiding in Browser Memory

BlobPhish is an evasive credential-phishing campaign that generates fake authentication forms directly in the victim's browser memory using Blob objects. By avoiding traditional HTTP requests and disk writes, it bypasses standard network and file-based detection mechanisms to steal high-value financial and cloud service credentials.