Elektrine lite

โ† Feed

ANY.RUN

anyrun_app@infosec.exchange

<p>Empowering businesses with proactive security solutions: Interactive Sandbox, TI Lookup and Feeds.</p>

Posts

  • View post

    โš ๏ธ Malware activity increased across nearly every major family last week. RATs like #Remcos and #AgentTesla, stealers like #Stealc and #Lumma, and loaders like #DonutLoader all gained momentum. ๐Ÿ“Œ Trend to watch: activity is accelerating across the threat landscape rather than around a single malware family, pointing to broader attacker activity rather than isolated campaigns. Monitor the malware driving todayโ€™s attacks: https://any.run/malware-trends/?utm_source=mastodon&amp;utm_medium=post&amp...

  • View post

    ๐Ÿฆ Financial institutions are the #1 target for ransomware, credential theft, and social engineering. A SOC at an investment bank prevented hundreds of attempts with #ANYRUN. ๐Ÿ“ˆ See how to strengthen security for banks: https://any.run/by-industry/finance/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=finance_success_story&amp;utm_term=060826&amp;utm_content=linktofinancelanding

  • View post

    Phishing activity in the past 7 days ๐ŸŸ Track latest #phishing threats in TI Lookup: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=top_phishing&amp;utm_content=linktoti&amp;utm_term=040826#%7B%2522query%2522:%2522threatName:%255C%2522%5Ephishing$%255C%2522%2522,%2522dateRange%2522:180%7D

  • View post

    ๐Ÿšจ #PhantomEnigma hijacks .gov.br portals to deliver backdoors while bypassing SPF, DKIM, and DMARC. Companies it targets face banking fraud and persistent RMM access โš ๏ธ Update your SOC defense with our actionable research: https://any.run/malware-trends/PhantomEnigma/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=phantomenigma_mtt&amp;utm_term=030826&amp;utm_content=linktomtt

  • View post

    โš ๏ธ While most leading malware families declined last week, #DonutLoader and #AgentTesla continued to grow. ๐Ÿ“Œ Trend to watch: quieter weeks don&#39;t affect every threat equally. Tracking which malware families continue to gain momentum helps SOC teams spot changes in attacker activity early. Monitor the malware driving todayโ€™s attacks: https://any.run/malware-trends/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=top_ten&amp;utm_term=030826&amp;utm_content=linktomtt #Top10Malware

  • View post

    One fake download page โžก๏ธ full remote access to your network โš ๏ธ SnappyClient shows how quickly a single click can turn into stolen credentials, hijacked payments, and a foothold attackers can exploit long after the initial breach. ๐Ÿ‘จโ€๐Ÿ’ป Learn more: https://any.run/malware-trends/snappyclient/?utm_source=mastodon&amp;amp;utm_medium=post&amp;amp;utm_campaign=snappyclient&amp;amp;utm_content=linktomtt&amp;amp;utm_term=200726 #cybersecurity #infosec

  • View post

    โšก You are one integration away from unique threat intelligence powered by a global community of 600K analysts. Bring #ANYRUN directly into your SIEM, SOAR, or EDR. ๐Ÿ”— Find your vendor and strengthen your security stack with #ANYRUN: https://any.run/integrations/?utm_source=mastodon&amp;amp;utm_medium=post&amp;amp;utm_campaign=all_integrations_connectors&amp;amp;utm_content=linktointegrations&amp;amp;utm_term=230726

  • View post

    Phishing activity in the past 7 days ๐ŸŸ Track latest #phishing threats in TI Lookup: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&amp;amp;utm_medium=post&amp;amp;utm_campaign=top_phishing&amp;amp;utm_content=linktoti&amp;amp;utm_term=280726#%7B%2522query%2522:%2522threatName:%255C%2522%5Ephishing$%255C%2522%2522,%2522dateRange%2522:180%7D โ—๏ธ Here&amp;#39;s what your SOC needs to know about rising EvilTokens: https://any.run/malware-trends/eviltokens/?utm_source=mastodon&amp;a...

  • View post

    โšก To detect emerging threats in Microsoft Sentinel you need fresh, unique intelligence. Thatโ€™ what #ANYRUN TI Feeds deliver โ€” live IOCs from sandbox analysis, 99% unique, real-time. ๐Ÿ“ˆ See how #ANYRUN strengthens your Microsoft Sentinel environment: https://any.run/integrations/microsoft-sentinel-integration/?utm_source=mastodon&amp;amp;utm_medium=post&amp;amp;utm_campaign=feeds_sentinel_integration&amp;amp;utm_term=300726&amp;amp;utm_content=linktointegrations #cybersecurity #infosec

  • View post

    ๐Ÿšจ A malicious LNK disguised as a PDF leads to DARTHVADER stealer deployment &amp;amp; persistence, turning a document-like lure into post-click compromise. Observed behavior: LOLBin and AutoIt execution, hidden cmd.exe activity, curl.exe downloads, PowerShell ExecutionPolicy Bypass, mutex creation, cmd.exe /V:ON for delayed environment variable expansion, and /D to disable AutoRun command processing. โ€๐Ÿ’ป Live detonation and IOCs for detection &amp;amp; response: https://app.any.run/tasks/81...

  • View post

    ๐ŸŽฏ What changed in #ANYRUNโ€™s threat coverage this July? 750+ new Suricata, YARA, and behavior rules help detect threats faster &amp; cut manual work. Plus, a new TI Report and research into emerging threats. See how updates can strengthen your SOC response๐Ÿ‘‡ https://any.run/cybersecurity-blog/july-threat-coverage-2026/?utm_source=mastodon&amp;utm_medium=article&amp;utm_campaign=july_threat_coverage_2026&amp;utm_term=300726&amp;utm_content=linktoblog

  • View post

    ๐Ÿ›ก๏ธ More cyber risk should not mean more SOC headcount. With 514K+ US cybersecurity jobs, $132K+ analyst salaries, and hiring cycles of up to 6 months, CFOs need a smarter way to grow security capacity. How to strengthen the SOC without growing payroll ๐Ÿ‘‡ https://any.run/cybersecurity-blog/cfo-cyber-risk-playbook/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=cfo_cyber_risk_playbook&amp;utm_term=290726&amp;utm_content=linktoblog #cybersecurity #infosec

  • View post

    โ— A US manufacturer had 200+ active vendors with no consistent way to validate incoming files. ๐Ÿ”ฅ #ANYRUN gave the team behavioral evidence which made triage 2x faster and significant reduction in escalations. ๐Ÿ“– See how to manage third-party risk: https://any.run/by-industry/manufacturing/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=manufacturing_real_case&amp;utm_term=290726&amp;utm_content=linktoblog

  • View post

    ๐Ÿ” Can your SOC investigate #phishing that leaves no malicious files behind? Modern AiTM attacks live inside the browser. Discover how browser visibility and threat intelligence expose what file-based analysis can&#39;t ๐Ÿ‘‡ https://any.run/cybersecurity-blog/enterprise-phishing-resilience/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=enterprise_phishing_resilience&amp;utm_term=280726&amp;utm_content=linktoblog #cybersecurity #infosec

  • View post

    ๐Ÿšจ #Kratos was recently dismantled, but it remains a blueprint for active phishing kits. PhaaS platforms continue to use the same methods to bypass MFA and hijack Microsoft 365 sessions. โšก๏ธ Update defense against evolving session-theft threats: https://any.run/malware-trends/kratos/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=kratos_mtt&amp;utm_term=270726&amp;utm_content=linktomtt #cybersecurity #infosec

  • View post

    โš ๏ธ #XWorm climbed into the week&#39;s top three, while #Formbook posted one of the strongest gains among the most active malware families. ๐Ÿ“Œ Trend to watch: As familiar threats change position, they can alter which malware analysts encounter most frequently and where detection efforts need the closest attention. Monitor the malware driving todayโ€™s attacks: https://any.run/malware-trends/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=top_ten&amp;utm_term=270726&amp;utm_content=linktom...

  • View post

    โ—๏ธ Kratos, one of the major M365 PhaaS operations, has been disrupted by German &amp; US law enforcement. 200+ servers were taken down, according to BKA. Good news, but PhaaS operators rebrand, affiliates switch kits, and the same workflows return in new campaigns ๐Ÿšจ ๐Ÿ” Our report breaks down the phishing flow, infrastructure patterns, artifacts, and detection logic analysts can reuse when investigating similar campaigns: https://any.run/cybersecurity-blog/kratos-phaas-account-takeover/?utm_sourc...

  • View post

    ๐Ÿšจ ๐—”๐˜๐˜๐—ฎ๐—ฐ๐—ธ๐—ฒ๐—ฟ ๐—–๐Ÿฎ ๐—–๐—ผ๐—ป๐˜๐—ฟ๐—ผ๐—น ๐—–๐—ฎ๐˜‚๐—ด๐—ต๐˜ ๐—ผ๐—ป ๐—ฎ ๐—Ÿ๐—ถ๐˜ƒ๐—ฒ ๐—ฆ๐˜†๐˜€๐˜๐—ฒ๐—บ. Interactive analysis let us capture what static detonation misses โš ๏ธ ๐—ข๐—ฏ๐˜€๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฑ ๐˜๐—ฎ๐—ฟ๐—ด๐—ฒ๐˜๐—ถ๐—ป๐—ด: ๐—š๐—ฒ๐—ฟ๐—บ๐—ฎ๐—ป๐˜† ๐—ฎ๐—ป๐—ฑ ๐—จ๐—ž โ—๏ธ The operator connected to the infected system, uploaded the next-stage payload, and triggered a full chain: we.exe PythonRAT โžก๏ธ exo.exe dropper โžก๏ธ Lenovo FnHotkeyUtility.exe โžก๏ธ spkvol.dll sideloading โžก๏ธ Rust loader โžก๏ธ In-memory OVERLORD RAT. ๐Ÿ”ฅ The initial implant was only the entry point. The real risk appeared later: DLL sideloading, in-memory ex...

  • View post

    ๐Ÿšจ #Kali365 is targeting US organizations through device code phishing hidden behind legitimate Microsoft authentication. One approved code can expose business email and data, leading to fraud and costly response. ๐Ÿ‘จโ€๐Ÿ’ป See an example of a SharePoint-themed lure &amp; gather IOCs: https://app.any.run/tasks/d078f430-c3cc-44e8-a809-5506205049c3/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=kali365_phishing_targeting_us&amp;utm_term=210726&amp;utm_content=linktoservice Explore the attack...

  • View post

    ๐Ÿšจ The malware arrives as a legal file from a police department email and passes SPF, DKIM, and DMARC. What&#39;s inside: a Delphi/Inno Setup installer dropping PhantomEnigma&#39;s JS backdoor that beacons, persists, and executes on command. ๐Ÿ‘จโ€๐Ÿ’ป Live detonation: https://app.any.run/tasks/1f6dd152-8b8c-427d-8b9d-b6dddd5ffb4b/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=phantomenigma_case&amp;utm_content=linktoservice&amp;utm_term=210726 The full report covers what your SOC needs: IOC...

  • View post

    Phishing activity in the past 7 days ๐ŸŸ Track latest #phishing threats in TI Lookup: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=top_phishing&amp;utm_content=linktoti&amp;utm_term=210726#%7B%2522query%2522:%2522threatName:%255C%2522%5Ephishing$%255C%2522%2522,%2522dateRange%2522:180%7D โ—๏ธ Here&#39;s what your SOC needs to know about rising Greatness phishkit: https://any.run/malware-trends/greatness/?utm_source=mastodon&amp;utm_medium=pos...

  • View post

    โš ๏ธ Malware activity remains concentrated around a familiar set of families, even as their positions continue to shift week by week. ๐Ÿ“Œ Trend to watch: today&#39;s challenge isn&#39;t keeping up with an endless stream of new malware names. It&#39;s recognizing when familiar threats change pace, because those shifts often influence where analysts need to focus first. Monitor the malware driving todayโ€™s attacks: https://any.run/malware-trends/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaig...

  • View post

    โœ๏ธ &quot;Timely sandboxing prevented the company from suffering millions of dollars in losses, damaged reputation, and years of litigation.&quot; โ€” Head of SOC, Investment bank ๐Ÿ“– See how #ANYRUN accelerates SOC triage at enterprise scale: https://any.run/enterprise/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=triage_challenges&amp;utm_content=linktoenterprise&amp;utm_term=170726

  • View post

    ๐Ÿšจ PhantomEnigma Hijacked 20+ Government Websites to Deliver Malware. #ANYRUN connected hundreds of unrelated &quot;generic&quot; samples into a coordinated operation targeting public sector. โ—๏ธ Campaign is active. Read the report and hunt with the IOCs: https://any.run/cybersecurity-blog/phantomenigma-research/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=phantomenigma_research&amp;utm_content=linktoblog&amp;utm_term=160726

  • View post

    ๐Ÿšจ Kratos PhaaS puts Microsoft 365 accounts across the US and Europe at risk. Your team may detect the phishing page and still miss the wider operation behind it โ—๏ธ See how to detect Kratos faster and contain account compromise before it leads to fraud or data exposure: https://any.run/cybersecurity-blog/kratos-phaas-account-takeover/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=kratos_phaas_account_takeover&amp;utm_content=linktoblog&amp;utm_term=140726

  • View post

    ๐ŸšจCrypto theft, ransomware, and full system takeover โ€” Neptune RAT poses real business destruction risk via everyday platforms. ๐Ÿ‘จโ€๐Ÿ’ป Essential reading for SOC teams on evolution, IOCs &amp; defenses: https://any.run/malware-trends/neptunerat/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=neptunerat&amp;utm_term=130726&amp;utm_content=linktomtt

  • View post

    ๐Ÿšจ Weโ€™re tracking increased #DestinyStealer activity targeting organizations across Europe and the US. โš ๏ธ At the code level, it acts as an all-in-one grabber, with clear code continuity from StormKitty, collecting browser data, cookies, passwords, wallet extension storage, Outlook, VPN and FileZilla data, Wi-Fi profiles, and desktop screenshots. โ—๏ธ Some samples were still undetected on VirusTotal at the time of analysis, while others lacked clear attribution, making behavior-based analysis critic...

  • View post

    โ“ Which cyber threats should your SOC prioritize today? ๐Ÿ“ˆ Explore the Top 30 threats targeting US organizations, based on fresh data from #ANYRUN Malware Trends Tracker and learn how to analyze and detect them faster with Interactive Sandbox and Threat Intelligence. Read the full report: https://any.run/cybersecurity-blog/usa-top-30-threats-2026/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=usa_top_30_threats_2026&amp;utm_content=linktoblog&amp;utm_term=090726

  • View post

    โœ… Check your SOC workflow against this checklist. If any stage rebuilds what the previous one already found โ€” the process is inefficient. #ANYRUN provides actionable &amp; sharable context at every stage โšก ๐ŸŽฏ How to use connected intelligence in your SOC: https://any.run/cybersecurity-blog/streamline-your-soc/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=workflow_checklist&amp;utm_content=linktoblog&amp;utm_term=090726

  • View post

    ๐Ÿ’ฐ Security gaps cost more when governance, detection, and response operate separately. Learn how CISOs can apply NIST CSF 2.0 with #ANYRUN to reduce exposure, speed up investigations, and turn security operations into measurable risk reduction โšก๏ธ Read now: https://any.run/cybersecurity-blog/nist-csf-guide-for-cisos/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=nist_csf_guide_for_cisos&amp;utm_content=linktomtt&amp;utm_term=080726