ANY.RUN
anyrun_app@infosec.exchange
<p>Empowering businesses with proactive security solutions: Interactive Sandbox, TI Lookup and Feeds.</p>
Posts
-
View post
โ ๏ธ Malware activity increased across nearly every major family last week. RATs like #Remcos and #AgentTesla, stealers like #Stealc and #Lumma, and loaders like #DonutLoader all gained momentum. ๐ Trend to watch: activity is accelerating across the threat landscape rather than around a single malware family, pointing to broader attacker activity rather than isolated campaigns. Monitor the malware driving todayโs attacks: https://any.run/malware-trends/?utm_source=mastodon&utm_medium=post&...
-
View post
๐ฆ Financial institutions are the #1 target for ransomware, credential theft, and social engineering. A SOC at an investment bank prevented hundreds of attempts with #ANYRUN. ๐ See how to strengthen security for banks: https://any.run/by-industry/finance/?utm_source=mastodon&utm_medium=post&utm_campaign=finance_success_story&utm_term=060826&utm_content=linktofinancelanding
-
View post
Phishing activity in the past 7 days ๐ Track latest #phishing threats in TI Lookup: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=top_phishing&utm_content=linktoti&utm_term=040826#%7B%2522query%2522:%2522threatName:%255C%2522%5Ephishing$%255C%2522%2522,%2522dateRange%2522:180%7D
-
View post
๐จ #PhantomEnigma hijacks .gov.br portals to deliver backdoors while bypassing SPF, DKIM, and DMARC. Companies it targets face banking fraud and persistent RMM access โ ๏ธ Update your SOC defense with our actionable research: https://any.run/malware-trends/PhantomEnigma/?utm_source=mastodon&utm_medium=post&utm_campaign=phantomenigma_mtt&utm_term=030826&utm_content=linktomtt
-
View post
โ ๏ธ While most leading malware families declined last week, #DonutLoader and #AgentTesla continued to grow. ๐ Trend to watch: quieter weeks don't affect every threat equally. Tracking which malware families continue to gain momentum helps SOC teams spot changes in attacker activity early. Monitor the malware driving todayโs attacks: https://any.run/malware-trends/?utm_source=mastodon&utm_medium=post&utm_campaign=top_ten&utm_term=030826&utm_content=linktomtt #Top10Malware
-
View post
One fake download page โก๏ธ full remote access to your network โ ๏ธ SnappyClient shows how quickly a single click can turn into stolen credentials, hijacked payments, and a foothold attackers can exploit long after the initial breach. ๐จโ๐ป Learn more: https://any.run/malware-trends/snappyclient/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=snappyclient&amp;utm_content=linktomtt&amp;utm_term=200726 #cybersecurity #infosec
-
View post
โก You are one integration away from unique threat intelligence powered by a global community of 600K analysts. Bring #ANYRUN directly into your SIEM, SOAR, or EDR. ๐ Find your vendor and strengthen your security stack with #ANYRUN: https://any.run/integrations/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=all_integrations_connectors&amp;utm_content=linktointegrations&amp;utm_term=230726
-
View post
Phishing activity in the past 7 days ๐ Track latest #phishing threats in TI Lookup: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=top_phishing&amp;utm_content=linktoti&amp;utm_term=280726#%7B%2522query%2522:%2522threatName:%255C%2522%5Ephishing$%255C%2522%2522,%2522dateRange%2522:180%7D โ๏ธ Here&#39;s what your SOC needs to know about rising EvilTokens: https://any.run/malware-trends/eviltokens/?utm_source=mastodon&a...
-
View post
โก To detect emerging threats in Microsoft Sentinel you need fresh, unique intelligence. Thatโ what #ANYRUN TI Feeds deliver โ live IOCs from sandbox analysis, 99% unique, real-time. ๐ See how #ANYRUN strengthens your Microsoft Sentinel environment: https://any.run/integrations/microsoft-sentinel-integration/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=feeds_sentinel_integration&amp;utm_term=300726&amp;utm_content=linktointegrations #cybersecurity #infosec
-
View post
๐จ A malicious LNK disguised as a PDF leads to DARTHVADER stealer deployment &amp; persistence, turning a document-like lure into post-click compromise. Observed behavior: LOLBin and AutoIt execution, hidden cmd.exe activity, curl.exe downloads, PowerShell ExecutionPolicy Bypass, mutex creation, cmd.exe /V:ON for delayed environment variable expansion, and /D to disable AutoRun command processing. โ๐ป Live detonation and IOCs for detection &amp; response: https://app.any.run/tasks/81...
-
View post
๐ฏ What changed in #ANYRUNโs threat coverage this July? 750+ new Suricata, YARA, and behavior rules help detect threats faster & cut manual work. Plus, a new TI Report and research into emerging threats. See how updates can strengthen your SOC response๐ https://any.run/cybersecurity-blog/july-threat-coverage-2026/?utm_source=mastodon&utm_medium=article&utm_campaign=july_threat_coverage_2026&utm_term=300726&utm_content=linktoblog
-
View post
๐ก๏ธ More cyber risk should not mean more SOC headcount. With 514K+ US cybersecurity jobs, $132K+ analyst salaries, and hiring cycles of up to 6 months, CFOs need a smarter way to grow security capacity. How to strengthen the SOC without growing payroll ๐ https://any.run/cybersecurity-blog/cfo-cyber-risk-playbook/?utm_source=mastodon&utm_medium=post&utm_campaign=cfo_cyber_risk_playbook&utm_term=290726&utm_content=linktoblog #cybersecurity #infosec
-
View post
โ A US manufacturer had 200+ active vendors with no consistent way to validate incoming files. ๐ฅ #ANYRUN gave the team behavioral evidence which made triage 2x faster and significant reduction in escalations. ๐ See how to manage third-party risk: https://any.run/by-industry/manufacturing/?utm_source=mastodon&utm_medium=post&utm_campaign=manufacturing_real_case&utm_term=290726&utm_content=linktoblog
-
View post
๐ Can your SOC investigate #phishing that leaves no malicious files behind? Modern AiTM attacks live inside the browser. Discover how browser visibility and threat intelligence expose what file-based analysis can't ๐ https://any.run/cybersecurity-blog/enterprise-phishing-resilience/?utm_source=mastodon&utm_medium=post&utm_campaign=enterprise_phishing_resilience&utm_term=280726&utm_content=linktoblog #cybersecurity #infosec
-
View post
๐จ #Kratos was recently dismantled, but it remains a blueprint for active phishing kits. PhaaS platforms continue to use the same methods to bypass MFA and hijack Microsoft 365 sessions. โก๏ธ Update defense against evolving session-theft threats: https://any.run/malware-trends/kratos/?utm_source=mastodon&utm_medium=post&utm_campaign=kratos_mtt&utm_term=270726&utm_content=linktomtt #cybersecurity #infosec
-
View post
โ ๏ธ #XWorm climbed into the week's top three, while #Formbook posted one of the strongest gains among the most active malware families. ๐ Trend to watch: As familiar threats change position, they can alter which malware analysts encounter most frequently and where detection efforts need the closest attention. Monitor the malware driving todayโs attacks: https://any.run/malware-trends/?utm_source=mastodon&utm_medium=post&utm_campaign=top_ten&utm_term=270726&utm_content=linktom...
-
View post
โ๏ธ Kratos, one of the major M365 PhaaS operations, has been disrupted by German & US law enforcement. 200+ servers were taken down, according to BKA. Good news, but PhaaS operators rebrand, affiliates switch kits, and the same workflows return in new campaigns ๐จ ๐ Our report breaks down the phishing flow, infrastructure patterns, artifacts, and detection logic analysts can reuse when investigating similar campaigns: https://any.run/cybersecurity-blog/kratos-phaas-account-takeover/?utm_sourc...
-
View post
๐จ ๐๐๐๐ฎ๐ฐ๐ธ๐ฒ๐ฟ ๐๐ฎ ๐๐ผ๐ป๐๐ฟ๐ผ๐น ๐๐ฎ๐๐ด๐ต๐ ๐ผ๐ป ๐ฎ ๐๐ถ๐๐ฒ ๐ฆ๐๐๐๐ฒ๐บ. Interactive analysis let us capture what static detonation misses โ ๏ธ ๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ ๐๐ฎ๐ฟ๐ด๐ฒ๐๐ถ๐ป๐ด: ๐๐ฒ๐ฟ๐บ๐ฎ๐ป๐ ๐ฎ๐ป๐ฑ ๐จ๐ โ๏ธ The operator connected to the infected system, uploaded the next-stage payload, and triggered a full chain: we.exe PythonRAT โก๏ธ exo.exe dropper โก๏ธ Lenovo FnHotkeyUtility.exe โก๏ธ spkvol.dll sideloading โก๏ธ Rust loader โก๏ธ In-memory OVERLORD RAT. ๐ฅ The initial implant was only the entry point. The real risk appeared later: DLL sideloading, in-memory ex...
-
View post
๐จ #Kali365 is targeting US organizations through device code phishing hidden behind legitimate Microsoft authentication. One approved code can expose business email and data, leading to fraud and costly response. ๐จโ๐ป See an example of a SharePoint-themed lure & gather IOCs: https://app.any.run/tasks/d078f430-c3cc-44e8-a809-5506205049c3/?utm_source=mastodon&utm_medium=post&utm_campaign=kali365_phishing_targeting_us&utm_term=210726&utm_content=linktoservice Explore the attack...
-
View post
๐จ The malware arrives as a legal file from a police department email and passes SPF, DKIM, and DMARC. What's inside: a Delphi/Inno Setup installer dropping PhantomEnigma's JS backdoor that beacons, persists, and executes on command. ๐จโ๐ป Live detonation: https://app.any.run/tasks/1f6dd152-8b8c-427d-8b9d-b6dddd5ffb4b/?utm_source=mastodon&utm_medium=post&utm_campaign=phantomenigma_case&utm_content=linktoservice&utm_term=210726 The full report covers what your SOC needs: IOC...
-
View post
Phishing activity in the past 7 days ๐ Track latest #phishing threats in TI Lookup: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=top_phishing&utm_content=linktoti&utm_term=210726#%7B%2522query%2522:%2522threatName:%255C%2522%5Ephishing$%255C%2522%2522,%2522dateRange%2522:180%7D โ๏ธ Here's what your SOC needs to know about rising Greatness phishkit: https://any.run/malware-trends/greatness/?utm_source=mastodon&utm_medium=pos...
-
View post
โ ๏ธ Malware activity remains concentrated around a familiar set of families, even as their positions continue to shift week by week. ๐ Trend to watch: today's challenge isn't keeping up with an endless stream of new malware names. It's recognizing when familiar threats change pace, because those shifts often influence where analysts need to focus first. Monitor the malware driving todayโs attacks: https://any.run/malware-trends/?utm_source=mastodon&utm_medium=post&utm_campaig...
-
View post
โ๏ธ "Timely sandboxing prevented the company from suffering millions of dollars in losses, damaged reputation, and years of litigation." โ Head of SOC, Investment bank ๐ See how #ANYRUN accelerates SOC triage at enterprise scale: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=triage_challenges&utm_content=linktoenterprise&utm_term=170726
-
View post
๐จ PhantomEnigma Hijacked 20+ Government Websites to Deliver Malware. #ANYRUN connected hundreds of unrelated "generic" samples into a coordinated operation targeting public sector. โ๏ธ Campaign is active. Read the report and hunt with the IOCs: https://any.run/cybersecurity-blog/phantomenigma-research/?utm_source=mastodon&utm_medium=post&utm_campaign=phantomenigma_research&utm_content=linktoblog&utm_term=160726
-
View post
๐จ Kratos PhaaS puts Microsoft 365 accounts across the US and Europe at risk. Your team may detect the phishing page and still miss the wider operation behind it โ๏ธ See how to detect Kratos faster and contain account compromise before it leads to fraud or data exposure: https://any.run/cybersecurity-blog/kratos-phaas-account-takeover/?utm_source=mastodon&utm_medium=post&utm_campaign=kratos_phaas_account_takeover&utm_content=linktoblog&utm_term=140726
-
View post
๐จCrypto theft, ransomware, and full system takeover โ Neptune RAT poses real business destruction risk via everyday platforms. ๐จโ๐ป Essential reading for SOC teams on evolution, IOCs & defenses: https://any.run/malware-trends/neptunerat/?utm_source=mastodon&utm_medium=post&utm_campaign=neptunerat&utm_term=130726&utm_content=linktomtt
-
View post
๐จ Weโre tracking increased #DestinyStealer activity targeting organizations across Europe and the US. โ ๏ธ At the code level, it acts as an all-in-one grabber, with clear code continuity from StormKitty, collecting browser data, cookies, passwords, wallet extension storage, Outlook, VPN and FileZilla data, Wi-Fi profiles, and desktop screenshots. โ๏ธ Some samples were still undetected on VirusTotal at the time of analysis, while others lacked clear attribution, making behavior-based analysis critic...
-
View post
โ Which cyber threats should your SOC prioritize today? ๐ Explore the Top 30 threats targeting US organizations, based on fresh data from #ANYRUN Malware Trends Tracker and learn how to analyze and detect them faster with Interactive Sandbox and Threat Intelligence. Read the full report: https://any.run/cybersecurity-blog/usa-top-30-threats-2026/?utm_source=mastodon&utm_medium=post&utm_campaign=usa_top_30_threats_2026&utm_content=linktoblog&utm_term=090726
-
View post
โ Check your SOC workflow against this checklist. If any stage rebuilds what the previous one already found โ the process is inefficient. #ANYRUN provides actionable & sharable context at every stage โก ๐ฏ How to use connected intelligence in your SOC: https://any.run/cybersecurity-blog/streamline-your-soc/?utm_source=mastodon&utm_medium=post&utm_campaign=workflow_checklist&utm_content=linktoblog&utm_term=090726
-
View post
๐ฐ Security gaps cost more when governance, detection, and response operate separately. Learn how CISOs can apply NIST CSF 2.0 with #ANYRUN to reduce exposure, speed up investigations, and turn security operations into measurable risk reduction โก๏ธ Read now: https://any.run/cybersecurity-blog/nist-csf-guide-for-cisos/?utm_source=mastodon&utm_medium=post&utm_campaign=nist_csf_guide_for_cisos&utm_content=linktomtt&utm_term=080726