Elektrine
EN
Log in Register
Paige Chat Timeline Gallery Friends Lists Email Drive DNS Resolver Domains VPN Kairo Nerve
Remote

ANY.RUN

@anyrun_app@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Empowering businesses with proactive security solutions: Interactive Sandbox, TI Lookup and Feeds.

267 Followers
34 Following
50 Posts
Joined November 19, 2024
Sign up:
https://app.any.run/?utm_source=mastodon
Website:
https://any.run/?utm_source=mastodon&utm_campaign=bio
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 2mo ago
🚨 The malware arrives as a legal file from a police department email and passes SPF, DKIM, and DMARC. What's inside: a Delphi/Inno Setup installer dropping PhantomEnigma's JS backdoor that beacons, persists, and executes on command. 👨‍💻 Live detonation: https://app.any.run/tasks/1f6dd152-8b8c-427d-8b9d-b6dddd5ffb4b/?utm_source=mastodon&utm_medium=post&utm_campaign=phantomenigma_case&utm_content=linktoservice&utm_term=210726 The full report covers what your SOC needs: IOCs, YARA hunting rules, TI Lookup queries to track new compromised hosts, Suricata signatures, and MITRE ATT&CK mapping 👇https://any.run/cybersecurity-blog/phantomenigma-research/?utm_source=discord&utm_medium=post&utm_campaign=phantomenigma_case&utm_content=linktoblog&utm_term=210726 #cybersecurity #infosec
2
0
1
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 3mo ago

🚨 𝗙𝗮𝗸𝗲 𝗖𝗹𝗮𝘂𝗱𝗲 & 𝗖𝗼𝗱𝗲𝘅 𝗗𝗲𝗹𝗶𝘃𝗲𝗿 𝗜𝗻-𝗠𝗲𝗺𝗼𝗿𝘆 𝗦𝘁𝗲𝗮𝗹𝗲𝗿: 𝗖𝗹𝗶𝗰𝗸𝗙𝗶𝘅 𝘃𝗶𝗮 𝗚𝗼𝗼𝗴𝗹𝗲 𝗦𝗶𝘁𝗲𝘀
⚠️ We’re tracking a #ClickFix campaign that mimics popular AI tools, including Codex and Claude, and abuses trusted Google Sites infrastructure to deliver stealer #malware.

With no standalone executable dropped to disk and network activity appearing as legitimate powershell.exe traffic, the attack can significantly reduce visibility during the early stages of compromise.

❗️ Victims are directed to trusted sites[.]google[.]com pages and instructed to execute an mshta command. The attack results in in-memory stealer execution, theft of browser, email, and cryptocurrency wallet data, and outbound communication with attacker-controlled C2 infrastructure, while leaving fewer traditional detection opportunities for SOC teams.

Execution chain:
Trusted Google Sites lure ➡️ User-executed mshta command ➡️ Multi-stage PowerShell delivery ➡️ Steganographic payload extraction from image ➡️ Shellcode deployment ➡️ In-memory execution inside powershell.exe ➡️ Browser, email & wallet data theft ➡️ C2 exfiltration

👨‍💻 Using #ANYRUN Sandbox, investigate the full ClickFix execution chain, validate detection coverage, and observe PowerShell staging, steganographic payload delivery, and credential theft activity. Explore the analysis sessions and collect IOCs:
🔹 Codex lure: https://app.any.run/tasks/151cfb30-5ef2-4962-a90e-58a59ecc43da/?utm_source=mastodon&utm_medium=post&utm_campaign=claude_codex_clickfix&utm_term=030626&utm_content=linktoservice
🔹 Claude lure: https://app.any.run/tasks/698e0bd5-01b6-40fe-814c-5c0885cea645/?utm_source=mastodon&utm_medium=post&utm_campaign=claude_codex_clickfix&utm_term=030626&utm_content=linktoservice

🔍 Track related ClickFix activity in #ANYRUN TI Lookup, identify additional Codex and Claude lures, and uncover related AI-themed ClickFix activity and infrastructure:
🔹 https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=claude_codex_clickfix&utm_content=030626&utm_term=linktotilookup#%7B%2522query%2522:%2522url:%255C%2522https:/sites.google.com/*/cdx%255C%2522%2520or%2520url:%255C%2522https:/sites.google.com/*/clau%255C%2522%2522,%2522dateRange%2522:7%7D
🔹 https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=claude_codex_clickfix&utm_content=030626&utm_term=linktotilookup#%7B%22query%22:%22ruleName:%5C%22AI-themed%20ClickFix%20phishing%20page%20has%20been%20detected%5C%22%22,%22dateRange%22:14%7D

🚀 Equip your SOC with stronger phishing detection and contain incidents faster: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=claude_codex_clickfix&utm_term=030626&utm_content=linktoenterprise

#cybersecurity #infosec

4
0
2
1
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 3mo ago

❓ How does a lean SOC team protect 50,000+ users?

🎓 UMass Boston backs its security decisions with #ANYRUN Sandbox, triaging threats in seconds and stopping costly incidents before impact.

Read the customer story and see how you can achieve the same👇
https://any.run/cybersecurity-blog/umass-boston-success-story/?utm_source=mastodon&utm_medium=post&utm_campaign=umass_boston_success_story&utm_term=090626&utm_content=linktoblog

1
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 3mo ago

🔥 Q1 2026 Cyber Risk report by #ANYRUN is out!

Explore the cyber risks and threat shifts for CISOs, including:
❗️ +14.7% credential theft
❗️ +98.3% loader attacks
❗️ +58.4% LOLBAS attacks

Turn Q1 intel into Q2 security priorities. Get the report: https://any.run/cybersecurity-blog/cyber-risk-report-q1-2026/?utm_source=mastodon&utm_medium=post&utm_campaign=cyber_risk_report_q1_2026&utm_content=linktoreport&utm_term=040626

#cybersecurity #infosec

1
0
1
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 2mo ago

One fake download page ➡️ full remote access to your network ⚠️

SnappyClient shows how quickly a single click can turn into stolen credentials, hijacked payments, and a foothold attackers can exploit long after the initial breach.

👨‍💻 Learn more: https://any.run/malware-trends/snappyclient/?utm_source=mastodon&utm_medium=post&utm_campaign=snappyclient&utm_content=linktomtt&utm_term=200726

#cybersecurity #infosec

0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 1mo ago

Phishing activity in the past 7 days 🐟
Track latest #phishing threats in TI Lookup: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=top_phishing&utm_content=linktoti&utm_term=280726#%7B%2522query%2522:%2522threatName:%255C%2522%5Ephishing$%255C%2522%2522,%2522dateRange%2522:180%7D

❗️ Here's what your SOC needs to know about rising EvilTokens: https://any.run/malware-trends/eviltokens/?utm_source=mastodon&utm_medium=post&utm_campaign=top_phishing&utm_content=linktomtt&utm_term=280726

Infosec Exchange

0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 2mo ago
⚠️ #AsyncRAT activity nearly doubled last week, while most other high-volume malware families remained stable or declined. At the same time, #ClearFake, #SalatStealer, and #DiscordNuker saw notable growth. 📌 Trend to watch: a sharp increase in one dominant malware family can easily overshadow emerging threats. For SOC teams, that means watching relative growth, not just the highest volumes. Monitor the malware driving today’s attacks: https://any.run/malware-trends/?utm_source=mastodon&utm_medium=post&utm_campaign=top_ten&utm_term=60726&utm_content=linktomtt #Top10Malware
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 2mo ago
Replying to @anyrun_app@infosec.exchange
🎯 IOCs and behavioral patterns: Python RAT (Stage 1): C2: live.rnsn[.]live → 69.169.111[.]81, TCP 8585 HTTP request markers: GET /International, X-Secret: 12345, Host: www.porsche[.]com, Referer: /|1.1.3 HTTP response decoy markers: Fullscreen Spinner + commands encoded in comment strings OVERLORD RAT (Stage 2): C2: lord.kirkdridebridge[.]com → 163.245.218[.]93, TCP 5173, mTLSv1.3 channel encryption Host artifacts: C:\Users\Public\Windows\win32\we.exe …\run.vbs …\win6\exo.exe .cmd C:\ProgramData\sysid.txt (we.exe bot UUID) C:\ProgramData\DeepSkyBlueIndianRed\* → FnHotkeyUtility.exe, spkvol.dll, ludp.dll, msvcp140.dll, vcruntime140*.dll dropped executables Registry: HKCU...\Run: SkypeUpd=…\win32\we.exe HKCU...\Run: Winrarservice=…\win32\run.vbs Mutexes: Global\Overlord-1_oVC9y33fSmT7DVUv0HJn9Y (ForestGreenLightSlateGray object) Inno Setup cmdline password: f1846950-ca2f-4f9b-bd08-4807e431faa9 SHA256: 38cec7299bcbcc334633c87de5ed0d8355df8c73fadd26a8b5ca3862c2ea4357 (we.exe) 6805a1cb9b26b629f94aa3cf062e78eb4a5d259f459c0d8ca5a43cc08b16154b (client1.1.3.pyc) 7f53b7a21ba1418f56afac2f5f9db18bcca48d0c9ab7c3bee15a01db57d5fe5c (exo.exe) 9ab2f85ab539cea0f868c0b2a5219c3a8ccfef5365d74cc2cd455cb06d243f65 (upd.exe) 31c97b6e93112cae7bfce17d5979ccd513111b74165fc6ef471a9f8c821ae879 (spkvol.dll) 📝 MITRE ATT&CK: T1059 — Command and Scripting Interpreter T1105 — Ingress Tool Transfer T1547.001 — Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder T1027 — Obfuscated Files or Information T1574.002 — Hijack Execution Flow: DLL Side-Loading T1113 — Screen Capture T1123 — Audio Capture T1056.001 — Input Capture: Keylogging T1041 — Exfiltration Over C2 Channel
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 2mo ago
🚨Crypto theft, ransomware, and full system takeover — Neptune RAT poses real business destruction risk via everyday platforms. 👨‍💻 Essential reading for SOC teams on evolution, IOCs & defenses: https://any.run/malware-trends/neptunerat/?utm_source=mastodon&utm_medium=post&utm_campaign=neptunerat&utm_term=130726&utm_content=linktomtt
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 1mo ago
🎯 What changed in #ANYRUN’s threat coverage this July? 750+ new Suricata, YARA, and behavior rules help detect threats faster & cut manual work. Plus, a new TI Report and research into emerging threats. See how updates can strengthen your SOC response👇 https://any.run/cybersecurity-blog/july-threat-coverage-2026/?utm_source=mastodon&utm_medium=article&utm_campaign=july_threat_coverage_2026&utm_term=300726&utm_content=linktoblog
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 1mo ago
❗️ Kratos, one of the major M365 PhaaS operations, has been disrupted by German & US law enforcement. 200+ servers were taken down, according to BKA. Good news, but PhaaS operators rebrand, affiliates switch kits, and the same workflows return in new campaigns 🚨 🔍 Our report breaks down the phishing flow, infrastructure patterns, artifacts, and detection logic analysts can reuse when investigating similar campaigns: https://any.run/cybersecurity-blog/kratos-phaas-account-takeover/?utm_source=mastodon&utm_medium=post&utm_campaign=kratos_phaas_takedown&utm_content=linktoblog&utm_term=230726 #cybersecurity #infosec
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 3mo ago

🎯 Threat hunting breaks when teams prioritize hypotheses based on assumptions instead of actual threats targeting their business.

For example, if you're protecting a U.S. financial organization, start with: 𝘀𝘂𝗯𝗺𝗶𝘀𝘀𝗶𝗼𝗻𝗖𝗼𝘂𝗻𝘁𝗿𝘆:"𝗨𝗦" 𝗔𝗡𝗗 𝗶𝗻𝗱𝘂𝘀𝘁𝗿𝘆:"𝗳𝗶𝗻𝗮𝗻𝗰𝗲"
🔍 Run the search in #ANYRUN TI Lookup: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=threat_hunting_practical_usecases&utm_term=100226&utm_content=linktolookup/#%7B%2522query%2522:%2522submissionCountry:%255C%2522US%255C%2522%2520and%2520industry:%255C%2522finance%255C%2522%2522,%2522dateRange%2522:180%7D

You'll see malware families, phishing campaigns, and attack techniques observed targeting organizations in your sector, helping prioritize hunts based on real attacker activity rather than broad industry reports.

👨‍💻 Learn how SOCs & MSSPs build hunts around observed threats to reduce wasted effort and focus on real business risk: https://any.run/cybersecurity-blog/threat-hunting-practical-usecases/?utm_source=mastodon&utm_medium=post&utm_campaign=threat_hunting_practical_usecases&utm_term=100226&utm_content=linktoblog

0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 2mo ago
Phishing activity in the past 7 days 🐟 Track latest #phishing threats in TI Lookup: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=top_phishing&utm_content=linktoti&utm_term=210726#%7B%2522query%2522:%2522threatName:%255C%2522%5Ephishing$%255C%2522%2522,%2522dateRange%2522:180%7D ❗️ Here's what your SOC needs to know about rising Greatness phishkit: https://any.run/malware-trends/greatness/?utm_source=mastodon&utm_medium=post&utm_campaign=top_phishing&utm_content=linktomtt&utm_term=210726 #cybersecurity #infosec
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 2mo ago
🚨 We’re tracking increased #DestinyStealer activity targeting organizations across Europe and the US. ⚠️ At the code level, it acts as an all-in-one grabber, with clear code continuity from StormKitty, collecting browser data, cookies, passwords, wallet extension storage, Outlook, VPN and FileZilla data, Wi-Fi profiles, and desktop screenshots. ❗️ Some samples were still undetected on VirusTotal at the time of analysis, while others lacked clear attribution, making behavior-based analysis critical for SOC teams. The attack starts with an IP check via ipinfo[.]io. The malware then creates a temporary directory at %TEMP%\\ for data collection. The collected data is then packed into %TEMP%\.zip. Exfiltration uses two parallel channels: HTTP to destinystealer[.]com/fileicin[.]php and raw TCP to tipidor-38534[.]portmap[.]host. 👨‍💻 See the full execution chain and collect IOCs to speed up detection and cut response time: https://app.any.run/tasks/01f70f9e-642d-46fa-b485-cf67dced6436/?utm_source=mastodon&utm_medium=post&utm_campaign=destiny_stealer&utm_content=linktoservice&utm_term=090726 🔍 Pivot from IOCs and subscribe to Query Updates to proactively track evolving attacks: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=destiny_stealer&utm_content=linktotilookup&utm_term=090726#%7B%22query%22:%22threatName:%5C%22destinystealer%5C%22%22,%22dateRange%22:180%7D ⚡️ Learn how #ANYRUN Sandbox helps SOC teams detect complex threats early: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=destiny_stealer&utm_content=linktoenterpriselanding&utm_term=090726 IOCs 50008cd78878cb1b3c142e1fd60db55917b233465b8f3f6769ca862902af58bb ca288e609c5e4be27b95b10c4d11c29d3898ea632739dfeed3586b5049e21f26 3d840505ad13b082d6a8d52399ad52f6f0e79c07f25f55357cda09113010b30a Domains: destinystealer[.]com tipidor-38534[.]portmap[.]host Exfil URL: hxxps[:]//destinystealer[.]com/fileicin[.]php
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 2mo ago
✍️ "Timely sandboxing prevented the company from suffering millions of dollars in losses, damaged reputation, and years of litigation." — Head of SOC, Investment bank 📖 See how #ANYRUN accelerates SOC triage at enterprise scale: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=triage_challenges&utm_content=linktoenterprise&utm_term=170726
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 1mo ago
⚠️ While most leading malware families declined last week, #DonutLoader and #AgentTesla continued to grow. 📌 Trend to watch: quieter weeks don't affect every threat equally. Tracking which malware families continue to gain momentum helps SOC teams spot changes in attacker activity early. Monitor the malware driving today’s attacks: https://any.run/malware-trends/?utm_source=mastodon&utm_medium=post&utm_campaign=top_ten&utm_term=030826&utm_content=linktomtt #Top10Malware
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 1mo ago
🛡️ More cyber risk should not mean more SOC headcount. With 514K+ US cybersecurity jobs, $132K+ analyst salaries, and hiring cycles of up to 6 months, CFOs need a smarter way to grow security capacity. How to strengthen the SOC without growing payroll 👇 https://any.run/cybersecurity-blog/cfo-cyber-risk-playbook/?utm_source=mastodon&utm_medium=post&utm_campaign=cfo_cyber_risk_playbook&utm_term=290726&utm_content=linktoblog #cybersecurity #infosec
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 2mo ago
⚠️ Malware activity remains concentrated around a familiar set of families, even as their positions continue to shift week by week. 📌 Trend to watch: today's challenge isn't keeping up with an endless stream of new malware names. It's recognizing when familiar threats change pace, because those shifts often influence where analysts need to focus first. Monitor the malware driving today’s attacks: https://any.run/malware-trends/?utm_source=mastodon&utm_medium=post&utm_campaign=top_ten&utm_term=200726&utm_content=linktomtt #cybersecurity #infosec
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 1mo ago
🏦 Financial institutions are the #1 target for ransomware, credential theft, and social engineering. A SOC at an investment bank prevented hundreds of attempts with #ANYRUN. 📈 See how to strengthen security for banks: https://any.run/by-industry/finance/?utm_source=mastodon&utm_medium=post&utm_campaign=finance_success_story&utm_term=060826&utm_content=linktofinancelanding
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 1mo ago
⚠️ Malware activity increased across nearly every major family last week. RATs like #Remcos and #AgentTesla, stealers like #Stealc and #Lumma, and loaders like #DonutLoader all gained momentum. 📌 Trend to watch: activity is accelerating across the threat landscape rather than around a single malware family, pointing to broader attacker activity rather than isolated campaigns. Monitor the malware driving today’s attacks: https://any.run/malware-trends/?utm_source=mastodon&utm_medium=post&utm_campaign=top_ten&utm_term=100826&utm_content=linktomtt #cybersecurity #infosec
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 1mo ago
🚨 #Kratos was recently dismantled, but it remains a blueprint for active phishing kits. PhaaS platforms continue to use the same methods to bypass MFA and hijack Microsoft 365 sessions. ⚡️ Update defense against evolving session-theft threats: https://any.run/malware-trends/kratos/?utm_source=mastodon&utm_medium=post&utm_campaign=kratos_mtt&utm_term=270726&utm_content=linktomtt #cybersecurity #infosec
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 3mo ago

🚨 #JSMonoGlyphRAT: The Persistent Backdoor Targeting US Businesses

A new backdoor is actively targeting enterprises through #phishing emails disguised as purchase orders, quotes, and business proposals. Most AV tools miss it entirely.

⚠️ Confirmed victims include organizations in the technology, telecom, education, and MSSP sectors. Once inside, attackers can deploy ransomware, steal data, and cause costly business disruption.

👨‍💻 Investigate the attack chain and persistence mechanisms in a sandbox session: https://app.any.run/tasks/e39d92e9-a8c3-4c71-8009-2087847fb669/?utm_source=mastodon&utm_medium=post&utm_campaign=monoglyphrat_attacks_us_enterprise&utm_term=020626&utm_content=linktoservice

📌 Learn how to detect JSMonoGlyphRAT before it turns into business impact: https://any.run/cybersecurity-blog/monoglyphrat-attacks-us-enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=monoglyphrat_attacks_us_enterprise&utm_term=020626&utm_content=linktoblog

#cybersecurity #infosec

0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 3mo ago

⚠️ In Q1 2026, phishing kits captured sessions using proxy authentication flows in real time.

It's hard to detect, because SOCs see no traditional indicator of compromise.

🎯 Learn how to improve phishing defense in Q1 Cyber Risk Report: https://files.any.run/images/q1_2026_cyber_risk_report_from_anyrun.pdf?utm_source=mastodon&utm_medium=post&utm_campaign=cyber_risk_report_1&utm_content=linktoreport&utm_term=090626

#cybersecurity #infosec

0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 3mo ago

⚠️ Fake event invitation #phishing bypasses standard automated scanners by hiding credential theft and unauthorized RMM delivery behind a routine CAPTCHA check, creating delayed detection risks for CISOs.

In a large-scale campaign targeting U.S. organizations, attackers deploy a repeatable framework with fixed resource paths to compromise mailboxes, intercept OTP codes, and deploy RMM tools for persistent access. See the full attack flow and process tree in an analysis session: https://app.any.run/tasks/4c2687da-1426-43c3-8e16-868f90fb9361/?utm_source=mastodon&utm_medium=post&utm_campaign=US_fake_invitation_phishing_case&utm_term=040626&utm_content=linktoservice

🎯 Read our technical breakdown to explore how SOC teams can use these huntable infrastructure signals to validate threats faster and get the complete IOC list: https://any.run/cybersecurity-blog/us-fake-invitation-phishing/?utm_source=mastodon&utm_medium=post&utm_campaign=US_fake_invitation_phishing_case&utm_term=040626&utm_content=linktoblog

#cybersecurity #infosec

Infosec Exchange

0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 3mo ago

Phishing activity in the past 7 days 🐟
Track latest #phishing threats in TI Lookup: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=top_phishing&utm_content=linktoti&utm_term=090626#%7B%2522query%2522:%2522threatName:%255C%2522%5Ephishing$%255C%2522%2522,%2522dateRange%2522:180%7D

#cybersecurity #infosec

Infosec Exchange

0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 2mo ago
⚠️ Active in June 2026. PhaaS kits that bypass MFA and target US organizations via Microsoft 365 accounts. 🔹 Sneaky 2FA. Intercepts live M365 session cookies through a reverse proxy, bypassing MFA in real time: https://any.run/malware-trends/sneaky2fa/?utm_source=mastodon&utm_medium=post&utm_campaign=mfa_bypass_brief&utm_content=linktomtt&utm_term=080726 🔹 Tycoon 2FA. Survived the March 2026 Microsoft/Europol takedown and pivoted to OAuth Device Code phishing within weeks: https://any.run/malware-trends/tycoon/?utm_source=mastodon&utm_medium=post&utm_campaign=mfa_bypass_brief&utm_content=linktomtt&utm_term=080726 🔹 EvilTokens. Compromised 340+ M365 organizations in its first five weeks: https://any.run/malware-trends/eviltokens/?utm_source=mastodon&utm_medium=post&utm_campaign=mfa_bypass_brief&utm_content=linktomtt&utm_term=080726 ⚡️ Use the links above to sharpen your SOC's detection of each kit.
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 1mo ago
🚨 #PhantomEnigma hijacks .gov.br portals to deliver backdoors while bypassing SPF, DKIM, and DMARC. Companies it targets face banking fraud and persistent RMM access ⚠️ Update your SOC defense with our actionable research: https://any.run/malware-trends/PhantomEnigma/?utm_source=mastodon&utm_medium=post&utm_campaign=phantomenigma_mtt&utm_term=030826&utm_content=linktomtt
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 3mo ago

Day 1 at Infosecurity Europe 2026 is a wrap 🇬🇧 One theme kept coming up in conversations with security leaders today: investigation speed matters, but decision confidence matters even more.

We're showing how #ANYRUN helps enterprise SOCs & MSSPs shorten time to insight while giving teams the context needed to make faster, more confident response decisions ⚡️

📍 Find our team at Stand C62 and learn how behavioral analysis and live threat intelligence help reduce uncertainty throughout the investigation process.

🎟️ Get your ticket: https://infosecurityeurope.com/en-gb/register.html?code=1666079269821849-VCP

0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 1mo ago
⚠️ #XWorm climbed into the week's top three, while #Formbook posted one of the strongest gains among the most active malware families. 📌 Trend to watch: As familiar threats change position, they can alter which malware analysts encounter most frequently and where detection efforts need the closest attention. Monitor the malware driving today’s attacks: https://any.run/malware-trends/?utm_source=mastodon&utm_medium=post&utm_campaign=top_ten&utm_term=270726&utm_content=linktomtt #cybersecurity #infosec
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 1mo ago

⚡ You are one integration away from unique threat intelligence powered by a global community of 600K analysts.

Bring #ANYRUN directly into your SIEM, SOAR, or EDR.

🔗 Find your vendor and strengthen your security stack with #ANYRUN: https://any.run/integrations/?utm_source=mastodon&utm_medium=post&utm_campaign=all_integrations_connectors&utm_content=linktointegrations&utm_term=230726

0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 2mo ago
🚨 PhantomEnigma Hijacked 20+ Government Websites to Deliver Malware. #ANYRUN connected hundreds of unrelated "generic" samples into a coordinated operation targeting public sector. ❗️ Campaign is active. Read the report and hunt with the IOCs: https://any.run/cybersecurity-blog/phantomenigma-research/?utm_source=mastodon&utm_medium=post&utm_campaign=phantomenigma_research&utm_content=linktoblog&utm_term=160726
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 3mo ago

⚠️ Remote access malware remained resilient despite broader declines. #AsyncRAT continued to grow and #Remcos rebounded, while most other major families trended downward.

📌 Trend to watch: when fewer families account for a larger share of activity, defenders can miss the signal by focusing on overall volume alone. Concentrated campaigns often create repeated exposure to the same attack paths, increasing the likelihood of successful compromise.

Expand threat visibility in your SOC: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=top_ten&utm_term=080626&utm_content=linktoenterprise

#cybersecurity #infosec

0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 2mo ago
📨 200+ vendors were sending files into a US manufacturer’s environment. The problem: lack of context to separate safe files from real threats, driving up investigation costs. ⚡️ See how the company made MTTD 2x faster without adding headcount 👇 https://any.run/cybersecurity-blog/us-manufacturer-security-risk/?utm_source=mastodon&utm_medium=post&utm_campaign=us_manufacturer_security_risk&utm_term=300626&utm_content=linktoblog #cybersecurity #infosec
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 3mo ago

⚡️ SOAR can move an alert through a workflow but can't determine what a URL does.

#ANYRUN Sandbox adds behavioral analysis, helping validate threats earlier and reduce manual checks that slow triage & response.

How this works across SOC workflows 👇
https://any.run/cybersecurity-blog/integrating-sandbox-into-soar-workflows/?utm_source=mastodon&utm_medium=post&utm_campaign=sandbox_soar&utm_term=100626&utm_content=linktoblog

0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 1mo ago

⚡ To detect emerging threats in Microsoft Sentinel you need fresh, unique intelligence.

That’ what #ANYRUN TI Feeds deliver — live IOCs from sandbox analysis, 99% unique, real-time.

📈 See how #ANYRUN strengthens your Microsoft Sentinel environment: https://any.run/integrations/microsoft-sentinel-integration/?utm_source=mastodon&utm_medium=post&utm_campaign=feeds_sentinel_integration&utm_term=300726&utm_content=linktointegrations

#cybersecurity #infosec

0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 2mo ago
🚨 #Kali365 is targeting US organizations through device code phishing hidden behind legitimate Microsoft authentication. One approved code can expose business email and data, leading to fraud and costly response. 👨‍💻 See an example of a SharePoint-themed lure & gather IOCs: https://app.any.run/tasks/d078f430-c3cc-44e8-a809-5506205049c3/?utm_source=mastodon&utm_medium=post&utm_campaign=kali365_phishing_targeting_us&utm_term=210726&utm_content=linktoservice Explore the attack details to reduce the risk of data exposure: https://any.run/cybersecurity-blog/kali365-phishing-targeting-us/?utm_source=mastodon&utm_medium=post&utm_campaign=kali365_phishing_targeting_us&utm_term=210726&utm_content=linktoblog #cybersecurity #infosec
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 2mo ago
❓ Which cyber threats should your SOC prioritize today? 📈 Explore the Top 30 threats targeting US organizations, based on fresh data from #ANYRUN Malware Trends Tracker and learn how to analyze and detect them faster with Interactive Sandbox and Threat Intelligence. Read the full report: https://any.run/cybersecurity-blog/usa-top-30-threats-2026/?utm_source=mastodon&utm_medium=post&utm_campaign=usa_top_30_threats_2026&utm_content=linktoblog&utm_term=090726
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 2mo ago
✅ Check your SOC workflow against this checklist. If any stage rebuilds what the previous one already found — the process is inefficient. #ANYRUN provides actionable & sharable context at every stage ⚡ 🎯 How to use connected intelligence in your SOC: https://any.run/cybersecurity-blog/streamline-your-soc/?utm_source=mastodon&utm_medium=post&utm_campaign=workflow_checklist&utm_content=linktoblog&utm_term=090726
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 1mo ago
Phishing activity in the past 7 days 🐟 Track latest #phishing threats in TI Lookup: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=top_phishing&utm_content=linktoti&utm_term=040826#%7B%2522query%2522:%2522threatName:%255C%2522%5Ephishing$%255C%2522%2522,%2522dateRange%2522:180%7D
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 3mo ago

⚡ Faster SOC decisions and stronger threat visibility with #ANYRUN’s May updates.

Explore Tier 1 Reports, Elastic Security integration for fresh IOCs, and 1,400+ new detections 🛡️

Learn more and strengthen your SOC response now 👇
https://any.run/cybersecurity-blog/release-notes-may-2026/?utm_source=mastodon&utm_medium=post&utm_campaign=release-notes-may-2026&utm_term=030626&utm_content=linktoblog

0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 2mo ago
🚨 Kratos PhaaS puts Microsoft 365 accounts across the US and Europe at risk. Your team may detect the phishing page and still miss the wider operation behind it ❗️ See how to detect Kratos faster and contain account compromise before it leads to fraud or data exposure: https://any.run/cybersecurity-blog/kratos-phaas-account-takeover/?utm_source=mastodon&utm_medium=post&utm_campaign=kratos_phaas_account_takeover&utm_content=linktoblog&utm_term=140726
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 1mo ago
❗ A US manufacturer had 200+ active vendors with no consistent way to validate incoming files. 🔥 #ANYRUN gave the team behavioral evidence which made triage 2x faster and significant reduction in escalations. 📖 See how to manage third-party risk: https://any.run/by-industry/manufacturing/?utm_source=mastodon&utm_medium=post&utm_campaign=manufacturing_real_case&utm_term=290726&utm_content=linktoblog
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 2mo ago
💰 Security gaps cost more when governance, detection, and response operate separately. Learn how CISOs can apply NIST CSF 2.0 with #ANYRUN to reduce exposure, speed up investigations, and turn security operations into measurable risk reduction ⚡️ Read now: https://any.run/cybersecurity-blog/nist-csf-guide-for-cisos/?utm_source=mastodon&utm_medium=post&utm_campaign=nist_csf_guide_for_cisos&utm_content=linktomtt&utm_term=080726
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 2mo ago
🚨 Banana RAT is targeting finance with custom payloads. It hides in legitimate cloud traffic and bypasses static blocklists ⚠️ Update your defenses with research by Moises Cerqueira: https://any.run/cybersecurity-blog/banana-rat-evolution-analysis/?utm_source=mastodon&utm_medium=post&utm_campaign=banana_rat_evolution&utm_content=linktobloh&utm_term=070726
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 1w ago
Replying to @anyrun_app@infosec.exchange
💡 #ANYRUN TI Feeds turn IOCs into continuous monitoring by streaming fresh, validated indicators and behavior-based threat data into your security stack. 📋 IOCs: C2 documentsphotos[.]com getimageinformation[.]com openandopen[.]com openpdfanywhere[.]com Lure (TerminalFix) updatemsnow[.]com updatecurrent[.]com uptodatehere[.]com superwebprotection[.]com exclusivecloudprotection[.]com extrafireprotection[.]com Redirect / fingerprint daskljtitaskastvv[.]pro momsdodigital[.]com beroniw[.]com Dropper 2e86d7adf50329896e81ce0a3d5f2c2bd0cb957bc47c8a69078e25ff6a6d6bba Trojanized mscoree.dll 18e3bc2b57f0de6a14b6abd283fa964ffde5b85bc3985988b56acc0a212b2099 Persistence %PROGRAMDATA%\NET Runtime Optimization Service WtACgCrCWnJB\ HKCU\...\CurrentVersion\Run - "NET Runtime Optimization Service uD9n5qAinyOu"
0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 3mo ago

⚠️ #JOMANGY malware hijacks your FreePBX system and runs fraudulent calls on SIP trunks — billed to you.

❗️ 6 self-healing persistence layers. 700+ businesses still infected 5 months later. Is your PBX off the internet?

See the impact of this threat: https://any.run/malware-trends/jomangy/?utm_source=mastodon&utm_medium=post&utm_campaign=jomangy_mtt&utm_term=080626&utm_content=linktomtt

#cybersecurity #infosec

Infosec Exchange

0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 1mo ago

🚨 A malicious LNK disguised as a PDF leads to DARTHVADER stealer deployment & persistence, turning a document-like lure into post-click compromise.

Observed behavior: LOLBin and AutoIt execution, hidden cmd.exe activity, curl.exe downloads, PowerShell ExecutionPolicy Bypass, mutex creation, cmd.exe /V:ON for delayed environment variable expansion, and /D to disable AutoRun command processing.

‍💻 Live detonation and IOCs for detection & response: https://app.any.run/tasks/81e896a9-849b-491f-8dc4-edd51fed632b/?utm_source=mastodon&utm_medium=post&utm_campaign=darthvader_lnk&utm_term=300726&utm_content=linktoservice

⚡️ Learn how #ANYRUN helps SOC teams detect complex threats early: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=darthvader_lnk&utm_term=300726&utm_content=linktoenterprise

#cybersecurity #infosec

0
0
0
0
Open post
ANY.RUN @anyrun_app@infosec.exchange
· 1mo ago
🔍 Can your SOC investigate #phishing that leaves no malicious files behind? Modern AiTM attacks live inside the browser. Discover how browser visibility and threat intelligence expose what file-based analysis can't 👇 https://any.run/cybersecurity-blog/enterprise-phishing-resilience/?utm_source=mastodon&utm_medium=post&utm_campaign=enterprise_phishing_resilience&utm_term=280726&utm_content=linktoblog #cybersecurity #infosec
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)
  • Source code

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 15:45:46 UTC