ANY.RUN
Empowering businesses with proactive security solutions: Interactive Sandbox, TI Lookup and Feeds.
🚨 𝗙𝗮𝗸𝗲 𝗖𝗹𝗮𝘂𝗱𝗲 & 𝗖𝗼𝗱𝗲𝘅 𝗗𝗲𝗹𝗶𝘃𝗲𝗿 𝗜𝗻-𝗠𝗲𝗺𝗼𝗿𝘆 𝗦𝘁𝗲𝗮𝗹𝗲𝗿: 𝗖𝗹𝗶𝗰𝗸𝗙𝗶𝘅 𝘃𝗶𝗮 𝗚𝗼𝗼𝗴𝗹𝗲 𝗦𝗶𝘁𝗲𝘀
⚠️ We’re tracking a #ClickFix campaign that mimics popular AI tools, including Codex and Claude, and abuses trusted Google Sites infrastructure to deliver stealer #malware.
With no standalone executable dropped to disk and network activity appearing as legitimate powershell.exe traffic, the attack can significantly reduce visibility during the early stages of compromise.
❗️ Victims are directed to trusted sites[.]google[.]com pages and instructed to execute an mshta command. The attack results in in-memory stealer execution, theft of browser, email, and cryptocurrency wallet data, and outbound communication with attacker-controlled C2 infrastructure, while leaving fewer traditional detection opportunities for SOC teams.
Execution chain:
Trusted Google Sites lure ➡️ User-executed mshta command ➡️ Multi-stage PowerShell delivery ➡️ Steganographic payload extraction from image ➡️ Shellcode deployment ➡️ In-memory execution inside powershell.exe ➡️ Browser, email & wallet data theft ➡️ C2 exfiltration
👨💻 Using #ANYRUN Sandbox, investigate the full ClickFix execution chain, validate detection coverage, and observe PowerShell staging, steganographic payload delivery, and credential theft activity. Explore the analysis sessions and collect IOCs:
🔹 Codex lure: https://app.any.run/tasks/151cfb30-5ef2-4962-a90e-58a59ecc43da/?utm_source=mastodon&utm_medium=post&utm_campaign=claude_codex_clickfix&utm_term=030626&utm_content=linktoservice
🔹 Claude lure: https://app.any.run/tasks/698e0bd5-01b6-40fe-814c-5c0885cea645/?utm_source=mastodon&utm_medium=post&utm_campaign=claude_codex_clickfix&utm_term=030626&utm_content=linktoservice
🔍 Track related ClickFix activity in #ANYRUN TI Lookup, identify additional Codex and Claude lures, and uncover related AI-themed ClickFix activity and infrastructure:
🔹 https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=claude_codex_clickfix&utm_content=030626&utm_term=linktotilookup#%7B%2522query%2522:%2522url:%255C%2522https:/sites.google.com/*/cdx%255C%2522%2520or%2520url:%255C%2522https:/sites.google.com/*/clau%255C%2522%2522,%2522dateRange%2522:7%7D
🔹 https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=claude_codex_clickfix&utm_content=030626&utm_term=linktotilookup#%7B%22query%22:%22ruleName:%5C%22AI-themed%20ClickFix%20phishing%20page%20has%20been%20detected%5C%22%22,%22dateRange%22:14%7D
🚀 Equip your SOC with stronger phishing detection and contain incidents faster: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=claude_codex_clickfix&utm_term=030626&utm_content=linktoenterprise
❓ How does a lean SOC team protect 50,000+ users?
🎓 UMass Boston backs its security decisions with #ANYRUN Sandbox, triaging threats in seconds and stopping costly incidents before impact.
Read the customer story and see how you can achieve the same👇
https://any.run/cybersecurity-blog/umass-boston-success-story/?utm_source=mastodon&utm_medium=post&utm_campaign=umass_boston_success_story&utm_term=090626&utm_content=linktoblog
🔥 Q1 2026 Cyber Risk report by #ANYRUN is out!
Explore the cyber risks and threat shifts for CISOs, including:
❗️ +14.7% credential theft
❗️ +98.3% loader attacks
❗️ +58.4% LOLBAS attacks
Turn Q1 intel into Q2 security priorities. Get the report: https://any.run/cybersecurity-blog/cyber-risk-report-q1-2026/?utm_source=mastodon&utm_medium=post&utm_campaign=cyber_risk_report_q1_2026&utm_content=linktoreport&utm_term=040626
One fake download page ➡️ full remote access to your network ⚠️
SnappyClient shows how quickly a single click can turn into stolen credentials, hijacked payments, and a foothold attackers can exploit long after the initial breach.
👨💻 Learn more: https://any.run/malware-trends/snappyclient/?utm_source=mastodon&utm_medium=post&utm_campaign=snappyclient&utm_content=linktomtt&utm_term=200726
Phishing activity in the past 7 days 🐟
Track latest #phishing threats in TI Lookup: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=top_phishing&utm_content=linktoti&utm_term=280726#%7B%2522query%2522:%2522threatName:%255C%2522%5Ephishing$%255C%2522%2522,%2522dateRange%2522:180%7D
❗️ Here's what your SOC needs to know about rising EvilTokens: https://any.run/malware-trends/eviltokens/?utm_source=mastodon&utm_medium=post&utm_campaign=top_phishing&utm_content=linktomtt&utm_term=280726
🎯 Threat hunting breaks when teams prioritize hypotheses based on assumptions instead of actual threats targeting their business.
For example, if you're protecting a U.S. financial organization, start with: 𝘀𝘂𝗯𝗺𝗶𝘀𝘀𝗶𝗼𝗻𝗖𝗼𝘂𝗻𝘁𝗿𝘆:"𝗨𝗦" 𝗔𝗡𝗗 𝗶𝗻𝗱𝘂𝘀𝘁𝗿𝘆:"𝗳𝗶𝗻𝗮𝗻𝗰𝗲"
🔍 Run the search in #ANYRUN TI Lookup: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=threat_hunting_practical_usecases&utm_term=100226&utm_content=linktolookup/#%7B%2522query%2522:%2522submissionCountry:%255C%2522US%255C%2522%2520and%2520industry:%255C%2522finance%255C%2522%2522,%2522dateRange%2522:180%7D
You'll see malware families, phishing campaigns, and attack techniques observed targeting organizations in your sector, helping prioritize hunts based on real attacker activity rather than broad industry reports.
👨💻 Learn how SOCs & MSSPs build hunts around observed threats to reduce wasted effort and focus on real business risk: https://any.run/cybersecurity-blog/threat-hunting-practical-usecases/?utm_source=mastodon&utm_medium=post&utm_campaign=threat_hunting_practical_usecases&utm_term=100226&utm_content=linktoblog
🚨 #JSMonoGlyphRAT: The Persistent Backdoor Targeting US Businesses
A new backdoor is actively targeting enterprises through #phishing emails disguised as purchase orders, quotes, and business proposals. Most AV tools miss it entirely.
⚠️ Confirmed victims include organizations in the technology, telecom, education, and MSSP sectors. Once inside, attackers can deploy ransomware, steal data, and cause costly business disruption.
👨💻 Investigate the attack chain and persistence mechanisms in a sandbox session: https://app.any.run/tasks/e39d92e9-a8c3-4c71-8009-2087847fb669/?utm_source=mastodon&utm_medium=post&utm_campaign=monoglyphrat_attacks_us_enterprise&utm_term=020626&utm_content=linktoservice
📌 Learn how to detect JSMonoGlyphRAT before it turns into business impact: https://any.run/cybersecurity-blog/monoglyphrat-attacks-us-enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=monoglyphrat_attacks_us_enterprise&utm_term=020626&utm_content=linktoblog
⚠️ In Q1 2026, phishing kits captured sessions using proxy authentication flows in real time.
It's hard to detect, because SOCs see no traditional indicator of compromise.
🎯 Learn how to improve phishing defense in Q1 Cyber Risk Report: https://files.any.run/images/q1_2026_cyber_risk_report_from_anyrun.pdf?utm_source=mastodon&utm_medium=post&utm_campaign=cyber_risk_report_1&utm_content=linktoreport&utm_term=090626
⚠️ Fake event invitation #phishing bypasses standard automated scanners by hiding credential theft and unauthorized RMM delivery behind a routine CAPTCHA check, creating delayed detection risks for CISOs.
In a large-scale campaign targeting U.S. organizations, attackers deploy a repeatable framework with fixed resource paths to compromise mailboxes, intercept OTP codes, and deploy RMM tools for persistent access. See the full attack flow and process tree in an analysis session: https://app.any.run/tasks/4c2687da-1426-43c3-8e16-868f90fb9361/?utm_source=mastodon&utm_medium=post&utm_campaign=US_fake_invitation_phishing_case&utm_term=040626&utm_content=linktoservice
🎯 Read our technical breakdown to explore how SOC teams can use these huntable infrastructure signals to validate threats faster and get the complete IOC list: https://any.run/cybersecurity-blog/us-fake-invitation-phishing/?utm_source=mastodon&utm_medium=post&utm_campaign=US_fake_invitation_phishing_case&utm_term=040626&utm_content=linktoblog
Phishing activity in the past 7 days 🐟
Track latest #phishing threats in TI Lookup: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=top_phishing&utm_content=linktoti&utm_term=090626#%7B%2522query%2522:%2522threatName:%255C%2522%5Ephishing$%255C%2522%2522,%2522dateRange%2522:180%7D
Day 1 at Infosecurity Europe 2026 is a wrap 🇬🇧 One theme kept coming up in conversations with security leaders today: investigation speed matters, but decision confidence matters even more.
We're showing how #ANYRUN helps enterprise SOCs & MSSPs shorten time to insight while giving teams the context needed to make faster, more confident response decisions ⚡️
📍 Find our team at Stand C62 and learn how behavioral analysis and live threat intelligence help reduce uncertainty throughout the investigation process.
🎟️ Get your ticket: https://infosecurityeurope.com/en-gb/register.html?code=1666079269821849-VCP
⚡ You are one integration away from unique threat intelligence powered by a global community of 600K analysts.
Bring #ANYRUN directly into your SIEM, SOAR, or EDR.
🔗 Find your vendor and strengthen your security stack with #ANYRUN: https://any.run/integrations/?utm_source=mastodon&utm_medium=post&utm_campaign=all_integrations_connectors&utm_content=linktointegrations&utm_term=230726
⚠️ Remote access malware remained resilient despite broader declines. #AsyncRAT continued to grow and #Remcos rebounded, while most other major families trended downward.
📌 Trend to watch: when fewer families account for a larger share of activity, defenders can miss the signal by focusing on overall volume alone. Concentrated campaigns often create repeated exposure to the same attack paths, increasing the likelihood of successful compromise.
Expand threat visibility in your SOC: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=top_ten&utm_term=080626&utm_content=linktoenterprise
⚡️ SOAR can move an alert through a workflow but can't determine what a URL does.
#ANYRUN Sandbox adds behavioral analysis, helping validate threats earlier and reduce manual checks that slow triage & response.
How this works across SOC workflows 👇
https://any.run/cybersecurity-blog/integrating-sandbox-into-soar-workflows/?utm_source=mastodon&utm_medium=post&utm_campaign=sandbox_soar&utm_term=100626&utm_content=linktoblog
⚡ To detect emerging threats in Microsoft Sentinel you need fresh, unique intelligence.
That’ what #ANYRUN TI Feeds deliver — live IOCs from sandbox analysis, 99% unique, real-time.
📈 See how #ANYRUN strengthens your Microsoft Sentinel environment: https://any.run/integrations/microsoft-sentinel-integration/?utm_source=mastodon&utm_medium=post&utm_campaign=feeds_sentinel_integration&utm_term=300726&utm_content=linktointegrations
⚡ Faster SOC decisions and stronger threat visibility with #ANYRUN’s May updates.
Explore Tier 1 Reports, Elastic Security integration for fresh IOCs, and 1,400+ new detections 🛡️
Learn more and strengthen your SOC response now 👇
https://any.run/cybersecurity-blog/release-notes-may-2026/?utm_source=mastodon&utm_medium=post&utm_campaign=release-notes-may-2026&utm_term=030626&utm_content=linktoblog
⚠️ #JOMANGY malware hijacks your FreePBX system and runs fraudulent calls on SIP trunks — billed to you.
❗️ 6 self-healing persistence layers. 700+ businesses still infected 5 months later. Is your PBX off the internet?
See the impact of this threat: https://any.run/malware-trends/jomangy/?utm_source=mastodon&utm_medium=post&utm_campaign=jomangy_mtt&utm_term=080626&utm_content=linktomtt
🚨 A malicious LNK disguised as a PDF leads to DARTHVADER stealer deployment & persistence, turning a document-like lure into post-click compromise.
Observed behavior: LOLBin and AutoIt execution, hidden cmd.exe activity, curl.exe downloads, PowerShell ExecutionPolicy Bypass, mutex creation, cmd.exe /V:ON for delayed environment variable expansion, and /D to disable AutoRun command processing.
💻 Live detonation and IOCs for detection & response: https://app.any.run/tasks/81e896a9-849b-491f-8dc4-edd51fed632b/?utm_source=mastodon&utm_medium=post&utm_campaign=darthvader_lnk&utm_term=300726&utm_content=linktoservice
⚡️ Learn how #ANYRUN helps SOC teams detect complex threats early: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=darthvader_lnk&utm_term=300726&utm_content=linktoenterprise