<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0">

<channel>
	<title>ANY.RUN RSS feed</title>
	<atom:link href="https://any.run/cybersecurity-blog/feed/" rel="self" type="application/rss+xml"/>
	<link/>
	<description>The latest posts and cybersecurity news</description>
	<lastBuildDate>Thu, 20 Aug 2026 07:58:36 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/cropped-Favicon_WebSite_Rounded-32x32.png</url>
	<title>ANY.RUN's Cybersecurity Blog</title>
	<link/>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>North Korean IT Workers Scheme: Detection IOCs and Tactics for Government and Corporate SOCs</title>
		<link>https://any.run/cybersecurity-blog/how-to-protect-organization-against-north-korean-it-workers/</link>
					<comments>https://any.run/cybersecurity-blog/how-to-protect-organization-against-north-korean-it-workers/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Thu, 20 Aug 2026 07:58:36 +0000</pubDate>
				<category><![CDATA[Cybersecurity Lifehacks]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[cybersecurity training]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=22729</guid>

					<description><![CDATA[<p>The infiltration of North Korean IT workers into American and European organizations has evolved into a sophisticated operation that bypasses traditional security perimeters. By using forged identities and AI-assisted workflows, these operatives successfully transition from external applicants to trusted insiders. Recent investigations highlight that this scheme is no longer limited to the private sector, posing [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/how-to-protect-organization-against-north-korean-it-workers/">North Korean IT Workers Scheme: Detection IOCs and Tactics for Government and Corporate SOCs</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">The infiltration of North Korean IT workers into American and European organizations has evolved into a sophisticated <strong>operation that bypasses traditional security perimeters</strong>. By using forged identities and AI-assisted workflows, these operatives successfully transition from external applicants to trusted insiders.</p>



<p class="wp-block-paragraph">Recent investigations highlight that <strong>this scheme is no longer limited to the private sector, posing a direct threat to government agencies.</strong> </p>



<p class="wp-block-paragraph">Here’s how organizations can <strong>defend against this threat effectively</strong>.</p>



<h2 class="wp-block-heading">The Escalating Risk of the DPRK Remote Worker Threat</h2>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img fetchpriority="high" decoding="async" width="1024" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-1024x1024.png" alt="DPRK Operatives caught" class="wp-image-22474" style="width:668px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-1024x1024.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-300x300.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-150x150.png 150w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-768x769.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-1534x1536.png 1534w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-70x70.png 70w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-370x370.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-270x270.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-740x741.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught.png 1636w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>DPRK Operatives caught by Bitso Quetzal Team while interviewing for a position at the Company</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The primary objective of the DPRK IT worker scheme <a href="https://any.run/cybersecurity-blog/lazarus-group-attacks-2025/" target="_blank" rel="noreferrer noopener">operated by the Lazarus APT</a> has historically been revenue generation, collectively earning hundreds of millions of dollars annually for the DPRK. However, the <strong>threat has escalated from financial fraud to a direct national security concern</strong> as these operatives penetrate the U.S. public sector.</p>



<p class="wp-block-paragraph">The <a href="https://federalnewsnetwork.com/technology-main/2026/08/fbi-investigating-north-korean-remote-it-staffer-working-for-u-s-agency/" target="_blank" rel="noreferrer noopener nofollow">FBI is currently investigating a recent case</a> where an unidentified U.S. federal agency <strong>unknowingly hired a North Korean remote IT worker</strong>. Last year, an individual who facilitated a North Korean national’s work on software development contracts for the Federal Aviation Administration (FAA) <strong>received a prison sentence</strong>. Such breaches grant unauthorized actors access to sensitive government systems and proprietary data.</p>



<p class="wp-block-paragraph">The full lifecycle, tools, and operational methods of these infiltrators were exposed in a comprehensive two-part joint investigation conducted by BCA LTD, NorthScan, and <a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener"><strong>ANY.RUN</strong></a>. </p>



<ul class="wp-block-list">
<li><strong><a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation/" target="_blank" rel="noreferrer noopener">In Part 1, researchers gained unprecedented access by posing as facilitators</a></strong>, deploying custom ANY.RUN sandbox environments disguised as developer laptops to record every click, command, and network connection executed by the operatives in real time. </li>



<li><strong><a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/" target="_blank" rel="noreferrer noopener">In Part 2, the team went a step further by establishing a simulated Web3 startup</a></strong>, tracking how Famous Chollima operatives collaborate, manage candidate pipelines, share infrastructure, and attempt to embed whole networks of &#8220;ghost developers&#8221; into target companies.</li>
</ul>



<h3 class="wp-block-heading">How DPRK IT worker scheme Operatives Hijack the Personnel Supply Chain</h3>



<p class="wp-block-paragraph">As demonstrated in the<a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/"> investigations</a>, threat actors combine stolen identities and artificial intelligence to infiltrate organizations. </p>



<figure class="wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe title="Lucas’ Interview" width="770" height="433" src="https://www.youtube.com/embed/dPAjfHr4kzk?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>
</div><figcaption class="wp-element-caption"><em>An interview with a North Korean remote work for a position in a fake DeFi startup</em></figcaption></figure>



<p class="wp-block-paragraph"><a href="https://youtu.be/dPAjfHr4kzk" target="_blank" rel="noreferrer noopener"><strong>Watch the video on YouTube</strong></a> and<strong> <a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/" target="_blank" rel="noreferrer noopener">read the full investigation</a></strong></p>



<p class="wp-block-paragraph">Security experts describe this phenomenon as a <strong>critical risk within the personnel supply chain</strong>. While companies traditionally focus on defending against external attackers, the North Korean IT worker fraud flips this model by getting hired.</p>



<p class="wp-block-paragraph"><strong>A DPRK IT worker functions as a &#8220;Trojan horse,&#8221;</strong> obtaining legitimate credentials, access to internal networks, and corporate resources. This creates a unique insider threat:</p>



<ul class="wp-block-list">
<li><strong>Persistent Access to Critical Infrastructure:</strong> Unlike traditional cyberattacks that are brief and noisy, an employee is expected to remain in the system, allowing months or years of continuous access to source code and intellectual property.</li>



<li><strong>Malicious Influence on Decision-Making:</strong> Once embedded, operatives can influence critical engineering decisions, review code, and approve pull requests, potentially introducing intentional vulnerabilities.</li>



<li><strong>Legitimate Cover:</strong> By maintaining a facade of productivity, operatives generate legitimate salaries while gathering intelligence and staging future cyberattacks.</li>
</ul>



<h2 class="wp-block-heading">Actionable Steps for SOCs to Detect North Korea Remote IT Workers Infiltration Early</h2>



<p class="wp-block-paragraph">Standard background checks, especially automated ones, are insufficient to ensure DPRK IT worker detection.</p>



<p class="wp-block-paragraph">Defending against this requires SOC and recruitment teams to adopt a technical vetting model that treats hiring as an attack vector.</p>



<h2 class="wp-block-heading">Spot Mass Outreach and GitHub Exploitation Tactics</h2>



<p class="wp-block-paragraph">The initial stage of the North Korean scheme often begins with wide-scale recruitment efforts targeting developers on platforms like Telegram and GitHub.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img decoding="async" width="963" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment-963x1024.png" alt="Angelo’s comment on GitHub looking for facilitators" class="wp-image-22552" style="aspect-ratio:0.9404355812122802;width:680px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment-963x1024.png 963w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment-282x300.png 282w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment-768x816.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment-1445x1536.png 1445w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment-370x393.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment-270x287.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment-740x786.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment.png 1592w" sizes="(max-width: 963px) 100vw, 963px" /><figcaption class="wp-element-caption"><em>A North Korean operative looking for facilitators on GitHub</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">A highly specific tactic involves recruiters spamming GitHub repositories with fraudulent job offers. These messages are often delivered as <strong>pull requests directly on a developer’s own repositories</strong>, making them difficult to ignore.</p>



<p class="wp-block-paragraph">Recruiters seek individuals who appear to have experience working with US companies, offering them &#8220;partnerships&#8221; where they can increase their income by attending interviews on behalf of the operative.</p>



<h2 class="wp-block-heading">Eliminate Rogue Team Leads from the Hiring Process</h2>



<p class="wp-block-paragraph">Famous Chollima operations often rely on a key team lead (a &#8220;horse trader&#8221; or agency manager) who acts as the primary point of contact to build trust and scale their footprint inside targeted organizations:</p>



<ul class="wp-block-list">
<li><strong>Beware of &#8220;Bring Your Own Team&#8221; Offers:</strong> A single lead will apply for or land a role, establish rapport with hiring managers, and then offer to recruit, manage, or refer additional developers. Under the guise of a turnkey contracting team, this facilitator brings in multiple North Korean operatives using fake or stolen identities.</li>



<li><strong>Enforce Direct, Individual Vetting:</strong> Never permit a single contractor, agency manager, or team lead to bypass individual KYC/background checks for their referred developers. Every individual applicant must undergo separate, direct identity verification and technical assessment.</li>
</ul>



<h2 class="wp-block-heading">Safely Triage Applicant Files and Links with a Sandbox</h2>



<p class="wp-block-paragraph">Your Security Operations Center (SOC) must actively participate in the vetting process by validating suspicious candidate deliverables before finalizing a hire.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="636" src="/cybersecurity-blog/wp-content/uploads/2025/01/5-1024x636.jpg" alt="" class="wp-image-11084" style="aspect-ratio:1.6101563709552562;width:754px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2025/01/5-1024x636.jpg 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/01/5-300x186.jpg 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/01/5-768x477.jpg 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/01/5-370x230.jpg 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/01/5-270x168.jpg 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/01/5-740x459.jpg 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/01/5.jpg 1200w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>DPRK-linked malware detected and analyzed inside ANY.RUN&#8217;s Interactive Sandbox</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Applicants routinely submit portfolios, code archives, or external links during technical assessments. Opening these directly on internal corporate workstations exposes the network to staging malware (such as <em><a href="https://any.run/cybersecurity-blog/ottercookie-malware-analysis/" target="_blank" rel="noreferrer noopener">OtterCookie</a></em>, <em><a href="https://any.run/cybersecurity-blog/invisibleferret-malware-analysis/" target="_blank" rel="noreferrer noopener">InvisibleFerret</a></em>, and <a href="https://any.run/cybersecurity-blog/pylangghost-malware-analysis/" target="_blank" rel="noreferrer noopener">PyLangGhost RAT</a>).</p>



<p class="wp-block-paragraph">Integrating ANY.RUN’s <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener"><strong>Interactive Sandbox</strong></a> into the technical vetting and SOC triage and response workflows provides critical security value and operational efficiency:</p>



<ul class="wp-block-list">
<li><strong>Uncover Evasive Phishing &amp; Malware in under 60 seconds</strong>: Automated tools often miss stealthy malware that requires human interaction. ANY.RUN allows analysts to actively interact with the candidate&#8217;s files and URLs in real time, clicking links and triggering behaviors that reveal hidden payloads.</li>



<li><strong>Ensure Early-Stage Attack Vector Neutralization</strong>: Proactive analysis of suspicious objects sent by candidates enables SOC teams to identify malicious intent early and prevent threat actors from ever obtaining legitimate corporate credentials, company laptops, or access to sensitive infrastructure.</li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Close malware &#038; phishing visibility gaps in your SOC.</span><br>
Detect threats in <60 sec and cut MTTR by 21 min per case.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&#038;utm_term=200826&amp;utm_content=linktoenterpriseform/#contact-sales" rel="noopener" target="_blank">
Integrate ANY.RUN</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Inspect Applicant Documents for AI Artifacts and Forensic Inconsistencies</h2>



<p class="wp-block-paragraph">North Korean operatives frequently submit manipulated identity documents containing digital creation fingerprints.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="645" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2-1024x645.png" alt="Lazarus Angelo's driving license" class="wp-image-22556" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2-1024x645.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2-300x189.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2-768x484.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2-1536x968.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2-370x233.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2-270x170.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2-740x466.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2.png 1698w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>A fake ID card provided by one of the operatives </em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Investigations show forged licenses often contain metadata proving processing via AI tools like Google Gemini, or feature embedded SynthID watermarks.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="543" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-1024x543.png" alt="Lazarus investigation: Angelo’s License Metadata" class="wp-image-22557" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-1024x543.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-300x159.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-768x408.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-1536x815.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-2048x1087.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-370x196.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-270x143.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-740x393.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The ID card&#8217;s metadata</em> <em>showing it was generated by AI</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">Analyze candidate data for geographic discrepancies (e.g., <a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/">claiming residence in Texas while presenting a California driver&#8217;s license and a New York bank account</a>). Forensic analysis often reveals stolen authentic photos re-used across multiple applications.</p>



<h2 class="wp-block-heading">Monitor for AI-Assisted and Suspicious Live Behavior</h2>



<p class="wp-block-paragraph">Apart from North Korean IT worker AI-generated personas, operatives rely heavily on live translation and dynamic AI prompt generators.</p>



<figure class="wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="Cough syrup" width="770" height="433" src="https://www.youtube.com/embed/hjpQBRR7lQ4?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>
</div><figcaption class="wp-element-caption"><em>A video of a DPRK operative faking a cough after his AI live translation tool</em>&#8216;s<em> malfunction during a call</em></figcaption></figure>



<p class="wp-block-paragraph"><a href="https://youtu.be/hjpQBRR7lQ4" target="_blank" rel="noreferrer noopener"><strong>Watch the video on YouTube</strong></a> and <a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/" target="_blank" rel="noreferrer noopener"><strong>read the full investigation</strong></a></p>



<p class="wp-block-paragraph">Watch for off-screen glances, unusual delays before answering technical queries, or physical distractions. In recorded instances, operatives faked medical emergencies or prolonged coughing fits to avoid speaking when translation tools failed.</p>



<h2 class="wp-block-heading">Trace Mule Accounts and Cryptocurrency Infrastructure</h2>



<p class="wp-block-paragraph">Salary exfiltration relies on complex networks of mule accounts, payment intermediaries, and digital wallets designed to route funds back to the DPRK.</p>



<p class="wp-block-paragraph">Always verify that the account holder&#8217;s name on banking or crypto payment details matches the verified candidate&#8217;s identity. <strong>Operatives frequently request payroll transfers to third-party accounts</strong>, domestic facilitators, or mule accounts tied to stolen Social Security Numbers (SSNs) and completely different names.</p>



<p class="wp-block-paragraph">To bypass traditional banking compliance and international sanctions, operatives push to receive compensation or transfer funds through non-custodial wallets or exchange wallets on platforms.</p>



<h2 class="wp-block-heading">Analyze Network Markers: Proxies, VPNs, and Jump Boxes</h2>



<p class="wp-block-paragraph">To maintain the illusion of being local U.S. residents, North Korean IT worker tactics involve multi-layered networking designed to hide their origin.</p>



<p class="wp-block-paragraph">During <a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/" target="_blank" rel="noreferrer noopener"><strong>the BCA LTD, NorthScan, and ANY.RUN investigation</strong></a>, researchers successfully exposed operatives&#8217; true locations by asking candidates to scan a QR code during a live interview to access a coding test. Embedded Canary Tokens silently recorded the candidates&#8217; actual IP addresses, User-Agents, and geolocation data, completely bypassing active VPNs like AstrillVPN.</p>



<p class="wp-block-paragraph">SOC and recruiting teams should closely monitor candidate connectivity and verify real network locations wherever possible:</p>



<ul class="wp-block-list">
<li><strong>Track network telemetry, User-Agent strings, and IP locations</strong> during video calls, technical assignments, or onboarding tasks to flag proxies and VPN exit nodes.</li>



<li><strong>Enforce strict policies against commercial VPN services</strong> (e.g., AstrillVPN) commonly used by Famous Chollima operatives to spoof major U.S. exit nodes.</li>
</ul>



<h2 class="wp-block-heading">DPRK IT Worker IOCs</h2>



<ul class="wp-block-list">
<li>IPv4: 89[.]187[.]185[.]11 // DPRK-operated VPS</li>



<li>IPv4: 45[.]77[.]71[.]42 // DPRK-operated VPS</li>



<li>IPv4: 185[.]152[.]67[.]39 // DPRK-operated VPS</li>



<li>IPv4: 104[.]250[.]148[.]58 // AstrillVPN exit node</li>



<li>IPv4: 192[.]200[.]115[.]226 // AstrillVPN exit node</li>



<li>IPv4: 107[.]150[.]38[.]250 // AstrillVPN exit node</li>



<li>IPv4: 206[.]217[.]134[.]34 // AstrillVPN exit node</li>



<li>IPv4:199[.]168[.]112[.]175 // AstrillVPN exit node</li>



<li>0x8953B9661339a48f4E6408aA1B359CD49F3A6CAd</li>



<li>0xA3D6938f152C47A411263573Bb3AF324C25A8eba</li>



<li>0xB26A7C7EA6D75956EbD8c5D294524903b1cf13D0</li>
</ul>



<h2 class="wp-block-heading">Keep Defenses Updated with Fresh Threat Intelligence </h2>



<p class="wp-block-paragraph">While North Korean IT worker schemes primarily rely on identity fraud and social engineering, their operations heavily overlap with broader state-sponsored campaigns run by North Korean APT groups (such as Lazarus / Famous Chollima). </p>



<p class="wp-block-paragraph">Threat actors routinely reuse command-and-control (C2) infrastructure, staging servers, malware delivery domains, and phishing URLs across both cyber espionage and remote worker infiltration schemes.</p>



<p class="wp-block-paragraph">SOC analysts can collect context on indicators from alerts like URLs, file hashes, mutexes, or proactively gather actionable intel on active threats using ANY.RUN’s <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence Lookup</strong></a>. </p>



<p class="wp-block-paragraph">Powered by real-time telemetry contributed by <strong>over 16,000 organizations and 700,000 security professionals worldwide</strong>, TI Lookup instantly cross-references indicators against known Lazarus/Famous Chollima malware samples (such as BeaverTail or InvisibleFerret), phishing infrastructure, and active C2 servers.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="578" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/lazrus_ti_lookup_screen-1024x578.png" alt="" class="wp-image-22753" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/lazrus_ti_lookup_screen-1024x578.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/lazrus_ti_lookup_screen-300x169.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/lazrus_ti_lookup_screen-768x433.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/lazrus_ti_lookup_screen-1536x866.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/lazrus_ti_lookup_screen-370x209.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/lazrus_ti_lookup_screen-270x152.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/lazrus_ti_lookup_screen-740x417.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/lazrus_ti_lookup_screen.png 1833w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Lookup provides the latest IOCs and other threat intel on Lazarus APT attacks</em></figcaption></figure>



<p class="wp-block-paragraph">For example, running a query like <a href="https://intelligence.any.run/analysis/lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktotilookup#{%22query%22:%22threatName:%5C%22lazarus%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">threatName:&#8221;lazarus&#8221;</a> reveals numerous indicators belonging to the latest malware campaigns run by Lazarus like TigerRAT and others. SOC teams can use these indicators to enrich their defense systems to identify attacks early and prevent an incident.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="468" src="/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds1-1024x468.png" alt="" class="wp-image-18792" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds1-1024x468.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds1-300x137.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds1-768x351.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds1-370x169.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds1-270x123.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds1-740x338.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds1.png 1465w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Threat Intelligence Feeds: data, features, integrations</em> </figcaption></figure>



<p class="wp-block-paragraph">Security teams can also ingest continuously updated <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence Feeds</strong></a> directly into their SIEM, EDR, and perimeter firewalls. By feeding real-time network indicators (IPs, domains, URLs) gathered from global investigations directly into your security stack, your SOC can automatically block malicious connections and prevent unauthorized data exfiltration.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Enrich your SOC&#8217;s triage, response, and hunting with actionable threat context. 
 </span><br>Shorten investigations to stops threats before they become incidents. 
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/plans-ti/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&#038;utm_term=200826&amp;utm_content=linktotiplansform#contact-sales" target="_blank" rel="noopener">
Integrate ANY.RUN&#8217;s Threat Intelligence
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">The North Korean IT worker scheme represents a unique hybrid threat, combining traditional human infiltration, social engineering, identity fraud, and software supply chain risk. Defensive strategies that focus strictly on traditional malware detection are insufficient when an attacker holds valid credentials, corporate devices, and a legitimate seat on your engineering team.</p>



<p class="wp-block-paragraph">Protecting your organization requires aligning HR, recruiting, and SOC workflows. By enforcing strict identity verification, monitoring candidate connection telemetry, running interactive file/link sandboxing during technical assessments, and feeding real-time Threat Intelligence into your security stack, companies and government agencies can stop Famous Chollima operatives before they gain a permanent foothold.</p>



<h2 class="wp-block-heading">About ANY.RUN</h2>



<p class="wp-block-paragraph"><strong><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a></strong> is a leading provider of interactive malware analysis and threat intelligence solutions, trusted by more than 16,000 organizations and over 700,000 security professionals worldwide.</p>



<p class="wp-block-paragraph">Its <strong><a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a></strong> enables SOC teams, MSSPs, and threat researchers to analyze malware, suspicious files, URLs, and candidate deliverables in controlled, live virtual environments. By offering full behavioral visibility in under 60 seconds, ANY.RUN helps analysts observe execution chains, capture network traffic, and make fast, confident response decisions.</p>



<p class="wp-block-paragraph">Additionally, <strong><a href="https://intelligence.any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktotiservice" target="_blank" rel="noreferrer noopener">ANY.RUN Threat Intelligence</a></strong> aggregates real-time indicators from global investigations. This allows security teams to enrich local SIEM/EDR alerts, uncover shared adversary infrastructure, and stay ahead of evolving APT tactics, phishing campaigns, and insider threat schemes.</p>



<h2 class="wp-block-heading">Frequently Asked Questions (FAQ)</h2>



<div class="schema-faq wp-block-yoast-faq-block"><div class="schema-faq-section" id="faq-question-1787177239111"><strong class="schema-faq-question"><strong>1. Why are North Korean IT workers targeting government agencies and corporate SOCs?</strong></strong> <p class="schema-faq-answer">Beyond earning revenue for the DPRK, placing operatives inside corporate or public sector organizations grants long-term, persistent access to source code, intellectual property, and internal networks. Operatives can gather intelligence, manipulate software supply chains, and stage future cyberattacks without ever needing to exploit software vulnerabilities.</p> </div> <div class="schema-faq-section" id="faq-question-1787177254143"><strong class="schema-faq-question"><strong>2. How do operatives bypass standard background checks and automated HR screening?</strong></strong> <p class="schema-faq-answer">Operatives rely on stolen identities, rented Social Security Numbers (SSNs), synthetic personas created with AI tools like Google Gemini, and domestic facilitators who host &#8220;laptop farms&#8221;. Standard background checks confirm that the identity itself exists, but they often fail to verify whether the remote candidate behind the screen is actually the person named in the documents.</p> </div> <div class="schema-faq-section" id="faq-question-1787177263630"><strong class="schema-faq-question"><strong>3. What is a &#8220;laptop farm&#8221; and how does it obscure the operative&#8217;s location?</strong></strong> <p class="schema-faq-answer">A laptop farm is a physical setup managed by a domestic facilitator (often based in the U.S. or EU). Corporate equipment sent by the employer is delivered to the facilitator&#8217;s address. The facilitator connects the devices to local residential internet and grants the North Korean operative 24/7 remote desktop access (via AnyDesk, Google Remote Desktop, etc.). This makes all network connections appear to originate from a legitimate local residence.</p> </div> <div class="schema-faq-section" id="faq-question-1787177275158"><strong class="schema-faq-question"><strong>4. How can a SOC safely inspect coding assignments, portfolios, or links sent by candidates?</strong></strong> <p class="schema-faq-answer">Candidate deliverables should never be opened directly on corporate endpoints. Using an interactive environment like <strong><a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">ANY.RUN Interactive Sandbox</a></strong>, SOC teams can open suspicious files, scripts, or URLs in a secure cloud container. Analysts can interactively test the submission, observe process trees, and monitor outbound network connections in real time without risking the internal network.</p> </div> <div class="schema-faq-section" id="faq-question-1787177378540"><strong class="schema-faq-question">5. <strong>How does Threat Intelligence help detect North Korean operative schemes?</strong></strong> <p class="schema-faq-answer">North Korean remote worker schemes heavily share infrastructure with state-sponsored APT groups like Lazarus (Famous Chollima). Operatives routinely reuse C2 servers, malware delivery domains, phishing links, and malicious code samples (such as <em>BeaverTail</em> or <em>InvisibleFerret</em>). Cross-referencing candidate links, domains, or infrastructure against <strong><a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">ANY.RUN Threat Intelligence Lookup</a></strong> and <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-to-identify-remote-workers&amp;utm_term=200826&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence Feeds</strong></a> allows SOC analysts to instantly spot overlaps with known DPRK cyber campaigns and block threats at the perimeter.</p> </div> </div>
<p>The post <a href="https://any.run/cybersecurity-blog/how-to-protect-organization-against-north-korean-it-workers/">North Korean IT Workers Scheme: Detection IOCs and Tactics for Government and Corporate SOCs</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/how-to-protect-organization-against-north-korean-it-workers/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Hunt Malware &amp; Phishing Threats with ANY.RUN for Proactive Enterprise Security</title>
		<link>https://any.run/cybersecurity-blog/proactive-threat-hunting/</link>
					<comments>https://any.run/cybersecurity-blog/proactive-threat-hunting/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Wed, 19 Aug 2026 10:27:03 +0000</pubDate>
				<category><![CDATA[Cybersecurity Lifehacks]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[malware analysis]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=22695</guid>

					<description><![CDATA[<p>One of the biggest challenges for every threat hunter is navigating endless alerts, scattered indicators, behavioral evidence, and infrastructural context. Data collection is just the first step – but how do you turn it into findings that lead to proactive protection against malware and phishing? ANY.RUN Threat Intelligence has the answer. Threat Intelligence: Thinking Ahead [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/proactive-threat-hunting/">Hunt Malware &amp; Phishing Threats with ANY.RUN for Proactive Enterprise Security</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">One of the biggest challenges for every threat hunter is navigating endless alerts, scattered indicators, behavioral evidence, and infrastructural context. Data collection is just the first step – but how do you turn it into findings that lead to proactive protection against malware and phishing? </p>



<p class="wp-block-paragraph"><a href="https://intelligence.any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">ANY.RUN Threat Intelligence</a> has the answer. </p>



<h2 class="wp-block-heading">Threat Intelligence: Thinking Ahead </h2>



<p class="wp-block-paragraph">It doesn’t take much to start a threat hunt. One suspicious indicator or an artifact – and the investigation is launched. But moving from the initial lead to realizing how it can be used to support malware &amp; phishing defenses is often a long journey. <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> changes that. </p>



<p class="wp-block-paragraph">It&#8217;s designed to shorten the path from a suspicious signal to validated findings, ready to be used for proactive security: from testing a hunting hypothesis and uncovering related infrastructure to expanding detection coverage. </p>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> gives threat hunters access to intelligence grounded in real-world threat data from investigations by 16,000+ SOC teams within a single environment, allowing you to: </p>



<ul class="wp-block-list">
<li>search for known observables </li>
</ul>



<ul class="wp-block-list">
<li>investigate related technical context </li>
</ul>



<ul class="wp-block-list">
<li>examine malicious behavior and infrastructure </li>
</ul>



<ul class="wp-block-list">
<li>narrow the results to the evidence relevant to your hunt </li>
</ul>



<p class="wp-block-paragraph">Doing this manually across disconnected sources would stretch every step of the investigation, making it easier to miss useful relationships. One day, this might mean missing a critical risk. </p>



<p class="wp-block-paragraph">To prevent that, <a href="https://any.run/plans-ti/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktotiplans" target="_blank" rel="noreferrer noopener">ANY.RUN Threat Intelligence</a> helps security teams: </p>



<ul class="wp-block-list">
<li><strong>Investigate threats faster: </strong>Move from an initial indicator to relevant context without spending as much time manually correlating fragmented data. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Build stronger hunting hypotheses: </strong>Use behavioral, network, and infrastructure intelligence to validate assumptions and identify additional leads. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Collect actionable observables: </strong>Identify relevant IOCs for retrospective hunting, blocking, enrichment, and further investigation in SIEM, NDR, and other security systems. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Improve detection coverage: </strong>Turn investigation findings into inputs that Detection &amp; Security Engineering teams can use to develop or expand detections. </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://any.run/cybersecurity-blog/threat-hunting-practical-usecases/" target="_blank" rel="noreferrer noopener"><strong>Streamline threat hunting</strong></a><strong> workflows: </strong>Reduce reliance on individual analysts manually piecing together threat context, helping SOC teams make investigations and <a href="https://any.run/cybersecurity-blog/soc-ready-reporting/" target="_blank" rel="noreferrer noopener">handoffs</a> more consistent. </li>
</ul>



<p class="wp-block-paragraph">For threat hunters, that means less time assembling context and more time testing hypotheses and uncovering malicious activity. For CISOs and SOC leaders, it means a more repeatable process for <a href="https://any.run/cybersecurity-blog/streamline-your-soc/" target="_blank" rel="noreferrer noopener">turning threat intelligence into security outcomes</a>, from investigation and escalation to detection and response. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Bring average MTTD down to <span class="highlight">14 seconds</span> with ANY.RUN<br>
Proactive security with intelligence from <span class="highlight">16K+ SOCs </span>
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=proactive-threat-hunting&#038;utm_term=190826&#038;utm_content=linktoenterprise#contact-sales" target="_blank" rel="noopener">
Explore in your SOC
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph">The value of threat intelligence is in how quickly your team can turn indicators into evidence, decisions, and better protection. </p>



<p class="wp-block-paragraph">What does that look like in an actual investigation? </p>



<h2 class="wp-block-heading">Use Case #1. Finding Infrastructure Shared by Threats </h2>



<p class="wp-block-paragraph">You’ve identified a threat relevant to <a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktoenterprise" target="_blank" rel="noreferrer noopener">your organization</a> and are approaching the final stage of the investigation: turning the findings into a set of actionable indicators that can be handed off to the detection &amp; security engineering team. </p>



<p class="wp-block-paragraph">For that, you need to identify IP addresses and domains associated with VPS or hosting providers that also have a negative reputation. These observables can reveal infrastructure used to support malicious activity and provide additional coverage beyond the indicators that initially led to the threat. </p>



<h3 class="wp-block-heading">Start with a known threat </h3>



<p class="wp-block-paragraph">Build a query in <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> using a <a href="https://any.run/cybersecurity-blog/search-operators-and-wildcards-in-ti-lookup/" target="_blank" rel="noreferrer noopener">wildcard</a> (*) to capture variations in Suricata messages and find URL activity related to <a href="https://any.run/cybersecurity-blog/salty2fa-tycoon2fa-hybrid-phishing-2025/" target="_blank" rel="noreferrer noopener">Tycoon2FA</a> without relying on an exact message string: </p>



<p class="wp-block-paragraph"><a href="https://intelligence.any.run/analysis/lookup?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktoservice#{%22query%22:%22suricataMessage:%5C%22tycoon*url%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">suricataMessage:&#8221;tycoon*url&#8221;</a> </p>



<p class="wp-block-paragraph">View <strong>Connections </strong>tab listing all related domains, IPs, and URLs. It helps you realize which indicators are connected to each other: </p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1530" height="864" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/connections3-1.gif" alt="" class="wp-image-22720"/></figure>



<p class="wp-block-paragraph"><em>Connections show observable relationships in ANY.RUN data to help you build and validate a hypothesis. Threat Intelligence Lookup</em> </p>



<h3 class="wp-block-heading">Narrow down the relevant observables </h3>



<p class="wp-block-paragraph">Whitelisted indicators are hidden by default, so the data you see is already pre-filtered to help you maintain focus on more relevant connections. Additionally, you can apply the Malicious filter and export the results as JSON. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="251" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.34.15-1024x251.png" alt="" class="wp-image-22700" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.34.15-1024x251.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.34.15-300x74.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.34.15-768x189.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.34.15-1536x377.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.34.15-2048x503.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.34.15-370x91.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.34.15-270x66.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.34.15-740x182.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Filters allow you to sort the observables by verdict to narrow down your search. Threat Intelligence Lookup</em> </figcaption></figure>



<h3 class="wp-block-heading">Check the underlying infrastructure </h3>



<p class="wp-block-paragraph">If a URL is malicious, but its IP appears benign, this probably means that a shared infrastructure is being used, such as a CDN or reverse proxy. For example: </p>



<p class="wp-block-paragraph"><strong>Cloudflare AS13335 — Captcha Reverse Proxy / Gateway </strong> </p>



<p class="wp-block-paragraph">https://ipinfo[.]io/188[.]114[.]97[.]3</p>



<p class="wp-block-paragraph">If both the URL and IP are marked malicious, this most likely points to VPS or hosting infrastructure used by threat actors, for example: </p>



<p class="wp-block-paragraph"><strong>HostPapa AS36352 — VPS Service </strong> </p>



<p class="wp-block-paragraph">https://ipinfo[.]io/23[.]94[.]153[.]149</p>



<h3 class="wp-block-heading">Put the findings to work </h3>



<p class="wp-block-paragraph">The resulting IOC set can be now used for retrospective hunting in SIEM/NDR to identify previous activity involving the same infrastructure, as well as for blocking on perimeter firewalls to reduce the risk of further communication with known suspicious infrastructure. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Shorten the path to investigation with TI Lookup<br>Hunt with threat intelligence from <span class="highlight">16K+ security teams
</span> 
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://login.any.run/register?redirect=https://intelligence.any.run/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=proactive-threat-hunting&#038;utm_term=190826&#038;utm_content=linktoservice  " target="_blank" rel="noopener">
Try TI Lookup
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Use Case #2. Validating Threat Hunting Hypotheses </h2>



<p class="wp-block-paragraph">While working with a <a href="https://any.run/cybersecurity-blog/threat-intelligence-reports/" target="_blank" rel="noreferrer noopener">TI Report</a> or an <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> analysis session, you notice that after downloading the payload, the malware established a C2 connection over the non-standard port 1337. Based on that, you come up with a hypothesis: all samples with similar behavior may be tied to common infrastructure. </p>



<p class="wp-block-paragraph">To confirm or disprove this hypothesis, you need to start with a Threat Intelligence Lookup query for the observed behavior, in this case, MITRE T1105 and destination port 1337. </p>



<p class="wp-block-paragraph">You can use <a href="https://any.run/cybersecurity-blog/expanded-free-ti-plan/" target="_blank" rel="noreferrer noopener">AI-powered search</a> and just list the desired TTP and port number without using proper syntax: </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="112" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.41.40-1024x112.png" alt="" class="wp-image-22703" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.41.40-1024x112.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.41.40-300x33.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.41.40-768x84.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.41.40-1536x168.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.41.40-370x40.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.41.40-270x30.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.41.40-740x81.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.41.40.png 1902w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Lookup is powered by AI search to help you with query building</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph"><a href="https://intelligence.any.run/analysis/lookup?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktoservice#{%22query%22:%22MITRE:%5C%22T1105%5C%22%20and%20destinationPort:%5C%221337%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">MITRE:&#8221;T1105&#8243; AND destinationPort:&#8221;1337&#8243;</a> </p>



<h3 class="wp-block-heading">Explore the related infrastructure </h3>



<p class="wp-block-paragraph">In Connections, you can see the number of unique addresses, their reputation, geographic context (in CN tab marking the country of submission), and potential C2 infrastructure: </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="396" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.43.07-1024x396.png" alt="" class="wp-image-22702" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.43.07-1024x396.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.43.07-300x116.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.43.07-768x297.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.43.07-1536x594.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.43.07-2048x791.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.43.07-370x143.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.43.07-270x104.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-2026-08-18-at-11.43.07-740x286.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Analyze connections between URLs, domains, IPs, ports, and countries related to your request. Threat Intelligence Lookup</em> </figcaption></figure>



<p class="wp-block-paragraph">To confirm or disprove the hypothesis, all you need to do is collect network IOCs and check them in your corporate SIEM. From the results, you can make an evidence-based conclusion. </p>



<h3 class="wp-block-heading">Pivot to Interactive Sandboxing </h3>



<p class="wp-block-paragraph">To further validate your hypothesis, open the <strong>Analyses </strong>tab and review related sandbox sessions. Select a sample to see how the attack unfolds and compare its behavior with the activity you initially observed. </p>



<p class="wp-block-paragraph">One of the samples in our TI Lookup results leads to a Sandbox analysis of a malicious script delivered via a user-opened ZIP file. Here, we can see the attack unfold — from scheduled-task persistence to system enumeration and potential data exfiltration. </p>



<p class="wp-block-paragraph"><a href="https://app.any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktoservice/tasks/38cb400c-5301-410b-9687-1153201f0f53" target="_blank" rel="noreferrer noopener">View analysis</a> </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="569" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/example_sb-1024x569.png" alt="" class="wp-image-22724" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/example_sb-1024x569.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/example_sb-300x167.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/example_sb-768x427.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/example_sb-1536x854.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/example_sb-370x206.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/example_sb-270x150.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/example_sb-740x411.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/example_sb.png 1823w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">A malicious sample analyzed in ANY.RUN’s Interactive Sandbox </figcaption></figure>



<h3 class="wp-block-heading">Submitting your findings </h3>



<p class="wp-block-paragraph">If your hypothesis was confirmed, pass the findings and context to the detection &amp; security engineering team to create new detection rules. They will contribute to your organization’s proactive security posture. </p>



<h2 class="wp-block-heading">Use Case #3. Reverse URL Search Across Domain Patterns </h2>



<p class="wp-block-paragraph">We investigate phishing campaigns. We’re particularly interested in domains related to brands, CTAs, and social engineering elements. </p>



<p class="wp-block-paragraph">When investigating phishing campaigns, you may need to find domains related to brands, CTAs, and <a href="https://any.run/cybersecurity-blog/social-engineering-attacks-2026/" target="_blank" rel="noreferrer noopener">social engineering</a> elements. </p>



<p class="wp-block-paragraph">You also need to enrich them with context to understand which URLs were observed, which IPs they resolved to, their reputation, and finally, which IOCs can be used to expand detection coverage.  </p>



<p class="wp-block-paragraph">This may sound like a lot, but with TI Lookup, this can be done fast. </p>



<p class="wp-block-paragraph">Build a query for the required threat, for example, DocuSign-related activity: </p>



<p class="wp-block-paragraph"><a href="https://intelligence.any.run/analysis/lookup?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktoservice#{%22query%22:%22domainName:%5C%22docusign*share%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">domainName:&#8221;docusign*share&#8221;</a> </p>



<p class="wp-block-paragraph">And you can check the dedicated Domains, URLs, and IPs tabs to explore related observables. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="337" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-ti-lookup-1024x337.png" alt="" class="wp-image-22706" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-ti-lookup-1024x337.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-ti-lookup-300x99.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-ti-lookup-768x253.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-ti-lookup-1536x505.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-ti-lookup-2048x674.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-ti-lookup-370x122.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-ti-lookup-270x89.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-ti-lookup-740x243.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Tab listing domains related to the DocuSign request in TI Lookup</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">To see connections between them, click <strong>Show relations </strong>for a full breakdown: </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="526" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-relation-ti-lookup-1-1024x526.png" alt="" class="wp-image-22708" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-relation-ti-lookup-1-1024x526.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-relation-ti-lookup-1-300x154.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-relation-ti-lookup-1-768x394.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-relation-ti-lookup-1-1536x788.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-relation-ti-lookup-1-2048x1051.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-relation-ti-lookup-1-370x190.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-relation-ti-lookup-1-270x139.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-relation-ti-lookup-1-585x300.png 585w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/docusign-relation-ti-lookup-1-740x380.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Relations between domains, URLs, and IPs for the same query. TI Lookup</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">This significantly accelerates the search and analysis of related IOCs by bringing the relevant network context into a single workflow. <br>Use the relevant IOCs to expand detection coverage and support further investigation of the phishing campaign. </p>



<h2 class="wp-block-heading">Use Case #4. For DFIR Analysts: Gathering C2 Infrastructure of Mirai </h2>



<p class="wp-block-paragraph">The <a href="https://any.run/cybersecurity-blog/triage-analyst-guide/" target="_blank" rel="noreferrer noopener">alert triage</a> team has passed you a confirmed incident related to Mirai. Your goal is to collect additional IOCs, find related URLs and IPs, and determine the scale of the threat. </p>



<p class="wp-block-paragraph">Once again, you start the investigation with what’s known. Browse the confirmed threat in TI Lookup to find relevant threat intelligence and associated infrastructure: </p>



<p class="wp-block-paragraph"><a href="https://intelligence.any.run/analysis/lookup?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktoservice#{%22query%22:%22threatName:%5C%22^mirai$%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">threatName:&#8221;^mirai$&#8221;</a> </p>



<p class="wp-block-paragraph">Narrow down the result by applying the Malicious filter: </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="535" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/threatname-mirai-lookup-1-1024x535.png" alt="" class="wp-image-22710" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/threatname-mirai-lookup-1-1024x535.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/threatname-mirai-lookup-1-300x157.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/threatname-mirai-lookup-1-768x401.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/threatname-mirai-lookup-1-1536x802.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/threatname-mirai-lookup-1-2048x1069.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/threatname-mirai-lookup-1-370x193.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/threatname-mirai-lookup-1-270x141.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/threatname-mirai-lookup-1-740x386.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Filtering results by verdict in Threat Intelligence Lookup</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">Collect the clean list of observables, including related URLs and IP addresses, and export the results:</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="288" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/searchresults-ti-lookup-anyrun-json-1-1024x288.png" alt="" class="wp-image-22712" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/searchresults-ti-lookup-anyrun-json-1-1024x288.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/searchresults-ti-lookup-anyrun-json-1-300x84.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/searchresults-ti-lookup-anyrun-json-1-768x216.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/searchresults-ti-lookup-anyrun-json-1-1536x432.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/searchresults-ti-lookup-anyrun-json-1-2048x576.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/searchresults-ti-lookup-anyrun-json-1-370x104.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/searchresults-ti-lookup-anyrun-json-1-270x76.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/searchresults-ti-lookup-anyrun-json-1-740x208.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Download search results in JSON format for easy handoff. TI Lookup</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">Pass the resulting IOC set to the detection &amp; security engineering team for retrospective hunting and to expand threat detection coverage. </p>



<p class="wp-block-paragraph">The team now has all data needed to update playbooks and detection rules based on collective threat intelligence from <a href="https://any.run/cybersecurity-blog/soc-business-success-cases-anyrun/" target="_blank" rel="noreferrer noopener">16K+ SOC teams</a>. </p>



<h2 class="wp-block-heading">Operational Impact for Security Teams </h2>



<ul class="wp-block-list">
<li><strong>Reduce manual investigation effort </strong>by spending less time switching between sources and correlating network infrastructure data. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Move faster from intelligence to action </strong>by turning TI findings into observables ready for retrospective hunting, blocking, or handoff to detection &amp; security engineering. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Make investigations more consistent and repeatable </strong>by bringing relationships, reputation data, and filtering into a unified workflow with exportable results. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Streamline cross-team handoffs</strong> by reducing the need to recollect and repackage data between threat hunting, DFIR, and detection engineering teams. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Increase team throughput </strong>by enabling analysts to handle more investigations without a proportional increase in manual effort. </li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Cut MTTR</span>  by 21 minutes per case <br>
<span class="highlight">Actionable</span>  threat intelligence for faster response in SOCs
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=proactive-threat-hunting&#038;utm_term=190826&#038;utm_content=linktotilookuplanding#contact-sales" target="_blank" rel="noopener">
Integrate TI Lookup
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Conclusion </h2>



<p class="wp-block-paragraph">Effective threat intelligence and proactive threat hunting are about turning threat data into action. With ANY.RUN Threat Intelligence, security teams can investigate malware and phishing activity, validatehunting hypotheses, uncover related infrastructure, collect actionable IOCs, and use those findings to strengthen detection and response. </p>



<h2 class="wp-block-heading">About ANY.RUN </h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> fits into modern SOC workflows, integrating with existing security processes and supporting operations across teams. This includes <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">safely detonating files and URLs to expose malicious behavior</a>, <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">enriching investigations with broader threat intelligence</a>, and applying <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=proactive-threat-hunting&amp;utm_term=190826&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">continuously updated intelligence</a> to support faster, more informed decisions. </p>



<p class="wp-block-paragraph">Today, more than 700,000 security professionals and 16,000 organizations use ANY.RUN to accelerate investigations, reduce unnecessary escalations, and strengthen their defenses against evolving malware and phishing threats. </p>



<p class="wp-block-paragraph">For the latest threat research, real-world attack analysis, and investigation insights, follow ANY.RUN on <a href="https://www.linkedin.com/company/any-run/" target="_blank" rel="noreferrer noopener">LinkedIn</a> and <a href="https://x.com/anyrun_app/" target="_blank" rel="noreferrer noopener">X</a>. </p>



<h2 class="wp-block-heading">FAQ </h2>



<div class="schema-faq wp-block-yoast-faq-block"><div class="schema-faq-section" id="faq-question-1787134332541"><strong class="schema-faq-question">What is proactive threat hunting? </strong> <p class="schema-faq-answer">Proactive threat hunting is the process of searching for threats before they trigger traditional security alerts. It uses threat intelligence, behavioral data, and IOCs to identify potentially malicious activity. </p> </div> <div class="schema-faq-section" id="faq-question-1787134338945"><strong class="schema-faq-question">How does ANY.RUN support threat hunting? </strong> <p class="schema-faq-answer">ANY.RUN Threat Intelligence helps analysts investigate malware and phishing threats, explore related infrastructure, validate hypotheses, and collect actionable IOCs. </p> </div> <div class="schema-faq-section" id="faq-question-1787134343695"><strong class="schema-faq-question">What is ANY.RUN Threat Intelligence Lookup? </strong> <p class="schema-faq-answer">Threat Intelligence Lookup is a search solution for investigating threats using indicators, behaviors, network data, and other threat intelligence collected through ANY.RUN. </p> </div> <div class="schema-faq-section" id="faq-question-1787134354584"><strong class="schema-faq-question">How can threat intelligence improve malware detection? </strong> <p class="schema-faq-answer">Threat intelligence provides additional context around malware behavior, infrastructure, and related observables. Security teams can use these findings to improve detection rules and expand coverage. </p> </div> <div class="schema-faq-section" id="faq-question-1787134362994"><strong class="schema-faq-question">Can ANY.RUN help investigate phishing attacks? </strong> <p class="schema-faq-answer">Yes. Analysts can use ANY.RUN to investigate phishing URLs, domains, IP addresses, infrastructure, and related indicators to better understand phishing campaigns. </p> </div> <div class="schema-faq-section" id="faq-question-1787134367980"><strong class="schema-faq-question">How can IOCs be used in SIEM and NDR? </strong> <p class="schema-faq-answer">Relevant IOCs can be checked against SIEM and NDR data for retrospective threat hunting and signs of previous malicious activity. Validated findings can also support new detections and response actions. </p> </div> <div class="schema-faq-section" id="faq-question-1787134375777"><strong class="schema-faq-question">How does threat intelligence help SOC teams? </strong> <p class="schema-faq-answer">Threat intelligence helps SOC teams reduce manual investigation, validate threats faster, and turn findings into actionable data for detection and response. </p> </div> </div>
<p>The post <a href="https://any.run/cybersecurity-blog/proactive-threat-hunting/">Hunt Malware &amp; Phishing Threats with ANY.RUN for Proactive Enterprise Security</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/proactive-threat-hunting/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US</title>
		<link>https://any.run/cybersecurity-blog/mirage2fa-phishing-targets-us-companies/</link>
					<comments>https://any.run/cybersecurity-blog/mirage2fa-phishing-targets-us-companies/#respond</comments>
		
		<dc:creator><![CDATA[ShiFu&nbsp;and&nbsp;raptur3]]></dc:creator>
		<pubDate>Tue, 18 Aug 2026 09:28:12 +0000</pubDate>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[malware analysis]]></category>
		<category><![CDATA[malware behavior]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=22613</guid>

					<description><![CDATA[<p>Mirage2FA is an active phishing-as-a-service toolkit built to steal Microsoft 365 credentials and authenticated sessions through Adversary-in-the-Middle (AiTM) attacks. ANY.RUN research shows that 63.7% of identified victims are in the US, with Technologies, Manufacturing, and Education among the most targeted industries. The operation has generated thousands of compromise events between 2024 and 2026, including stolen [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/mirage2fa-phishing-targets-us-companies/">Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Mirage2FA is an active phishing-as-a-service toolkit built to steal Microsoft 365 credentials and authenticated sessions through Adversary-in-the-Middle (AiTM) attacks. </p>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mirage2fa-phishing-blog&amp;utm_term=180826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> research shows that <strong>63.7% of identified victims are in the US</strong>, with <a href="https://any.run/by-industry/technology/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mirage2fa-phishing-blog&amp;utm_term=180826&amp;utm_content=linktotechnology" target="_blank" rel="noreferrer noopener">Technologies</a>, <a href="https://any.run/by-industry/manufacturing/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mirage2fa-phishing-blog&amp;utm_term=180826&amp;utm_content=linktomanufacturing" target="_blank" rel="noreferrer noopener">Manufacturing</a>, and Education among the most targeted industries. The operation has generated thousands of compromise events between 2024 and 2026, including stolen session cookies, passwords, and SSO access.</p>



<p class="wp-block-paragraph">Once an authenticated Microsoft 365 session is hijacked, attackers may gain access to corporate email, sensitive data, and trusted business accounts, creating a path for <strong>impersonation, fraud, and further compromise</strong>. Detecting the attack before stolen sessions are reused can help security teams contain account takeover earlier and reduce the potential business impact. </p>



<h2 class="wp-block-heading">Key Takeaways </h2>



<ul class="wp-block-list">
<li><strong>Mirage2FA bypasses conventional MFA to hijack active Microsoft 365 sessions.</strong> The PhaaS toolkit uses an Adversary-in-the-Middle (AiTM) flow to capture credentials, 2FA codes, and authenticated session cookies. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Mirage2FA activity was linked to 3,518 unique organization email domains</strong>, showing the campaign’s broad reach across US and EU corporate environments.* </li>
</ul>



<ul class="wp-block-list">
<li><strong>The kit shows a high potential compromise rate.</strong> Of 9,426 unique targeted email addresses, <strong>4,532 were potentially compromised — about 48%</strong>.* </li>
</ul>



<ul class="wp-block-list">
<li><strong>The US is the main victim market.</strong> <strong>2,885 victims, or 63.7% of the total</strong>, were located in the United States, while victim activity was recorded across 94 countries. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Session theft is the most common compromise outcome.</strong> The dataset contains <strong>9,332 potential compromise events</strong>, including 4,561 cookie-theft events, 3,044 password/2FA events, 1,339 SSO logins, and 388 other outcomes.* </li>
</ul>



<ul class="wp-block-list">
<li><strong>Mirage2FA relies on browser-based delivery rather than binary malware.</strong> .htm, .xhtml, and .svg stagers, QR codes, JavaScript obfuscation, and WebSocket-based AiTM activity allow the attack to run largely inside the browser. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Mobile users make up a significant share of successful activity.</strong> <strong>33.3% of successful login events came from mobile devices</strong>, where phishing pages can be harder to inspect due to limited URL visibility. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Recurring technical patterns remain useful even as infrastructure changes.</strong> The /xls/*.js loader structure, and LINX* markers provide hunting opportunities beyond individual domains and IP addresses. </li>
</ul>



<p class="wp-block-paragraph"><strong>Note:</strong> All victim, compromise, and campaign-scale figures in this report are approximate estimates based on the available dataset and represent potential impact rather than independently confirmed compromises. </p>



<!-- CTA Split START -->
<div class="cta-split">
<div class="cta__split-left">

<!-- Image -->
<img decoding="async" loading="lazy" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA_article-block.png" alt="PhantomEnigma Threat Report from ANY.RUN" class="cta__split-icon">
</div>

<div class="cta__split-right">
<div>

<!-- Heading -->
<h3 class="cta__split-heading"><br>Read Complete Mirage2FA Research in TI Reports</h3>

<!-- Text -->
<p class="cta__split-text">
Get a detailed version of the report for SOC and MSSP teams:
 </p><ul>
    <li><strong>A complete list of IOCs</strong></li><strong>
    <li><strong>Additional info on Mirage2FA</strong></li><strong>
    <li><strong>Access to other reports</strong></li><strong>
  </strong></strong></strong></ul><strong><strong><strong>
<a target="_blank" rel="noopener" href="https://intelligence.any.run/plans/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mirage2fa-phishing-blog&amp;utm_term=180826&amp;utm_content=linktopricing" style="text-decoration: underline; color: #02c0fc;">Available for users with ANY.RUN TI Core and Complete plans. See details →</a>

<br>

</strong></strong></strong></div><strong><strong><strong>
<!-- CTA Link -->
<a target="_blank" rel="noopener" id="article-banner-split" href="https://intelligence.any.run/reports/08-17-2026-mirage2fa/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=mirage2fa-phishing-blog&#038;utm_term=180826&#038;utm_content=linktotireports"><div class="cta__split-link"><strong>Explore full report</strong></div></a>
</strong></strong></strong></div><strong><strong>
</strong></strong></div><strong><strong>
<!-- CTA Split END -->
<!-- CTA Split Styles START -->
<style>
.cta-split {
overflow: hidden;
margin: 3rem 0;
display: grid;
justify-items: center;
border-radius: 0.5rem;
width: 100%;
min-height: 25rem;
grid-template-columns: repeat(2, 1fr);
border: 1px solid rgba(75, 174, 227, 0.32);
font-family: 'Catamaran Bold';
}

.cta__split-left {
display: flex;
align-items: center;
justify-content: center;
height: 100%;
width: 100%;
background-color: #161c59;
background-position: center center;
background: rgba(32, 168, 241, 0.1);
}

.cta__split-icon { 
width: 100%;
height: auto;
object-fit: contain;
max-width: 100%;
}

.cta__split-right {
display: flex;
flex-direction: column;
justify-content: space-between;
padding: 2rem;
}

.cta__split-heading { font-size: 1.5rem; }

.cta__split-text {
margin-top: 1rem;
font-family: Lato, Roboto, sans-serif;
}

.cta__split-link {
padding: 0.5rem 1rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: white;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
display: block;
z-index: 1000;
position: relative;
cursor: pointer !important;
}

.cta__split-link:hover {
background-color: #68CBFF;
color: white;
cursor: pointer;
}

.highlight { color: #ea2526;}


/* Mobile styles START */
@media only screen and (max-width: 768px) {

.cta-split {
grid-template-columns: 1fr;
min-height: auto;
}

.cta__split-left {
height: auto;
min-height: 10rem;
}


.cta__split-left, .cta__split-right {
height: auto;
}

.cta__split-heading { font-size: 1.2rem; }

.cta__split-text { font-size: 1rem; }
.cta__split-icon {
max-height: auto;
object-fit: cover;
}

}
/* Mobile styles END */
</style>
<!-- CTA Split Styles END --></strong></strong>



<h2 class="wp-block-heading">Mirage2FA Overview </h2>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="707" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-in-brief-1024x707.png" alt="" class="wp-image-22639" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-in-brief-1024x707.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-in-brief-300x207.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-in-brief-768x530.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-in-brief-1536x1060.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-in-brief-2048x1413.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-in-brief-370x255.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-in-brief-270x186.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-in-brief-435x300.png 435w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-in-brief-740x511.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Mirage2FA phishing targets US companies in technology and manufacturing</figcaption></figure>
</div>


<p class="wp-block-paragraph">Mirage2FA is a commercial phishing-as-a-service offering aimed at compromising corporate Microsoft 365 accounts and active sessions (session cookies) while bypassing two-factor authentication. The operator distributes malicious attachments that execute in the victim’s browser and silently fetch harvesting logic from a C2, proxying the login/2FA flow in real time (AiTM).</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-355"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="2"
           data-rows="8"
           data-wpID="355"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Threat type                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Phishing-as-a-Service (PhaaS); AiTM / 2FA bypass                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Objective                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Microsoft 365 / OAuth credentials and session cookies                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Capabilities                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        HTML smuggling (.htm/.xhtml), SVG redirect, JS obfuscation (XOR+Base64+eval, hex decoder,obfuscator.io), AiTM over WebSocket, cookie theft, QR-code lures, IP/fingerprint filtering                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Delivery                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Email attachments (.htm/.xhtml/.svg), links; distribution including Amazon SES                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Motivation                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Financial (theft/resale of access and sessions; PhaaS)                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Operator / brand                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        LinX Coders (LINX placeholders, botslinxlogsss…bot, channel LinXcoded)                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Known links                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        C2 domains *.cheacker.store, *.volatilesour.store and others                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Activity window                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        2024-09 - 2026-07 (observed)                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-355'>
table#wpdtSimpleTable-355{ table-layout: fixed !important; }
table#wpdtSimpleTable-355 td, table.wpdtSimpleTable355 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">Business impact can include: </p>



<ul class="wp-block-list">
<li><strong>Identity-driven access risk:</strong> Stolen sessions can give attackers trusted access to Microsoft 365 and connected cloud services. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Fraud and impersonation exposure:</strong> Compromised accounts can be used to target employees, customers, suppliers, or finance teams. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Higher containment costs:</strong> Session theft often requires more than a password reset, increasing response effort and investigation scope. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Greater blast radius:</strong> One compromised identity can create follow-on access across email, SSO-connected apps, and internal workflows. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Control gaps despite MFA:</strong> Successful AiTM attacks can expose weaknesses in authentication and session-management strategies. </li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Lower the cost of account compromise with early detection.</span><br>Keep one stolen session from becoming a wider business incident.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=mirage2fa-phishing-blog&#038;utm_term=180826&#038;utm_content=linktolanding#contact-sales" target="_blank" rel="noopener">
Integrate ANY.RUN in your SOC
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Where Mirage2FA Hits Hardest: Targeted Industries, Regions, and Compromise Outcomes </h2>



<p class="wp-block-paragraph">Mirage2FA activity increased sharply throughout 2026, while victim data shows a clear concentration in the United States and in industries that depend heavily on Microsoft 365 for daily operations. </p>



<p class="wp-block-paragraph">By the time data collection ended in July 2026, <strong>445 Mirage2FA sandbox sessions had already been recorded for the month</strong>. Although the dataset does not cover the full month, the volume of observed activity confirms that Mirage2FA remained active during the reporting period. </p>



<h3 class="wp-block-heading">Mirage2FA Activity Increased Sharply in 2026 </h3>



<p class="wp-block-paragraph">ANY.RUN recorded a steady rise in Mirage2FA sandbox activity from March through July 2026: </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="649" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage-2FA_Sandbox-sessions-per-month-1024x649.png" alt="" class="wp-image-22641" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage-2FA_Sandbox-sessions-per-month-1024x649.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage-2FA_Sandbox-sessions-per-month-300x190.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage-2FA_Sandbox-sessions-per-month-768x486.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage-2FA_Sandbox-sessions-per-month-1536x973.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage-2FA_Sandbox-sessions-per-month-2048x1297.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage-2FA_Sandbox-sessions-per-month-370x234.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage-2FA_Sandbox-sessions-per-month-270x171.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage-2FA_Sandbox-sessions-per-month-740x469.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">ANY.RUN&#8217;s Threat Intelligence shows a steady rise in Mirage2FA attacks</figcaption></figure>
</div>


<h3 class="wp-block-heading">Technology, MSSPs, and Manufacturing Face the Highest Exposure </h3>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="904" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Targeted-Industries-1-904x1024.png" alt="" class="wp-image-22649" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Targeted-Industries-1-904x1024.png 904w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Targeted-Industries-1-265x300.png 265w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Targeted-Industries-1-768x870.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Targeted-Industries-1-1355x1536.png 1355w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Targeted-Industries-1-1807x2048.png 1807w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Targeted-Industries-1-370x419.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Targeted-Industries-1-270x306.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Targeted-Industries-1-740x839.png 740w" sizes="auto, (max-width: 904px) 100vw, 904px" /><figcaption class="wp-element-caption">Technology and manufacturing are the main industries targeted by Mirage2FA</figcaption></figure>
</div>


<p class="wp-block-paragraph">Mirage2FA activity spans multiple industries, but ANY.RUN telemetry shows a higher concentration in several sectors: </p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-356"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="2"
           data-rows="9"
           data-wpID="356"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Industry                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Share                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Technologies                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        19.2%                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Manufacturing                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        11.1%                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Education                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        9.9%                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Consulting                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        8.3%                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Telecommunications                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        6.6%                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Health                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        5.4%                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Finance                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        3.1%                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Other                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        19.3%                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-356'>
table#wpdtSimpleTable-356{ table-layout: fixed !important; }
table#wpdtSimpleTable-356 td, table.wpdtSimpleTable356 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">Successful Microsoft 365 account takeover in these environments can expose more than one mailbox. Compromised identities may provide access to customer communications, internal documents, cloud applications, supplier relationships, or privileged workflows, increasing the potential impact of a single successful phishing attempt. </p>



<h2 class="wp-block-heading">63.7% of Identified Victims Are in the United States </h2>



<p class="wp-block-paragraph">Mirage2FA shows a strong concentration in the United States, which accounts for <strong>2,885 victims, or 63.7% of the total</strong>. Victim activity was also observed in India, Singapore, the United Kingdom, Canada, Saudi Arabia, South Africa, and other countries. </p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-357"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="9"
           data-wpID="357"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Country                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Victims                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Share                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        United States                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        2,885                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        63.7%                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Unknown                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        574                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        12.7%                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        India                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        229                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        5.1%                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Singapore                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        186                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        4.1%                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        United Kingdom                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        76                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        1.7%                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Canada                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        75                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        1.7%                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Saudi Arabia                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        63                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        1.4%                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        South Africa                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        46                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C9"
                    data-col-index="2"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        1.0%                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-357'>
table#wpdtSimpleTable-357{ table-layout: fixed !important; }
table#wpdtSimpleTable-357 td, table.wpdtSimpleTable357 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">This distinction matters: sandbox submissions reflect <strong>where analysts encounter and investigate samples</strong>, not necessarily where the attackers are finding victims. The compromise data shows that Mirage2FA is particularly focused on <strong>US organizations</strong>, with Singapore also showing disproportionately high victim activity compared with its share of submissions.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="649" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Submission-Geograph_VS_Victim-Geography-1-1024x649.png" alt="" class="wp-image-22646" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Submission-Geograph_VS_Victim-Geography-1-1024x649.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Submission-Geograph_VS_Victim-Geography-1-300x190.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Submission-Geograph_VS_Victim-Geography-1-768x486.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Submission-Geograph_VS_Victim-Geography-1-1536x973.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Submission-Geograph_VS_Victim-Geography-1-2048x1297.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Submission-Geograph_VS_Victim-Geography-1-370x234.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Submission-Geograph_VS_Victim-Geography-1-270x171.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Submission-Geograph_VS_Victim-Geography-1-740x469.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">US companies are the core target from Mirage2FA attacks</figcaption></figure>
</div>


<p class="wp-block-paragraph"></p>



<h2 class="wp-block-heading">Session Theft Is the Most Common Compromise Outcome </h2>



<p class="wp-block-paragraph">The open-source dataset records <strong>9332 successful compromise events</strong> across several outcomes: </p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-358"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="6"
           data-wpID="358"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Outcome                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Events                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Unique victims                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Session cookie theft                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        4,561                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        2,541                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Password / 2FA compromise                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        3,044                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        1,589                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        SSO login                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        1,339                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        616                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Other events                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        388                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        270                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Total                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        9332                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        4532                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-358'>
table#wpdtSimpleTable-358{ table-layout: fixed !important; }
table#wpdtSimpleTable-358 td, table.wpdtSimpleTable358 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">Session-cookie theft was the most common result, accounting for <strong>more than half of all recorded compromise events</strong>. </p>



<h2 class="wp-block-heading">How Mirage2FA Attacks Organizations: The Full Attack Flow </h2>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="649" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Attack-Flow-1-1024x649.png" alt="" class="wp-image-22652" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Attack-Flow-1-1024x649.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Attack-Flow-1-300x190.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Attack-Flow-1-768x486.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Attack-Flow-1-1536x973.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Attack-Flow-1-2048x1297.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Attack-Flow-1-370x234.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Attack-Flow-1-270x171.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Attack-Flow-1-740x469.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">The entire attack flow of Mirage2FA</figcaption></figure>
</div>


<p class="wp-block-paragraph">To see how Mirage2FA moves from a phishing message to Microsoft 365 account takeover, you can check its behavior in an ANY.RUN sandbox session. The attack takes place almost entirely in the browser, using malicious attachments, remote JavaScript, and an AiTM proxy to intercept authentication in real time. </p>



<p class="wp-block-paragraph">Here is how the compromise unfolds: </p>



<p class="wp-block-paragraph"><a href="https://app.any.run/tasks/fcab7b28-0ee4-4761-bb6e-281b4979567d/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mirage2fa-phishing-blog&amp;utm_term=180826&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">View analysis session with Mirage2FA</a> </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="559" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image6-1024x559.png" alt="" class="wp-image-22654" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image6-1024x559.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image6-300x164.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image6-768x419.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image6-1536x838.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image6-370x202.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image6-270x147.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image6-740x404.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image6.png 1951w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Full attack chain analyzed inside ANY.RUN’s sandbox</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph"><strong>1. Delivery: </strong>A phishing email delivers a malicious .htm, .xhtml, or .svg attachment, or directs the victim to a QR-code link. Mirage2FA campaigns have also been distributed at scale through Amazon SES. <em>(MITRE T1566.001 / T1566.002)</em> </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">See the full attack chain and give analysts the context to act faster.</span><br>Reduce investigation time before account compromise turns into a larger incident.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mirage2fa-phishing-blog&amp;utm_term=180826&amp;utm_content=linktolanding#contact-sales" target="_blank" rel="noopener">
Cut MTTR by 21 mins per case
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph"><strong>2. Execution: </strong>The victim opens the attachment, causing the browser to execute the embedded stager. <em>(T1204.002)</em> </p>



<p class="wp-block-paragraph"><strong>3. Client-side staging: </strong>Obfuscated HTML smuggling or an SVG inline script decodes and executes in the browser. The stager reads a per-recipient token: the victim’s email, Base64-encoded as <strong>LINXB64EMAIL</strong>. <em>(T1027 / T1027.006)</em> </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="574" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image7-1024x574.png" alt="" class="wp-image-22656" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image7-1024x574.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image7-300x168.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image7-768x430.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image7-370x207.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image7-270x151.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image7-740x414.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image7.png 1423w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Verification carried out inside ANY.RUN sandbox</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph"><strong>4. Loader retrieval: </strong>The stager retrieves the harvesting logic from a remote loader using the /xls/&lt;token&gt;.js pattern. <em>(T1105)</em> </p>



<p class="wp-block-paragraph"><strong>5. AiTM presentation: </strong>The victim is shown a fake Microsoft 365 login page backed by an Adversary-in-the-Middle reverse proxy. </p>



<p class="wp-block-paragraph"><strong>6. Credential and 2FA capture: </strong>The victim enters their username, password, and one-time 2FA code into the phishing page. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="766" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image8-1024x766.png" alt="" class="wp-image-22658" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image8-1024x766.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image8-300x224.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image8-768x575.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image8-370x277.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image8-270x202.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image8-740x554.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image8-80x60.png 80w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image8.png 1421w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Victims entering their usernames and passwords on a fake Microsoft login page</em></figcaption></figure>
</div>


<p class="wp-block-paragraph"><strong>7. Real-time relay: </strong>Mirage2FA relays the authentication data to the legitimate Microsoft 365 service over a <strong>WebSocket channel</strong>. Once authentication succeeds, the proxy receives a valid authenticated session, effectively bypassing MFA. <em>(T1557 / T1111)</em> </p>



<p class="wp-block-paragraph"><strong>8. Session theft: </strong>The authenticated session cookies, together with captured credentials, are exfiltrated to the operator panel. Mirage2FA stores the stolen cookies as <strong>Base64-encoded .txt dumps</strong>. <em>(T1539)</em> </p>



<p class="wp-block-paragraph"><strong>9. Account takeover: </strong>The attacker can reuse the stolen session to access the victim’s Microsoft 365 account, read email, and impersonate the user without having to enter the password or complete MFA again. <em>(T1539 / T1071.001)</em> </p>



<h3 class="wp-block-heading">What Mirage2FA Attachments Look Like </h3>



<p class="wp-block-paragraph">Mirage2FA relies on browser-executed <strong>XHTML, .htm, and SVG attachments</strong>. Each acts as a stager, carrying a recipient-specific token such as <strong>LINXB64EMAIL, LINXEMAIL, or LINXCODERSEMAIL</strong> and retrieving the harvesting logic from the remote /xls/&lt;token&gt;.js loader. </p>



<p class="wp-block-paragraph">Across the samples analyzed, .htm was the dominant format: </p>



<ul class="wp-block-list">
<li><strong>629 .htm samples:</strong> 176 plain, 453 obfuscated </li>
</ul>



<ul class="wp-block-list">
<li><strong>198 XHTML samples:</strong> 167 plain, 31 obfuscated </li>
</ul>



<ul class="wp-block-list">
<li><strong>187 SVG samples:</strong> 175 plain, 12 obfuscated </li>
</ul>



<p class="wp-block-paragraph">Notably, the campaign uses .htm rather than .html, and researchers observed <strong>no binary malware</strong> in this dataset. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="538" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Compromise-Outcomes-1024x538.png" alt="" class="wp-image-22643" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Compromise-Outcomes-1024x538.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Compromise-Outcomes-300x158.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Compromise-Outcomes-768x403.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Compromise-Outcomes-1536x806.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Compromise-Outcomes-2048x1075.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Compromise-Outcomes-370x194.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Compromise-Outcomes-270x142.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA-Compromise-Outcomes-740x389.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Mirage2FA steals login information from affected companies</figcaption></figure>
</div>


<p class="wp-block-paragraph">The attack is carried out through browser-readable files and JavaScript, making inspection of suspicious web attachments and their runtime behavior especially important. </p>



<h2 class="wp-block-heading">How Mirage2FA Stagers Hide Their Activity </h2>



<p class="wp-block-paragraph">Although the attachments serve the same purpose, Mirage2FA uses several techniques to hide the redirect and loader logic from users and security controls. </p>



<h3 class="wp-block-heading">XHTML: Non-Obfuscated (Dynamic Iframe + Remote Loader) </h3>



<p class="wp-block-paragraph">The page builds a full-screen <strong>iframe</strong>, writes a document into it, and injects an external script (<strong>a1p2i.js</strong>). The token is read from the <strong>?ref=</strong> query parameter, defaulting to the placeholder <strong>LINXB64EMAIL</strong>. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="826" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagea-826x1024.png" alt="" class="wp-image-22667" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagea-826x1024.png 826w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagea-242x300.png 242w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagea-768x952.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagea-1239x1536.png 1239w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagea-370x459.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagea-270x335.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagea-740x917.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagea.png 1252w" sizes="auto, (max-width: 826px) 100vw, 826px" /></figure>



<h3 class="wp-block-heading">XHTML: Obfuscated (Hex-String Decoder) </h3>



<p class="wp-block-paragraph">The obfuscated XHTML variant hides its logic behind a hex-to-string decoder (<strong>rsy</strong>) and reads the token from <strong>?sdv=</strong> or the URL fragment, defaulting to <strong>LINXEMAIL</strong>. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="578" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imageb-1024x578.png" alt="" class="wp-image-22666" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imageb-1024x578.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imageb-300x169.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imageb-768x434.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imageb-370x209.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imageb-270x152.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imageb-740x418.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imageb.png 1410w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h3 class="wp-block-heading">HTML (.htm): Non-Obfuscated (Remote-Loader Stub) </h3>



<p class="wp-block-paragraph">The plainest HTML stager is a two-line loader: it sets the recipient token (<strong>uid</strong>) and pulls the remote harvesting script. This is the same <strong>/api/xls/a1p2i.js</strong> loader used by the XHTML variant, on a different domain. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="396" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagec-1024x396.png" alt="" class="wp-image-22665" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagec-1024x396.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagec-300x116.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagec-768x297.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagec-370x143.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagec-270x104.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagec-740x286.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagec.png 1222w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h3 class="wp-block-heading">HTML (.htm): Obfuscated (XOR + Base64 + eval) </h3>



<p class="wp-block-paragraph">The obfuscated HTML variant is self-contained: Base64-decodes a blob, XORs each byte with the key <strong>0xAD</strong> (173), then <strong>evals</strong> the resulting source. The token placeholder is exposed as <strong>RSTRING2</strong>. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="444" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imaged-1024x444.png" alt="" class="wp-image-22664" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imaged-1024x444.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imaged-300x130.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imaged-768x333.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imaged-1536x666.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imaged-370x160.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imaged-270x117.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imaged-740x321.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imaged.png 1670w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h3 class="wp-block-heading">SVG: Non-Obfuscated (Inline-Script Redirect) </h3>



<p class="wp-block-paragraph">The SVG payload abuses the &lt;<strong>script</strong>&gt; element permitted in standalone SVG documents. On open, it navigates the browser directly to the phishing URL, passing the recipient token via a query parameter (<strong>LINXB64EMAIL</strong>). </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="483" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagee-1024x483.png" alt="" class="wp-image-22663" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagee-1024x483.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagee-300x141.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagee-768x362.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagee-1536x724.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagee-370x174.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagee-270x127.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagee-740x349.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagee.png 1612w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h3 class="wp-block-heading">SVG: Obfuscated (obfuscator.io _0x Wrapper) </h3>



<p class="wp-block-paragraph">A minority of SVGs (12 unique) wrap the same redirect in an <strong>&lt;html&gt;&lt;body&gt;&lt;svg&gt;</strong> shell and an <strong>obfuscator.io</strong>-style string-array decoder to conceal the destination. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="396" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagef-1024x396.png" alt="" class="wp-image-22662" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagef-1024x396.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagef-300x116.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagef-768x297.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagef-1536x594.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagef-370x143.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagef-270x104.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagef-740x286.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/imagef.png 1686w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h2 class="wp-block-heading">Behavior Observed in the Sandbox </h2>



<p class="wp-block-paragraph">Across <strong>1,249 Mirage2FA sandbox sessions</strong>, dominant behaviors included phishing, obfuscated JavaScript, and WebSocket activity linked to the toolkit’s real-time AiTM channel. Researchers also observed IP and browser fingerprinting, QR-code delivery, and Amazon SES activity. </p>



<h2 class="wp-block-heading">Network Infrastructure </h2>



<p class="wp-block-paragraph">In total, we identified the entire cluster using a single <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mirage2fa-phishing-blog&amp;utm_term=180826&amp;utm_content=linktotilookup" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> query. This dataset is clearly visible in the new Connections block: all links, domains, and IP addresses, along with their reputations, are now in one place.</p>



<p class="wp-block-paragraph"><em>TI Lookup query: </em><a href="https://intelligence.any.run/analysis/lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mirage2fa-phishing-blog&amp;utm_term=180826&amp;utm_content=linktotilookup#{%22query%22:%22url:%5C%22/???/xls/?????*.js$%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener"><em>url:&#8221;/???/xls/?????*.js$&#8221;</em></a></p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="627" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image10-1-1024x627.png" alt="" class="wp-image-22670" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image10-1-1024x627.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image10-1-300x184.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image10-1-768x470.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image10-1-1536x941.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image10-1-370x227.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image10-1-270x165.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image10-1-740x453.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image10-1.png 1726w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">TI Lookup provides real-time intel related to Mirage2FA attacks </figcaption></figure>



<p class="wp-block-paragraph">The dataset is substantial. Therefore, the decision was made to proceed as follows: for each link <strong>X</strong>, take the malicious script <strong>M</strong>, deobfuscate it, and extract all the malicious links. To illustrate, we present the results of our work using a section of the interconnection graph.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="532" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image11-1024x532.png" alt="" class="wp-image-22672" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image11-1024x532.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image11-300x156.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image11-768x399.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image11-1536x797.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image11-370x192.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image11-270x140.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image11-740x384.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image11.png 2015w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Graph showing connections between Mirage2FA infrastructure</figcaption></figure>
</div>


<p class="wp-block-paragraph">Each script contained its own link to a PHP endpoint for data exfiltration and CAPTCHA solving. However, this endpoint had another feature: an open WebDAV/Opendir server. This feature allowed us to enrich the cluster data, significantly expanding our statistics.  </p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="996" height="254" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image12-1.png" alt="" class="wp-image-22674" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image12-1.png 996w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image12-1-300x77.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image12-1-768x196.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image12-1-370x94.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image12-1-270x69.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image12-1-740x189.png 740w" sizes="auto, (max-width: 996px) 100vw, 996px" /></figure>



<p class="wp-block-paragraph">Nevertheless, let us first describe what our sandbox has managed to discover over time. </p>



<p class="wp-block-paragraph"><strong>C2 / loader (ANY.RUN):</strong> </p>



<ul class="wp-block-list">
<li>IP <strong>185.174.100.224: </strong>ASN <strong>as-colocrossing</strong>. </li>
</ul>



<ul class="wp-block-list">
<li>Domains: <strong>user.cheacker.store</strong> (TL2), <strong>hvr.volatilesour.store</strong> (TL2), ver.bandhiem.com (TL0), pynutech.store and others. </li>
</ul>



<ul class="wp-block-list">
<li>Loader pattern: <strong>https://&lt;host&gt;/&lt;3-letter-code&gt;/xls/&lt;token&gt;.js</strong> — routing codes (api, ulr, eor, pxk, dsk, ncb, tsk, clr, vtk, bmr, …) match the paths seen in the SVG redirects; token suffixes: c2v, cpt, or none. Canonical endpoint: <strong>/api/xls/a1p2i.js</strong>. </li>
</ul>



<p class="wp-block-paragraph"><strong>Network signatures:</strong> </p>



<ul class="wp-block-list">
<li>GET /*/xls/*.js requests to *.cheacker.store / *.volatilesour.store (path regex: /[a-z]{3}/xls/[a-z0-9]+(?:c2v|cpt)?\.js. OR <em>/???/xls/?????*.js$</em>). </li>
</ul>



<ul class="wp-block-list">
<li>DNS query of the form &lt;base64&gt;.cheacker.store, where the label decodes to an email address. </li>
</ul>



<ul class="wp-block-list">
<li>Outbound <strong>WebSocket</strong> to the C2 after the loader executes (AiTM proxy). </li>
</ul>



<h2 class="wp-block-heading">Cluster Expansion </h2>



<h3 class="wp-block-heading">Operator infrastructure: IP activity </h3>



<p class="wp-block-paragraph">Drawing on data from open sources and information gathered during the study of the cluster, we began analyzing the developer&#8217;s characteristic patterns and the list of potential victims. </p>



<p class="wp-block-paragraph">While analyzing the messages sent by the Mirage2FA, we observed a consistent pattern: the substring &#8220;<strong>LINX</strong>&#8221; (LinxCode, Linx&#8230;) is used pervasively by the author and sometimes appears as a placeholder in request parameters. We hypothesize that the author used this method to test their own infrastructure. Below is a list of the IP addresses from which the author conducted these tests. </p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-359"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="6"
           data-rows="22"
           data-wpID="359"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:16.666666666667%;                    padding:10px;
                    "
                    >
                                        IP                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:16.666666666667%;                    padding:10px;
                    "
                    >
                                        Geo                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:16.666666666667%;                    padding:10px;
                    "
                    >
                                        Placeholder                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="D1"
                    data-col-index="3"
                    data-row-index="0"
                    style=" width:16.666666666667%;                    padding:10px;
                    "
                    >
                                        Msgs                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="E1"
                    data-col-index="4"
                    data-row-index="0"
                    style=" width:16.666666666667%;                    padding:10px;
                    "
                    >
                                        Bots                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="F1"
                    data-col-index="5"
                    data-row-index="0"
                    style=" width:16.666666666667%;                    padding:10px;
                    "
                    >
                                        Period (first to last)                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        209[.]205[.]192[.]6                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        US                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        LINXCODERSEMAIL                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D2"
                    data-col-index="3"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="E2"
                    data-col-index="4"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="F2"
                    data-col-index="5"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        2024-09-23                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        141[.]95[.]59[.]233                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        DE                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        LINXCODERSEMAIL                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D3"
                    data-col-index="3"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        6                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="E3"
                    data-col-index="4"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="F3"
                    data-col-index="5"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        2024-09-26 - 2025-02-17                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        185[.]174[.]100[.]20                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        US                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        LINXCODERSEMAIL ×12, LINXEMAIL ×1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D4"
                    data-col-index="3"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        13                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="E4"
                    data-col-index="4"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        3                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="F4"
                    data-col-index="5"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        2024-10-19 - 2025-09-15                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        181[.]214[.]165[.]173                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        US                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        LINXCODERSEMAIL                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D5"
                    data-col-index="3"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="E5"
                    data-col-index="4"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="F5"
                    data-col-index="5"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        2024-11-29                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        84[.]239[.]43[.]155                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        US                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        LINXCODERSEMAIL                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D6"
                    data-col-index="3"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="E6"
                    data-col-index="4"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="F6"
                    data-col-index="5"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        2024-12-02                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        83[.]147[.]53[.]130                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        US                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        LINXCODERSEMAIL                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D7"
                    data-col-index="3"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        2                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="E7"
                    data-col-index="4"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="F7"
                    data-col-index="5"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        2024-12-10                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        146[.]70[.]195[.]104                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        US                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        LINXCODERSEMAIL                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D8"
                    data-col-index="3"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        3                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="E8"
                    data-col-index="4"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="F8"
                    data-col-index="5"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        2025-02-05 - 02-06                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        139[.]28[.]36[.]38                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        UA                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C9"
                    data-col-index="2"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        LINXCODERSEMAIL                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D9"
                    data-col-index="3"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        4                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="E9"
                    data-col-index="4"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        3                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="F9"
                    data-col-index="5"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        2025-02-16                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A10"
                    data-col-index="0"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        185[.]174[.]100[.]76                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B10"
                    data-col-index="1"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        US                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C10"
                    data-col-index="2"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        LINXCODERSEMAIL ×2, LINXEMAIL ×2                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D10"
                    data-col-index="3"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        4                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="E10"
                    data-col-index="4"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        4                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="F10"
                    data-col-index="5"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        2025-02-18 - 03-11                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A11"
                    data-col-index="0"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        209[.]205[.]197[.]130                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B11"
                    data-col-index="1"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        US                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C11"
                    data-col-index="2"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        LINXCODERSEMAIL                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D11"
                    data-col-index="3"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        2                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="E11"
                    data-col-index="4"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="F11"
                    data-col-index="5"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        2025-02-18                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A12"
                    data-col-index="0"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        98[.]144[.]204[.]109                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B12"
                    data-col-index="1"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        US                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C12"
                    data-col-index="2"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        LINXCODERSEMAIL                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D12"
                    data-col-index="3"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="E12"
                    data-col-index="4"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="F12"
                    data-col-index="5"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        2025-02-27                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A13"
                    data-col-index="0"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        84[.]239[.]25[.]144                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B13"
                    data-col-index="1"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        US                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C13"
                    data-col-index="2"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        LINXCODERSEMAIL                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D13"
                    data-col-index="3"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        2                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="E13"
                    data-col-index="4"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="F13"
                    data-col-index="5"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        2025-02-27                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A14"
                    data-col-index="0"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        84[.]239[.]25[.]135                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B14"
                    data-col-index="1"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        US                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C14"
                    data-col-index="2"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        LINXCODERSEMAIL                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D14"
                    data-col-index="3"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="E14"
                    data-col-index="4"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="F14"
                    data-col-index="5"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        2025-02-28                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A15"
                    data-col-index="0"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        84[.]239[.]27[.]17                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B15"
                    data-col-index="1"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        US                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C15"
                    data-col-index="2"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        LINXCODERSEMAIL                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D15"
                    data-col-index="3"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="E15"
                    data-col-index="4"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="F15"
                    data-col-index="5"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        2025-02-28                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A16"
                    data-col-index="0"
                    data-row-index="15"
                    style="                    padding:10px;
                    "
                    >
                                        98[.]98[.]79[.]35                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B16"
                    data-col-index="1"
                    data-row-index="15"
                    style="                    padding:10px;
                    "
                    >
                                        US                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C16"
                    data-col-index="2"
                    data-row-index="15"
                    style="                    padding:10px;
                    "
                    >
                                        LINXEMAIL                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D16"
                    data-col-index="3"
                    data-row-index="15"
                    style="                    padding:10px;
                    "
                    >
                                        2                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="E16"
                    data-col-index="4"
                    data-row-index="15"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="F16"
                    data-col-index="5"
                    data-row-index="15"
                    style="                    padding:10px;
                    "
                    >
                                        2025-03-03                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A17"
                    data-col-index="0"
                    data-row-index="16"
                    style="                    padding:10px;
                    "
                    >
                                        185[.]91[.]122[.]32                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B17"
                    data-col-index="1"
                    data-row-index="16"
                    style="                    padding:10px;
                    "
                    >
                                        UK                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C17"
                    data-col-index="2"
                    data-row-index="16"
                    style="                    padding:10px;
                    "
                    >
                                        LINXEMAIL                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D17"
                    data-col-index="3"
                    data-row-index="16"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="E17"
                    data-col-index="4"
                    data-row-index="16"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="F17"
                    data-col-index="5"
                    data-row-index="16"
                    style="                    padding:10px;
                    "
                    >
                                        2025-03-03                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A18"
                    data-col-index="0"
                    data-row-index="17"
                    style="                    padding:10px;
                    "
                    >
                                        185[.]199[.]103[.]116                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B18"
                    data-col-index="1"
                    data-row-index="17"
                    style="                    padding:10px;
                    "
                    >
                                        US                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C18"
                    data-col-index="2"
                    data-row-index="17"
                    style="                    padding:10px;
                    "
                    >
                                        LINXEMAIL                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D18"
                    data-col-index="3"
                    data-row-index="17"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="E18"
                    data-col-index="4"
                    data-row-index="17"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="F18"
                    data-col-index="5"
                    data-row-index="17"
                    style="                    padding:10px;
                    "
                    >
                                        2025-03-03                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A19"
                    data-col-index="0"
                    data-row-index="18"
                    style="                    padding:10px;
                    "
                    >
                                        192[.]52[.]166[.]55                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B19"
                    data-col-index="1"
                    data-row-index="18"
                    style="                    padding:10px;
                    "
                    >
                                        US                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C19"
                    data-col-index="2"
                    data-row-index="18"
                    style="                    padding:10px;
                    "
                    >
                                        LINXEMAIL                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D19"
                    data-col-index="3"
                    data-row-index="18"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="E19"
                    data-col-index="4"
                    data-row-index="18"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="F19"
                    data-col-index="5"
                    data-row-index="18"
                    style="                    padding:10px;
                    "
                    >
                                        2025-03-06                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A20"
                    data-col-index="0"
                    data-row-index="19"
                    style="                    padding:10px;
                    "
                    >
                                        84[.]239[.]25[.]139                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B20"
                    data-col-index="1"
                    data-row-index="19"
                    style="                    padding:10px;
                    "
                    >
                                        US                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C20"
                    data-col-index="2"
                    data-row-index="19"
                    style="                    padding:10px;
                    "
                    >
                                        LINXEMAIL                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D20"
                    data-col-index="3"
                    data-row-index="19"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="E20"
                    data-col-index="4"
                    data-row-index="19"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="F20"
                    data-col-index="5"
                    data-row-index="19"
                    style="                    padding:10px;
                    "
                    >
                                        2025-03-11                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A21"
                    data-col-index="0"
                    data-row-index="20"
                    style="                    padding:10px;
                    "
                    >
                                        199[.]233[.]237[.]30                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B21"
                    data-col-index="1"
                    data-row-index="20"
                    style="                    padding:10px;
                    "
                    >
                                        US                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C21"
                    data-col-index="2"
                    data-row-index="20"
                    style="                    padding:10px;
                    "
                    >
                                        LINXB64EMAIL                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D21"
                    data-col-index="3"
                    data-row-index="20"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="E21"
                    data-col-index="4"
                    data-row-index="20"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="F21"
                    data-col-index="5"
                    data-row-index="20"
                    style="                    padding:10px;
                    "
                    >
                                        2025-05-08                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A22"
                    data-col-index="0"
                    data-row-index="21"
                    style="                    padding:10px;
                    "
                    >
                                        98[.]93[.]13[.]101                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B22"
                    data-col-index="1"
                    data-row-index="21"
                    style="                    padding:10px;
                    "
                    >
                                        US                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C22"
                    data-col-index="2"
                    data-row-index="21"
                    style="                    padding:10px;
                    "
                    >
                                        pw:linxz                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D22"
                    data-col-index="3"
                    data-row-index="21"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="E22"
                    data-col-index="4"
                    data-row-index="21"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="F22"
                    data-col-index="5"
                    data-row-index="21"
                    style="                    padding:10px;
                    "
                    >
                                        2026-07-03 (latest)                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-359'>
table#wpdtSimpleTable-359{ table-layout: fixed !important; }
table#wpdtSimpleTable-359 td, table.wpdtSimpleTable359 th { white-space: normal !important; }
</style>




<h2 class="wp-block-heading">How Mirage2FA Has Evolved </h2>



<p class="wp-block-paragraph">Mirage2FA has changed significantly since it was first observed in 2024, while retaining several recognizable patterns. </p>



<ul class="wp-block-list">
<li><strong>Build markers:</strong> LINXCODERSEMAIL → LINXEMAIL → LINXB64EMAIL, followed by markers such as #LINXMASKEMAIL, #LINXRANDSTRING, and linxz. </li>
</ul>



<ul class="wp-block-list">
<li><strong>JavaScript obfuscation:</strong> plain loaders evolved into XOR + Base64 + eval, hex-based decoders, and obfuscator.io-style _0x wrappers. Obfuscation was most common in .htm samples, appearing in <strong>453 of 629</strong>. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Delivery methods:</strong> the operation expanded beyond .htm, .xhtml, and .svg attachments to include QR-code lures and Amazon SES distribution. HR and <strong>401(k) benefits</strong> appeared repeatedly as lure themes. </li>
</ul>



<ul class="wp-block-list">
<li><strong>C2 structure:</strong> Mirage2FA introduced more /\&lt;code\&gt;/xls/*.js routes and token variations while rotating domains over time. </li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Keep detection effective as Mirage2FA changes.</span><br>Reduce the risk of wider compromise.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mirage2fa-phishing-blog&amp;utm_term=180826&amp;utm_content=linktolanding#contact-sales" target="_blank" rel="noopener">
Detect phishing in <60 secs in your SOC
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Attribution </h2>



<p class="wp-block-paragraph">The cluster we expanded is highly likely to be the Mirage2FA phishkit, given the observed similarities in indicators and URL patterns with another <a href="https://f4n6.co.uk/inside-mirage2fa-reverse-engineering/" target="_blank" rel="noreferrer noopener">research</a>. To this attribution, we add our own patterns (see the IOCs section for details) and the specific characteristics of the utility&#8217;s author. </p>



<ul class="wp-block-list">
<li><strong>Brand/operator:  LinX Coders.</strong> Corroborated by the placeholder LINXCODERSEMAIL (the substitution variable name), the bot names linxlogsss…bot / linxxlogss…bot, and the channel LinXcoded. Moreover, there is a bot to your subscription account and it’s still active (see below) </li>
</ul>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="306" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image13-1024x306.png" alt="" class="wp-image-22675" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image13-1024x306.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image13-300x90.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image13-768x230.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image13-370x111.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image13-270x81.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image13-740x221.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image13.png 1271w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>LinXcoded channel </em> </figcaption></figure>
</div>


<ul class="wp-block-list">
<li><strong>Operator cross-bot test IPs</strong> (dry-run kit submissions where the email equals a placeholder): </li>
</ul>



<ul class="wp-block-list">
<li>185[.]174[.]100[.]20: 13 tests across <strong>3 distinct bots</strong>, 2024-10 to 2025-09; </li>
</ul>



<ul class="wp-block-list">
<li>185[.]174.[.]00[.]76: 4 tests across <strong>4 bots</strong>, 2025-02 to 03; </li>
</ul>



<ul class="wp-block-list">
<li>139[.]28[.]36[.]38: 4 tests across 3 bots (2025-02). </li>
</ul>



<ul class="wp-block-list">
<li><strong>Link to C2:</strong> The C2 185[.]174[.]100[.]224 is in the same subnet 185[.]174[.]100[.]0/24 and provider AS-Colocrossing. A single range serving both bot deployment/testing and the production loader points to <strong>centralized author/seller infrastructure</strong>. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Continuity:</strong> bot 7010301660 links the 2024–2025 tests to the 2026 lure activity. </li>
</ul>



<p class="wp-block-paragraph"><strong>Caveat.</strong> IP/geo in the open-source collection come from the panel’s own self-logging (VPN/spoofing possible); the most reliable signal is IP reuse across multiple bots together with the subnet match against an independent source (ANY.RUN). </p>



<h2 class="wp-block-heading">How Organizations Can Reduce the Risk from Mirage2FA </h2>



<p class="wp-block-paragraph">By stealing active Microsoft 365 sessions, Mirage2FA can give attackers access even after MFA has been completed. Defending against it means covering the whole path from the phishing email to session theft and account takeover. </p>



<h3 class="wp-block-heading">Strengthen Email and Browser Controls </h3>



<p class="wp-block-paragraph">Block or quarantine .htm, .xhtml, and .svg attachments where possible, and add detection for HTML smuggling, attc-html, and obfuscated-js characteristics. </p>



<p class="wp-block-paragraph">Security teams should also pay closer attention to suspicious QR-code campaigns and email delivered through services such as Amazon SES, especially when they contain browser-executed attachments. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="559" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image6-1-1024x559.png" alt="" class="wp-image-22677" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image6-1-1024x559.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image6-1-300x164.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image6-1-768x419.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image6-1-1536x838.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image6-1-370x202.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image6-1-270x147.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image6-1-740x404.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image6-1.png 1951w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Full attack chain analyzed inside ANY.RUN’s sandbox</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Unknown files should be opened only in an isolated environment. <strong>ANY.RUN’s </strong><a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mirage2fa-phishing-blog&amp;utm_term=180826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener"><strong>Interactive Sandbox</strong></a> can show what the attachment actually does, including JavaScript execution, redirects, fingerprinting, loader activity, WebSocket connections, and fake Microsoft 365 login pages. </p>



<h3 class="wp-block-heading">Move Beyond Traditional MFA </h3>



<p class="wp-block-paragraph">Mirage2FA can intercept passwords and one-time 2FA codes in real time, which means conventional MFA alone may not be enough. </p>



<p class="wp-block-paragraph">Organizations should move high-risk users toward <strong>phishing-resistant MFA such as FIDO2/WebAuthn and passkeys</strong>, particularly administrators, executives, finance teams, and other accounts with access to sensitive systems or business processes. </p>



<p class="wp-block-paragraph">Shorter session lifetimes, token binding, and <strong>Continuous Access Evaluation in Microsoft Entra ID</strong> can also reduce the window in which a stolen authenticated session remains useful. </p>



<h3 class="wp-block-heading">Detect Mirage2FA Behavior, Not Just Known IOCs </h3>



<p class="wp-block-paragraph">Domains and IP addresses can change quickly, so detection should not depend on static indicators alone. </p>



<p class="wp-block-paragraph">SOC teams should alert on requests matching patterns such as /&lt;3char&gt;/xls/*.js, DNS queries where a <strong>Base64-encoded email address appears as a subdomain label</strong>, and outbound WebSocket connections to unknown hosts shortly after a JavaScript loader is fetched. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="466" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image130-1024x466.png" alt="" class="wp-image-22679" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image130-1024x466.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image130-300x136.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image130-768x349.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image130-1536x698.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image130-2048x931.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image130-370x168.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image130-270x123.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image130-740x337.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Actionable IOCs based on data from 16k SOCs and 700k analysts</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">Fresh <strong><a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mirage2fa-phishing-blog&amp;utm_term=180826&amp;utm_content=linktotifeedslanding#contact-sales">Threat Intelligence Feeds</a></strong>, built from real-world threat data contributed by <strong>16,000 organizations and 700,000 security professionals</strong>, can push known malicious infrastructure into SIEM, EDR, firewalls, and other existing security controls. Behavioral detections can then provide coverage as Mirage2FA rotates domains, paths, and infrastructure.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Expand threat coverage in your SOC.</span><br>Integrate 99% unique TI Feeds based on live threat data from 16K companies.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mirage2fa-phishing-blog&amp;utm_term=180826&amp;utm_content=linktotifeedslanding#contact-sales" target="_blank" rel="noopener">
Get access to TI Feeds
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h3 class="wp-block-heading">Expand the Investigation with Threat Intelligence </h3>



<p class="wp-block-paragraph">One malicious attachment may be part of a much larger campaign. </p>



<p class="wp-block-paragraph">Analysts can use <strong>ANY.RUN Threat Intelligence Lookup</strong> to pivot from a suspicious URL, domain, IP, or loader pattern to related infrastructure, previous sandbox sessions, and other connected activity. </p>



<p class="wp-block-paragraph"><strong>TI Lookup: </strong><a href="https://intelligence.any.run/analysis/lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mirage2fa-phishing-blog&amp;utm_term=180826&amp;utm_content=linktotilookup#{%22query%22:%22url:%5C%22/???/xls/?????*.js$%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener"><strong>url:&#8221;/???/xls/?????*.js$&#8221;</strong></a> </p>



<p class="wp-block-paragraph">This approach played an important role in the Mirage2FA investigation itself. Researchers followed the characteristic /xls/*.js loader pattern and used it to uncover a broader cluster instead of treating each phishing sample as a separate incident. </p>



<h3 class="wp-block-heading">Hunt for Mirage2FA Across the Environment </h3>



<p class="wp-block-paragraph">Threat hunting should focus on recurring Mirage2FA patterns across mail gateways, proxy logs, EDR telemetry, and browser activity. </p>



<p class="wp-block-paragraph">Useful hunting points include <strong>LINX* placeholder strings</strong>, /xls/*.js loader paths, suspicious HTML attachments, Base64-encoded recipient data, and WebSocket traffic following browser-executed JavaScript. </p>



<p class="wp-block-paragraph">Findings from these hunts can then be checked against current threat intelligence and expanded further through TI Lookup. </p>



<h3 class="wp-block-heading">Treat Session Theft as an Identity Incident </h3>



<p class="wp-block-paragraph">If Mirage2FA successfully steals a session cookie, resetting the user’s password may not be enough. </p>



<p class="wp-block-paragraph">Response teams should <strong>revoke all active sessions and tokens</strong>, review Microsoft 365 mail-forwarding rules, check OAuth grants, and investigate activity performed through the compromised identity. </p>



<p class="wp-block-paragraph">The goal is to remove the attacker’s access completely; not just change the credential they may no longer need. </p>



<h2 class="wp-block-heading">Conclusion </h2>



<p class="wp-block-paragraph">Mirage2FA shows how far phishing has moved beyond simple credential theft. By intercepting Microsoft 365 authentication in real time and stealing active session cookies, the toolkit can bypass conventional MFA and give attackers access to trusted corporate accounts. </p>



<p class="wp-block-paragraph">The campaign has remained active from <strong>2024 through 2026</strong>, with the strongest victim concentration in the <strong>United States a</strong>nd significant exposure across Technology, MSSPs, Manufacturing, and Education. For businesses, a single successful attack can lead to email compromise, impersonation, data exposure, and further access through a legitimate user identity. </p>



<p class="wp-block-paragraph">Reducing that risk requires more than blocking known domains. Organizations need phishing-resistant MFA, behavioral detection, safe analysis of suspicious attachments, current threat intelligence, and response procedures built specifically for session theft. The faster teams can connect a suspicious email to the wider campaign and revoke stolen access, the less room attackers have to turn one compromised account into a larger incident. </p>



<h2 class="wp-block-heading">About ANY.RUN </h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mirage2fa-blog&amp;utm_term=180826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener"><strong>ANY.RUN</strong></a> is a leading provider of interactive malware analysis and threat intelligence solutions trusted by more than 15,000 organizations worldwide, including 74 of the Fortune 100.  </p>



<p class="wp-block-paragraph">Its <strong><a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mirage2fa-blog&amp;utm_term=180826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a></strong> and <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mirage2fa-blog&amp;utm_term=180826&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence</strong></a> solutions help SOC teams analyze suspicious  files and URLs, uncover malicious behavior, enrich alerts with actionable context, and connect related activity across files, infrastructure, and campaigns. This enables faster investigations, more confident response decisions, and earlier containment of threats before they create wider business impact. </p>



<h2 class="wp-block-heading">IOCs </h2>



<h3 class="wp-block-heading">Detection patterns </h3>



<ul class="wp-block-list">
<li>Loader request path: GET /[a-z]{3}/xls/[a-z0-9]+(?:c2v|cpt)?\.js to a kit domain (canonical /api/xls/a1p2i.js). </li>
</ul>



<ul class="wp-block-list">
<li>Outbound WebSocket to the C2 immediately after the JS loader is fetched (AiTM relay). </li>
</ul>



<ul class="wp-block-list">
<li>HTML attachment containing atob(&#8230;).map(x =&gt; x.charCodeAt(0) ^ 173) followed by eval(&#8230;) (XOR key 0xAD). </li>
</ul>



<ul class="wp-block-list">
<li>SVG document with an inline &lt;script type=&#8221;application/ecmascript&#8221;&gt; performing a window.location redirect. </li>
</ul>



<h3 class="wp-block-heading">Operator / build markers </h3>



<ul class="wp-block-list">
<li>Placeholder tokens: LINXB64EMAIL, LINXEMAIL, LINXCODERSEMAIL, LINXCODERSRANDSTRING, #LINXMASKEMAIL, #LINXRANDSTRING. </li>
</ul>



<ul class="wp-block-list">
<li>In-page variables exposing the token: uid, self.u, RSTRING2. </li>
</ul>



<ul class="wp-block-list">
<li>Test / self markers: password value linxz; XOR key 0xAD; canonical loader filename a1p2i.js. </li>
</ul>



<h3 class="wp-block-heading">Phishing domains </h3>



<div class="wp-block-group is-layout-grid wp-container-core-group-is-layout-9d260ee2 wp-block-group-is-layout-grid">
<ul class="wp-block-list">
<li>adp[.]pslcertlive[.]site </li>
</ul>



<ul class="wp-block-list">
<li>ans[.]rsxbenefits[.]com </li>
</ul>



<ul class="wp-block-list">
<li>ari[.]vslbertlive[.]info </li>
</ul>



<ul class="wp-block-list">
<li>ars[.]greebys[.]com </li>
</ul>



<ul class="wp-block-list">
<li>asvbtech[.]store </li>
</ul>



<ul class="wp-block-list">
<li>avsbtech[.]store </li>
</ul>



<ul class="wp-block-list">
<li>bezdelz[.]store </li>
</ul>



<ul class="wp-block-list">
<li>bns[.]baseasix[.]com </li>
</ul>



<ul class="wp-block-list">
<li>bsf[.]allmetreod[.]com </li>
</ul>



<ul class="wp-block-list">
<li>bverster[.]store </li>
</ul>



<ul class="wp-block-list">
<li>cementslabconstruction[.]com </li>
</ul>



<ul class="wp-block-list">
<li>cer[.]septey[.]shop </li>
</ul>



<ul class="wp-block-list">
<li>cer[.]verpox[.]shop </li>
</ul>



<ul class="wp-block-list">
<li>cureaveritax[.]store </li>
</ul>



<ul class="wp-block-list">
<li>cvs[.]pcvgtech[.]online </li>
</ul>



<ul class="wp-block-list">
<li>dezbelz[.]store </li>
</ul>



<ul class="wp-block-list">
<li>dverster[.]store </li>
</ul>



<ul class="wp-block-list">
<li>everster[.]store </li>
</ul>



<ul class="wp-block-list">
<li>fureaveritax[.]store </li>
</ul>



<ul class="wp-block-list">
<li>fverster[.]store </li>
</ul>



<ul class="wp-block-list">
<li>gacorslot7d[.]com </li>
</ul>



<ul class="wp-block-list">
<li>galatasaraydanhaberler[.]com </li>
</ul>



<ul class="wp-block-list">
<li>gectech[.]store </li>
</ul>



<ul class="wp-block-list">
<li>gverster[.]store </li>
</ul>



<ul class="wp-block-list">
<li>gztev[.]it[.]com </li>
</ul>



<ul class="wp-block-list">
<li>hpn[.]bandhiem[.]com </li>
</ul>



<ul class="wp-block-list">
<li>hverster[.]store </li>
</ul>



<ul class="wp-block-list">
<li>hynutech[.]store </li>
</ul>



<ul class="wp-block-list">
<li>implentedgucedirectory[.]com </li>
</ul>



<ul class="wp-block-list">
<li>intrugementslayerdocuservice[.]com </li>
</ul>



<ul class="wp-block-list">
<li>iverster[.]store </li>
</ul>



<ul class="wp-block-list">
<li>jscvbtech[.]store </li>
</ul>



<ul class="wp-block-list">
<li>jureaveritax[.]store </li>
</ul>



<ul class="wp-block-list">
<li>jverster[.]store </li>
</ul>



<ul class="wp-block-list">
<li>mettsoll[.]com </li>
</ul>



<ul class="wp-block-list">
<li>oectech[.]store </li>
</ul>



<ul class="wp-block-list">
<li>office[.]avcbtech[.]store </li>
</ul>



<ul class="wp-block-list">
<li>office[.]pcvgtech[.]store </li>
</ul>



<ul class="wp-block-list">
<li>pancincorp[.]com </li>
</ul>



<ul class="wp-block-list">
<li>pavetech[.]store </li>
</ul>



<ul class="wp-block-list">
<li>pectech[.]store </li>
</ul>



<ul class="wp-block-list">
<li>pezbelz[.]store </li>
</ul>



<ul class="wp-block-list">
<li>pureaveritax[.]store </li>
</ul>



<ul class="wp-block-list">
<li>pvf[.]schwiessdoors[.]com </li>
</ul>



<ul class="wp-block-list">
<li>pvs[.]schwiessdoors[.]com </li>
</ul>



<ul class="wp-block-list">
<li>pxvbtech[.]store </li>
</ul>



<ul class="wp-block-list">
<li>pynutech[.]store </li>
</ul>



<ul class="wp-block-list">
<li>rfm[.]m3-bulders[.]com </li>
</ul>



<ul class="wp-block-list">
<li>rmf[.]diversesgs[.]com </li>
</ul>



<ul class="wp-block-list">
<li>rmf[.]m3-bulders[.]com </li>
</ul>



<ul class="wp-block-list">
<li>sopbtech[.]store </li>
</ul>



<ul class="wp-block-list">
<li>svn[.]dpsindustrialsgroup[.]com </li>
</ul>



<ul class="wp-block-list">
<li>svr[.]schwiessdoors[.]com </li>
</ul>



<ul class="wp-block-list">
<li>ver[.]verpox[.]shop </li>
</ul>



<ul class="wp-block-list">
<li>vezbelz[.]store </li>
</ul>



<ul class="wp-block-list">
<li>vns[.]pigotnet[.]com </li>
</ul>



<ul class="wp-block-list">
<li>vns[.]tvgsv[.]com </li>
</ul>



<ul class="wp-block-list">
<li>vns1[.]pigotnet[.]com </li>
</ul>



<ul class="wp-block-list">
<li>vrf[.]atskinsonel[.]com </li>
</ul>



<ul class="wp-block-list">
<li>vrf[.]bereetro[.]it[.]com </li>
</ul>



<ul class="wp-block-list">
<li>vrf[.]gavernova[.]com </li>
</ul>



<ul class="wp-block-list">
<li>vrf[.]iar0nline[.]com </li>
</ul>



<ul class="wp-block-list">
<li>wectech[.]store </li>
</ul>



<ul class="wp-block-list">
<li>wes[.]cadsta[.]online </li>
</ul>



<ul class="wp-block-list">
<li>zectech[.]store </li>
</ul>
</div>



<!-- CTA Split START -->
<div class="cta-split">
<div class="cta__split-left">

<!-- Image -->
<img decoding="async" loading="lazy" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Mirage2FA_article-block.png" alt="PhantomEnigma Threat Report from ANY.RUN" class="cta__split-icon">
</div>

<div class="cta__split-right">
<div>

<!-- Heading -->
<h3 class="cta__split-heading"><br>Read Complete Mirage2FA Research in TI Reports</h3>

<!-- Text -->
<p class="cta__split-text">
Get a detailed version of the report for SOC and MSSP teams:
 </p><ul>
    <li><strong>A complete list of IOCs</strong></li><strong>
    <li><strong>Additional info on Mirage2FA</strong></li><strong>
    <li><strong>Access to other reports</strong></li><strong>
  </strong></strong></strong></ul><strong><strong><strong>
<a target="_blank" rel="noopener" href="https://intelligence.any.run/plans/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mirage2fa-phishing-blog&amp;utm_term=180826&amp;utm_content=linktopricing" style="text-decoration: underline; color: #02c0fc;">Available for users with ANY.RUN TI Core and Complete plans. See details →</a>

<br>

</strong></strong></strong></div><strong><strong><strong>
<!-- CTA Link -->
<a target="_blank" rel="noopener" id="article-banner-split" href="https://intelligence.any.run/reports/08-17-2026-mirage2fa/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=mirage2fa-phishing-blog&#038;utm_term=180826&#038;utm_content=linktotireports"><div class="cta__split-link"><strong>Explore full report</strong></div></a>
</strong></strong></strong></div><strong><strong>
</strong></strong></div><strong><strong>
<!-- CTA Split END -->
<!-- CTA Split Styles START -->
<style>
.cta-split {
overflow: hidden;
margin: 3rem 0;
display: grid;
justify-items: center;
border-radius: 0.5rem;
width: 100%;
min-height: 25rem;
grid-template-columns: repeat(2, 1fr);
border: 1px solid rgba(75, 174, 227, 0.32);
font-family: 'Catamaran Bold';
}

.cta__split-left {
display: flex;
align-items: center;
justify-content: center;
height: 100%;
width: 100%;
background-color: #161c59;
background-position: center center;
background: rgba(32, 168, 241, 0.1);
}

.cta__split-icon { 
width: 100%;
height: auto;
object-fit: contain;
max-width: 100%;
}

.cta__split-right {
display: flex;
flex-direction: column;
justify-content: space-between;
padding: 2rem;
}

.cta__split-heading { font-size: 1.5rem; }

.cta__split-text {
margin-top: 1rem;
font-family: Lato, Roboto, sans-serif;
}

.cta__split-link {
padding: 0.5rem 1rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: white;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
display: block;
z-index: 1000;
position: relative;
cursor: pointer !important;
}

.cta__split-link:hover {
background-color: #68CBFF;
color: white;
cursor: pointer;
}

.highlight { color: #ea2526;}


/* Mobile styles START */
@media only screen and (max-width: 768px) {

.cta-split {
grid-template-columns: 1fr;
min-height: auto;
}

.cta__split-left {
height: auto;
min-height: 10rem;
}


.cta__split-left, .cta__split-right {
height: auto;
}

.cta__split-heading { font-size: 1.2rem; }

.cta__split-text { font-size: 1rem; }
.cta__split-icon {
max-height: auto;
object-fit: cover;
}

}
/* Mobile styles END */
</style>
<!-- CTA Split Styles END --></strong></strong>



<h2 class="wp-block-heading">FAQ</h2>



<div class="schema-faq wp-block-yoast-faq-block"><div class="schema-faq-section" id="faq-question-1787045581891"><strong class="schema-faq-question">What is Mirage2FA and how does it bypass MFA?</strong> <p class="schema-faq-answer">Mirage2FA is an active Phishing-as-a-Service (PhaaS) toolkit designed to steal Microsoft 365 credentials and active session cookies. It bypasses conventional Multi-Factor Authentication (MFA) using an Adversary-in-the-Middle (AiTM) reverse proxy architecture. When a victim enters their username, password, and one-time 2FA code on a fake login page, Mirage2FA relays these credentials to the legitimate Microsoft service over a WebSocket channel in real time, capturing both the credentials and the valid authenticated session cookie.</p> </div> <div class="schema-faq-section" id="faq-question-1787045768625"><strong class="schema-faq-question">Which industries and regions are most targeted by Mirage2FA?</strong> <p class="schema-faq-answer">According to threat intelligence telemetry from ANY.RUN, 63.7% of identified Mirage2FA victims are located in the United States, though activity has been recorded across 94 countries. The campaign heavily targets organizations relying on Microsoft 365 for core operations, with the highest concentration of victims found in Technology, Manufacturing, and Education.</p> </div> <div class="schema-faq-section" id="faq-question-1787045795957"><strong class="schema-faq-question">How is Mirage2FA delivered to victim devices?</strong> <p class="schema-faq-answer">Mirage2FA relies on browser-executed stagers rather than traditional binary malware. Delivery mechanisms include:<br>&#8211; <strong>Malicious Attachments:</strong> Extensions such as .htm (the most dominant), .xhtml, and .svg.<br>&#8211; <strong>QR-Code Lures:</strong> Directing users to phishing links via mobile devices.<br>&#8211; <strong>Email Services:</strong> High-volume distribution utilizing legitimate services like Amazon SES.<br>&#8211; <strong>Lure Themes:</strong> Frequently disguised as Human Resources (HR) communications or 401(k) benefit updates.</p> </div> <div class="schema-faq-section" id="faq-question-1787045816920"><strong class="schema-faq-question">Why is resetting a password insufficient after a Mirage2FA compromise?</strong> <p class="schema-faq-answer">Because Mirage2FA steals active authenticated session cookies in addition to passwords, resetting a user&#8217;s password does not automatically invalidate the attacker&#8217;s active session. The adversary can continue using the stolen session cookie to access Microsoft 365 applications, read emails, and move laterally across connected single sign-on (SSO) systems. Incident response must include explicitly revoking all active user sessions and tokens in Microsoft Entra ID.</p> </div> <div class="schema-faq-section" id="faq-question-1787045884825"><strong class="schema-faq-question">How can security teams protect their organizations against Mirage2FA?</strong> <p class="schema-faq-answer"><strong>&#8211; Phishing-Resistant MFA</strong>: Transition high-risk accounts to FIDO2/WebAuthn hardware keys or passkeys that cannot be proxied by AiTM tools.<br><strong>&#8211; Attachment &amp; Dynamic Analysis</strong>: Block or quarantine incoming .htm, .xhtml, and .svg attachments at the email gateway. Safely detonate and inspect suspicious files using <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mirage2fa-phishing-blog&amp;utm_term=180826&amp;utm_content=linktosandboxlanding">ANY.RUN&#8217;s Interactive Sandbox</a> to observe real-time JavaScript execution, dynamic redirects, and underlying WebSocket traffic.<br><strong>&#8211; Behavioral Detection &amp; Threat Intelligence</strong>: Monitor proxy logs and SIEM alerts for loader patterns (/xls/*.js) and feed live indicators into security controls using ANY.RUN&#8217;s <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=mirage2fa-phishing-blog&amp;utm_term=180826&amp;utm_content=linktotifeedslanding#contact-sales">Threat Intelligence Feeds</a>.<br></p> </div> </div>
<p>The post <a href="https://any.run/cybersecurity-blog/mirage2fa-phishing-targets-us-companies/">Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/mirage2fa-phishing-targets-us-companies/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Intelligence-Driven SOC: Modernizing Threat Monitoring and Detection Engineering for Ultimate MTTR Reduction</title>
		<link>https://any.run/cybersecurity-blog/threat-monitoring-ti-feeds/</link>
					<comments>https://any.run/cybersecurity-blog/threat-monitoring-ti-feeds/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Wed, 12 Aug 2026 07:58:16 +0000</pubDate>
				<category><![CDATA[Cybersecurity Lifehacks]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[feeds]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malware analysis]]></category>
		<category><![CDATA[monitoring]]></category>
		<category><![CDATA[MSSP]]></category>
		<category><![CDATA[SOC]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<guid isPermaLink="false">/cybersecurity-blog/?p=18785</guid>

					<description><![CDATA[<p>Threat monitoring serves as the vital connective tissue of modern security operations. It ensures that every function from triage to response operates effectively. To meet evolving threat challenges, SOC teams and MSSPs must transition from simple log collection to a proactive, intelligence-driven framework. ANY.RUN’s Threat Intelligence provides the essential solutions to power this transformation across [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/threat-monitoring-ti-feeds/">Intelligence-Driven SOC: Modernizing Threat Monitoring and Detection Engineering for Ultimate MTTR Reduction</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Threat monitoring serves as the vital connective tissue of modern security operations. It ensures that every function from triage to response operates effectively. To meet evolving threat challenges, <a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=threat-monitoring-ti-feeds&amp;utm_term=250226&amp;utm_content=linktoenterprisepage"><strong>SOC teams</strong></a> and <a href="https://any.run/mssp/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=threat-monitoring-ti-feeds&amp;utm_term=250226&amp;utm_content=linktomssppage" target="_blank" rel="noreferrer noopener"><strong>MSSPs</strong></a> must transition from simple log collection to a proactive, intelligence-driven framework. </p>



<p class="wp-block-paragraph">ANY.RUN’s <a href="https://intelligence.any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=threat-monitoring-ti-feeds&amp;utm_term=250226&amp;utm_content=linktothreatintelligence"><strong>Threat Intelligence</strong></a> provides the essential solutions to power this transformation across the entire operational cycle.</p>



<h2 class="wp-block-heading">Key Takeaways </h2>



<ol class="wp-block-list">
<li>Aligning Monitoring and Detection Engineering ensures that high-priority alerts are surfaced early, which <strong>directly reduces MTTR and the financial risk associated with potential data exfiltration</strong>.</li>



<li>Transitioning to a proactive defense posture allows organizations to block threats potentially weeks before public disclosure, shifting the SOC from a reactive incident response model to one of <strong>strategic business resilience</strong>.</li>



<li>Leveraging high-fidelity intelligence maximizes analyst efficiency by automating enrichment and significantly reducing false positives, which <strong>protects the ROI of security talent</strong> by refocusing them on high-level decision-making.</li>



<li>An intelligence-driven SOC provides the empirical data necessary for strategic planning and board confidence, allowing C-suite leaders to demonstrate due diligence and <strong>justify security investments to non-technical stakeholders</strong>.</li>



<li>Integrating ANY.RUN’s <a href="https://intelligence.any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=threat-monitoring-ti-feeds&amp;utm_term=250226&amp;utm_content=linktothreatintelligence"><strong>Threat Intelligence</strong></a> creates a continuous operational loop where real-world data from sandbox analysis, automated feeds, and behavioral hunting works together to <strong>close coverage gaps</strong>.</li>
</ol>



<h2 class="wp-block-heading">The Critical Role of Threat Monitoring and Detection Engineering</h2>



<p class="wp-block-paragraph">While connected, <strong>Threat Monitoring</strong> and <strong>Detection Engineering</strong> are distinct, high-impact processes that are a must-have for cyberresilient organizations.</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-354"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="5"
           data-wpID="354"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:28.31541218638%;                    padding:10px;
                    "
                    >
                                        Feature                    </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:35.84229390681%;                    padding:10px;
                    "
                    >
                                        Threat Monitoring                    </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:35.84229390681%;                    padding:10px;
                    "
                    >
                                        Detection Engineering                    </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Definition                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        The <strong>continuous operational process of collecting and analyzing telemetry</strong> to surface malicious activity in real time.                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        The specialized <strong>process of creating detection logic</strong> (such as YARA or Sigma) used to identify threats.                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Primary Goal                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        <strong>To reduce dwell time and financial risk</strong> by ensuring high-priority alerts are surfaced early.                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        <strong>To transform intelligence into detection rules</strong> that reflect real-world TTPs.                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Core Output                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        <strong>Context-rich, prioritized signals</strong> for alert triage and incident response.                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        <strong>Actionable detection rules</strong> and signatures that define "what" is malicious.                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Nature                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        <strong>Adaptive and Operational</strong>: It consumes rules to drive response workflows.                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        <strong>Content-Driven</strong>: It provides the technical logic that powers the monitoring stack.                    </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-354'>
table#wpdtSimpleTable-354{ table-layout: fixed !important; }
table#wpdtSimpleTable-354 td, table.wpdtSimpleTable354 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">These two functions are deeply interdependent, creating a feedback loop that defines SOC efficiency:</p>



<ul class="wp-block-list">
<li><strong>Intelligence Ingestion:</strong> Detection engineering uses intelligence from <strong>threat intelligence </strong>sources to create new rules, which are then operationalized within the monitoring workflow.</li>



<li><strong>Operational Validation:</strong> Monitoring acts as the testing ground, revealing where detection rules fail, generate excessive noise, or miss real-world adversary behavior.</li>



<li><strong>Continuous Improvement:</strong> Insights from monitoring, such as historical alert patterns or detection gaps, inform the next cycle of engineering, allowing teams to tune and refine their logic.</li>



<li><strong>Business Resilience:</strong> When these processes are connected, the SOC moves from simply &#8220;responding to incidents&#8221; to a proactive posture that can block threats weeks before public disclosure.</li>
</ul>



<p class="wp-block-paragraph">Building powerful <strong>Threat Monitoring and Detection Engineering workflows in your </strong><a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=threat-monitoring-ti-feeds&amp;utm_term=250226&amp;utm_content=linktoenterprisepage"><strong>SOC</strong></a><strong> or </strong><a href="https://any.run/mssp/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=threat-monitoring-ti-feeds&amp;utm_term=250226&amp;utm_content=linktomssppage"><strong>MSSP</strong></a> requires implementing several important layers.</p>



<h2 class="wp-block-heading">How to Build Threat Monitoring &amp; Detection Engineering That Works</h2>



<h2 class="wp-block-heading">Layer 1: Channel Live Intelligence into Your Security Stack</h2>



<p class="wp-block-paragraph">The first layer of a proactive monitoring strategy is the automated injection of high-fidelity data directly into the security infrastructure. <strong>ANY.RUN’s </strong><a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=threat-monitoring-ti-feeds&amp;utm_term=250226&amp;utm_content=linktotifeedslanding"><strong>Threat Intelligence Feeds</strong></a> provide a continuous, live stream of malicious IPs, domains, and URLs. </p>



<p class="wp-block-paragraph">The true power of this layer lies in its massive scale. ANY.RUN leverages a global <strong>network effect</strong> powered by over <strong>600,000 security professionals</strong> who analyze real-world samples in its <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=threat-monitoring-ti-feeds&amp;utm_term=250226&amp;utm_content=linktosandboxlanding"><strong>Interactive Sandbox</strong></a>. This collective intelligence means that when one organization faces an incident, the extracted data helps others anticipate and prevent it.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="488" src="/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds0-1024x488.png" alt="" class="wp-image-18791" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds0-1024x488.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds0-300x143.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds0-768x366.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds0-1536x733.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds0-370x176.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds0-270x129.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds0-740x353.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds0.png 1843w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Moonrise trojan detonated in the Sandbox</em> </figcaption></figure>



<p class="wp-block-paragraph">With each indicator connected to a complete sandbox analysis, these feeds facilitate <strong>faster alert enrichment</strong> and provide the necessary context for analysts to instantly understand the severity of a signal. This shift from manual research to automated intelligence allows the SOC to move from &#8220;indicator-overloaded&#8221; to &#8220;intelligence-infused,&#8221; freeing up expensive talent to focus on high-level decision-making rather than basic validation.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="468" src="/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds1-1024x468.png" alt="" class="wp-image-18792" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds1-1024x468.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds1-300x137.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds1-768x351.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds1-370x169.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds1-270x123.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds1-740x338.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds1.png 1465w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Threat Intelligence Feeds: data, features, integrations</em> </figcaption></figure>



<p class="wp-block-paragraph">These feeds are delivered in standardized <strong>STIX/TAXII formats</strong>, ensuring <a href="https://any.run/integrations/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=threat-monitoring-ti-feeds&amp;utm_term=250226&amp;utm_content=linktointegrations">seamless integration with existing SIEM, EDR, SOAR environments</a>, including popular platforms like Microsoft Sentinel and Google SecOps.</p>



<p class="wp-block-paragraph">Instead of simply adding more indicators, these feeds strengthen the connective tissue between intelligence and monitoring workflows. Monitoring becomes intelligence-infused rather than indicator-overloaded.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text"> Strengthen monitoring with fresh, validated intelligence <br>
that reduces response time and
<span class="highlight">minimizes business disruption. 
</span>
&nbsp;   
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=threat-monitoring-ti-feeds&#038;utm_term=250226&#038;utm_content=linktotifeedslanding#contact-sales" rel="noopener" target="_blank">
Integrate TI Feeds
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Layer 2: Equip Your SOC with Faster Threat Investigation Process</h2>



<p class="wp-block-paragraph">While automated feeds are essential for real-time blocking, <strong>ANY.RUN’s </strong><a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=threat-monitoring-ti-feeds&amp;utm_term=250226&amp;utm_content=linktotilookuplanding"><strong>Threat Intelligence Lookup</strong></a> multiplies their effect by moving beyond simple hash-matching and static IP lists. It allows analysts to transition from basic indicators to more complex behavioral markers, such as <a href="https://any.run/cybersecurity-blog/iocs-iobs-ioas-explained/"><strong>Indicators of Behavior (IOBs)</strong>, <strong>Indicators of Attack (IOAs)</strong></a>, and <a href="https://any.run/cybersecurity-blog/malware-ttps-explained/"><strong>TTPs</strong></a> mapped directly to the MITRE ATT&amp;CK framework. By querying a database derived from millions of sandbox sessions, analysts can determine if a specific indicator is a standalone threat or part of a larger, more sophisticated campaign.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="434" src="/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds4-1024x434.png" alt="" class="wp-image-18797" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds4-1024x434.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds4-300x127.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds4-768x325.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds4-1536x651.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds4-370x157.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds4-270x114.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds4-740x313.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/02/monitoring_feeds4.png 1563w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Search TI Lookup for malware that performs certain registry changes</em> </figcaption></figure>



<p class="wp-block-paragraph">TI Lookup provides <strong>granular searching</strong> capabilities, allowing teams to query the database for highly specific artifacts, including:</p>



<ul class="wp-block-list">
<li><strong>Registry activity and file paths:</strong> For example, identifying malware that uses scheduled tasks by searching for specific registry keys paired with .exe values.</li>



<li><strong>Command-line strings:</strong> Uncovering the exact commands used during an execution chain.</li>



<li><strong>Specific network behaviors:</strong> Searching by JA3/JA3S TLS fingerprints, port numbers, or Suricata rule IDs to identify unique infrastructure characteristics.</li>
</ul>



<p class="wp-block-paragraph">This level of detail allows analysts to reconstruct the attack timeline and understand the mechanics of an infection rather than just its presence. Furthermore, this proactive hunting can surface new indicators, such as behavioral patterns associated with a specific threat actor, that have not yet appeared in automated feeds, allowing the SOC to build custom detections and close coverage gaps before a campaign fully unfolds.</p>



<h2 class="wp-block-heading">Layer 3: Streamline Detection Rule Creation </h2>



<p class="wp-block-paragraph">TI Lookup focuses on behavioral indicators and metadata, <a href="https://intelligence.any.run/analysis/yara/"><strong>YARA Search</strong></a> introduces a deeper level of analysis by identifying threats based on the actual contents of files. The service allows security teams to utilize <strong>binary signatures, textual patterns, or regular expressions (regex)</strong> to describe malware characteristics and scan them against a massive threat intelligence database. </p>



<p class="wp-block-paragraph">Beyond mere discovery, <strong>YARA Search</strong> serves as a high-velocity <strong>testing ground</strong> for SOC teams to refine their detection logic. ANY.RUN provides a robust <strong>online editor and debugger</strong> that allows for the seamless creation, testing, and management of rules within a single interface.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="A Guide to ANY.RUN’s YARA Search" width="770" height="433" src="https://www.youtube.com/embed/NqDvdiT2zg4?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>
</div></figure>



<p class="wp-block-paragraph"><a href="https://www.youtube.com/watch?v=NqDvdiT2zg4" target="_blank" rel="noreferrer noopener">Check out this video on YARA Search in TI Lookup</a>.</p>



<p class="wp-block-paragraph">For example, an analyst might identify a specific malicious command-line string or a unique registry pattern (IOB/IOA) within TI Lookup. They can then <strong>instantly translate that behavior into a YARA rule</strong> and run it against ANY.RUN’s massive database of millions of real-world samples. With initial results returned in <strong>under five seconds</strong>, engineers can immediately see if their rule is effective at catching known malware or if it needs further tuning to reduce false positives. This capability allows teams to move from &#8220;intelligence discovery&#8221; to &#8220;detection validation&#8221; in a matter of minutes.</p>



<p class="wp-block-paragraph">When a custom YARA rule matches a file, the platform bridges the gap between a static signature and <strong>dynamic adversary behavior</strong>. Every match provides a direct link to <strong>associated sandbox analysis sessions</strong>, allowing analysts to watch exactly how the identified file operates within a system.</p>



<h2 class="wp-block-heading">Layer 4: Source Intelligence and Context on Emerging Attacks </h2>



<p class="wp-block-paragraph">While automated data provides speed, strategic decision-making requires the depth of human expertise. <strong>ANY.RUN’s </strong><a href="https://intelligence.any.run/reports/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=threat-monitoring-ti-feeds&amp;utm_term=250226&amp;utm_content=linktotireports"><strong>Threat Intelligence Reports</strong></a> are manually composed by experienced analysts. They provide investigative overviews of the most critical cyber threats currently facing companies. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="539" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-1024x539.png" alt="TI Reports on malware and phishing attacks" class="wp-image-22390" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-1024x539.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-300x158.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-768x404.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-1536x808.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-2048x1078.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-370x195.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-270x142.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-740x389.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Reports on malware and phishing attacks for deeper investigations</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The reports move beyond raw data to offer actionable info on <strong>APTs, cybercriminal groups, ransomware, and </strong><a href="https://any.run/use-case/phishing/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=threat-monitoring-ti-feeds&amp;utm_term=250226&amp;utm_content=linktophishingpage"><strong>phishing campaigns</strong></a>, detailing an adversary’s aims, origins, and first-seen dates. By processing fresh, real-world data from the global community-powered sandbox, ANY.RUN analysts provide the necessary context to help security teams understand the relevance of a threat to their specific industry or geographic region.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Reduce delays between threat confirmation and containment.  </span><br>
Cut MTTR by 21 mins in your SOC. 
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=Moonrise-rat-analysis&#038;utm_term=240226&#038;utm_content=linktoenterpriseform#contact-sales" rel="noopener" target="_blank">
Integrate ANY.RUN&#8217;s solutions</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Layer 5: Integrate Threat Intelligence into a Unified Ecosystem</h2>



<p class="wp-block-paragraph">The true strength of ANY.RUN’s <strong>Threat Intelligence solutions </strong>lies in their <strong>unified integration</strong>. Each solution functions not as a silo but as part of a continuous operational loop. At the core of this ecosystem is the <strong><a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=threat-monitoring-ti-feeds&amp;utm_term=250226&amp;utm_content=linktosandboxlanding">Interactive Sandbox</a></strong>, which generates the raw, real-world data (IOCs, IOBs, TTPs) that fuels every other intelligence layer.</p>



<p class="wp-block-paragraph">While <strong><a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=threat-monitoring-ti-feeds&amp;utm_term=250226&amp;utm_content=linktotifeedslanding">TI Feeds</a></strong> provide the automated &#8220;blocking&#8221; layer for known threats, proactive hunting in <strong><a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=threat-monitoring-ti-feeds&amp;utm_term=250226&amp;utm_content=linktotilookuplanding">TI Lookup</a></strong> or <strong><a href="https://intelligence.any.run/analysis/yara/">YARA Search</a></strong> can surface new, previously unknown indicators. These findings can then be manually added to detection rules, effectively updating the monitoring stack before a campaign even hits a public feed.</p>



<h2 class="wp-block-heading">Business Impact and ROI</h2>



<p class="wp-block-paragraph">Modernizing threat monitoring is more than a technical upgrade; it is a <strong>cost-control strategy</strong> that translates technical efficiency into material business value.</p>



<ul class="wp-block-list">
<li><strong>Reducing Dwell Time and Financial Risk:</strong> By utilizing fresh, validated intelligence to surface high-risk alerts early, organizations can drastically reduce the time an attacker remains undetected. The reduction minimizes data exfiltration and remediation costs, while also helping organizations meet <strong>regulatory notification obligations</strong>.</li>



<li><strong>Maximizing Analyst Efficiency:</strong> High-fidelity intelligence from <strong>TI Feeds</strong> and <strong>TI Lookup</strong> significantly <strong>reduces false positives</strong> and automates the enrichment process. Instead of wasting expensive talent on manual research and &#8220;chasing noise,&#8221; analysts can focus on high-level decision-making and rapid containment. </li>



<li><strong>Strategic Planning and Board Confidence:</strong> Security leaders can move the narrative from &#8220;reacting to incidents&#8221; to <strong>&#8220;proactive prevention&#8221;</strong>. Using <strong>TI insights </strong>to explain the threat landscape to non-technical stakeholders demonstrates <strong>due diligence</strong> and justifies security investments. Proving that the SOC detected and blocked a major threat weeks before public disclosure serves as a powerful proof point of a resilient, proactive security posture.</li>



<li><strong>Competitive Advantage for MSSPs:</strong> For service providers, intelligence-driven monitoring acts as a <strong>product feature</strong>, ensuring that client SLAs are met with superior detection speed and coverage breadth. This strengthens client trust and differentiates the provider in a creative, fast-moving threat landscape.</li>
</ul>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph"><strong>Effective threat monitoring and detection engineering must be treated as a first-class, continuously maintained operational capability</strong>. It is the foundation upon which triage, hunting, response, and reporting must be built to achieve true business resilience.</p>



<p class="wp-block-paragraph">The path to this modern standard lies in the <strong>seamless integration of real-world intelligence into every layer of the SOC</strong>. ANY.RUN’s unified ecosystem provides this direct path, bridging the gap between raw telemetry and actionable defense.</p>



<h2 class="wp-block-heading">About ANY.RUN </h2>



<p class="wp-block-paragraph">ANY.RUN is part of modern SOC workflows, integrating easily into existing processes and strengthening the entire operational cycle across Tier 1, Tier 2, and Tier 3.   </p>



<p class="wp-block-paragraph">It supports every stage of investigation, from <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=threat-monitoring-ti-feeds&amp;utm_term=250226&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener"><strong>exposing malicious file/URL behavior during safe detonation</strong></a>, to <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=threat-monitoring-ti-feeds&amp;utm_term=250226&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener"><strong>enriching analysis with broader threat context</strong></a>, and delivering continuous intelligence that helps teams move faster and make confident decisions.</p>



<p class="wp-block-paragraph">Today, more than 600,000 security professionals and 15,000 organizations rely on ANY.RUN to accelerate triage, reduce unnecessary escalations, and stay ahead of evolving phishing and malware campaigns.   </p>



<p class="wp-block-paragraph">To stay informed about newly discovered threats and real-world attack analysis, follow ANY.RUN’s team on <a href="https://www.linkedin.com/company/any-run/" target="_blank" rel="noreferrer noopener">LinkedIn</a> and <a href="https://x.com/anyrun_app" target="_blank" rel="noreferrer noopener">X</a>, where weekly updates highlight the latest research, detections, and investigation insights. </p>



<h2 class="wp-block-heading">FAQ </h2>



<div class="schema-faq wp-block-yoast-faq-block"><div class="schema-faq-section" id="faq-question-1772013133568"><strong class="schema-faq-question"><strong>What is threat monitoring in a SOC?</strong></strong> <p class="schema-faq-answer">Threat monitoring is the continuous process of collecting, correlating, and analyzing security telemetry to detect malicious activity in real time.</p> </div> <div class="schema-faq-section" id="faq-question-1772013167768"><strong class="schema-faq-question"><strong>How is threat monitoring different from detection?</strong></strong> <p class="schema-faq-answer">Detection refers to the logic or rules that identify malicious behavior. Monitoring is the broader operational process that consumes detections, prioritizes alerts, and drives response workflows.</p> </div> <div class="schema-faq-section" id="faq-question-1772013178159"><strong class="schema-faq-question"><strong>What makes threat monitoring “effective”?</strong></strong> <p class="schema-faq-answer">It is risk-aligned, intelligence-driven, adaptive, and capable of surfacing high-impact threats early while minimizing noise.</p> </div> <div class="schema-faq-section" id="faq-question-1772013193116"><strong class="schema-faq-question"><strong>How can I measure whether monitoring is working?</strong></strong> <p class="schema-faq-answer">Key indicators include reduced MTTD, lower false positive rates, improved alert prioritization accuracy, and faster containment times.</p> </div> <div class="schema-faq-section" id="faq-question-1772013203680"><strong class="schema-faq-question"><strong>Why do many SOCs struggle with monitoring?</strong></strong> <p class="schema-faq-answer">Common issues include over-collection of logs, static IOC feeds, lack of intelligence integration, and weak feedback loops between incidents and detection updates.</p> </div> <div class="schema-faq-section" id="faq-question-1772013219455"><strong class="schema-faq-question"><strong>How does threat intelligence improve monitoring?</strong></strong> <p class="schema-faq-answer">It provides contextual, real-world adversary data that enhances detection logic, prioritization, enrichment, and proactive hunting.</p> </div> <div class="schema-faq-section" id="faq-question-1772013229623"><strong class="schema-faq-question"><strong>How can MSSPs benefit from enhanced monitoring?</strong></strong> <p class="schema-faq-answer">Intelligence-driven monitoring improves service differentiation, reduces analyst workload, increases detection accuracy, and strengthens client trust.</p> </div> </div>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://any.run/cybersecurity-blog/threat-monitoring-ti-feeds/">Intelligence-Driven SOC: Modernizing Threat Monitoring and Detection Engineering for Ultimate MTTR Reduction</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/threat-monitoring-ti-feeds/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Supply Chain Security: How ANY.RUN Helps US and EU Enterprises Prevent Incidents</title>
		<link>https://any.run/cybersecurity-blog/supply-chain-security-for-us-and-eu-companies/</link>
					<comments>https://any.run/cybersecurity-blog/supply-chain-security-for-us-and-eu-companies/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Tue, 11 Aug 2026 07:39:10 +0000</pubDate>
				<category><![CDATA[Cybersecurity Lifehacks]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=22526</guid>

					<description><![CDATA[<p>Supply chain vulnerabilities represent a growing attack surface for US and EU organizations. With advanced threat tactics on the rise, reducing Mean Time to Detect (MTTD) and Respond (MTTR) is essential. ANY.RUN integrates directly into the SOC workflows as an investigative layer, providing fast malware analysis and threat intelligence to help security teams boost their [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/supply-chain-security-for-us-and-eu-companies/">Supply Chain Security: How ANY.RUN Helps US and EU Enterprises Prevent Incidents</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Supply chain vulnerabilities represent a growing attack surface for US and EU organizations. With advanced threat tactics on the rise, reducing Mean Time to Detect (MTTD) and Respond (MTTR) is essential. <a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=supply-chain-security&amp;utm_term=110826&amp;utm_content=linktoenterpriselanding"><strong>ANY.RUN integrates directly into the SOC workflows</strong></a> as an investigative layer, providing fast malware analysis and threat intelligence to help security teams boost their efforts in preventing third-party compromise from turning into a company-wide incident.</p>



<h2 class="wp-block-heading">The Supply Chain Security: Trust as a Vulnerability</h2>



<p class="wp-block-paragraph">Threat actors increasingly utilize <strong>supply chain attacks</strong>, where they first compromise a smaller contractor or vendor to use their &#8220;trusted&#8221; status as a springboard into the head company. Because these communications arrive via verified email addresses and legitimate vendor mailboxes, they often bypass standard email gateways and static filters.</p>



<p class="wp-block-paragraph">A typical enterprise, such as an <a href="https://any.run/cybersecurity-blog/us-manufacturer-security-risk/"><strong>automotive manufacturer</strong></a>, may manage over <strong>200 active vendors</strong>. This creates a massive, constantly shifting entry point for risk where hundreds of files, invoices, technical specs, and contracts are exchanged weekly.</p>



<p class="wp-block-paragraph">The window for response is shrinking rapidly. The median time for an attacker to move from initial access to <strong>lateral movement is now just 29 minutes</strong>. If a suspicious supplier file is not analyzed and contained immediately, the breach can escalate before a human analyst even begins the manual triage process.</p>



<p class="wp-block-paragraph">SOC teams are often overwhelmed by fragmented tools that provide &#8220;red flags&#8221; without behavioral proof. As the Head of SOC at a <a href="https://any.run/cybersecurity-blog/us-manufacturer-security-risk/" target="_blank" rel="noreferrer noopener">US manufacturer</a> noted:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph"><strong>“The volume itself was not the only challenge. The bigger issue was that analysts did not have enough context to quickly decide which supplier files were safe and which required further action”.</strong></p>



<p class="wp-block-paragraph"><strong>Head of SOC, US Automotive Manufacturer</strong></p>
</blockquote>



<p class="wp-block-paragraph"><a href="https://any.run/cybersecurity-blog/us-manufacturer-security-risk/">Read a full case study of how an American manufacturing company reduced third-party risks →</a></p>



<p class="wp-block-paragraph">When security operations lack a connected investigative layer, the SOC becomes a <strong>&#8220;relay race&#8221;</strong> where evidence is dropped during every handoff between Tier 1 analysts and senior responders.</p>



<p class="wp-block-paragraph">Currently, many analysts spend over <strong>20% of their work week</strong> on manual data correlation between disconnected tools. This manual overhead leads to <strong>alert fatigue</strong>, resulting in a dangerous reality where up to <strong>62% of alerts are closed without a full investigation</strong> due to a lack of resources. This operational blind spot is exactly what supply chain attackers exploit: they hide their malicious activity within the noise of &#8220;trusted&#8221; but unverified vendor interactions.</p>



<h2 class="wp-block-heading"><strong>What CISOs Can Do to Reduce Supply Chain Security Risks</strong></h2>



<h2 class="wp-block-heading"><strong>1. Shorten the Detection Window for Phishing in Contractor Ecosystems</strong></h2>



<p class="wp-block-paragraph">In a contractor-heavy ecosystem, the most <a href="https://any.run/cybersecurity-blog/enterprise-phishing-resilience/">dangerous phishing attempts</a> are those that arrive from a legitimate, compromised vendor account. Standard email gateways and static URL scanners frequently fail to identify modern supply chain phishing because the malicious content is often <strong>dynamically rendered</strong> only after a user interacts with the page or passes an anti-bot check. </p>



<p class="wp-block-paragraph">To an automated filter, the initial link appears benign, creating a significant &#8220;visibility gap&#8221; where critical attack stages unfold entirely within an encrypted browser session.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="620" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/unfo2-1024x620.png" alt="" class="wp-image-21661" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/unfo2-1024x620.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/unfo2-300x182.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/unfo2-768x465.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/unfo2-1536x929.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/unfo2-2048x1239.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/unfo2-370x224.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/unfo2-270x163.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/unfo2-740x448.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>ANY.RUN delivers complete URL phishing context within seconds</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph"><a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=supply-chain-security&amp;utm_term=110826&amp;utm_content=linktosandboxlanding">ANY.RUN’s Interactive Sandbox</a> addresses this by providing <a href="https://any.run/cybersecurity-blog/in-browser-data-inspection/"><strong>in-browser data inspection</strong></a>. This allows analysts to observe the attack exactly as the user experienced it, <strong>capturing dynamically injected credential forms, hidden redirect chains, and DOM changes</strong> that static analysis structurally cannot see. By exposing what is happening inside the browser session, security teams can confirm a credential theft attempt even when there is no file-based trace on the endpoint.</p>



<p class="wp-block-paragraph">In the context of a busy enterprise, security must not become a bottleneck for business-critical communications. Every minute an analyst spends manually correlating browser events or waiting for a static report is a minute where a compromised vendor could be harvesting corporate credentials. </p>



<p class="wp-block-paragraph">By integrating behavioral evidence directly into the triage workflow, organizations can move from a suspicious signal to a confirmed verdict in a fraction of the time. </p>



<p class="wp-block-paragraph">As a specialist at <strong><a href="https://any.run/cybersecurity-blog/umass-boston-success-story/" target="_blank" rel="noreferrer noopener">UMass Boston</a></strong> noted regarding their sandbox-driven workflow: </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph"><strong>“Having ANY.RUN’s API connection with our email security vendor has really increased our performance&#8230; Instead of minutes, [investigations] take seconds”</strong>.</p>



<p class="wp-block-paragraph">Senior Information Security Specialist, UMass Boston</p>
</blockquote>



<p class="wp-block-paragraph"><a href="https://any.run/cybersecurity-blog/umass-boston-success-story/">Read a full case study of how UMass Boston scaled their triage to protect 50,000 users →</a></p>



<p class="wp-block-paragraph">This transition from minutes to seconds is the primary driver of ROI, allowing lean teams to handle higher alert volumes without increasing headcount.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Reduce triage time. Cut MTTR by 21 minutes. </span><br>Integrate ANY.RUN&#8217;s solutions trusted by 74 Fortune 100 companies.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=supply-chain-security&#038;utm_term=110826&#038;utm_content=linktoenterpriseform#contact-sales" target="_blank" rel="noopener">
Strengthen your SOC
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading"><strong>2. Power Proactive Defense with Live Tracking of Threat Actor Infrastructure</strong></h2>



<p class="wp-block-paragraph">Resilient SOC teams in EU and US companies are moving toward a <strong>proactive defense model</strong> that involves <a href="https://any.run/cybersecurity-blog/industry-geo-threat-landscape/"><strong>monitoring the industry threat landscape</strong></a> to identify and neutralize malicious infrastructure used against their peers before it ever hits their own perimeter.</p>



<p class="wp-block-paragraph">The primary obstacle to proactive defense is the volatility of attacker infrastructure. <strong>Threat actors frequently cycle their Command-and-Control (C2) IPs every 48 hours</strong>, meaning that intelligence found in static public reports is often outdated by the time it is operationalized. </p>



<p class="wp-block-paragraph">To bridge this gap, ANY.RUN allows SOC teams to shift their focus from static artifacts to <a href="https://any.run/cybersecurity-blog/iocs-iobs-ioas-explained/"><strong>Indicators of Behavior</strong></a><strong> (IOBs)</strong>. While an attacker can easily change a file&#8217;s hash with a minor rebuild, their <strong>behavioral patterns</strong>, such as specific mutexes, command-line arguments, registry modifications, and process execution chains, are far more stable and difficult to alter without re-engineering the entire attack.</p>



<p class="wp-block-paragraph">By using <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=supply-chain-security&amp;utm_term=110826&amp;utm_content=linktotilookuplanding"><strong>Threat Intelligence Lookup</strong></a>, analysts can pivot from a single suspicious artifact found in a supplier email to a broader campaign-level view. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="539" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-1024x539.png" alt="TI Reports on malware and phishing attacks" class="wp-image-22390" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-1024x539.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-300x158.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-768x404.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-1536x808.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-2048x1078.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-370x195.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-270x142.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-740x389.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Reports on malware and phishing attacks for deeper investigations</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">To learn about the latest supply chain attacks early, SOC teams also rely on <a href="https://intelligence.any.run/reports/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=supply-chain-security&amp;utm_term=110826&amp;utm_content=linktotireports" target="_blank" rel="noreferrer noopener">ANY.RUN&#8217;s TI Reports</a> that provide overviews of emerging threats. Curated by an expert team of threat intelligence analysts, these reports offer actionable indicators along with recommendations on how to detect new malware strains.</p>



<p class="wp-block-paragraph">ANY.RUN’s intelligence is built on a global community of 15K organizations and 600K SOC analysts who analyze the latest malware &amp; phishing attacks inside the <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=supply-chain-security&amp;utm_term=110826&amp;utm_content=linktosandboxlanding"><strong>Interactive Sandbox</strong></a>. The actionable indicators from these investigations then become available through TI Lookup and TI Feeds.</p>



<p class="wp-block-paragraph">The result is SOC teams can track the latest intel on the threats that are targeting their industry or country at the moment. For example, here’s a TI Lookup query for <a href="https://any.run/by-industry/finance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=supply-chain-security&amp;utm_term=110826&amp;utm_content=linktofinancepage">banking companies</a> in Germany: </p>



<p class="wp-block-paragraph"><a href="https://intelligence.any.run/analysis/lookup#%7B%22query%22:%22submissionCountry:%5C%22de%5C%22%20AND%20industry:%5C%22Banking%5C%22%22,%22dateRange%22:180%7D">submissionCountry:&#8221;de&#8221; AND industry:&#8221;Banking&#8221;</a></p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="600" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-from-2026-08-11-00-38-49-1024x600.png" alt="" class="wp-image-22534" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-from-2026-08-11-00-38-49-1024x600.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-from-2026-08-11-00-38-49-300x176.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-from-2026-08-11-00-38-49-768x450.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-from-2026-08-11-00-38-49-1536x901.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-from-2026-08-11-00-38-49-370x217.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-from-2026-08-11-00-38-49-270x158.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-from-2026-08-11-00-38-49-740x434.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Screenshot-from-2026-08-11-00-38-49.png 1835w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">TI Lookup gives complete attack context to SOC teams, including industrial and country threat landscape </figcaption></figure>



<p class="wp-block-paragraph">Within seconds, TI Lookup reveals that one of the key threats the German banking industry is currently facing is OAuth phishing. The analysts can continue the investigation and collect more intel on this threat to update the detection systems.</p>



<p class="wp-block-paragraph">This transition from manual research to an intelligence-fed loop transforms how a SOC prioritizes its workload. Instead of treating every alert with the same urgency, teams can focus on threats that are actively &#8220;trending&#8221; within their specific industry. Reflecting on the operational impact of this real-time visibility, the <strong>CISO at an <a href="https://any.run/cybersecurity-blog/how-transport-company-monitors-threats/" target="_blank" rel="noreferrer noopener">international transport company</a></strong> managing complex logistics across multiple continents shared:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph"><strong>“The result is that we can follow active threats that may potentially target our company almost in real time because TI Lookup is updated with fresh data”</strong>.</p>



<p class="wp-block-paragraph">CISO at an International Transport Company</p>
</blockquote>



<p class="wp-block-paragraph"><a href="https://any.run/cybersecurity-blog/how-transport-company-monitors-threats/">Read a full case study of how a transport company improved proactive defense →</a></p>



<p class="wp-block-paragraph">By identifying these threats in advance, the SOC can update its detection rules and blocklists with <strong>sandbox-verified data</strong> before the vendor-based attack is even launched against their organization. This strategic lead time is what allows lean security teams to protect large-scale operations without a proportional increase in headcount.</p>



<h2 class="wp-block-heading"><strong>3. Scale Early Detection without Headcount Growth</strong></h2>



<p class="wp-block-paragraph">For US and EU enterprises, particularly those in the <a href="https://any.run/by-industry/manufacturing/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=supply-chain-security&amp;utm_term=110826&amp;utm_content=linktomanufacturingpage">manufacturing</a> and <a href="https://any.run/by-industry/transportation/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=supply-chain-security&amp;utm_term=110826&amp;utm_content=linktotransportationpage">logistics</a> sectors, the operational pressure on the SOC is reaching a tipping point. Security teams in these industries typically carry an <strong>18% to 20% higher workload</strong> than those in other sectors due to the sheer volume of supplier-related file exchanges. </p>



<p class="wp-block-paragraph">The business value of integrating ANY.RUN’s solutions lies in its ability to serve as a <strong>force multiplier</strong>, allowing existing teams to handle hundreds of suspicious supplier files weekly without adding headcount. By providing a cloud-based investigative layer that integrates directly <a href="https://any.run/integrations/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=supply-chain-security&amp;utm_term=110826&amp;utm_content=linktointegrations">into existing SIEM or SOAR platforms</a>, enterprises can transform their SOC from a reactive &#8220;alert processor&#8221; into a streamlined intelligence hub.</p>



<p class="wp-block-paragraph">A major drain on SOC productivity is fragmented threat context that forces analysts to manually correlate data across multiple dashboards. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="582" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image5-1024x582.png" alt="" class="wp-image-22530" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image5-1024x582.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image5-300x171.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image5-768x437.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image5-1536x873.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image5-2048x1164.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image5-370x210.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image5-270x154.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image5-740x421.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">ANY.RUN&#8217;s Sandbox provides standardized Tier 1 reports ready for response</figcaption></figure>



<p class="wp-block-paragraph">ANY.RUN addresses this by <a href="https://any.run/cybersecurity-blog/soc-ready-reporting/"><strong>standardizing Tier 1 reports</strong></a>. These structured summaries package the entire behavioral analysis, including process trees, network activity, and <a href="https://any.run/cybersecurity-blog/mitre-ciso-risk-reduction/">MITRE ATT&amp;CK mapping</a>, into a single, decision-ready document. This ensures that findings move between tiers as <strong>intelligence rather than raw technical data</strong>, preserving the full context of a vendor-borne threat and eliminating the need for duplicated effort.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph"><strong>“We cut the time it takes to move from a suspicious supplier file to a clear decision in half. That gave the business faster answers and reduced the time potential threats remained unresolved.” </strong></p>



<p class="wp-block-paragraph"><strong>Head of SOC, US Automotive Manufacturer </strong></p>
</blockquote>



<p class="wp-block-paragraph"><a href="https://any.run/cybersecurity-blog/us-manufacturer-security-risk/">Read a full case study of how an American manufacturing company reduced third-party risks →</a></p>



<p class="wp-block-paragraph">ANY.RUN also provides <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=supply-chain-security&amp;utm_term=110826&amp;utm_content=linktotifeedslanding">Threat Intelligence Feeds</a> that deliver fresh IOCs (IPs, domains, URLs) to companies’ existing security stacks, ensuring they have the ability to identify new malware and phishing early. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="464" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image4-1024x464.png" alt="" class="wp-image-22532" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image4-1024x464.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image4-300x136.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image4-768x348.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image4-1536x695.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image4-370x167.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image4-270x122.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image4-740x335.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/image4.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">TI Feeds offer a live stream of actionable IOCs from the latest malware &amp; phishing threats</figcaption></figure>



<p class="wp-block-paragraph">The continuous stream of updated indicators helps US and EU enterprises scale their security operations alongside their growing supplier networks, maintaining a lean, effective team that prioritizes <strong>response-ready decisions</strong> over manual data collection.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Detect emerging supply chain attacks before they escalate. </span><br>Strengthen detection coverage with fresh, context-rich IOCs.&nbsp;  
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=supply-chain-security&amp;utm_term=110826&amp;utm_content=linktotifeedsform" target="_blank" rel="noopener">
Integrate TI Feeds
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading"><strong>Conclusion</strong></h2>



<p class="wp-block-paragraph">For US and EU enterprises, securing the supply chain means <strong>shortening the distance between a suspicious signal and a definitive business action</strong>. ANY.RUN serves as the <strong>connective investigative layer</strong> that transforms raw, unverified alerts from trusted partners into actionable behavioral proof. By replacing manual correlation and guesswork with interactive analysis and threat intelligence, security teams can effectively identify and act on third-party risks while maintaining global operations without interruptions.</p>



<h2 class="wp-block-heading"><strong>FAQ: Strengthening Supply Chain Resilience</strong></h2>



<div class="schema-faq wp-block-yoast-faq-block"><div class="schema-faq-section" id="faq-question-1786427723577"><strong class="schema-faq-question"><strong>What is a supply chain attack, and why are traditional defenses failing to detect them?</strong></strong> <p class="schema-faq-answer">A supply chain attack, often categorized as <strong>&#8220;System Intrusion,&#8221;</strong> involves threat actors compromising a trusted vendor or contractor to use their verified status as a springboard into a larger head company. These attacks are difficult to detect because malicious payloads often arrive through legitimate, verified communication channels that bypass standard email gateways and static filters. <a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=supply-chain-security&amp;utm_term=110826&amp;utm_content=linktolanding"><strong>ANY.RUN</strong></a> addresses this by providing an <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=supply-chain-security&amp;utm_term=110826&amp;utm_content=linktosandboxlanding"><strong>interactive behavioral analysis</strong></a><strong> and </strong><a href="https://intelligence.any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=supply-chain-security&amp;utm_term=110826&amp;utm_content=linktotiservice"><strong>threat intelligence</strong></a>. It allows analysts to detonate vendor files and enrich indicators with context.</p> </div> <div class="schema-faq-section" id="faq-question-1786427733178"><strong class="schema-faq-question"><strong>How can organizations manage the high volume of third-party files without increasing SOC headcount?</strong></strong> <p class="schema-faq-answer">Enterprises in sectors like manufacturing and logistics often face a <strong>20% higher security workload</strong> due to the constant exchange of supplier documents. By integrating solutions like ANY.RUN via API into existing workflows, organizations can achieve a <a href="https://any.run/cybersecurity-blog/us-manufacturer-security-risk/"><strong>2x improvement in triage speed</strong></a> and increased <strong>Tier 1 closure rates. </strong>This efficiency ensures that business-critical supplier communication isn&#8217;t stalled by security bottlenecks.</p> </div> <div class="schema-faq-section" id="faq-question-1786427749258"><strong class="schema-faq-question"><strong>How do you identify sophisticated phishing attacks originating from a compromised vendor mailbox?</strong></strong> <p class="schema-faq-answer">Attackers frequently use compromised vendor accounts to launch <strong>Adversary-in-the-Middle (AiTM)</strong> attacks, which often leave no file-based trace on the endpoint. <strong>To </strong>neutralize this visibility gap, SOC teams can utilize <a href="https://any.run/cybersecurity-blog/in-browser-data-inspection/"><strong>in-browser data inspection</strong></a>. This capability allows security teams to observe dynamically rendered content, hidden redirect chains, and injected forms as the user experiences them, providing the definitive proof needed to confirm credential theft even when traditional endpoint controls see nothing.</p> </div> <div class="schema-faq-section" id="faq-question-1786427758283"><strong class="schema-faq-question"><strong>What is the role of Threat Intelligence in reducing supply chain risk?</strong></strong> <p class="schema-faq-answer">Relying on static Indicators of Compromise (IOCs) is a liability because attackers often cycle their infrastructure every 48 hours. <strong>ANY.RUN</strong> enables a proactive defense by providing <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=supply-chain-security&amp;utm_term=110826&amp;utm_content=linktotilookuplanding"><strong>Threat Intelligence Lookup</strong></a>, which allows analysts to pivot from a single suspicious artifact (like a vendor’s IP) to a broader campaign-level view. By tracking <strong>Indicators of Behavior (IOBs)</strong>, such as specific mutexes or process patterns, teams can identify malicious infrastructure used against their peers before it ever hits their own perimeter.</p> </div> </div>
<p>The post <a href="https://any.run/cybersecurity-blog/supply-chain-security-for-us-and-eu-companies/">Supply Chain Security: How ANY.RUN Helps US and EU Enterprises Prevent Incidents</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/supply-chain-security-for-us-and-eu-companies/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup</title>
		<link>https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/</link>
					<comments>https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/#respond</comments>
		
		<dc:creator><![CDATA[Mauro Eldritch&nbsp;and&nbsp;Heiner García Pérez]]></dc:creator>
		<pubDate>Mon, 10 Aug 2026 12:41:39 +0000</pubDate>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[malware analysis]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=22466</guid>

					<description><![CDATA[<p>Editor’s note: This work is a collaboration between Mauro Eldritch from BCA LTD, a company dedicated to threat intelligence and hunting, Heiner García from NorthScan, a threat intelligence initiative uncovering North Korean IT worker infiltration, and ANY.RUN, the leading company in malware analysis and threat intelligence. The article was written by Mauro and Heiner. Key [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/">Smile, You&#8217;re on Camera. Part 2: Hiring Lazarus APT&#8217;s IT Workers in a Fake DeFi Startup</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><em>Editor’s note: This work is a collaboration between Mauro Eldritch from BCA LTD, a company dedicated to threat intelligence and hunting, Heiner García from NorthScan, a threat intelligence initiative uncovering North Korean IT worker infiltration, and </em><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a><em>, the leading company in malware analysis and threat intelligence</em>.  </p>



<p class="wp-block-paragraph"><em>The article was written by Mauro and Heiner.</em> </p>



<h2 class="wp-block-heading"><strong>Key Takeaways</strong> </h2>



<ul class="wp-block-list">
<li>Researchers created a fake DeFi startup and <strong>hired suspected Famous Chollima operatives</strong>, providing a rare inside view of a DPRK IT worker operation. </li>



<li><strong>The investigation followed the scheme beyond recruitment</strong>, showing how the operatives worked, collaborated, and accessed company resources after being hired. </li>



<li><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> sandbox environments provided <strong>a live view of the operatives’ behavior</strong>, exposing their evolving toolset, remote access workflow, AI usage, and supporting infrastructure. </li>



<li>The findings show that DPRK IT worker schemes are <strong>not only a hiring risk</strong>. Once inside, operatives can gain legitimate access to code, systems, intellectual property, and trusted business processes. </li>
</ul>



<h2 class="wp-block-heading"><strong>Introduction</strong> </h2>



<p class="wp-block-paragraph">Back in December, we were <strong>the first ever to fully record the Famous Chollima infiltration cycle</strong>. From recruiting collaborators to help them land jobs at Western companies, to forging documents, shipping laptops to facilitators’ houses, and even using AI tools for live assistance and translation during interviews.  </p>



<p class="wp-block-paragraph">During that investigation, we posed as facilitators willing to take job interviews and lend them laptops so they could find a job in exchange for a percentage of their salaries. The trick was that those laptops were actually <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener"><strong>ANY.RUN </strong>sandbox environments</a>, recording every click and every movement they made. This gave us tons of indicators, endless hours of laptop and face-to-face footage, and <strong><a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation/" target="_blank" rel="noreferrer noopener">an unprecedented investigation </a></strong>that made it to the top of many media outlets. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="463" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Famous-Chollima-Recruiter-Exposed-1024x463.png" alt="Aaron A.K.A “Blaze”, Famous Chollima Recruiter" class="wp-image-22469" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Famous-Chollima-Recruiter-Exposed-1024x463.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Famous-Chollima-Recruiter-Exposed-300x136.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Famous-Chollima-Recruiter-Exposed-768x348.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Famous-Chollima-Recruiter-Exposed-1536x695.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Famous-Chollima-Recruiter-Exposed-2048x927.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Famous-Chollima-Recruiter-Exposed-370x167.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Famous-Chollima-Recruiter-Exposed-270x122.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Famous-Chollima-Recruiter-Exposed-740x335.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Aaron A.K.A “Blaze”, Famous Chollima Recruiter from Episode 1</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">It was definitely not for the faint of heart, requiring months of dedication as we profiled them while acting as their partners in crime. But today, we want to raise the stakes.  </p>



<p class="wp-block-paragraph">This time, instead of playing facilitators, we posed as the founders of <strong>Ballena Azul LTD</strong>, a new DeFi protocol working directly with crypto whales across different chains and looking for new developers to build it. Developers we could trust with <em>lots of money</em>. More than you and all your friends could ever fit in your pockets. Numbers you can barely read without counting the commas. All while resisting the temptation to drain it to an embargoed nation far away to the East. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="629" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-Blue-Whale-LTD-Website-1-1024x629.png" alt="Ballena Azul LTD / Blue Whale LTD Website" class="wp-image-22547" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-Blue-Whale-LTD-Website-1-1024x629.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-Blue-Whale-LTD-Website-1-300x184.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-Blue-Whale-LTD-Website-1-768x472.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-Blue-Whale-LTD-Website-1-1536x943.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-Blue-Whale-LTD-Website-1-2048x1258.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-Blue-Whale-LTD-Website-1-370x227.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-Blue-Whale-LTD-Website-1-270x166.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-Blue-Whale-LTD-Website-1-740x454.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Ballena Azul LTD / Blue Whale LTD Website</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">This new episode has it all: <strong>an overconfident CEO </strong>who does not run background checks on employees, <strong>fake developers </strong>with forged documents, <strong>mule bank accounts</strong>, <strong>journalists posing as venture capitalists,</strong> and <strong>an Italian lawyer </strong>who will blow everything up in the end. </p>



<p class="wp-block-paragraph"><strong>This is Smile, You’re on Camera! Episode 2. </strong> </p>



<p class="wp-block-paragraph">I hope you already have your popcorn ready.  </p>



<figure class="wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="Hello DEF CON" width="770" height="433" src="https://www.youtube.com/embed/18_sVD1Mz3M?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>
</div><figcaption class="wp-element-caption"><em>Hello DEF CON</em></figcaption></figure>



<p class="wp-block-paragraph"><a href="https://youtu.be/18_sVD1Mz3M" target="_blank" rel="noreferrer noopener">Watch the video on YouTube</a></p>



<h2 class="wp-block-heading"><strong>Chapter I: The Chollimas</strong> </h2>



<p class="wp-block-paragraph">Let’s introduce our main antagonist. Take this as a short recap in case, you’re new to this series or need a refresher on what we are dealing with. </p>



<p class="wp-block-paragraph">One of the many divisions operating under the <strong>Lazarus </strong>umbrella is <strong>Famous Chollima</strong>. Their goal is simple: get hired by Western companies. </p>



<p class="wp-block-paragraph">They seek remote positions in industries where both intelligence and money are plentiful. Cryptocurrency, finance, and healthcare have historically been among their favorite targets, while more recent campaigns have expanded into pharmaceuticals, civil engineering, architecture, and other sectors. </p>



<p class="wp-block-paragraph">To secure those positions, they rely on forged identities, fake résumés, proxy interviews, remote facilitators and ghost developers, all working together to convince companies that the person they hired is exactly who they claim to be. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-1024x1024.png" alt="DPRK Operatives caught" class="wp-image-22474" style="width:668px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-1024x1024.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-300x300.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-150x150.png 150w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-768x769.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-1534x1536.png 1534w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-70x70.png 70w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-370x370.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-270x270.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught-740x741.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DPRK-Operatives-caught.png 1636w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>DPRK Operatives caught by Bitso Quetzal Team while interviewing for a position at the Company</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Unlike a traditional intrusion, their objective is not to compromise an organization for a few hours or days, but to become a part of it. A successful placement can provide months or even years of continuous access to internal systems, source code, intellectual property and corporate decision-making, while simultaneously generating a legitimate salary that is ultimately channeled back to the DPRK regime. </p>



<p class="wp-block-paragraph">This makes Famous Chollima a very different kind of threat. Malware operations can produce spectacular results overnight, as demonstrated by recent compromises involving cryptocurrency bridge signers. But those operations are also inherently noisy and carry a significant risk of discovery. An employee, on the other hand, is expected to be there. </p>



<p class="wp-block-paragraph">The longer they remain trusted, the greater the opportunity to gather intelligence, influence decisions, and gradually become part of the organization itself. If enough operatives were to secure positions within the same company, they could eventually influence engineering decisions, code reviews, pull requests, approvals, or other trust-based processes without ever exploiting software vulnerability. </p>



<p class="wp-block-paragraph">Knowing that they actively pursue these kinds of opportunities, we decided to create one ourselves. </p>



<h2 class="wp-block-heading"><strong>Chapter II: The Company</strong> </h2>



<p class="wp-block-paragraph">The answer was <strong>Ballena Azul LTD / Blue Whale LTD</strong>. </p>



<p class="wp-block-paragraph">On paper, it was exactly the kind of company Famous Chollima would love to work for: <strong>a DeFi protocol working alongside cryptocurrency whales</strong> across multiple blockchains and looking for experienced developers to help build the platform. </p>



<p class="wp-block-paragraph">The protocol itself was simple. By combining NFTs and other on-chain mechanisms, whale wallets could voluntarily identify themselves and publicly signal ownership. The idea was to reduce unnecessary market speculation whenever large sums of money moved, avoiding rumors of exchange hacks, wallet drainers, exit scams, or other events that often trigger panic across the ecosystem. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="677" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-on-NFT-Marketplace-2-1024x677.png" alt="Ballena Azul LTD on OpenSea NFT Marketplace" class="wp-image-22549" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-on-NFT-Marketplace-2-1024x677.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-on-NFT-Marketplace-2-300x198.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-on-NFT-Marketplace-2-768x508.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-on-NFT-Marketplace-2-1536x1015.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-on-NFT-Marketplace-2-2048x1353.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-on-NFT-Marketplace-2-370x245.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-on-NFT-Marketplace-2-270x178.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-on-NFT-Marketplace-2-740x489.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Ballena Azul LTD on OpenSea NFT Marketplace</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Everything had to look legitimate. A professional website, corporate branding, documentation, an online presence and, most importantly, a product that made sense. Not because we expected investors to believe it, but because we expected them to.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="842" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-registration-in-the-UK-1024x842.png" alt="Ballena Azul LTD registration in the UK" class="wp-image-22550" style="width:766px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-registration-in-the-UK-1024x842.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-registration-in-the-UK-300x247.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-registration-in-the-UK-768x631.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-registration-in-the-UK-1536x1263.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-registration-in-the-UK-2048x1684.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-registration-in-the-UK-370x304.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-registration-in-the-UK-270x222.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Ballena-Azul-LTD-registration-in-the-UK-740x608.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>An existing Ballena Azul LTD registration in the UK Companies House helped reinforce the company’s legitimacy. This entity is unrelated to our operation</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">I became Leonardo Nelson, co-founder of Ballena Azul LTD. My business partner, <strong>Benito</strong>, would be joining our meetings from Italy. At the same time, Heiner returned as <strong>Andy Jones</strong>, the developer and facilitator from <a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation/" target="_blank" rel="noreferrer noopener">Episode 1</a>. This time he was Ballena Azul’s Team Lead and had been personally recommended to me by Benito. </p>



<p class="wp-block-paragraph">For the infrastructure, we turned to our most trusted provider: <a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener"><strong>ANY.RUN</strong></a>. Now all we needed were developers. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Give your SOC faster access to investigation context. <br><span class="highlight">Cut MTTR by up to 21 minutes per case.</span>
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=lazarus-group-it-workers-investigation-part-two&#038;utm_term=100826&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Accelerate Threat Investigations</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph">Fortunately, Andy knew just the right person for the job: <strong>Angelo Cruz</strong>, <strong>a recruiter from</strong> <strong>Famous Chollima </strong>who was eager to make a name for himself. </p>



<h2 class="wp-block-heading"><strong>Chapter III: The Horse Trader</strong>  </h2>



<p class="wp-block-paragraph">Angelo Cruz met Andy on <strong>GitHub</strong>, definitely a strange place to make friends. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="963" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment-963x1024.png" alt="Angelo’s comment on GitHub looking for facilitators" class="wp-image-22552" style="aspect-ratio:0.9404355812122802;width:680px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment-963x1024.png 963w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment-282x300.png 282w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment-768x816.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment-1445x1536.png 1445w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment-370x393.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment-270x287.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment-740x786.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelos-comment.png 1592w" sizes="auto, (max-width: 963px) 100vw, 963px" /><figcaption class="wp-element-caption"><em>Angelo’s comment on GitHub looking for facilitators</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">They started chatting and before long, Cruz convinced Andy they should work together, with Andy acting as <strong>his trusted facilitator </strong>to help his developers find jobs. Andy agreed and soon <strong>introduced Angelo to Ballena Azul LTD</strong> as the perfect opportunity. According to the plan, Ballena Azul LTD would become just another company to rob. After all, we trusted Andy’s judgment. Whoever he chose was welcome aboard. </p>



<figure class="wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="Interview with the Chollima" width="770" height="433" src="https://www.youtube.com/embed/vxgf12VoMDM?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>
</div><figcaption class="wp-element-caption"><em>Interview with the Chollima</em></figcaption></figure>



<p class="wp-block-paragraph"><a href="https://youtu.be/vxgf12VoMDM" target="_blank" rel="noreferrer noopener">Watch the video on YouTube</a></p>



<p class="wp-block-paragraph">To generate a false sense of trust, Andy offered to lend them his brother’s ID, but at the end it was not necessary. Not long afterwards, Angelo introduced us to <strong>our first engineer: Angelo Espree</strong>. </p>



<h2 class="wp-block-heading"><strong>Chapter IV: The Team</strong>  </h2>



<p class="wp-block-paragraph">Angelo Espree was the first to accept a position at Ballena Azul LTD, making him the <strong>first DPRK IT Worker</strong> to step inside our company. He would also become the first dossier in our investigation. </p>



<p class="wp-block-paragraph">Before the interview, Andy and Angelo agreed on a simple story. They would tell me, the CEO, that Benito already knew Angelo, personally vouched for him, and had approved bringing him into the company. </p>



<p class="wp-block-paragraph">That was how <strong>our first interview began</strong>. A Real Madrid supporter with a background in mathematics, Angelo would be responsible for developing the company’s smart contracts. </p>



<figure class="wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="Angelo’s Interview" width="770" height="433" src="https://www.youtube.com/embed/KqhOVIogLGY?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>
</div><figcaption class="wp-element-caption"><em>Angelo’s Interview</em></figcaption></figure>



<p class="wp-block-paragraph"><a href="https://youtu.be/KqhOVIogLGY" target="_blank" rel="noreferrer noopener">Watch the video on YouTube</a></p>



<p class="wp-block-paragraph">During the interview, we asked Angelo to <strong>scan a QR code </strong>to confirm his attendance. He did, and of course, fell for the oldest trick in the book. The QR code silently redirected him to one of our <strong>Canary Tokens</strong>, which recorded information about anyone who triggered it, including their <strong>IP address</strong>, User-Agent, and more. At the time, it seemed like a small mistake. Later, it would become a key piece of evidence in uncovering <strong>a much broader conspiracy</strong>. But we’ll get to that later. For now, we were simply happy to have made new friends. </p>



<p class="wp-block-paragraph">As friends, we explained that Ballena Azul operated as a fully trust-based environment and that we intended to recruit only people we could genuinely rely on. Angelo already had someone in mind: <strong>his friend Jack Anderson</strong>. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="628" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelo-1024x628.png" alt="Angelo's happiness" class="wp-image-22554" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelo-1024x628.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelo-300x184.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelo-768x471.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelo-1536x941.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelo-2048x1255.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelo-370x227.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelo-270x165.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelo-740x454.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Happiness</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Jack was noticeably quieter and struggled with English. Throughout the interview, we caught him repeatedly glancing off-screen, as if reading from a second monitor <strong>running a live translation tool</strong>, something we had already documented as part of Famous Chollima’s standard toolkit in Episode 1. Like Angelo, Jack had studied mathematics, supported Real Madrid, and didn&#8217;t laugh easily. He nevertheless convinced us, and we welcomed him to Ballena Azul LTD as our Front-end Developer. </p>



<figure class="wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="Jack’s Interview" width="770" height="433" src="https://www.youtube.com/embed/GNuF0H_K4Tc?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>
</div><figcaption class="wp-element-caption"><em>Jack’s Interview</em></figcaption></figure>



<p class="wp-block-paragraph"><a href="https://youtu.be/GNuF0H_K4Tc" target="_blank" rel="noreferrer noopener">Watch the video on YouTube</a></p>



<p class="wp-block-paragraph">One thing leads to another, and in this line of work everyone needs someone they can trust. Jack had Lucas<strong> Theo, a seasoned Backend Developer</strong>. We interviewed him. He understood the role, showed genuine interest in the position, and even told us about his dog, Lulú, his honeymoon in Philippines and his love for hiking. We had no reason to distrust him. </p>



<p class="wp-block-paragraph">So, we welcomed him to the Ballena Azul family as well. </p>



<figure class="wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="Lucas’ Interview" width="770" height="433" src="https://www.youtube.com/embed/dPAjfHr4kzk?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>
</div><figcaption class="wp-element-caption"><em>Lucas’ Interview</em></figcaption></figure>



<p class="wp-block-paragraph"><a href="https://youtu.be/dPAjfHr4kzk" target="_blank" rel="noreferrer noopener">Watch the video on YouTube</a></p>



<p class="wp-block-paragraph">With that, they had assembled the perfect crew for a master heist. We, on the other hand, had a stable full of Chollimas waiting to be broken in. </p>



<p class="wp-block-paragraph">But you know, every good lie needs paperwork. A lot of paperwork. </p>



<h2 class="wp-block-heading"><strong>Chapter V: The Imposters</strong> </h2>



<p class="wp-block-paragraph">It was time to sign the contracts and seal our alliance. But as an experienced CEO, I needed to run a quick background check on my new employees. Surely asking for an ID would be enough, right? I also requested their <strong>address</strong>, <strong>cryptocurrency wallets</strong>, and <strong>banking details</strong>. Standard onboarding paperwork. </p>



<p class="wp-block-paragraph">Jack sent a <strong>driver’s license from Austin</strong>, <strong>Texas</strong>, where he supposedly lived, along with a valid SSN and a bank account at <strong>Lead Bank </strong>in <strong>Kansas City</strong>. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="648" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Jacks-Fake-License-1024x648.png" alt="Lazarus Jack’s Fake License" class="wp-image-22555" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Jacks-Fake-License-1024x648.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Jacks-Fake-License-300x190.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Jacks-Fake-License-768x486.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Jacks-Fake-License-1536x971.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Jacks-Fake-License-2048x1295.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Jacks-Fake-License-370x234.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Jacks-Fake-License-270x171.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Jacks-Fake-License-740x468.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Jack’s driving license</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Angelo was far more daring. He claimed to be living in <strong>Pasadena</strong>, <strong>Texas</strong>, yet sent us a <strong>California </strong>driver’s license together with a <strong>Citibank </strong>account in <strong>New York</strong>. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="645" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2-1024x645.png" alt="Lazarus Angelo's driving license" class="wp-image-22556" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2-1024x645.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2-300x189.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2-768x484.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2-1536x968.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2-370x233.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2-270x170.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2-740x466.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelos-ID-2.png 1698w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Angelo’s driving license</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The most interesting part was hidden in the <strong>metadata</strong>. Several EXIF entries revealed that the image had been processed with <strong>Google Gemini</strong>, and a <strong>SynthID </strong>watermark had been embedded as well. Between that and the obvious visual inconsistencies, the forgery was almost trivial to detect, unbeknownst to him. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="543" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-1024x543.png" alt="Lazarus investigation: Angelo’s License Metadata" class="wp-image-22557" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-1024x543.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-300x159.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-768x408.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-1536x815.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-2048x1087.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-370x196.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-270x143.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-License-Metadata-740x393.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Angelo’s License Metadata</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">If that seemed bold, Lucas<strong> </strong>managed to raise the stakes even further. </p>



<p class="wp-block-paragraph">Instead of sending documents under his own name, he shared a <strong>New York </strong>driver’s license belonging to <strong>Pui Chin Teoh</strong>, together with a bank account from <strong>Wise</strong>. Unlike Angelo’s document, the metadata showed it was an <strong>authentic photograph</strong> originally taken with an iPhone 15.</p>



<p class="wp-block-paragraph">Unfortunately for us, the GPS coordinates had been stripped. Our best guess was that Pui Chin is a real person who had photographed their own driver’s license for a KYC process or similar, only for that image to later be leaked and eventually find its way into Lucas’ hands. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="543" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lucass-License-Metadata-1024x543.png" alt="Lazarus investigation Lucas license metadata" class="wp-image-22558" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lucass-License-Metadata-1024x543.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lucass-License-Metadata-300x159.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lucass-License-Metadata-768x408.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lucass-License-Metadata-1536x815.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lucass-License-Metadata-2048x1087.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lucass-License-Metadata-370x196.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lucass-License-Metadata-270x143.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lucass-License-Metadata-740x393.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Lucas’s License Metadata</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">By now, we had <strong>fake identities</strong>, <strong>stolen SSNs</strong>, <strong>mule bank accounts</strong>, possible <strong>facilitator safe houses</strong>, and <strong>cryptocurrency wallets </strong>with transaction history. </p>



<p class="wp-block-paragraph">So, it was finally time to put my all-star team to work. We still didn’t have laptops ready to ship, but that wasn’t a problem. We told them our provider had set us up with virtual desktops so they could start right away. </p>



<p class="wp-block-paragraph">That provider was <a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener"><strong>ANY.RUN</strong></a>. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Reduce investigation risk without exposing systems.</span><br>
Give your SOC visibility before impact spreads.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=lazarus-group-it-workers-investigation-part-two&#038;utm_term=100826&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Reduce Operational Risk</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading"><strong>Chapter VI: The North Korean Job</strong> </h2>



<p class="wp-block-paragraph">Capturing face-to-face footage is just as important as capturing everything happening inside the machine. Both provide different pieces of the same puzzle. <a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener"><strong>ANY.RUN</strong></a><strong> </strong>was the perfect solution for this, allowing us to record <strong>every file opened</strong>, <strong>every network connection</strong>, and virtually <strong>every click </strong>made inside the system. Not a single byte could move without us noticing <strong>in real time</strong>. These instances were especially crafted for this operation, lasting for hours just like a real VDI would do. </p>



<p class="wp-block-paragraph">We spun up three separate instances and handed each developer their own environment. It was time to watch them work. </p>



<p class="wp-block-paragraph">On the first day, Angelo and the team scouted their machines using almost the exact same playbook from Episode 1. They started with dxdiag (DirectX Diagnostic Tool), systeminfo, and wmic to get a detailed overview of the system, then checked where in the world they appeared to be by visiting legitimate IP lookup websites, in this case IP8.</p>



<p class="wp-block-paragraph">Everything looked good, so Angelo felt safe enough to open his Google account, install Google Remote Desktop, just as we’d seen in Episode 1, and sync his account with the machine. </p>



<p class="wp-block-paragraph">Yes, sync his account. Just like in Episode 1. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="612" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-investigation-misclick-1024x612.png" alt="Lazarus investigation misclick" class="wp-image-22559" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-investigation-misclick-1024x612.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-investigation-misclick-300x179.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-investigation-misclick-768x459.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-investigation-misclick-1536x918.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-investigation-misclick-2048x1224.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-investigation-misclick-370x221.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-investigation-misclick-270x161.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-investigation-misclick-740x442.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>A misclick worth millions</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">For those unfamiliar with how Google account synchronization works, it means that all the user’s stored information becomes available on that device, including browsing history, search history, saved passwords, and installed extensions. All of his, from a single misplaced click. In Episode 1, this allowed us to identify the entire Famous Chollima toolset, including the AI tools they used throughout the job acquisition process. </p>



<p class="wp-block-paragraph">However, he didn’t seem to notice and simply moved on to logging into his GitHub account. Business as usual. </p>



<figure class="wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="A hard day’s work" width="770" height="433" src="https://www.youtube.com/embed/6EcYGRgCUDY?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>
</div><figcaption class="wp-element-caption"><em>A hard day’s work</em></figcaption></figure>



<p class="wp-block-paragraph"><a href="https://youtu.be/6EcYGRgCUDY" target="_blank" rel="noreferrer noopener">Watch the video on YouTube</a></p>



<p class="wp-block-paragraph">The team advanced on multiple fronts at a rapid pace, which isn’t to say they were doing things the right way. </p>



<p class="wp-block-paragraph">Jack struggled to deliver a frontend that didn’t look completely vibe-coded and identical to half the internet, while Angelo and Lucas wrestled with the backend and the smart contracts. </p>



<p class="wp-block-paragraph">They <strong>googled the basics</strong>, like how to build upgradeable smart contracts, imported an existing MetaMask wallet, and then struggled to scrape together some crypto from testnet faucets. At one point, they even pasted the testnet URL into the wallet address field before eventually complaining to ChatGPT that “all of them require real money now.” </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="604" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelo-uses-ChatGPT-1024x604.png" alt="Lazarus: Angelo using ChatGPT" class="wp-image-22560" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelo-uses-ChatGPT-1024x604.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelo-uses-ChatGPT-300x177.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelo-uses-ChatGPT-768x453.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelo-uses-ChatGPT-1536x906.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelo-uses-ChatGPT-2048x1208.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelo-uses-ChatGPT-370x218.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelo-uses-ChatGPT-270x159.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Angelo-uses-ChatGPT-740x437.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Angelo using ChatGPT</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">They then carried on working in their repository, now with entirely imaginary assets after failing to claim funds from any faucet. At this point, we were seriously questioning whether this had been the right business decision. Ballena Azul’s next quarterly report was not looking promising. </p>



<figure class="wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="Employee of the Month" width="770" height="433" src="https://www.youtube.com/embed/eAXLc9gJwO0?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>
</div><figcaption class="wp-element-caption"><em>Employee of the Month</em></figcaption></figure>



<p class="wp-block-paragraph"><a href="https://youtu.be/eAXLc9gJwO0" target="_blank" rel="noreferrer noopener">Watch the video on YouTube</a></p>



<p class="wp-block-paragraph">Maybe it was just a bad day at work. Everyone has those. </p>



<p class="wp-block-paragraph">But it never rains but pours. So, we decided to make it a little worse. </p>



<p class="wp-block-paragraph">In Episode 1, we introduced artificial crashes and network outages to slow the operatives down, then immediately scolded them for “breaking” the laptops we’d lent them. This time, we kept the selective network outages but also made the mouse cursor disappear randomly.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="604" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-debugging-a-selective-network-outage-2-1024x604.png" alt="Lazarus research: Angelo debugging network outage" class="wp-image-22562" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-debugging-a-selective-network-outage-2-1024x604.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-debugging-a-selective-network-outage-2-300x177.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-debugging-a-selective-network-outage-2-768x453.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-debugging-a-selective-network-outage-2-1536x906.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-debugging-a-selective-network-outage-2-2048x1208.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-debugging-a-selective-network-outage-2-370x218.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-debugging-a-selective-network-outage-2-270x159.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-debugging-a-selective-network-outage-2-740x437.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Angelo debugging a selective network outage</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Whenever they complained, we told them that one of our provider’s IT support agents would connect and fix the issue. </p>



<p class="wp-block-paragraph">What followed was an unexpected reminiscence of something Aaron did with Andy in Episode 1, except this time between Angelo and one of our “IT Support” agents: chatting via Notepad. </p>



<figure class="wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="Are you there?" width="770" height="433" src="https://www.youtube.com/embed/pB6vYAuq-BA?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>
</div><figcaption class="wp-element-caption"><em>Are you there?</em></figcaption></figure>



<p class="wp-block-paragraph"><a href="https://youtu.be/pB6vYAuq-BA" target="_blank" rel="noreferrer noopener">Watch the video on YouTube</a></p>



<p class="wp-block-paragraph">Their vibecoding session continued, now wrestling with a faulty NPM installation and dealing with the occasional network outages while juggling ChatGPT results between <strong>Remix and Visual Studio</strong>, hoping for the best. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="604" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Debugging-Node.js-issues-with-ChatGPT-1024x604.png" alt="Lazarus: Debugging Node.js issues" class="wp-image-22564" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Debugging-Node.js-issues-with-ChatGPT-1024x604.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Debugging-Node.js-issues-with-ChatGPT-300x177.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Debugging-Node.js-issues-with-ChatGPT-768x453.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Debugging-Node.js-issues-with-ChatGPT-1536x906.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Debugging-Node.js-issues-with-ChatGPT-2048x1208.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Debugging-Node.js-issues-with-ChatGPT-370x218.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Debugging-Node.js-issues-with-ChatGPT-270x159.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Debugging-Node.js-issues-with-ChatGPT-740x437.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Debugging Node.js issues with ChatGPT</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">They were busy, short-staffed, short-skilled, and had first-week deadlines looming over them, so this was the perfect time to summon an old villain from this series: <strong>Captcha Hell</strong>. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="604" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-stuck-in-an-endless-CAPTCHA-loop-1024x604.png" alt="Angelo stuck in an endless CAPTCHA loop" class="wp-image-22565" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-stuck-in-an-endless-CAPTCHA-loop-1024x604.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-stuck-in-an-endless-CAPTCHA-loop-300x177.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-stuck-in-an-endless-CAPTCHA-loop-768x453.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-stuck-in-an-endless-CAPTCHA-loop-1536x906.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-stuck-in-an-endless-CAPTCHA-loop-2048x1208.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-stuck-in-an-endless-CAPTCHA-loop-370x218.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-stuck-in-an-endless-CAPTCHA-loop-270x159.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Angelo-stuck-in-an-endless-CAPTCHA-loop-740x437.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Angelo stuck in an endless CAPTCHA loop</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">After dealing with CAPTCHAs for a couple of minutes, a network failure “forced the VDI to be disposed of”, wiping out all unsaved progress. </p>



<p class="wp-block-paragraph">The days went by with the Chollimas prancing all over the stable, leaving behind not only faulty code but plenty of tracks: AstrillVPN exit nodes everywhere, chat logs, conversations with AI agents, wallets, and hours of live face footage. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="604" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-dream-building-2-1024x604.png" alt="Lazarus investigation: dream building" class="wp-image-22566" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-dream-building-2-1024x604.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-dream-building-2-300x177.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-dream-building-2-768x453.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-dream-building-2-1536x906.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-dream-building-2-2048x1208.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-dream-building-2-370x218.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-dream-building-2-270x159.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-dream-building-2-740x437.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Building the dream</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">But better than all of that, they exposed something far more interesting, caught in flagrante: <strong>operative servers</strong> used as proxies and vantage points to jump into the VDIs. </p>



<p class="wp-block-paragraph">This particular finding is highly valuable, as their servers tend to be long-lived, are often recycled, sometimes host multiple malware families reflecting the evolution of their campaigns over time, and by the end of their lifecycle accumulate tags across the entire threat intelligence landscape. </p>



<p class="wp-block-paragraph">This was the case for one of them, but not for the other two, which had barely been seen and were tagged simply as “scanner” (“this host conducts port scans”) and, oddly enough, “honeypot”. </p>



<p class="wp-block-paragraph">But as the days went by, not only did our intelligence collection grow, so did Ballena Azul LTD. It grew so much that it caught the attention of someone who wanted to meet the team behind the next crypto unicorn: a VC investor. </p>



<h2 class="wp-block-heading"><strong>Chapter VII: The Investor</strong> </h2>



<p class="wp-block-paragraph">Mr. Aelin Ashriver worked for Definitive Communications (abbreviated as Def-Comm, which sounds remarkably similar to DEF CON, the conference where we presented this work) and was interested in funding our dream. We held multiple “practice” sessions with the team, rehearsing our team salute: “Hello Def Comm, we’re Ballena Azul LTD!” When the big day finally arrived, everything went smoothly. </p>



<p class="wp-block-paragraph">At one point during the meeting, Mr. Ashriver asked whether we’d be interested in getting some media attention, mentioning that he could help with that and even claiming to be quite close to Cointelegraph. Of course he was. </p>



<p class="wp-block-paragraph">Mr. Ashriver was, in reality, Yohan Yun, a South Korean correspondent for Cointelegraph and was our partner in crime all the time. And you, dear reader, thought we were done with the plot twists. </p>



<p class="wp-block-paragraph">Definitive Communications decided to fund Ballena Azul LTD, and you could almost see the dollar signs branded into their retinas. They could already taste the money pouring in. Securing one of the first spots at a startup often meant landing a trusted position, and they could practically feel those cold wallet private keys at the tip of their hooves. </p>



<p class="wp-block-paragraph">We were climbing to the top. But everything that goes up… eventually comes down. And so, our downfall began. </p>



<h2 class="wp-block-heading"><strong>Chapter VIII: The Lawyer</strong>  </h2>



<p class="wp-block-paragraph">I told you we had more plot twists. And believe me, this isn’t the last one. </p>



<p class="wp-block-paragraph">So far, Heiner (Andy) and I (Leonardo Nelson) had been working with Jack, Angelo and Lucas on a daily basis. But if you’ve been paying attention, there’s one missing name in this equation: Mr. Benito, my co-founder (played by our friend Alejo). He had been in Milan, busy with work and life, and trusted us to keep the house in order while he was away. When he returned, however, he found that we’d turned the house into a stable, and he was not happy about it. </p>



<figure class="wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="The Many Lives of Mr Anderson" width="770" height="433" src="https://www.youtube.com/embed/PIHLsv-jZqQ?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>
</div><figcaption class="wp-element-caption"><em>The Many Lives of Mr. Anderson</em></figcaption></figure>



<p class="wp-block-paragraph"><a href="https://youtu.be/PIHLsv-jZqQ" target="_blank" rel="noreferrer noopener">Watch the video on YouTube</a></p>



<p class="wp-block-paragraph">The first to run away was Angelo, <strong>completely terrified</strong>. Jack took longer to understand what was happening (remember he relied on a rather unusual live translation tool). Benito took full advantage of that and landed one Matrix reference after another while we tried to keep a straight face (“<em>I’ll be as forthcoming as I can be, Mr. Anderson</em>”, “<em>Are you living two lives, Mr. Anderson?</em>”). Once Jack finally understood the situation, he simply left. </p>



<p class="wp-block-paragraph">Once the three of us were alone, we had a laugh to decompress and I could finally say that it was the last time using that costume, even if Benito thought the cap suited me well. But that wasn’t the end of it. Our Telegram channel turned into a screaming match between me, the betrayed CEO, and Andy, the employee with a rather lax attitude towards employment law. </p>



<p class="wp-block-paragraph">I accused him of bringing in “illegal workers”, still pretending not to fully understand what was really going on, and told him he was going to get me into trouble. </p>



<p class="wp-block-paragraph">He fired back that he’d been under enormous pressure to build a team quickly and that I wasn’t paying him enough to do it. He’d done the best he could with what he had. </p>



<p class="wp-block-paragraph">The argument went on for a while until I decided to end not only our partnership, but our friendship as well, telling him that if he had anything else to say, he could channel it through my assistant or through Benito. </p>



<p class="wp-block-paragraph">In a gesture of humanity that I genuinely respect (and I mean it), Angelo reached out to Andy privately to ask whether he was alright and to say he was sorry about what had happened between us. </p>



<p class="wp-block-paragraph">We never heard from the rest of the group again, who, to this day, still have no idea they were being reverse-spied on. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Reduce Tier 1-to-Tier 2 escalations by up to 30%.</span><br>
Give your SOC clearer evidence for faster decisions.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Reduce SOC Workload</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading"><strong>Bonus Chapter I: Fool me thrice</strong> </h2>



<p class="wp-block-paragraph">What kind of second season would this be if we couldn’t feature a returning character who mysteriously disappeared without a trace in the first one? </p>



<p class="wp-block-paragraph">By the time we had assembled the team, we were already too deep to back out, so we did what anyone else would do in our situation: keep going and hire our fifth Beatle. But this one was an old acquaintance, both for you and for us. See for yourself, you probably recognize that voice. </p>



<figure class="wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="You’re alive!" width="770" height="433" src="https://www.youtube.com/embed/MYlwvTm0qzU?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>
</div><figcaption class="wp-element-caption"><em>You’re alive!</em></figcaption></figure>



<p class="wp-block-paragraph"><a href="https://youtu.be/MYlwvTm0qzU" target="_blank" rel="noreferrer noopener">Watch the video on YouTube</a></p>



<p class="wp-block-paragraph">Aaron Schulz (“Blaze” from Episode 1) made a <strong>heroic return</strong> and was willing to join Ballena Azul LTD, but in the end, we had certain irreconcilable artistic differences: he failed to provide a photo ID “at least for a month, until we were able to pay the first salary.” So, he ended up making a short cameo, but we’re glad to know he’s OK. </p>



<p class="wp-block-paragraph">Still, there’s one curious surprise left. What would you do if your live translation software suddenly acted up in the middle of the daily stand-up? </p>



<h2 class="wp-block-heading"><strong>Bonus Chapter II: Cough Syrup</strong>  </h2>



<p class="wp-block-paragraph">This happened to Jack during one of our daily stand-ups. We noticed him panicking in his corner of the meeting as his turn to speak got closer, and we immediately understood that something was acting up on his side, most likely his live translation tool. </p>



<p class="wp-block-paragraph">So, he handled the situation like a man. </p>



<figure class="wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="Cough syrup" width="770" height="433" src="https://www.youtube.com/embed/hjpQBRR7lQ4?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>
</div><figcaption class="wp-element-caption"><em>Cough syrup</em></figcaption></figure>



<p class="wp-block-paragraph"><a href="https://youtu.be/hjpQBRR7lQ4" target="_blank" rel="noreferrer noopener">Watch the video on YouTube</a></p>



<p class="wp-block-paragraph">He was ready to fake passing out if he had to, so we just let him get away with it this time. </p>



<p class="wp-block-paragraph">Now, that was our last surprise, fun fact, or weird tape to show. </p>



<p class="wp-block-paragraph">Before closing this episode, let’s backtrack for a moment and remember that, funny as these guys are, they still pose a threat to our companies and assets. Maybe not willingly, maybe not by choice, but they still do. </p>



<p class="wp-block-paragraph">So, let’s analyze their latest toolset, updating what we’ve seen and what has changed since our last engagement last December. </p>



<h2 class="wp-block-heading"><strong>Famous Chollima New Toolset &amp; Infrastructure</strong>  </h2>



<p class="wp-block-paragraph">This list includes only the<strong> tools we’ve observed</strong> in this new episode, which may vary over time or across different operative clusters. </p>



<ul class="wp-block-list">
<li>AnyDesk, Google Remote Desktop: Remote desktop software. </li>



<li>AstrillVPN: VPN service. </li>



<li>Browser extensions: Saved Prompts for GPT, Simplify Copilot, AIApply, Final Round AI. </li>



<li>ChatGPT: Writing and coding. They rely heavily on it to ask mundane questions about things they don’t understand, even completing assignments instead of asking us. </li>



<li>Google Gemini: Image alteration, especially document forgery. </li>



<li>2fa.cn: Sharing 2FA codes across operatives. We noticed they are no longer using authenticator.cc or otp.ee, as in previous engagements. </li>



<li>Cursor, Visual Studio Code and Remix: Coding. </li>



<li>MetaMask, Bitget Wallet: Cryptocurrency wallets. </li>



<li>ip8.com: Checking their exit IP address. </li>



<li>Outlook.com: Previously, we had only observed them using Gmail during these engagements. </li>



<li>System tools: dxdiag, systeminfo, wmic. </li>



<li>VPS: Vultr, Gorilla Servers.</li>
</ul>



<p class="wp-block-paragraph">This concludes our engagement. Sadly, it’s time to say goodbye! </p>



<h2 class="wp-block-heading"><strong>Until next time, Famous Chollima</strong> </h2>



<p class="wp-block-paragraph">Last time we had to part ways, we closed Episode 1 with this very same title: half bad omen, half veiled threat. Whichever it was, it came true, and we’re reusing it here because we still believe this won’t be our last encounter.</p>



<p class="wp-block-paragraph">And it probably won’t be yours either. At the end of the day, there’s no silver bullet, but the classic playbook still applies: </p>



<p class="wp-block-paragraph">Do your background checks and KYC. If you’re a remote-first company, make them periodic and include in-person verification. </p>



<p class="wp-block-paragraph">Train your recruiters to spot the red flags. They’re the first line of defense protecting your company.</p>



<p class="wp-block-paragraph">Block AstrillVPN immediately, along with every service that refuses to cooperate with takedowns or law enforcement requests. </p>



<p class="wp-block-paragraph">If you spot a Famous Chollima, make them really famous by recording their face and sharing it with the intelligence community. You’ll help spread awareness and might prevent an unsuspecting company from hiring a spy or even facing sanctions. </p>



<p class="wp-block-paragraph">Always doubt. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Always-Doubt-1024x1024.png" alt="Lazarus investigation IT workers" class="wp-image-22569" style="width:644px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Always-Doubt-1024x1024.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Always-Doubt-300x300.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Always-Doubt-150x150.png 150w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Always-Doubt-768x768.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Always-Doubt-70x70.png 70w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Always-Doubt-370x370.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Always-Doubt-270x270.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Always-Doubt-740x740.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-Always-Doubt.png 1254w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Always Doubt</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Trust no one. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-trust-no-one-1024x1024.png" alt="Lazarus investigation IT worker scheme" class="wp-image-22572" style="width:642px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-trust-no-one-1024x1024.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-trust-no-one-300x300.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-trust-no-one-150x150.png 150w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-trust-no-one-768x768.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-trust-no-one-70x70.png 70w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-trust-no-one-370x370.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-trust-no-one-270x270.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-trust-no-one-740x740.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-trust-no-one.png 1254w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Trust No One</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">And don’t forget to smile, you’re on camera! <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f642.png" alt="🙂" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-smile-1024x1024.png" alt="Lazarus investigation IT workers" class="wp-image-22573" style="width:642px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-smile-1024x1024.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-smile-300x300.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-smile-150x150.png 150w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-smile-768x768.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-smile-70x70.png 70w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-smile-370x370.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-smile-270x270.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-smile-740x740.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Lazarus-smile.png 1254w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Smile! You’re on Camera</em></figcaption></figure>
</div>


<h2 class="wp-block-heading"><strong>How ANY.RUN Supports Investigations Like This</strong> </h2>



<p class="wp-block-paragraph">This investigation produced several layers of evidence, from live activity inside the virtual desktops to accounts, wallets, VPN infrastructure, browser data, and network connections linked to the operatives. </p>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> provided the controlled environment needed to capture that activity as it unfolded, preserve the evidence, and examine each action without exposing real corporate systems. </p>



<p class="wp-block-paragraph">For researchers and security teams, this kind of visibility makes it easier to understand how identities, infrastructure, tools, and behavior come together within an operation. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Trusted by 74% of Fortune 100 companies.</span><br>
Scale investigations without adding operational friction.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Strengthen Security Operations</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading"><strong>About ANY.RUN</strong>  </h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a>, a leading provider of interactive malware analysis and threat intelligence solutions, helps SOCs, MSSPs, and enterprise security teams investigate threats faster and make response decisions based on clear behavioral evidence. </p>



<p class="wp-block-paragraph">Its <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> allows teams to analyze malware, phishing pages, suspicious files, and URLs in a controlled environment while observing the full attack chain in real time. <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence</a> built on investigations from more than 15,000 organizations and 600,000 security professionals helps teams enrich alerts, uncover related activity, and bring current threat context into detection, hunting, and response workflows. </p>



<p class="wp-block-paragraph">ANY.RUN is <a href="https://any.run/compliance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=lazarus-group-it-workers-investigation-part-two&amp;utm_term=100826&amp;utm_content=linktocompliance" target="_blank" rel="noreferrer noopener">SOC 2 Type II attested</a>, reflecting its commitment to strong security controls and customer data protection. </p>



<h2 class="wp-block-heading"><strong>IOCs</strong> </h2>



<ul class="wp-block-list">
<li>IPv4: 62[.]33[.]223[.]165 // INVESTSTROY-NET (InvestStroyTrest)</li>



<li>IPv4: 89[.]187[.]185[.]11 // DPRK-operated VPS</li>



<li>IPv4: 45[.]77[.]71[.]42 // DPRK-operated VPS</li>



<li>IPv4: 185[.]152[.]67[.]39 // DPRK-operated VPS</li>



<li>IPv4: 104[.]250[.]148[.]58 // AstrillVPN exit node</li>



<li>IPv4: 192[.]200[.]115[.]226 // AstrillVPN exit node</li>



<li>IPv4: 107[.]150[.]38[.]250 // AstrillVPN exit node</li>



<li>IPv4: 206[.]217[.]134[.]34 // AstrillVPN exit node</li>



<li>IPv4:199[.]168[.]112[.]175 // AstrillVPN exit node</li>



<li>0x8953B9661339a48f4E6408aA1B359CD49F3A6CAd</li>



<li>0xA3D6938f152C47A411263573Bb3AF324C25A8eba</li>



<li>0xB26A7C7EA6D75956EbD8c5D294524903b1cf13D0</li>
</ul>



<h2 class="wp-block-heading"><strong>Further Reading</strong>  </h2>



<ul class="wp-block-list">
<li><a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation/" target="_blank" rel="noreferrer noopener">ANY.RUN Blog: Smile, You’re on Camera! Episode 1</a></li>



<li><a href="https://insomnihack.ch/talks/smile-youre-on-camera-livestreaming-from-north-koreas-it-workers-laptop-farm/" target="_blank" rel="noreferrer noopener">InsomniHack Switzerland: Smile, You’re on Camera!</a></li>
</ul>
<p>The post <a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/">Smile, You&#8217;re on Camera. Part 2: Hiring Lazarus APT&#8217;s IT Workers in a Fake DeFi Startup</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Safeguarding 200M Users: How ChongLuaDao Scales Threat Validation with ANY.RUN</title>
		<link>https://any.run/cybersecurity-blog/chongluadao-success-story/</link>
					<comments>https://any.run/cybersecurity-blog/chongluadao-success-story/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 08:01:49 +0000</pubDate>
				<category><![CDATA[Customer Success Story]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=22449</guid>

					<description><![CDATA[<p>ChongLuaDao protects over 200 million users from cybercrime, having detected more than 1.4 million malicious websites since 2020. Rapid processing of community reports is essential to their operations. In our recent conversation, ChongLuaDao co-founder Hieu Ngo told us how ANY.RUN plays an integral role in the project&#8217;s infrastructure, helping it power thousands of safety checks [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/chongluadao-success-story/">Safeguarding 200M Users: How ChongLuaDao Scales Threat Validation with ANY.RUN</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><a href="https://chongluadao.vn/en" target="_blank" rel="noreferrer noopener"><strong>ChongLuaDao</strong></a> protects over 200 million users from cybercrime, having detected <strong>more than 1.4 million malicious websites</strong> since 2020. Rapid processing of community reports is essential to their operations.  </p>



<p class="wp-block-paragraph">In our recent conversation, ChongLuaDao co-founder <strong>Hieu Ngo told us how </strong><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ChongLuaDao-success-story&amp;utm_term=050826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener"><strong>ANY.RUN</strong></a><strong> plays an integral role</strong> in the project&#8217;s infrastructure, <strong>helping it power thousands of safety checks</strong> to stop cyber threats before they reach potential victims. </p>



<h2 class="wp-block-heading">A Community-Driven Mission: Small Team, Global Impact </h2>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="684" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/695354483_1584128597053587_7444900592870612304_n-1024x684.jpg" alt="" class="wp-image-22459" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/695354483_1584128597053587_7444900592870612304_n-1024x684.jpg 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/695354483_1584128597053587_7444900592870612304_n-300x200.jpg 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/695354483_1584128597053587_7444900592870612304_n-768x513.jpg 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/695354483_1584128597053587_7444900592870612304_n-1536x1025.jpg 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/695354483_1584128597053587_7444900592870612304_n-370x247.jpg 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/695354483_1584128597053587_7444900592870612304_n-270x180.jpg 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/695354483_1584128597053587_7444900592870612304_n-740x494.jpg 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/695354483_1584128597053587_7444900592870612304_n.jpg 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">ChongLuaDao team. Photo: Chongluadao.vn Facebook page</figcaption></figure>



<p class="wp-block-paragraph">Based in <strong>Ho Chi Minh City, Vietnam</strong>, ChongLuaDao is a <strong>non-profit, community-driven cybersecurity initiative</strong> with a singular mission: to make online safety free, practical, and accessible for everyone. </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">&#8220;Our mission is to make online safety free, practical, and accessible by helping people verify suspicious websites, report scams, and block dangerous links before victims are harmed.&#8221;</p>
</blockquote>



<p class="wp-block-paragraph">The organization operates with a lean but highly efficient structure: </p>



<ul class="wp-block-list">
<li><strong>A Small Core Team:</strong> A specialized group of security analysts, engineers, and investigators who manage the project’s strategy and technical infrastructure. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Global Volunteer Power:</strong> A massive community of <strong>more than 200 volunteer moderators and cybersecurity experts</strong> who assist in reviewing and validating user-submitted scam reports. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Enterprise-Scale Ecosystem:</strong> Despite its non-profit status, the project’s impact is massive, <strong>serving over one million daily queries via its threat intelligence API</strong> and maintaining strategic partnerships with global leaders like <strong>APWG and PhishTank</strong>. </li>
</ul>



<p class="wp-block-paragraph">Through this unique blend of human expertise and advanced technology, ChongLuaDao has turned a local initiative into a <strong>critical node of the global threat intelligence network</strong>. </p>



<h2 class="wp-block-heading">The Challenge: Scaling Analysis for the Constantly Changing Scam Infrastructure </h2>



<p class="wp-block-paragraph">For ChongLuaDao, the primary operational bottleneck was <strong>speed</strong>. The landscape of modern cybercrime in Vietnam is dominated by <strong>short-lived infrastructure</strong>: scam domains, phishing pages, and malicious APKs often appear and disappear within hours. Relying on <strong>manual review alone became impossible</strong> as the volume of daily suspicious submissions began to outpace the team’s capacity. </p>



<p class="wp-block-paragraph">This massive influx of data created <a href="https://any.run/cybersecurity-blog/cfo-cyber-risk-playbook/" target="_blank" rel="noreferrer noopener"><strong>heavy pressure on the analyst team</strong></a>. Without the ability to perform fast dynamic analysis, validating a single suspicious file or URL could take too long. These delays had real-world consequences, leading to <a href="https://any.run/cybersecurity-blog/efficient-soc-for-fast-response/" target="_blank" rel="noreferrer noopener"><strong>slower response times in blocking threats</strong></a>, warning potential victims, and sharing intelligence with global partners. </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">&#8220;Scam domains, phishing pages, fake investment sites, malicious APKs, and credential theft pages appear and disappear very quickly, so manual review alone could not keep up with the volume or urgency&#8221;</p>
</blockquote>



<p class="wp-block-paragraph">The challenge was further intensified by the organization’s status as a <strong>non-profit with limited staff, budget, and time</strong>. To protect millions of users effectively, ChongLuaDao needed an <strong>enterprise-grade solution</strong> that could drastically <strong>reduce analyst workload</strong> and provide the high-fidelity evidence required to make confident, life-saving blocking decisions in real time. </p>



<h2 class="wp-block-heading">ANY.RUN Integration: Moving Beyond Static Analysis to Unmask &#8220;Smart&#8221; Phishing in Real Time </h2>



<p class="wp-block-paragraph">ChongLuaDao integrated ANY.RUN to overcome the technical limitations of static analysis when facing sophisticated, evasive threats. The team selected the solution based on its ability to provide <strong>real-time interaction within secure cloud-based VMs</strong>, a capability essential for analyzing modern scam infrastructure. </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">&#8220;From a leadership perspective, <strong>ANY.RUN helps ChongLuaDao scale our mission</strong>.&#8221;</p>
</blockquote>



<p class="wp-block-paragraph"><a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ChongLuaDao-success-story&amp;utm_term=050826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">ANY.RUN’s Interactive Sandbox</a> delivered instant value to ChongLuaDao, offering several operational advantages: </p>



<ul class="wp-block-list">
<li><strong>Detection of Evasive and Multi-Stage Threats:</strong> Many phishing campaigns are multi-stage and depend on specific user interactions like clicking. ANY.RUN’s interactive nature allows analysts to <strong>simulate user behavior</strong>, exposing malicious flows that remain dormant and undetected in passive sandboxes. </li>
</ul>



<ul class="wp-block-list">
<li><strong>High-Fidelity Verdicts and Reduced False Alarms:</strong> By providing full visibility into the <strong>entire behavior chain</strong> rather than relying on static indicators, the sandbox improves analyst confidence. This clarity is critical for distinguishing sophisticated phishing kits from legitimate but abused infrastructure, ensuring that blocking decisions are accurate. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Operational Efficiency for Resource-Constrained Teams:</strong> As a non-profit managing 200 million protected users with a lean staff, ChongLuaDao requires solutions that reduce manual workload. ANY.RUN acts as a force multiplier, transforming what used to be <strong>hours of manual forensic checking into minutes of interactive validation</strong>. </li>
</ul>



<p class="wp-block-paragraph">By prioritizing <strong>interactive visibility</strong>, ChongLuaDao has moved from simply flagging suspicious links to confirming and neutralizing complex threats in a single workflow. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Close visibility gaps that delay investigations and increase exposure.</span><br>
Give your SOC the evidence to act faster.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=ChongLuaDao-success-story&#038;utm_term=050826&#038;utm_content=linktoenterpriseform/#contact-sales" rel="noopener" target="_blank">
Reduce Security Exposure</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Triaging Threats in Minutes Instead of Hours </h2>



<p class="wp-block-paragraph">By integrating ANY.RUN, the organization successfully transitioned from time-intensive manual forensics to a streamlined interactive triage process.</p>



<p class="wp-block-paragraph">The efficiency allows a lean core team to handle enterprise-level volumes of data, <strong>accelerating the time-to-block</strong> for confirmed threats and significantly increasing daily analyst throughput. </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">&#8220;For complex cases, ANY.RUN helped reduce analysis from hours of manual checking to minutes of interactive validation.&#8221;</p>
</blockquote>



<h2 class="wp-block-heading">Exposing Multi-Stage Scams Through Real-Time Human-in-the-Loop Interaction </h2>



<p class="wp-block-paragraph">Sophisticated cybercrime campaigns in Vietnam, such as &#8220;Không Một Mình,&#8221; often utilize geo-fencing or multi-stage execution that remains dormant in passive sandboxes. These threats require specific user actions to trigger their malicious payloads.  </p>



<p class="wp-block-paragraph">Using ANY.RUN’s <strong>interactive environment, analysts can click </strong><a href="https://any.run/cybersecurity-blog/enterprise-phishing-resilience/" target="_blank" rel="noreferrer noopener"><strong>through phishing flows</strong></a><strong>, scroll, and enter data in real time</strong> to observe the threat&#8217;s actual behavior. This &#8220;human-in-the-loop&#8221; capability allows the team to <a href="https://any.run/cybersecurity-blog/in-browser-data-inspection/" target="_blank" rel="noreferrer noopener"><strong>unmask malicious flows that automated systems miss</strong></a>, ensuring that complex, interaction-dependent scams are identified and neutralized before they reach victims. </p>



<!-- Highlight Block HTML START -->
<div class="window">
  <div class="window-header">
    <div class="pill"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f680.png" alt="🚀" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Key ChongLuaDao Metrics Improved with ANY.RUN</div>
  </div>
  <div class="window-body">
<ul>
  <li><strong>Time-to-Verdict:</strong> For complex cases, the analysis window was compressed from hours of manual forensic checking to just minutes of interactive validation.</li>
  <li><strong>Time-to-Block:</strong> The speed of neutralizing threats increased due to the immediate extraction of network indicators, domains, and IPs directly from the sandbox.</li>
  <li><strong>Daily Analyst Throughput:</strong> The number of reports analysts and volunteer moderators can process per day has significantly increased, allowing the team to keep pace with the high volume of user submissions.</li>
</ul>
  </div>
</div>
<!-- Highlight Block HTML END -->


<!-- Highlight Block CSS START -->
<style>
  .window {
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);

    border-radius: 4px;
    margin: 20px auto 50px auto;
    padding: 20px 40px;
    line-height: 2rem;
  }

  .window-header {
    display: flex;
    justify-content: center;
    margin-bottom: 20px;
  }

  .pill {
    background-color: #fff;
    border-radius: 20px;
    color: #333;
    font-weight: bold;
    padding: 8px 32px;
border: 1px solid rgba(75, 174, 227, 0.32);
  }

  @media (max-width: 480px) {
    .window {
      padding: 10px;
    }
    
    .pill {
      font-size: 14px;
      padding: 6px 12px;
    }
  }
</style>
<!-- Highlight Block CSS END -->



<h2 class="wp-block-heading">Reaching Confident Verdicts with Full Visibility into Malicious Behavior </h2>



<p class="wp-block-paragraph">Maintaining a blocklist for 200 million users requires accurate decisions to avoid disrupting legitimate services. ANY.RUN helps ChongLuaDao achieve this by providing <strong>complete visibility into the behavioral chain</strong>, including process trees, network activity, and file system changes.  </p>



<p class="wp-block-paragraph">The forensic depth allows analysts to <strong>definitively </strong><a href="https://any.run/cybersecurity-blog/kali365-phishing-targeting-us/" target="_blank" rel="noreferrer noopener"><strong>distinguish phishing kits</strong></a><strong> from false alarms or legitimate but abused infrastructure</strong>. </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">&#8220;ANY.RUN improves confidence because <strong>analysts can see the full behavior chain</strong> instead of relying only on static indicators.&#8221;</p>
</blockquote>



<p class="wp-block-paragraph">By moving from static indicators to observed behavioral proof, ChongLuaDao has <strong>increased the reliability of its intelligence and reduced the risk of false positives</strong>. </p>



<h2 class="wp-block-heading">Providing Actionable Intelligence for Law Enforcement and Global Takedown Partners </h2>



<p class="wp-block-paragraph">ChongLuaDao serves as a critical intelligence node for partners like <strong>INTERPOL, UNODC, and global hosting providers</strong>. ANY.RUN facilitates this cooperation by generating <strong>forensic-grade reports that include process graphs, screenshots, and detailed network logs</strong>.  </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">&#8220;ANY.RUN makes our reports more actionable because <strong>partners can see not only a suspicious link, but also the observed malicious behavior behind it</strong>.&#8221;</p>
</blockquote>



<p class="wp-block-paragraph">Complete intelligence packages make the organization&#8217;s findings <strong>immediately actionable for partners</strong>, as they provide visual and technical proof of malicious intent rather than just a suspicious URL. The evidence-based approach <strong>directly accelerates the takedown of malicious infrastructure</strong> and strengthens global efforts to dismantle cybercrime networks. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Reduce delays between threat confirmation and containment.  </span><br>
Give responders the evidence to act faster. 
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=ChongLuaDao-success-story&#038;utm_term=050826&#038;utm_content=linktoenterpriseform#contact-sales" rel="noopener" target="_blank">
Accelerate Incident Response</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Conclusion </h2>



<p class="wp-block-paragraph">The <strong>ChongLuaDao</strong> case demonstrates how a <strong>lean, community-driven non-profit</strong> can successfully defend <strong>200 million users</strong> by augmenting human expertise with professional-grade interactive analysis. By integrating <strong>ANY.RUN</strong>, the organization has effectively addressed the challenge of <strong>scam infrastructure</strong>, transforming what was once a manual bottleneck into a high-speed, <strong>evidence-based validation workflow</strong>. </p>



<p class="wp-block-paragraph">We would like to thank the <strong>ChongLuaDao leadership and their community of 200+ volunteer experts</strong> for allowing us an inside look at their security operations. Their commitment to making online safety free and accessible is an inspiration, and we are proud to support their mission to build a <strong>safer digital environment for millions of users</strong> globally. </p>



<h2 class="wp-block-heading">About ANY.RUN </h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ChongLuaDao-success-story&amp;utm_term=050826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener"><strong>ANY.RUN</strong></a>, a leading provider of interactive malware analysis and threat intelligence solutions, helps SOC teams, <a href="https://any.run/mssp/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ChongLuaDao-success-story&amp;utm_term=050826&amp;utm_content=linktomssplanding" target="_blank" rel="noreferrer noopener">MSSPs</a>, and enterprises investigate threats faster and make more confident security decisions. </p>



<p class="wp-block-paragraph">With its <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ChongLuaDao-success-story&amp;utm_term=050826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener"><strong>cloud-based Interactive Sandbox</strong></a>, security teams can safely analyze suspicious files, links, and emails in real time, observe malicious behavior, and receive <strong>clear evidence for response</strong> without maintaining complex in-house infrastructure. </p>



<p class="wp-block-paragraph"><a href="https://intelligence.any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ChongLuaDao-success-story&amp;utm_term=050826&amp;utm_content=linktotiservice" target="_blank" rel="noreferrer noopener">ANY.RUN’s Threat Intelligence solutions</a> also help organizations uncover threat context, enrich security workflows, and improve visibility into emerging risks. Together, these capabilities support <strong>faster triage, stronger incident prevention, and more efficient security operations at scale</strong>. </p>



<p class="wp-block-paragraph"><a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ChongLuaDao-success-story&amp;utm_term=050826&amp;utm_content=linktoenterpriseform#contact-sales" target="_blank" rel="noreferrer noopener"><strong>Scale your SOC with faster threat validation →</strong></a><strong></strong> </p>
<p>The post <a href="https://any.run/cybersecurity-blog/chongluadao-success-story/">Safeguarding 200M Users: How ChongLuaDao Scales Threat Validation with ANY.RUN</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/chongluadao-success-story/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Major Cyber Attacks in July 2026: US and EU Organizations Hit by Phishing, RATs, and Stealers</title>
		<link>https://any.run/cybersecurity-blog/major-cyber-attacks-july-2026/</link>
					<comments>https://any.run/cybersecurity-blog/major-cyber-attacks-july-2026/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Tue, 04 Aug 2026 08:30:51 +0000</pubDate>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[malware analysis]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=22417</guid>

					<description><![CDATA[<p>July 2026 showed how trusted business workflows can quickly turn into account takeover, data exposure, fraud, and persistent access. ANY.RUN observed attacks that put cloud accounts, financial processes, sensitive data, and business continuity at risk across the US, Europe, and Brazil. Here are the major attacks from July, the business risks they exposed, and the [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/major-cyber-attacks-july-2026/">Major Cyber Attacks in July 2026: US and EU Organizations Hit by Phishing, RATs, and Stealers</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">July 2026 showed how trusted business workflows can quickly turn into account takeover, data exposure, fraud, and persistent access. <a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-july-2026&amp;utm_term=040826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> observed attacks that put cloud accounts, financial processes, sensitive data, and business continuity at risk across the US, Europe, and Brazil. </p>



<p class="wp-block-paragraph">Here are the major attacks from July, the business risks they exposed, and the actions security leaders should prioritize to contain them faster. </p>



<h2 class="wp-block-heading">What July’s Attacks Revealed About Enterprise Risk </h2>



<p class="wp-block-paragraph">July’s attacks showed how easily routine business activity can become a path to account compromise, data exposure, fraud, and operational disruption. Attackers used trusted platforms, legitimate authentication flows, familiar documents, and built-in system tools to reduce suspicion and delay the moment when security teams could confirm the true scale of an incident. </p>



<p class="wp-block-paragraph"><strong>Trusted business services created false confidence:</strong> SharePoint, OneDrive, Zoom Events, Microsoft authentication pages, and compromised government systems appeared in attack chains. Their presence made malicious activity look more credible and increased the chance that employees or security controls would allow it to continue. </p>



<p class="wp-block-paragraph"><strong>Identity attacks threatened core business workflows:</strong> Kratos and Kali365 put Microsoft 365 accounts, corporate email, shared files, supplier communication, and payment conversations at risk. In cases involving active sessions, refresh tokens, or OAuth access, changing a password alone might not fully remove the attacker. </p>



<p class="wp-block-paragraph"><strong>A single endpoint could expose access across the business:</strong> DestinyStealer, Banana RAT, DARTHVADER Stealer, and OVERLORD RAT collected or targeted browser credentials, cookies, Outlook data, VPN access, file-transfer accounts, cryptocurrency wallets, and other sensitive information. One infected device could therefore create exposure across several systems and require a much broader response than endpoint cleanup alone. </p>



<p class="wp-block-paragraph"><strong>Legitimate tools made malicious activity harder to separate from normal operations:</strong> PowerShell, AutoIt, Windows utilities, trusted applications, and cloud services helped attackers hide inside familiar system activity. This increased the risk of delayed containment, unnecessary escalations, and longer investigations. </p>



<p class="wp-block-paragraph"><strong>Changing infrastructure weakened indicator-only defenses:</strong> Several campaigns rotated domains, command-and-control servers, or delivery paths. Blocking one URL or IP address could stop only a small part of the operation, while related activity continued elsewhere. </p>



<p class="wp-block-paragraph"><strong>Incomplete context increased response costs:</strong> A clean initial verdict, a legitimate first-stage URL, or one isolated alert did not always reveal the full compromise. Without a clear view of affected accounts, stolen data, persistence, and follow-on activity, leaders could underestimate business exposure or approve containment actions that were either too narrow or unnecessarily disruptive. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Strengthen your entire SOC to close blind spots.
 </span><br>Integrate ANY.RUN for faster MTTR and MTTD.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=major-cyber-attacks-july-2026&#038;utm_term=040826&#038;utm_content=linktoenterprise#contact-sales" target="_blank" rel="noopener">
Stengthen SOC response 
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Who Attackers Targeted in July </h2>



<p class="wp-block-paragraph">July’s campaigns reached organizations across the United States, Europe, and Brazil, with activity affecting both private and public-sector environments. </p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-353"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="2"
           data-rows="9"
           data-wpID="353"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Target Group                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Campaigns and Observed Focus                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Microsoft 365 users                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Kratos and Kali365 targeted cloud accounts across the US and Europe.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        US enterprises                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Kali365 activity appeared across manufacturing, technology, healthcare, government, consulting, and MSSPs.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        European organizations                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Kratos affected SMBs, law firms, schools, polytechnic institutions, and industrial organizations, with a strong concentration in Spain and Southern Europe.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Banking organizations in Brazil                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Banana RAT was associated with banking sessions and Pix-related fraud, while PhantomEnigma targeted the financial sector.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Brazilian public-sector organizations                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        PhantomEnigma used police and legal themes and compromised government infrastructure during delivery.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Employees handling business documents                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Invoice, DocuSign, document-sharing, and fake PDF lures targeted users accustomed to opening external files.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Staff engaging with partners and events                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Fake Meta, OpenAI, and Anthropic summits targeted users through Zoom-themed event invitations.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Users with stored account data                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        DestinyStealer focused on credentials and information held in browsers, Outlook, VPN clients, FileZilla, Wi-Fi profiles, and wallet extensions.                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-353'>
table#wpdtSimpleTable-353{ table-layout: fixed !important; }
table#wpdtSimpleTable-353 td, table.wpdtSimpleTable353 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">The targeting was broad, but not random. Attackers focused on users and sectors with access to cloud accounts, financial activity, sensitive records, and trusted external communications.  </p>



<h2 class="wp-block-heading">1. Kratos Put Microsoft 365 Accounts and Business Workflows at Risk Across the US and Europe </h2>



<p class="wp-block-paragraph">In July, ANY.RUN researchers documented Kratos, a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the United States, Europe, and other regions. The campaign used document-sharing, DocuSign, and invoice lures, often routing victims through trusted services such as SharePoint, OneDrive, Microsoft Forms, Canva, and Tilda before displaying a fake Microsoft login page. </p>



<p class="wp-block-paragraph"><a href="https://any.run/cybersecurity-blog/kratos-phaas-account-takeover/" target="_blank" rel="noreferrer noopener"><strong>Check detailed breakdown</strong></a> </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="709" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-Phishing-Attacks-US-and-EU-Companies-1024x709.png" alt="Kratos analysis" class="wp-image-22336" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-Phishing-Attacks-US-and-EU-Companies-1024x709.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-Phishing-Attacks-US-and-EU-Companies-300x208.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-Phishing-Attacks-US-and-EU-Companies-768x532.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-Phishing-Attacks-US-and-EU-Companies-1536x1064.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-Phishing-Attacks-US-and-EU-Companies-370x256.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-Phishing-Attacks-US-and-EU-Companies-270x187.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-Phishing-Attacks-US-and-EU-Companies-435x300.png 435w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-Phishing-Attacks-US-and-EU-Companies-740x512.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-Phishing-Attacks-US-and-EU-Companies.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Attack chain of Kratos phishing campaign</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">For organizations, the risk extended beyond a stolen password. Compromised accounts could expose corporate email, cloud files, supplier communication, and payment workflows, supporting business email compromise, payment redirection, data exposure, and fraudulent requests from trusted accounts. Some sessions also established WebSocket connections, which may indicate possible adversary-in-the-middle activity or live credential relaying, although this alone does not confirm session theft. </p>



<p class="wp-block-paragraph"><strong>Account takeover risk to address:</strong> A password reset may not fully contain the incident if attackers have already gained access to an active Microsoft 365 session. Organizations should review sign-in activity, revoke active sessions and refresh tokens when needed, and determine whether the account was used to access sensitive files, financial conversations, or external partner communications. Teams should also trace the full redirect chain rather than broadly blocking trusted services that may have served only as an intermediate step. </p>



<h2 class="wp-block-heading">2. PhantomEnigma Abused Trusted Government Systems to Reach Banks and Public-Sector Targets </h2>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/PhantomEnigma/" target="_blank" rel="noreferrer noopener">PhantomEnigma</a> targeted banking and public-sector organizations in Brazil through fake Polícia Civil and digital power-of-attorney communications. At least 20 compromised .gov.br municipal and police portals were used to distribute malware, while compromised government mailboxes allowed some phishing emails to pass SPF, DKIM, and DMARC checks. These government systems were part of the delivery chain and were not confirmed as the campaign’s intended targets. </p>



<p class="wp-block-paragraph"><a href="https://any.run/cybersecurity-blog/phantomenigma-research/" target="_blank" rel="noreferrer noopener"><strong>Check detailed breakdown</strong></a> </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="576" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/timeline-1024x576.png" alt="Phantomenigma timeline" class="wp-image-22132" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/timeline-1024x576.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/timeline-300x169.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/timeline-768x432.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/timeline-1536x864.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/timeline-2048x1152.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/timeline-370x208.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/timeline-270x152.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/timeline-740x416.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Timeline of PhantomEnigma’s malicious activity</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">Once installed, the modular backdoor could collect system information, establish persistence, execute commands, and deliver additional payloads such as stealers, loaders, or remote management tools. Rotating command-and-control infrastructure and initial clean verdicts could also cause connected alerts to be investigated separately, delaying containment and increasing the risk of fraud, data exposure, operational disruption, and higher recovery costs. </p>



<p class="wp-block-paragraph"><strong>Investigation gap to close:</strong> A single domain, file, or clean initial verdict may reveal only one part of the campaign. Teams need enough context to connect the phishing message, compromised government infrastructure, malware behavior, command-and-control activity, and any additional payloads delivered afterward. This broader view helps security leaders understand whether they are dealing with one isolated alert or a coordinated operation affecting multiple users or systems, so containment can begin before the business impact grows. </p>



<h2 class="wp-block-heading">3. Kali365 Turned Legitimate Microsoft Sign-Ins into Cloud Access Risk for US Organizations </h2>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/kali365/" target="_blank" rel="noreferrer noopener">Kali365</a> targeted U.S. organizations with device code phishing that abused Microsoft’s legitimate authentication process. Instead of collecting passwords through a fake login page, the kit directed victims to Microsoft’s real device login page and persuaded them to enter an attacker-controlled code. More than 80 related public sandbox sessions were recorded each week, with activity observed across MSSPs, manufacturing, technology, government, healthcare, and consulting. </p>



<p class="wp-block-paragraph"><a href="https://any.run/cybersecurity-blog/kali365-phishing-targeting-us/" target="_blank" rel="noreferrer noopener"><strong>Check detailed breakdown</strong></a> </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="490" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kali-industries-1024x490.webp" alt="Kali industries it targets" class="wp-image-22418" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kali-industries-1024x490.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kali-industries-300x143.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kali-industries-768x367.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kali-industries-1536x734.webp 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kali-industries-370x177.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kali-industries-270x129.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kali-industries-740x354.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kali-industries.webp 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>US industries being targeted by Kali 365</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">Successful authentication could give attackers OAuth access and refresh tokens, potentially providing continued access to corporate email, documents, and cloud resources without directly stealing the victim’s password. Because the login took place on a legitimate Microsoft page, the activity could appear routine, delaying detection while attackers accessed sensitive data, altered business communications, or used trusted accounts for fraud. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Reduce the cost of delayed threat confirmation.
 </span><br>Give your SOC the evidence to contain attacks before exposure spreads.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=major-cyber-attacks-july-2026&#038;utm_term=040826&#038;utm_content=linktoenterprise#contact-sales" target="_blank" rel="noopener">
Cut Response Time
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph"><strong>Access control to strengthen:</strong> Device code authentication should be limited to users and workflows that genuinely require it. Organizations should also investigate unexpected authorization requests and unusual access to Microsoft 365 services. Because Kali365 sends victims through a legitimate Microsoft login page, ANY.RUN helps reveal the original lure, redirects, and device-code flow that may otherwise look safe.</p>



<h2 class="wp-block-heading">4. Banana RAT Increased Fraud Risk by Evolving Its Remote Access Capabilities </h2>



<p class="wp-block-paragraph">Banana RAT is a banking-focused remote access trojan associated with Brazilian financial activity, including banking sessions and Pix-related fraud. Research published in July compared two branches tied to the same staging infrastructure. The older branch used fixed Microsoft-style filenames and installation paths, while the newer version introduced randomized identifiers, stronger persistence, and encrypted WebSocket communication through host-specific subdomains. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="589" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/bananarat_lookup-1024x589.webp" alt="Banana RAT" class="wp-image-22419" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/bananarat_lookup-1024x589.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/bananarat_lookup-300x173.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/bananarat_lookup-768x442.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/bananarat_lookup-1536x883.webp 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/bananarat_lookup-370x213.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/bananarat_lookup-270x155.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/bananarat_lookup-740x426.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/bananarat_lookup.webp 1826w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Lookup quickly links an isolated hash to the full BananaRAT sample complete with a sandbox session</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The newer branch could monitor screens and sessions, capture keyboard input, transfer files, control the infected system remotely, and maintain access through scheduled tasks or registry-based persistence. For banks and businesses handling payments, an infected endpoint could expose credentials, enable fraudulent transactions, and give attackers continued access even after the original malicious file is removed. </p>



<p class="wp-block-paragraph"><strong>Evolving threat to track:</strong> Blocking one filename, path, or server may not stop Banana RAT as operators continue changing how the malware installs itself and communicates. Teams need behavioral context that connects hidden PowerShell activity, persistence, remote-control capabilities, and network communication across different variants. ANY.RUN helps compare related samples and reveal the stable behavior behind changing artifacts, allowing security teams to update detection and containment before a new branch affects more systems or financial workflows. </p>



<h2 class="wp-block-heading">5. A Fake PDF Shortcut Turned One Click into Credential Theft and Persistent Access </h2>



<p class="wp-block-paragraph">A malicious LNK file disguised as a PDF launched a multi-stage infection chain using cmd.exe, legitimate Windows utilities, AutoIt, and PowerShell before deploying DARTHVADER Stealer. The attack also establishedpersistence, allowing the compromise to continue beyond the initial click. </p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/posts/any-run_anyrun-explorewithanyrun-activity-7488581811447668736-AsbM/" target="_blank" rel="noreferrer noopener"><strong>Check technical details on Linkedin</strong></a> </p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="848" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/sandbox-analysis-details-848x1024.jpeg" alt="ANY.RUN’s sandbox revealing all the hidden processes " class="wp-image-22420" style="aspect-ratio:0.8281343869864596;width:464px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/sandbox-analysis-details-848x1024.jpeg 848w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/sandbox-analysis-details-248x300.jpeg 248w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/sandbox-analysis-details-768x928.jpeg 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/sandbox-analysis-details-370x447.jpeg 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/sandbox-analysis-details-270x326.jpeg 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/sandbox-analysis-details-740x894.jpeg 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/sandbox-analysis-details.jpeg 995w" sizes="auto, (max-width: 848px) 100vw, 848px" /><figcaption class="wp-element-caption"><em>ANY.RUN’s sandbox revealing all the hidden processes</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">The chain used hidden command execution, curl.exe downloads, PowerShell ExecutionPolicy Bypass, mutex creation, and persistence setup. The use of legitimate system tools and reduced command output created fewer obvious artifacts, making the activity harder to trace and potentially delaying containment while the stealer remained active. </p>



<p class="wp-block-paragraph"><strong>Post-click risk to reduce:</strong> Security controls should not stop at checking whether a file looks like a PDF or whether a trusted Windows utility was used. Teams need visibility into what happens after the shortcut is opened, including hidden commands, downloaded components, PowerShell activity, AutoIt execution, and persistence. ANY.RUN helps expose this sequence in one analysis, giving teams the evidence needed to identify the stealer and contain affected systems before stolen data or persistent access creates wider business impact. </p>



<h2 class="wp-block-heading">6. Live Attacker Control Exposed Organizations to Data Theft and Continued Access </h2>



<p class="wp-block-paragraph">While analyzing a PythonRAT infection, ANY.RUN observed the attacker connect to the compromised system, upload another payload, and deploy OVERLORD RAT in real time. The activity, seen targeting Germany and the UK, showed that the initial infection was only the first step in a broader compromise. </p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/posts/any-run_anyrun-overlord-anyrun-activity-7485698702142099457-tRRC/" target="_blank" rel="noreferrer noopener"><strong>Check technical details on Linkedin</strong></a> </p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="678" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/OVERLORD-exposed-1024x678.jpeg" alt=" OVERLORD is delivered via live C2 channel " class="wp-image-22422" style="aspect-ratio:1.5103358783233243;width:554px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/OVERLORD-exposed-1024x678.jpeg 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/OVERLORD-exposed-300x199.jpeg 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/OVERLORD-exposed-768x508.jpeg 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/OVERLORD-exposed-370x245.jpeg 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/OVERLORD-exposed-270x179.jpeg 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/OVERLORD-exposed-740x490.jpeg 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/OVERLORD-exposed.jpeg 1280w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>ANY.RUN reveals how OVERLORD is delivered via live C2 channel</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">OVERLORD gave the attacker extensive control over the system, including access to files, browser data, messages, cryptocurrency wallets, keyboard input, and audio. During 45 minutes of analysis, the agent transmitted approximately 86 MB of data, highlighting how quickly one infected endpoint can turn into a serious data exposure and remote-access incident. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Stop initial infections from becoming active compromise.
 </span><br>Contain threats before sensitive data is exposed. 
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=major-cyber-attacks-july-2026&#038;utm_term=040826&#038;utm_content=linktoenterprise#contact-sales" target="_blank" rel="noopener">
Contain Threats Earlier 
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph"><strong>Business exposure to confirm:</strong> An initial malware alert may not show whether an attacker is already active inside the environment. Interactive analysis in ANY.RUN revealed the operator’s actions and the additional payload as they appeared, helping teams understand the true scope of the compromise and move faster to isolate the system, protect exposed accounts, and prevent further access. </p>



<h2 class="wp-block-heading">7. Fake Zoom Events Put Trusted Partner Communications at Risk </h2>



<p class="wp-block-paragraph">A multi-flow phishing campaign used legitimate Zoom event pages to promote fake virtual summits linked to Meta, OpenAI, and Anthropic. The invitations appeared to offer access to events such as the Meta Agency Summit 2026, OpenAI Partner Summit 2026, and Anthropic AI Marketing Summit 2026. After users selected “Continue to register,” they were redirected from events.zoom.us to attacker-controlled domains. </p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/posts/any-run_anyrun-explorewithanyrun-activity-7483136027788906496-1goQ/" target="_blank" rel="noreferrer noopener"><strong>Check technical details on Linkedin</strong></a> </p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="768" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Zoom-events-abused-1-768x1024.jpeg" alt="Meta, OpenAI and Anthropic lures " class="wp-image-22424" style="width:502px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Zoom-events-abused-1-768x1024.jpeg 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Zoom-events-abused-1-225x300.jpeg 225w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Zoom-events-abused-1-1152x1536.jpeg 1152w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Zoom-events-abused-1-370x493.jpeg 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Zoom-events-abused-1-270x360.jpeg 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Zoom-events-abused-1-740x986.jpeg 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Zoom-events-abused-1.jpeg 1280w" sizes="auto, (max-width: 768px) 100vw, 768px" /><figcaption class="wp-element-caption"><em>Meta, OpenAI and Anthropic lures used in a multi-flow phishing campaign</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">The campaign then followed different paths. Some samples used Microsoft device code phishing, while others used an adversary-in-the-middle flow impersonating Microsoft authentication. By starting on a trusted event platform and using familiar technology brands, the attackers reduced suspicion and made the early stages of the campaign less likely to stand out during triage. </p>



<p class="wp-block-paragraph"><strong>Trusted redirect risk to reduce:</strong> Security teams should treat event invitations as complete journeys rather than judging only the first page or final destination. Redirects from legitimate SaaS platforms into unexpected authentication flows should be reviewed together, especially when an event registration suddenly asks users to authorize Microsoft access. ANY.RUN helps reproduce these transitions safely and reveal where a credible invitation turns into credential or session compromise. </p>



<h2 class="wp-block-heading">8. DestinyStealer Put Credentials and Corporate Access Data at Risk Across the US and Europe </h2>



<p class="wp-block-paragraph">DestinyStealer activity increased across Europe and the United States, with the malware operating as an all-in-one data grabber. It collected browser data, cookies, passwords, cryptocurrency wallet extension storage, Outlook and VPN data, FileZilla credentials, Wi-Fi profiles, and desktop screenshots. Its code also showed clear continuity with StormKitty. </p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/posts/destinystealer-anyrun-share-7480976690031149056-jlJD/" target="_blank" rel="noreferrer noopener"><strong>Check technical details on Linkedin</strong></a> </p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="768" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DestinyStealer-execution-768x1024.jpeg" alt="DestinyStealer targets US and EU " class="wp-image-22425" style="width:540px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DestinyStealer-execution-768x1024.jpeg 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DestinyStealer-execution-225x300.jpeg 225w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DestinyStealer-execution-1152x1536.jpeg 1152w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DestinyStealer-execution-370x493.jpeg 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DestinyStealer-execution-270x360.jpeg 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DestinyStealer-execution-740x986.jpeg 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/DestinyStealer-execution.jpeg 1280w" sizes="auto, (max-width: 768px) 100vw, 768px" /><figcaption class="wp-element-caption"><em>How DestinyStealer targets organizations across US and EU</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">Some samples were still undetected on VirusTotal at the time of analysis, while others lacked clear attribution. After checking the victim’s public IP address, the malware collected the stolen information in a temporary directory, packaged it into a ZIP archive, and exfiltrated it through two parallel channels: HTTP and raw TCP. This combination could allow valuable credentials and access data to leave the system before conventional detections provide teams with a clear verdict. </p>



<p class="wp-block-paragraph"><strong>Exposure scope to determine:</strong> A DestinyStealer infection should not be treated as a problem limited to one endpoint. Teams need to establish which browsers, email accounts, VPN access, file-transfer credentials, cookies, and cryptocurrency wallets were exposed. <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-july-2026&amp;utm_term=040826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Behavior-based analysis</a> in ANY.RUN reveals what the malware collected and where it attempted to send the data, helping security teams identify affected accounts and contain the wider access risk. </p>



<h2 class="wp-block-heading">Turn July’s Attack Evidence into Stronger SOC Defense </h2>



<p class="wp-block-paragraph">July’s campaigns changed domains, abused trusted services, hid behind legitimate activity, and expanded after the first alert. Reducing exposure requires more than blocking the indicator found in one incident. SOC teams need fresh intelligence for their controls, behavioral evidence for faster investigations, and campaign context for proactive hunting. </p>



<h3 class="wp-block-heading">1. Keep Security Controls Updated with Fresh Threat Intelligence </h3>



<p class="wp-block-paragraph">Kratos, PhantomEnigma, Banana RAT, and other July threats changed infrastructure, delivery paths, or technical artifacts as their campaigns evolved. A domain or IP address taken from one confirmed incident may quickly lose value, while connected infrastructure remains active elsewhere. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="464" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Threat-Intelligence-Feed-ANY.RUN_-1024x464.png" alt="TI Feeds" class="wp-image-22275" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Threat-Intelligence-Feed-ANY.RUN_-1024x464.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Threat-Intelligence-Feed-ANY.RUN_-300x136.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Threat-Intelligence-Feed-ANY.RUN_-768x348.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Threat-Intelligence-Feed-ANY.RUN_-1536x695.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Threat-Intelligence-Feed-ANY.RUN_-2048x927.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Threat-Intelligence-Feed-ANY.RUN_-370x167.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Threat-Intelligence-Feed-ANY.RUN_-270x122.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Threat-Intelligence-Feed-ANY.RUN_-740x335.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Feeds provides actionable IOCs to your existing stack</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">ANY.RUN’s <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-july-2026&amp;utm_term=040826&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Feeds</a> deliver newly observed malicious IPs, domains, and URLs to SIEM, SOAR, TIP, firewalls, and other security controls through STIX/TAXII, API, and SDK. The intelligence is drawn from sandbox investigations submitted by more than 15,000 organizations and 600,000 security professionals worldwide, giving teams a continuously updated view of threats seen in real environments. </p>



<p class="wp-block-paragraph">Each indicator links back to the sandbox session where it was observed, helping defenders validate it before taking action. This is especially important when attackers use compromised websites, shared cloud infrastructure, or legitimate platforms that should not be blocked without review. </p>



<h3 class="wp-block-heading">2. Give SOC Teams the Evidence to Act Faster </h3>



<p class="wp-block-paragraph">July’s incidents showed how easily an alert can look harmless at first and become much more serious after execution. A trusted URL, familiar sign-in page, or clean initial verdict may reveal little about the access gained, data collected, or attacker activity that follows. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="566" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis-1024x566.webp" alt="sandbox analysis" class="wp-image-22337" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis-1024x566.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis-300x166.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis-768x425.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis-1536x849.webp 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis-370x205.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis-270x149.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis-740x409.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis.webp 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Complex phishing investigation inside ANY.RUN’s sandbox </em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">Behavior-based analysis helps teams see what a file or URL actually does after it is opened. ANY.RUN’s <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-july-2026&amp;utm_term=040826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> reveals redirects, authentication flows, hidden execution, persistence, downloaded payloads, remote-control activity, and data collection in one investigation. This gives Tier 1 the evidence needed to confirm malicious behavior and understand the potential business exposure behind an uncertain verdict. </p>



<p class="wp-block-paragraph">Ready-made reports bring together the verdict, IOCs, TTPs, screenshots, and behavioral evidence in a shareable format. With the attack chain already documented, teams can make faster containment decisions and hand off complex cases without rebuilding the investigation across several sources. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Turn uncertain alerts into confident response decisions. 
 </span><br>Reveal the true scope of threats before impact grows. 
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=major-cyber-attacks-july-2026&#038;utm_term=040826&#038;utm_content=linktoenterprise#contact-sales" target="_blank" rel="noopener">
Accelerate Threat Response  
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h3 class="wp-block-heading">3. Turn Isolated Alerts into Campaign-Level Intelligence </h3>



<p class="wp-block-paragraph">When related activity is investigated case by case, security teams may miss the scale of the threat and repeat the same work across multiple incidents. The result is slower attribution, weaker hunting, and less time to prepare for the next wave of the campaign. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="550" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kali365-sandbox-sessions-1024x550.webp" alt="Kali365 sandbox sessions" class="wp-image-22426" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kali365-sandbox-sessions-1024x550.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kali365-sandbox-sessions-300x161.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kali365-sandbox-sessions-768x413.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kali365-sandbox-sessions-1536x825.webp 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kali365-sandbox-sessions-370x199.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kali365-sandbox-sessions-270x145.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kali365-sandbox-sessions-740x397.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/08/Kali365-sandbox-sessions.webp 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Relevant sandbox sessions displayed inside TI Lookup for full context</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">ANY.RUN’s <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-july-2026&amp;utm_term=040826&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> helps teams connect suspicious files, URLs, infrastructure, behaviors, screenshots, and sandbox sessions across current and historical data. This makes it easier to determine whether an alert is isolated or part of activity already affecting other organizations, sectors, or regions.</p>



<p class="wp-block-paragraph"><a href="https://intelligence.any.run/reports?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-july-2026&amp;utm_term=040826&amp;utm_content=linktotireports" target="_blank" rel="noreferrer noopener">Threat Intelligence Reports</a> add analyst-led research on active malware, phishing operations, APTs, and cybercriminal groups. Each report includes investigation findings and ready-to-use TI Lookup queries that teams can apply to threat hunting, detection reviews, and incident enrichment. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="539" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-1024x539.png" alt="TI reports" class="wp-image-22390" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-1024x539.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-300x158.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-768x404.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-1536x808.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-2048x1078.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-370x195.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-270x142.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-740x389.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>ANY.RUN’s analyst-led research on active malware, phishing operations, APTs, and cybercriminal groups</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Together, TI Lookup and TI Reports help SOC teams move from reacting to one alert at a time to identifying wider campaign activity earlier, uncovering related exposure, and updating defenses before the same threat reaches more users or systems.</p>



<h2 class="wp-block-heading">About ANY.RUN </h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-july-2026&amp;utm_term=040826&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a>, a leading provider of interactive malware analysis and threat intelligence solutions, helps SOCs, MSSPs, and enterprise security teams investigate threats faster and make response decisions based on clear behavioral evidence.</p>



<p class="wp-block-paragraph">Its <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-july-2026&amp;utm_term=040826&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> allows teams to analyze malware, phishing pages, suspicious files, and URLs in a controlled environment while observing the full attack chain in real time. <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-july-2026&amp;utm_term=040826&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence</a> built on investigations from more than 15,000 organizations and 600,000 security professionals help teams enrich alerts, uncover related activity, and bring current threat context into detection, hunting, and response workflows.</p>



<p class="wp-block-paragraph">ANY.RUN is <a href="https://any.run/compliance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-july-2026&amp;utm_term=040826&amp;utm_content=linktocompliance" target="_blank" rel="noreferrer noopener">SOC 2 Type II attested</a>, reflecting its commitment to strong security controls and customer data protection. By combining behavior-based analysis with continuously updated threat intelligence, ANY.RUN helps security teams reduce investigation uncertainty, speed up triage, and contain threats before they create wider business impact.</p>
<p>The post <a href="https://any.run/cybersecurity-blog/major-cyber-attacks-july-2026/">Major Cyber Attacks in July 2026: US and EU Organizations Hit by Phishing, RATs, and Stealers</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/major-cyber-attacks-july-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Threat Coverage Digest: New TI Report, Threat Research and 750+ Detection Rules</title>
		<link>https://any.run/cybersecurity-blog/july-threat-coverage-2026/</link>
					<comments>https://any.run/cybersecurity-blog/july-threat-coverage-2026/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Thu, 30 Jul 2026 06:13:53 +0000</pubDate>
				<category><![CDATA[Service Updates]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[update]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=22386</guid>

					<description><![CDATA[<p>July brought another set of threat coverage updates designed to help security teams work faster and with more confidence. ANY.RUN added 42 behavior signatures, 11 YARA rules, and&#160;703&#160;Suricata rules, giving SOCs broader visibility across files, malware behavior, and network activity.&#160; We also published new threat intelligence and technical research on active malware and phishing campaigns. [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/july-threat-coverage-2026/">Threat Coverage Digest: New TI Report, Threat Research and 750+ Detection Rules</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">July brought another set of threat coverage updates designed to help security teams work faster and with more confidence. <a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> added 42 behavior signatures, 11 YARA rules, and&nbsp;703&nbsp;Suricata rules, giving SOCs broader visibility across files, malware behavior, and network activity.&nbsp;</p>



<p class="wp-block-paragraph">We also published new threat intelligence and technical research on active malware and phishing campaigns. Together, these updates help teams validate alerts sooner, reduce manual investigation work, and make faster response decisions.&nbsp;</p>



<p class="wp-block-paragraph">Here is a closer look at July’s threat coverage and research updates.&nbsp;</p>



<h2 class="wp-block-heading">Threat Intelligence Report&nbsp;</h2>



<p class="wp-block-paragraph">In July, we published a new&nbsp;<a href="https://intelligence.any.run/reports?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktotireports" target="_blank" rel="noreferrer noopener">Threat Intelligence Report</a>&nbsp;covering ORACLESPY, Rokarolla, and ZOHOMURK.&nbsp;</p>



<p class="wp-block-paragraph">Available to&nbsp;<a href="https://intelligence.any.run/plans/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktotiplans" target="_blank" rel="noreferrer noopener">TI Lookup Premium</a>&nbsp;users, the report includes IOCs, detection guidance, MITRE ATT&amp;CK mappings, and TI Lookup queries for exploring related activity and sandbox sessions.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="539" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-1024x539.png" alt="TI Reports on malware and phishing attacks" class="wp-image-22390" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-1024x539.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-300x158.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-768x404.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-1536x808.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-2048x1078.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-370x195.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-270x142.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/TI-Reports-740x389.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Reports on malware and phishing attacks for deeper investigations</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The report covers:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>ORACLESPY:</strong>&nbsp;Windows spyware that collects system and storage information before preparing it for exfiltration.&nbsp;</li>



<li><strong>Rokarolla:</strong>&nbsp;An Android banking trojan targeting more than 200 banking and cryptocurrency applications through fake apps, overlays, and Accessibility Services abuse.&nbsp;</li>



<li><strong>ZOHOMURK:</strong>&nbsp;A Windows backdoor linked to Mustang Panda that uses Zoho WorkDrive for command-and-control communication and data exfiltration.&nbsp;</li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Turn threat intelligence into faster response decisions.
 </span><br>Give your team the context needed to act sooner.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktoenterprise#contact-sales" target="_blank" rel="noopener">
Stengthen SOC response 
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Behavior Signatures&nbsp;</h2>



<p class="wp-block-paragraph">The latest behavior coverage expansion brings 42 new signatures to ANY.RUN’s <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a>. The new detections include:</p>



<div class="wp-block-group is-layout-grid wp-container-core-group-is-layout-9d260ee2 wp-block-group-is-layout-grid">
<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/1cb5a3c8-11a6-4c88-b42d-7412bc084903?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">ModBeacon</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/fc5690dc-cbac-4585-8d7b-8f795620d72b?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">ClickLock</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/cad869fd-375c-46e7-aa44-b96931f5bc2b?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">GrobRAT</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/a0a7f6a9-885e-4dc0-8b06-3e74b91cf50d?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">IronWorm</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/150816e7-c32b-49da-bcd8-114a68d3f99b?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Everest</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/42d3627d-bb9f-4e26-8a13-efe1b7f882df?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">SprySOCKS</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/0ba838e8-f5e1-4c25-b6da-2093737bbe1d?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">SilvaTweaks</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/9100fec2-0d3a-49f5-b64b-20f49d86f6a2?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Blakcsee</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/2db7fd71-3eff-4774-8e46-ced531514863?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">TONResolver</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/0d2c06a1-ab3d-4b1f-b54f-7f3fc09776d8?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Quimarat</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/bc75ecfd-b6ec-4d56-b07a-9698c8b6a726?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Eaglepazer</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/87700faa-f497-4bda-a203-6148d7f5b8ee?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">GoSteal</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/233124f5-214d-433b-b835-5d665a416771?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">ZOHOMURK</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/e67f7a9f-5aa8-4bda-a8aa-e3ca2864154e?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">PAMStealer</a>&nbsp;</li>
</ul>
</div>



<p class="wp-block-paragraph">Malicious activity is highlighted directly in sandbox sessions, allowing SOC teams to validate alerts faster, avoid unnecessary escalations, and move toward response with clearer evidence.</p>



<h2 class="wp-block-heading">YARA Rules&nbsp;</h2>



<p class="wp-block-paragraph">The latest update expands YARA coverage with 11 rules designed to identify malicious patterns in files and processes</p>



<p class="wp-block-paragraph">Together with behavior signatures and network detections, they add another layer of evidence for classifying samples and reaching faster investigation decisions.</p>



<h2 class="wp-block-heading">Suricata Rules&nbsp;</h2>



<p class="wp-block-paragraph">703 new Suricata rules were added to ANY.RUN’s Interactive Sandbox. The new rules cover malicious connections, phishing-related requests, and command-and-control traffic. </p>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/d9de2be2-0b30-437c-9b34-1020971d5344/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Kratos related URL chain observed</a>&nbsp;(sid: 84003881): Detects Kratos PhaaS resources fetch HTTP activity&nbsp;</li>



<li><a href="https://app.any.run/tasks/0dfe9d32-a296-43b9-896e-154f45a6ecb1/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Hiring and Events-themed phishing URL observed</a>&nbsp;(sid: 89004057): Identifies social engineering threats based on hiring &amp; events invitation lures&nbsp;</li>



<li><a href="https://app.any.run/tasks/e44440f8-d975-4c78-ad80-014e8c5e94c4/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">SalatStealer HTTP activity</a>&nbsp;(sid: 84003924): Tracks SalatStealer CnC check-in attempts via HTTP&nbsp;</li>
</ul>



<h2 class="wp-block-heading">Latest Threat Research&nbsp;</h2>



<p class="wp-block-paragraph">ANY.RUN researchers also published four new investigations into active malware and phishing campaigns. The findings provide practical indicators and detection insights that can be used to investigate related activity and strengthen their response. </p>



<ul class="wp-block-list">
<li><a href="https://any.run/cybersecurity-blog/kratos-phaas-account-takeover/" target="_blank" rel="noreferrer noopener">Kratos PhaaS</a>:&nbsp;An investigation into three generations of the Microsoft 365 phishing kit that uncovered 1,484 previously unattributed sandbox sessions and new fingerprints for threat hunting.&nbsp;</li>



<li><a href="https://any.run/cybersecurity-blog/phantomenigma-research/" target="_blank" rel="noreferrer noopener">PhantomEnigma</a><strong>:</strong>&nbsp;Research into an active campaign abusing more than 20 compromised Brazilian government websites to deliver malware to banking and public-sector targets.&nbsp;</li>



<li><a href="https://any.run/cybersecurity-blog/kali365-phishing-targeting-us/" target="_blank" rel="noreferrer noopener">Kali365</a><strong>:</strong>&nbsp;An analysis of a device code phishing kit that abuses legitimate Microsoft authentication to gain access to Microsoft 365 accounts without directly stealing passwords.&nbsp;</li>



<li><a href="https://any.run/cybersecurity-blog/banana-rat-evolution-analysis/" target="_blank" rel="noreferrer noopener">Banana RAT Evolution</a>:&nbsp;A comparison of two malware branches connected to the same infrastructure, revealing changes in persistence, command-and-control communication, and other behavior.&nbsp;</li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Strengthen threat detection across your SOC.
 </span><br>Turn suspicious activity into clear investigation evidence.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=july-threat-coverage-2026&#038;utm_term=300726&#038;utm_content=linktoenterprise#contact-sales" target="_blank" rel="noopener">
Integrate ANY.RUN now
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">About ANY.RUN&nbsp;</h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> is a leading provider of interactive malware analysis and threat intelligence solutions for SOCs, MSSPs, and security teams.&nbsp;</p>



<p class="wp-block-paragraph">The <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> helps teams safely analyze suspicious files, URLs, and phishing attacks while observing real-time behavior across processes, network connections, files, registry activity, and browser interactions. <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=july-threat-coverage-2026&amp;utm_term=300726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence</a> adds further context, helping teams connect findings, investigate related activity, and improve detection coverage.&nbsp;</p>



<p class="wp-block-paragraph">More than 600,000 security professionals across 15,000 organizations use ANY.RUN to validate alerts faster, reduce manual investigation work, and respond to threats with greater confidence.&nbsp;</p>
<p>The post <a href="https://any.run/cybersecurity-blog/july-threat-coverage-2026/">Threat Coverage Digest: New TI Report, Threat Research and 750+ Detection Rules</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/july-threat-coverage-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The US CFO’s Playbook: How to Reduce Cyber Risk Without Scaling SOC Team in a Tight Labor Market</title>
		<link>https://any.run/cybersecurity-blog/cfo-cyber-risk-playbook/</link>
					<comments>https://any.run/cybersecurity-blog/cfo-cyber-risk-playbook/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Wed, 29 Jul 2026 09:36:23 +0000</pubDate>
				<category><![CDATA[Cybersecurity Lifehacks]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=22368</guid>

					<description><![CDATA[<p>Cyber risk is increasing, but so is the cost of managing it. More than 514,000 cybersecurity job listings appeared in the US between May 2024 and April 2025, while the mean annual wage for an information security&#160;analyst reached $132,510.&#160; Even after the budget is approved, hiring can take three to six months, with additional time [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/cfo-cyber-risk-playbook/">The US CFO’s Playbook: How to Reduce Cyber Risk Without Scaling SOC Team in a Tight Labor Market</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Cyber risk is increasing, but so is the cost of managing it. More than 514,000 cybersecurity job listings appeared in the US between May 2024 and April 2025, while the mean annual wage for an information security&nbsp;analyst reached $132,510.&nbsp;</p>



<p class="wp-block-paragraph">Even after the budget is approved, hiring can take three to six months, with additional time needed for onboarding and training. Meanwhile, alert volumes keep growing, senior employees remain tied up in routine investigations, and the financial exposure from a delayed response does not disappear.</p>



<p class="wp-block-paragraph">The&nbsp;real challenge&nbsp;for CFOs is finding a way to strengthen security without turning every increase in workload into another hiring request.&nbsp;</p>



<h2 class="wp-block-heading">The Headcount Trap&nbsp;</h2>



<p class="wp-block-paragraph">When the SOC is overloaded, hiring often&nbsp;looks like the obvious solution. More alerts come in, investigations take longer, and the team asks for&nbsp;additional&nbsp;analysts.&nbsp;</p>



<p class="wp-block-paragraph">But headcount is a costly way to solve an efficiency problem.&nbsp;</p>



<p class="wp-block-paragraph">Each new hire adds salary, benefits, recruitment costs, training, and management overhead. It can also take months before that person is ready to handle investigations independently. During that time, experienced employees are still carrying the workload while also supporting onboarding.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="576" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/The-Headcount-Trap-1024x576.png" alt="The headcount traps most CFOs face in the US" class="wp-image-22370" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/The-Headcount-Trap-1024x576.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/The-Headcount-Trap-300x169.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/The-Headcount-Trap-768x432.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/The-Headcount-Trap-1536x864.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/The-Headcount-Trap-2048x1152.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/The-Headcount-Trap-370x208.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/The-Headcount-Trap-270x152.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/The-Headcount-Trap-740x416.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The headcount traps most CFOs face in the US</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">The result is a cycle many CFOs know well: alert volume grows, the security budget grows with it, but the underlying process stays the same. Routine cases still consume senior time, manual checks still slow investigations, and the next hiring request is never far behind.&nbsp;</p>



<p class="wp-block-paragraph">Adding people may increase capacity for a while. It does not fix the work that makes the SOC expensive in the first place.&nbsp;</p>



<h2 class="wp-block-heading">The Financial Cost of Slow Incident Response&nbsp;</h2>



<p class="wp-block-paragraph">An overloaded SOC creates costs that are easy to overlook&nbsp;in the security budget. Payroll is only the most visible expense. Manual investigations, repeated escalations, delayed containment, and business disruption can all increase the total cost of managing cyber risk.&nbsp;</p>



<p class="wp-block-paragraph">Each alert has a unit cost. A Tier 1&nbsp;analyst reviews it, a more experienced employee may&nbsp;validate&nbsp;it, and a senior specialist may step in when the available evidence is unclear. The company can end up paying several employees to work on the same case, driving up the cost per investigation.&nbsp;</p>



<p class="wp-block-paragraph">CFOs can estimate this direct expense using a simple calculation:&nbsp;</p>



<p class="has-gridlove-highlight-acc-background-color has-background wp-block-paragraph"><strong>Annual investigation cost = Annual case volume × Average handling time × Fully loaded hourly&nbsp;labor&nbsp;cost</strong>&nbsp;</p>



<p class="wp-block-paragraph">The same calculation can be applied to escalations. It shows how much high-cost senior capacity is being used for routine cases that could have been resolved earlier with clearer evidence and faster access to&nbsp;threat&nbsp;context.&nbsp;</p>



<h3 class="wp-block-heading">Manual Work Limits Operating Capacity&nbsp;</h3>



<p class="wp-block-paragraph">SOC teams often spend hours opening files, checking URLs, comparing indicators across separate sources, reproducing suspicious activity, and preparing reports. These tasks are necessary, but they do not always&nbsp;require&nbsp;senior&nbsp;expertise.&nbsp;</p>



<p class="wp-block-paragraph">When they take too long, backlogs grow and expensive specialists have less time for complex incidents,&nbsp;threat&nbsp;hunting, and detection improvement. The company may then need to approve&nbsp;additionalheadcount or contractor spending simply to&nbsp;maintain&nbsp;current service levels.&nbsp;</p>



<p class="wp-block-paragraph">The financial value of faster investigations can be measured as:&nbsp;</p>



<p class="has-gridlove-highlight-acc-background-color has-background wp-block-paragraph"><strong>Annual capacity recovered = Time saved per case × Annual case volume</strong>&nbsp;</p>



<p class="wp-block-paragraph">That capacity may translate into delayed hiring, fewer contractor hours, lower escalation rates, or more cases handled by the existing team. It improves the operating leverage of the SOC by allowing workload to grow without an equal increase in payroll.&nbsp;</p>



<h3 class="wp-block-heading">Delayed Response Increases Loss Exposure&nbsp;</h3>



<p class="wp-block-paragraph">The&nbsp;financial impact&nbsp;rises sharply when a genuine&nbsp;threat&nbsp;remains&nbsp;active while the SOC gathers enough evidence to respond.&nbsp;</p>



<p class="wp-block-paragraph">The average cost of a data breach in the US reached $10.22 million in 2025, according to IBM. That figure can include recovery expenses, operational downtime, legal and regulatory costs, customer notification, and lost business. </p>



<p class="wp-block-paragraph">Not every slow investigation leads to a breach. Still, longer decision times extend the period during which the company carries the risk of a larger financial event.&nbsp;</p>



<p class="wp-block-paragraph">For CFOs, faster investigation supports both cost control and loss prevention. It reduces the unit cost of security operations, protects senior capacity, and helps&nbsp;contain&nbsp;threats before their&nbsp;financial impactgrows.&nbsp;</p>



<h2 class="wp-block-heading">Expand SOC Capacity Without Growing Payroll&nbsp;</h2>



<p class="wp-block-paragraph">Improving SOC economics does not require every investigation to reach a highly paid senior specialist. Junior and mid-level&nbsp;analysts can handle more cases when they receive&nbsp;clear evidence&nbsp;early in the process.&nbsp;</p>



<p class="wp-block-paragraph">For many US SOCs, the more practical model combines automation with full attack-chain visibility. Suspicious files and URLs can be&nbsp;analyzed&nbsp;automatically, while&nbsp;analysts see the processes launched, files created, network connections, redirects, extracted indicators, and detected&nbsp;behaviors&nbsp;within seconds.&nbsp;</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="576" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/The-SOC-Capacity-Model-1024x576.png" alt="The SOC capacity model for CFOs" class="wp-image-22372" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/The-SOC-Capacity-Model-1024x576.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/The-SOC-Capacity-Model-300x169.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/The-SOC-Capacity-Model-768x432.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/The-SOC-Capacity-Model-1536x864.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/The-SOC-Capacity-Model-2048x1152.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/The-SOC-Capacity-Model-370x208.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/The-SOC-Capacity-Model-270x152.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/The-SOC-Capacity-Model-740x416.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The SOC capacity model for CFOs</em></figcaption></figure>



<p class="wp-block-paragraph">This removes much of the time spent rebuilding an investigation across several tools. It also gives less-experienced&nbsp;analysts enough context to understand what happened, decide whether the activity is malicious, and escalate serious cases with the evidence already attached.&nbsp;</p>



<p class="wp-block-paragraph">The staffing impact is significant. Routine alerts stay with junior and mid-level analysts, while senior specialists spend more time on complex incidents, threat hunting, detection engineering, and response planning. New employees can also become productive faster because the investigation process is clearer and less dependent on specialist knowledge.</p>



<p class="wp-block-paragraph">Speed of adoption matters as well. A solution that requires lengthy deployment, custom infrastructure, or months of training delays the return on the investment. Cloud-based&nbsp;solutions&nbsp;with intuitive workflows can begin reducing handling time sooner and help the SOC absorb more work before another hiring cycle becomes necessary.&nbsp;</p>



<p class="wp-block-paragraph">For CFOs, this creates a more efficient workforce mix. The company gets more value from existing payroll, lowers its dependence on scarce senior talent, and increases security capacity without adding the same level of fixed cost.&nbsp;</p>



<h2 class="wp-block-heading">The Efficiency Engine Behind a Lower-Cost, Higher-Capacity SOC&nbsp;</h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=cfo-cyber-risk-playbook&amp;utm_term=290726&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a>&nbsp;brings interactive&nbsp;analysis, automated investigation,&nbsp;threat&nbsp;intelligence, and full attack visibility into one cloud-based workflow. The financial value comes from reducing the work required per case, allowing more investigations to remain with junior and mid-level&nbsp;analysts, and avoiding the infrastructure costs of an internal malware-analysis&nbsp;environment.&nbsp;</p>



<h3 class="wp-block-heading">Reduce the Cost of File and URL Investigations&nbsp;</h3>



<p class="wp-block-paragraph">Investigating a suspicious file, link, email, or phishing page can take hours when analysts must reproduce each stage manually and collect evidence across several tools.</p>



<p class="wp-block-paragraph">ANY.RUN’s&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=cfo-cyber-risk-playbook&amp;utm_term=290726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive&nbsp;Sandbox</a>&nbsp;can expose the&nbsp;full&nbsp;attack flow in approximately two minutes.&nbsp;Analysts see the processes launched, files created, network connections, HTTP requests, redirects, IOCs,&nbsp;behavioral&nbsp;indicators, screenshots, and MITRE ATT&amp;CK techniques in one investigation view.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="566" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis-1024x566.webp" alt="sandbox analysis" class="wp-image-22337" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis-1024x566.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis-300x166.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis-768x425.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis-1536x849.webp 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis-370x205.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis-270x149.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis-740x409.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis.webp 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Complex phishing attack analyzed in ANY.RUN sandbox in just 1 min</em></figcaption></figure>
</div>


<p class="wp-block-paragraph"><a href="https://any.run/cybersecurity-blog/automated-interactivity-stage-two/" target="_blank" rel="noreferrer noopener">Automated Interactivity</a>&nbsp;performs many of the actions an&nbsp;analyst would otherwise complete by hand. It can launch attachments, extract and follow links, click&nbsp;through pages, solve CAPTCHA challenges, and continue&nbsp;through multi-stage attacks. The&nbsp;sandbox&nbsp;mimics the actions&nbsp;required&nbsp;to keep the malicious flow running instead of stopping when a&nbsp;threat&nbsp;waits for user input.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="576" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/automated-interactivity-1024x576.webp" alt="automated interactivity with ANY.RUN" class="wp-image-22373" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/automated-interactivity-1024x576.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/automated-interactivity-300x169.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/automated-interactivity-768x432.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/automated-interactivity-370x208.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/automated-interactivity-270x152.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/automated-interactivity-740x416.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/automated-interactivity.webp 1280w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The sandbox automatically solves CAPTCHA challenges</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">This reduces handling time and keeps&nbsp;analysts from rebuilding the same evidence manually. Junior and mid-level employees can make decisions with greater confidence, while senior specialists become involved only when the case genuinely requires deeper&nbsp;expertise.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Get more value from every security investigation. 
 </span><br>Help your existing team handle more threats with less manual effort.&nbsp;
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=cfo-cyber-risk-playbook&amp;utm_term=290726&amp;utm_content=linktoenterprise#contact-sales" target="_blank" rel="noopener">
Increase SOC Capacity  &nbsp;
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h3 class="wp-block-heading">Lower the Labor Cost of IOC Enrichment&nbsp;</h3>



<p class="wp-block-paragraph">An isolated IP address, domain, URL, or file hash often requires several searches before an&nbsp;analyst can&nbsp;determine&nbsp;its relevance. Each&nbsp;additional&nbsp;source adds handling time, and incomplete context increases the chance of an unnecessary escalation.&nbsp;</p>



<p class="wp-block-paragraph"><a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=cfo-cyber-risk-playbook&amp;utm_term=290726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat&nbsp;Intelligence&nbsp;Lookup</a>&nbsp;gives&nbsp;analysts access to data collected from&nbsp;sandbox&nbsp;sessions&nbsp;submitted&nbsp;by 15,000 organizations and 600,000 security professionals worldwide.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="384" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-with-TI-Lookup-1024x384.png" alt="Deeper analysis with TI Lookup" class="wp-image-22333" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-with-TI-Lookup-1024x384.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-with-TI-Lookup-300x113.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-with-TI-Lookup-768x288.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-with-TI-Lookup-1536x576.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-with-TI-Lookup-2048x768.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-with-TI-Lookup-370x139.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-with-TI-Lookup-270x101.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-with-TI-Lookup-740x278.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Threat context with relevant sandbox sessions showcased in TI Lookup for deeper research</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">Each indicator&nbsp;is&nbsp;connected to the&nbsp;sandbox&nbsp;sessions where it appeared. The&nbsp;analyst can review related samples, infrastructure, network activity,&nbsp;behavior, and attacker techniques without assembling the investigation from separate sources.&nbsp;</p>



<p class="wp-block-paragraph">The cost benefit grows with case volume. Shorter enrichment time reduces the unit cost of each investigation, helps the team process more alerts, and lowers the amount of senior&nbsp;labor&nbsp;spent&nbsp;validatingroutine indicators.&nbsp;</p>



<h3 class="wp-block-heading">Get More Value from Existing Security Investments&nbsp;</h3>



<p class="wp-block-paragraph">Security systems lose value when they depend on stale indicators or require employees to research and&nbsp;validate&nbsp;incoming intelligence manually.&nbsp;</p>



<p class="wp-block-paragraph">ANY.RUN’s&nbsp;<a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=cfo-cyber-risk-playbook&amp;utm_term=290726&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat&nbsp;Intelligence&nbsp;Feeds</a>&nbsp;provide&nbsp;continuously updated malicious IP addresses, domains, and URLs extracted from live&nbsp;sandbox&nbsp;investigations. New indicators are added as current malware and phishing&nbsp;threats are&nbsp;analyzed, rather than relying only on historical or broadly aggregated data.&nbsp;</p>



<p class="wp-block-paragraph">Every IOC is connected to supporting context and the relevant&nbsp;sandbox&nbsp;session. This lets the SOC see why an indicator was classified as malicious and review the&nbsp;behavior&nbsp;and TTPs behind it without beginning a separate investigation from zero.&nbsp;</p>



<p class="wp-block-paragraph">The feeds can be delivered into SIEM, SOAR, XDR, EDR, and&nbsp;threat&nbsp;intelligence&nbsp;systems&nbsp;through existing integrations, APIs, SDKs, and STIX/TAXII.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="464" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Threat-Intelligence-Feed-ANY.RUN_-1024x464.png" alt="TI Feeds provides actionable IOCs " class="wp-image-22275" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Threat-Intelligence-Feed-ANY.RUN_-1024x464.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Threat-Intelligence-Feed-ANY.RUN_-300x136.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Threat-Intelligence-Feed-ANY.RUN_-768x348.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Threat-Intelligence-Feed-ANY.RUN_-1536x695.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Threat-Intelligence-Feed-ANY.RUN_-2048x927.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Threat-Intelligence-Feed-ANY.RUN_-370x167.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Threat-Intelligence-Feed-ANY.RUN_-270x122.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Threat-Intelligence-Feed-ANY.RUN_-740x335.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Feeds provides actionable IOCs</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">This increases the return on systems the company already funds. Fresher intelligence improves their detection coverage, while&nbsp;analysts spend less time collecting, checking, and distributing indicators across the security stack.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Turn faster threat analysis into stronger security outcomes.  &nbsp;
 </span><br>Help your team act sooner with clearer evidence.  &nbsp;
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=cfo-cyber-risk-playbook&amp;utm_term=290726&amp;utm_content=linktoenterprise#contact-sales" target="_blank" rel="noopener">
Strengthen Security Operations &nbsp;
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h3 class="wp-block-heading">Lower TCO with Cloud Delivery&nbsp;</h3>



<p class="wp-block-paragraph">An internal malware-analysis&nbsp;environment carries costs beyond the&nbsp;initial&nbsp;hardware purchase. It requires isolated servers or virtual machines, operating-system images, security controls, updates, maintenance, internal support, and&nbsp;additional&nbsp;capacity as submission volume grows.&nbsp;</p>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=cfo-cyber-risk-playbook&amp;utm_term=290726&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a>&nbsp;is cloud-based and fully accessible&nbsp;through a browser. Teams can begin investigating&nbsp;threats without deploying dedicated servers or asking internal engineering teams to build and&nbsp;maintain&nbsp;a separate&nbsp;analysis&nbsp;environment.&nbsp;</p>



<p class="wp-block-paragraph">This makes the total cost of ownership easier to forecast. The company avoids much of the capital spending, maintenance work, infrastructure support, and future expansion associated with an on-premises&nbsp;sandbox.&nbsp;</p>



<p class="wp-block-paragraph">The savings build across all four areas: fewer&nbsp;analyst hours per investigation, lower dependence on senior specialists, better use of existing security investments, and less infrastructure overhead. The SOC gains capacity while payroll and operational costs&nbsp;remain&nbsp;more controlled.&nbsp;</p>



<h2 class="wp-block-heading">The CFO Payoff: Lower Costs, More Capacity, Less Risk&nbsp;</h2>



<p class="wp-block-paragraph">ANY.RUN&nbsp;helps convert security improvements into measurable financial outcomes:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Lower operating cost per case:</strong> Reducing MTTR by up to 21 minutes per investigation means fewer paid hours spent handling each alert and more capacity from the existing payroll. </li>



<li><strong>Delay additional hiring:</strong> A workload reduction of up to 20% for Tier 1 gives the SOC room to absorb higher alert volumes before another recruitment cycle is required. </li>



<li><strong>Protect high-cost specialist capacity:</strong> A 30% reduction in Tier 1-to-Tier 2 escalations keeps more routine work away from senior employees and lowers the blended labor cost of investigations. </li>



<li><strong>Improve workforce productivity:</strong> With 94% of users reporting faster triage, the team can process more cases within the same staffing budget and reduce the cost created by growing backlogs. </li>



<li><strong>Shorten time-to-productivity:</strong> Visual attack evidence and structured reports help junior employees become effective sooner, reducing onboarding pressure on senior staff. </li>



<li><strong>Avoid infrastructure spending:</strong> Cloud delivery removes the need to purchase, maintain, and expand dedicated malware-analysis hardware and virtual environments. </li>



<li><strong>Increase the return on the existing security stack:</strong> Actionable IOCs and threat context strengthen the SIEM, SOAR, XDR, and other systems already included in the security budget. </li>



<li><strong>Reduce financial exposure:</strong> Earlier threat detection and faster response help limit the likelihood that a manageable security event develops into costly downtime, recovery work, regulatory action, or lost business. </li>
</ul>



<p class="wp-block-paragraph">Together, these outcomes improve the unit economics of the SOC. The company can handle more risk with the team and systems already in place, while keeping payroll growth, infrastructure costs, and potential incident losses under tighter control.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Reduce costs without adding SOC headcount. &nbsp;
 </span><br>Help your team respond to threats with greater speed and confidence. &nbsp;
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=cfo-cyber-risk-playbook&#038;utm_term=290726&#038;utm_content=linktoenterprise#contact-sales" target="_blank" rel="noopener">
Improve SOC Efficiency &nbsp;
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">About&nbsp;ANY.RUN&nbsp;</h2>



<p class="wp-block-paragraph">ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions, helps organizations investigate threats faster and make response decisions based on clear behavioral evidence. </p>



<p class="wp-block-paragraph">Its solutions include the <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=cfo-cyber-risk-playbook&amp;utm_term=290726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> for enterprise-scale malware and phishing analysis, along with <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=cfo-cyber-risk-playbook&amp;utm_term=290726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence</a> products built on investigation data from more than 15,000 organizations. This intelligence helps security teams enrich alerts, uncover active threats earlier, and add relevant context to detection, investigation, and response workflows. </p>



<p class="wp-block-paragraph">ANY.RUN is <a href="https://any.run/compliance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=cfo-cyber-risk-playbook&amp;utm_term=290726&amp;utm_content=linktocomliance" target="_blank" rel="noreferrer noopener">SOC 2 Type II attested</a>, demonstrating its commitment to strong security controls and customer data protection. For SOCs, MSSPs, and enterprise security teams, the platform helps reduce investigation uncertainty, accelerate triage, and turn threat analysis into actionable findings. </p>
<p>The post <a href="https://any.run/cybersecurity-blog/cfo-cyber-risk-playbook/">The US CFO’s Playbook: How to Reduce Cyber Risk Without Scaling SOC Team in a Tight Labor Market</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/cfo-cyber-risk-playbook/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>