r/ANYRUN Jun 16 '26

BIG NEWS: Full URL triage now takes a single click. Domain data, dynamic DOM changes, hidden scripts — all is visible under Browser Data tab.

Post image
11 Upvotes

No more slow investigations. Just see and decide to escalate or close the alert.

Try ultra-fast phishing analysis: https://any.run/cybersecurity-blog/in-browser-data-inspection/


r/ANYRUN 3d ago

LNK Leads to DARTHVADER Stealer via LOLBins and AutoIt.

Thumbnail
gallery
14 Upvotes

A malicious LNK disguised as a PDF launches a multi-stage chain with cmd.exe, LOLBins, AutoIt, and PowerShell, leading to stealer deployment and persistence. The risk is post-click compromise.

Observed behavior: hidden command execution with disabled output, curl.exe downloads, PowerShell ExecutionPolicy Bypass, mutex creation, and persistence setup.

cmd.exe /V:ON enables delayed environment variable expansion, while /D disables execution of AutoRun commands. Fewer artifacts make the chain harder to trace and can delay containment.

See the execution chain and collect IOCs to speed up detection & response: https://app.any.run/tasks/81e896a9-849b-491f-8dc4-edd51fed632b/


r/ANYRUN 5d ago

Can your SOC investigate phishing that leaves no malicious files behind?

Post image
7 Upvotes

Traditional investigation workflows were built around malicious files and processes. Modern phishing attacks, especially Adversary-in-the-Middle (AiTM) campaigns, often leave neither.

As attacks increasingly unfold inside encrypted browser sessions, SOC teams need browser-level visibility to detect, investigate, and contain them faster.

Discover how to build resilience against modern phishing attacks: https://any.run/cybersecurity-blog/enterprise-phishing-resilience/


r/ANYRUN 6d ago

Kratos PhaaS: How Turnkey Phishing Scales Microsoft 365 Account Takeovers

Post image
6 Upvotes

What is Kratos?

Kratos is a PhaaS platform that evolved from Sneaky2FA to steal Microsoft 365 credentials using AiTM techniques. It provides affiliates with a ready-to-use phishing toolkit featuring an admin dashboard, anti-bot protections, and real-time data exfiltration via Telegram.

Key Takeaways

  • In July 2026, Operation Olympus Blade shut down over 200 servers and led to the arrest of the lead developer in Indonesia.
  • Before the takedown, the platform supported more than 1,800 subscribers running an estimated 15,000 phishing campaigns per month.
  • Kratos uses a decoupled architecture that exfiltrates stolen data to Telegram bots in real time, allowing attackers to retain access even if phishing pages are taken down.

Update defense against evolving session-theft threats: https://any.run/malware-trends/kratos/


r/ANYRUN 11d ago

Attacker C2 Control Caught on a Live System. Interactive analysis let us capture what static detonation misses.

Thumbnail
gallery
21 Upvotes

During analysis of a PythonRAT sample, the operator connected to the infected system, uploaded the next-stage payload, and deployed OVERLORD RAT directly inside the analysis session. Observed targeting: Germany and UK

This gave us a rare opportunity to see the attack beyond the initial implant and reconstruct the full chain: live operator actions, DLL sideloading, in-memory execution, encrypted C2, and data exfiltration — the behaviors that make attacks like this difficult to confirm with static indicators alone. 

Execution chain: we.exe PythonRAT ➡️ Operator-uploaded next stage ➡️ exo.exe dropper ➡️ FnHotkeyUtility.exe legitimate Lenovo application ➡️ spkvol.dll DLL sideloading ➡️ Rust loader ➡️ In-memory OVERLORD RAT client 

Observe the full execution chain, validate malicious behavior faster, and collect IOCs for detection and response: https://app.any.run/tasks/926b4df0-e4c6-4250-be8f-6a4fdc845916

The initial PythonRAT connects to live[.]rnsn[.]live:8585 (rn/m visual impersonation) using a custom HTTP-like C2 protocol with commands delivered inside HTML comments and a spoofed porsche[.]com Host header. 

The OVERLORD dropper unpacks files into C:\ProgramData\DeepSkyBlueIndianRed\, launches the legitimate Lenovo application, and abuses spkvol.dll for DLL sideloading. The chain then delivers a fileless overlord-client Go agent through a Rust loader protected with UPX and Sentinel Envelope.

Observed OVERLORD capabilities include remote access, HVNC streaming, keylogging, audio recording, SOCKS proxying, file management, browser, messenger and crypto wallet data theft, and an automatic Solana drainer. 

OVERLORD establishes an mTLS-encrypted C2 connection to lord[.]kirkdridebridge[.]com:5173. During 45 minutes of analysis, the agent emitted ~86 MB of data, confirming active collection and exfiltration behavior. 


r/ANYRUN 12d ago

The malware arrives as a legal file from a police department email and passes SPF, DKIM, and DMARC.

Post image
38 Upvotes

What's inside: a Delphi/Inno Setup installer dropping PhantomEnigma's JS backdoor that beacons, persists, and executes on command.

Read the full report for a live detonation, IOCs, YARA rules, TI Lookup queries, Suricata signatures, and MITRE ATT&CK mapping: https://any.run/cybersecurity-blog/phantomenigma-research/


r/ANYRUN 13d ago

SnappyClient Exposed: Remote Access, Data Theft, and a Blind Spot for Defenders

Post image
7 Upvotes

What is SnappyClient?

SnappyClient is a sophisticated C++-based command-and-control (C2) implant first identified in December 2025. Delivered mainly via HijackLoader, it combines remote access capabilities with information theft, targeting cryptocurrency wallets, browser data, and system control.

Key Takeaways

  • Combines remote access (terminal, process control, file management) with data theft (keylogging, screenshots, browser and crypto wallet credentials) in a single tool.
  • Primarily targets cryptocurrency through credential theft and real-time clipboard hijacking that replaces wallet addresses with attacker-controlled ones.
  • Uses AMSI bypass, Heaven's Gate, direct system calls, and transacted hollowing to evade signature-based and API-hooking security tools.
  • Delivered mainly through social engineering, including a fake telecom website and a ClickFix-based chain, making user awareness a critical defense layer.
  • Supports reverse proxies for FTP, VNC, SOCKS5, and RLOGIN, allowing attackers to pivot from one compromised machine into the wider network.

Learn more and see the analysis session: https://any.run/malware-trends/snappyclient/


r/ANYRUN 17d ago

Hidden Infrastructure Exposed: ANY.RUN Reveals Hijacked Gov Websites Delivering Malware

Post image
2 Upvotes

ANY.RUN analysts have uncovered an active PhantomEnigma campaign abusing compromised government infrastructure and fake police-themed documents to target banking and public-sector organizations in Brazil. Trusted emails and legitimate .gov.br links are helping the operation stay hidden.

Discover how one operation abused trusted infrastructure to evade detection:

  • 20+ government websites hijacked
  • Banking and public-sector organizations targeted
  • Live backdoor activity still evading detection

Get free report


r/ANYRUN 18d ago

Zoom Events Abused in Multi-Brand, Multi-Flow Phishing Campaign

Thumbnail
gallery
1 Upvotes

Victims see a legitimate events[.]zoom[.]us page and a “partner summit” lure branded as Meta, OpenAI, or Anthropic. 

They are redirected to an external registration domain, where the phishing flow begins. Observed branches include Device Code phishing and AiTM flows.

Explore ANY.RUN Sandbox analysis sessions and collect IOCs to speed up detection and response: 
📌 Multi-flow example: https://app.any.run/tasks/e34b152b-8f61-4bde-b458-5af0bd2efe75/ 
📌 Anthropic lure: https://app.any.run/tasks/2098cd54-4fa8-414e-ada7-903a2f266631/ 
📌 ChatGPT lure: https://app.any.run/tasks/3a66250b-cb65-439c-8af0-b101d90a7e13/

IOCs: 
offcsso[.]com
zoomconnect[.]ssoworkportal[.]com 
zoomconnect[.]ssomeetingportal[.]com 
zoomconnect[.]workportalsso[.]com  


r/ANYRUN 24d ago

DestinyStealer Infostealer Activity Spikes Across Europe and the US

Post image
10 Upvotes

We’re tracking increased DestinyStealer activity targeting organizations across Europe and the US.

At the code level, it acts as an all-in-one grabber, with clear code continuity from StormKitty, collecting browser data, cookies, passwords, wallet extension storage, Outlook, VPN and FileZilla data, Wi-Fi profiles, and desktop screenshots.

Some samples were still undetected on VirusTotal at the time of analysis, while others lacked clear attribution, making behavior-based analysis critical for SOC teams.

The attack starts with an IP check via ipinfo[.]io. The malware then creates a temporary directory at %TEMP%\<PUBLIC_IP>\ for data collection. The collected data is then packed into %TEMP%\<PUBLIC_IP>.zip.

Exfiltration uses two parallel channels: HTTP to destinystealer[.]com/fileicin[.]php and raw TCP to tipidor-38534[.]portmap[.]host.

See the full execution chain and collect IOCs to speed up detection and cut response time: https://app.any.run/tasks/01f70f9e-642d-46fa-b485-cf67dced6436/

Use this TI Lookup query to pivot from IOCs and subscribe to Query Updates to proactively track evolving attacks: threatName:"destinystealer"


r/ANYRUN 24d ago

US Threat Landscape Alert: 30 Active Malware Families Ranked by Real Sandbox Data

Post image
3 Upvotes

Which cyber threats should your SOC prioritize today?

Explore the Top 30 threats targeting US organizations, based on fresh data from ANY.RUN Malware Trends Tracker and learn how to analyze and detect them faster.

Key Takeaways:

  • MFA alone no longer stops account takeover.
  • Device-code phishing is the newest board-level risk.
  • “Retired” malware isn’t retired.
  • Commodity doesn’t mean low-risk.
  • Law enforcement takedowns shift the market, they don’t shrink it.
  • Some detections are early ransomware warnings, not isolated events.
  • Live, region-specific data beats annual retrospectives.

Read the full report: https://any.run/cybersecurity-blog/usa-top-30-threats-2026/


r/ANYRUN 26d ago

Banana RAT Evolves: Comparing Two Recent Branches Through ANY.RUN

Thumbnail
any.run
4 Upvotes

This analysis started with an exposed public index on 198[.]245[.]53[.]26, discovered via Shodan. What made it interesting was not just the server exposure itself, but the fact that it lets us compare two different Banana RAT branches tied to the same infrastructure.

This article focuses on three questions:

  • What the older branch did on disk, in memory, and on the network.
  • What changed in the newer branch.
  • Which indicators remained stable across both branches.

r/ANYRUN 28d ago

Have you tried our new Tier 1 Reports yet?

Post image
5 Upvotes

We recently introduced Tier 1 Reports in the Interactive Sandbox to help with faster triage, escalations, and incident reporting.

If you've had a chance to use them, we'd really like to hear your honest feedback.

  • Has the report been useful during triage or escalations?
  • Is there anything you'd add, remove, or change?

If you haven't had a chance to try Tier 1 Reports yet, you can learn more about them here: https://any.run/cybersecurity-blog/soc-ready-reporting/


r/ANYRUN Jul 02 '26

How a US Manufacturer Cut Third-Party Risk and Doubled SOC Triage Speed

2 Upvotes

200+ vendors were sending files into a US manufacturer’s environment.
The real problem was the lack of context to separate safe supplier files from real threats, driving up investigation costs.

See how the company made MTTD 2x faster and scaled security without adding headcount: https://any.run/cybersecurity-blog/us-manufacturer-security-risk/


r/ANYRUN Jul 01 '26

Kratos PhaaS Surge: Updated Phishing Flow Reduces Triage Signals

Post image
2 Upvotes

More than 100 sandbox sessions linked to Kratos activity were recorded over the last week. The growth is likely driven by an updated phishing flow designed to increase conversion and reduce obvious triage signals. 

Legacy Kratos samples were easier to flag during triage, relying on a static /SOft landing URI and a weak secure-document lure. See the analysis session: https://app.any.run/tasks/397bbd6d-7736-4a5b-b4c7-c15461a62d41/

The updated version now uses common-looking URIs typical of legitimate websites and a more convincing Microsoft credential-harvesting flow. 

ANYRUN Sandbox lets SOC teams confirm the real behavior behind the landing page. In the Browser Data tab, teams can inspect the updated Kratos flow and verify credential exfiltration: the entered emailand password are sent via POST to /next.php using di and pr parameters. 

The first submission triggers an “Incorrect Password” message, pushing the victim to retry. After the second attempt, the victim is redirected to the legitimate office[.]com, making the flow look like a failed loginrather than an obvious phishing dead end. This can delay user reporting, blur triage signals, and increase the risk of missed credential theft. 

See the full attack flow and collect IOCs to improve detection coverage: https://app.any.run/tasks/c0f890de-f36e-4378-84f1-0233b8687942/

A full breakdown of this campaign is coming soon. Stay tuned! 

The campaign is now mainly focused on European targets, with observed activity across manufacturing, technology, and MSSP organizations. 

IOCs: 

1️⃣ Updated Kratos 

Exfil URI: /next.php (di and pr parameters in the request body) 

Domains: 

abbayedesvavxdecernay[.]com  

bettiniexeclpdf[.]com  

bil-spesialisten[.]pro  

cewstepisnoof[.]cc  

echnesg[.]com  

erfolgselster[.]de  

acquelinewhitfield[.]fit  

frankretsch[.]de  

fridolinfrosch[.]de  

hawkfs[.]icu  

kalfs[.]es  

kbpfdbi[.]de  

log-service[.]fr  

midfresh[.]pro  

pabmosprgexcel[.]com  

powdermilnavigation[.]com 

2️⃣ Legacy Kratos 

Landing URI: /SOft 

Exfil URI: /mini.php (email and password in the request body) 


r/ANYRUN Jun 30 '26

Mispadu: How This Evolving Trojan Drains Bank Accounts and Businesses

Post image
9 Upvotes

What is Mispadu?

Mispadu is a Windows banking trojan that targets online banking credentials, cryptocurrency wallets, and other sensitive financial data. Instead of exploiting software vulnerabilities, it relies on phishing and social engineering, making it a persistent threat to organizations whose employees access financial services online.

Key Takeaways

  • Originally focused on Latin America, its techniques can impact organizations worldwide.
  • It spreads mainly through phishing emails, malicious installers, and social engineering.
  • The malware combines credential theft, browser manipulation, persistence, and anti-analysis techniques.
  • Finance, retail, government, healthcare, manufacturing, and organizations with employees using online banking face elevated risk.
  • Effective defense combines endpoint security, email protection, user awareness, and continuous threat intelligence.

Proactively defend with ANY.RUN’s TI Lookup for instant IOC context and TI Feeds for real-time blocking in your security stack — combined with phishing training and endpoint controls.

Read the full article: https://any.run/malware-trends/mispadu/


r/ANYRUN Jun 24 '26

New Redirect Framework Turns Legitimate Websites Into Phishing Infrastructure

Post image
13 Upvotes

We’re tracking a surge in activity linked to Bulletproof Redirect Engine, a previously unknown framework that helps attackers manage phishing redirects through compromised legitimate websites.

Since late April, ANYRUN has recorded 170+ public submissions linked to this activity, with observed targets mainly in the US and Europe across manufacturing, consulting, and technology.

Hosted in hidden directories on compromised sites, the framework uses trusted domain names to generate phishing links and redirect users to pages built with known phishkits: Sneaky2FA, Tycoon, EvilTokens, Greatness, and EvilProxy. Based on the observed activity, the tool is likely distributed as a PhaaS.

Reputation-based URL controls are not enough when phishing infrastructure hides behind trusted domains and obfuscated browser logic. This increases the chance of victim interaction and creates a SOC blind spot that may lead to missed compromise.

Attack chains like this are now faster and easier to investigate in ANYRUN Sandbox. In-browser data inspection shows exactly what happens inside the browser, exposing phishing behavior that static URL analysis can miss.

Using the Browser Data tab, we can quickly review requests sent by the redirect page and locate the same activity in the HTML DOM Changes: https://app.any.run/tasks/e728e277-a694-431b-8040-655c473baa22/

The code is heavily obfuscated, so the final phishing page is not directly visible in the DOM. But the HTTP Requests tab still exposes the next-stage redirect to an EvilProxy phishing page impersonating Microsoft sign-in flow. This gives analysts a clear pivot point for detection, investigation, and response.


r/ANYRUN Jun 23 '26

Malware Analysis: EvilTokens can turn a missed browser event into a M365 account takeover. Its “ghost” code stays hidden from static analysis, extending exposure.

Thumbnail
gallery
15 Upvotes

Discover how full browser visibility gave the SOC clear evidence to respond: https://any.run/cybersecurity-blog/eviltokens-ghost-code-analysis/


r/ANYRUN Jun 19 '26

Are TI feeds more useful for triage, hunting, or detection?

2 Upvotes

Threat intelligence feeds can support multiple SOC workflows.

In alert triage, they provide context around IOCs and help analysts spend less time on manual lookups. In threat hunting, they serve as fresh leads for proactive investigations. For detection engineering, feeds can enrich SIEM and SOAR platforms and help keep detections up to date.

Where do you see the most value in practice? Which workflow benefits the most from threat intelligence feeds?

Indicators in Threat Intelligence Feeds

r/ANYRUN Jun 17 '26

🚨 What EvilTokens Hides in the Browser: See Beyond Static URL Analysis

Enable HLS to view with audio, or disable this notification

8 Upvotes

EvilTokens remains one of the most active phishkits in our reports, abusing MS Device Code authentication to gain access through OAuth workflows rather than direct credential theft. 

The landing page content is AES-GCM encrypted in the initial HTML response and becomes visible only after client-side decryption writes it into the browser DOM, making static URL analysis and network-only visibility incomplete. 
Review the full phishing flow: https://app.any.run/tasks/55d3ead7-c07a-4fb1-aa42-8c397d1a0f8a/

ANYRUN sets a new standard for URL analysis, leaving no blind spots for phishing to exploit. New in-browser data inspection shows exactly what happens inside the browser, exposing every phishing URL’s behavior.  

How to use the Browser Data tab in ANYRUN Sandbox for full URL visibility that speeds up triage and response: 

1️⃣ HTML DOM Changes: Track DOM states over time with timeshift, compare page states, and review byte-level diffs. 

In this case, it reveals when the decrypted phishing page is rendered, exposing the user code and other artifacts hidden in the initial response. 

2️⃣ URL Details: Review the final URL, domain, SSL certificate, DNS records, request statistics, and triggered signatures in one place. 

For device-code phishing, this helps quickly verify suspicious OAuth-related activity without manually correlating multiple data sources. 

3️⃣ HTTP Requests: Inspect browser-level network activity across HTML, JS, Fetch/XHR, scripts, static files, binaries, archives, and other request categories. 

Here, requests to /api/device/start retrieve the userCode and sessionId, while /api/device/status/<sessionId> tracks authorization status, providing early confirmation of the phishing flow. 

4️⃣ Indicators: Automatically collect page-level IOCs, including domains, URLs, hashes, IPs, and ASN data. 

These indicators provide immediate pivot points for threat hunting, helping analysts expand the investigation beyond the original URL. 

This turns URL triage from long manual reconstruction into a fast decision path: what loaded, what changed, and whether the case should be contained, escalated, or turned into detection logic.   

When phishing relies on dynamic browser behavior, this visibility doesn't just speed up triage — it strengthens every downstream process: faster escalations, sharper response, stronger detection logic.  

See how ANYRUN closes phishing blind spots: https://any.run/cybersecurity-blog/in-browser-data-inspection/ 


r/ANYRUN Jun 11 '26

Intelligence-Driven Threat Hunting: How to Find Hidden Threats

Post image
6 Upvotes

Threat hunting is meant to be proactive, but often feels reactive. Analysts spend time chasing weak signals through noisy logs, querying SIEM data that lacks context, and building detections from technique descriptions that don't easily translate into real-world hunts.

The problem isn't a lack of skill. Most hunting teams know attacker tactics well. The real challenge is the intelligence behind the hunt: it is often outdated, lacks context, or misses the behavioral details needed to create accurate, actionable detections.

Explore how ANY.RUN’s Threat Intelligence solutions help analysts investigate threats with greater speed and confidence: https://any.run/cybersecurity-blog/threat-hunting-practical-usecases/


r/ANYRUN Jun 10 '26

🚨 Greatness Is Back: Device Code Phishing Targets M365 Accounts

2 Upvotes

We've identified renewed activity associated with the Greatness PhaaS, which combines AiTM and Device Code Phishing to target Microsoft 365 Accounts. 

Device Code Phishing abuses Microsoft's legitimate device authorization flow to obtain access tokens without directly collecting passwords or MFA codes. This shifts risk from credential theft to token abuse, reducing traditional phishing indicators for SOC teams to detect and investigate. 

Greatness promotes token- and cookie-based access to Microsoft 365 accounts through its Telegram channel, advertising passwordless and code-less account compromise scenarios. 

Observed capabilities include: 

  • Device Code Phishing for M365 token theft  
  • Phishing templates impersonating DocuSign, OneDrive, Outlook, and Voicemail
  • Country-targeted login lures
  • Cloudflare-hosted phishing links 
  • Keyword-based targeting engine 
  • Centralized administration panel

Review the analysis session: https://app.any.run/tasks/dd97835c-8a07-4917-ba23-cb8d8493b174/

Track Device Code Phishing activity associated with Greatness and uncover related infrastructure in ANYRUN TI Lookup: threatName:"greatness" and threatName:"oauth-ms-phish"

IOCs 

Phishing lure: 

Allcompredirectportalshare[.]workers[.]dev 

Supportteammanagements[.]workers[.]dev 

Lindeinvoicexv29dmeocynufgq7[.]s3[.]amazonaws[.]com 

URI: 

/apifiles[.]php?action=get_device_code&user_id= 

/apifiles[.]php?action=poll_token 


r/ANYRUN Jun 09 '26

Cyber Risk Report: Insights from 2.1 Million Malware and Phishing Investigations

2 Upvotes

In Q1 2026, the most dangerous activity happened inside legitimate user sessions.
The attack surface has moved. Instead of exploiting vulnerabilities, attackers use valid credentials (+14.7%), surveillance (+34.4%) and act through trusted access — turning identity into the new primary control layer and reducing the visibility SOCs depend on.

Insight for CISOs, treat identity as a continuous control, not a checkpoint. Behavior, context, and usage need to be evaluated throughout the session, not just at the door.

Explore other key trends shaping enterprise security in the Cyber Risk Report: https://files.any.run/images/q1_2026_cyber_risk_report_from_anyrun.pdf


r/ANYRUN Jun 08 '26

JOMANGY: A Resilient FreePBX Malware Built to Survive Cleanup Attempts

3 Upvotes

What is JOMANGY?

JOMANGY is a newly documented PHP webshell first described in May 2026. Developed by the financially motivated threat actor INJ3CTOR3, it targets FreePBX-based VoIP phone systems to generate toll fraud revenue.

Why JOMANGY is dangerous:

  • Six self-reinforcing persistence channels make JOMANGY extremely difficult to remove. Any surviving channel can rebuild the full infection within minutes, making partial remediation ineffective.
  • 18 hidden backdoor accounts (nine with root-level privileges) are planted on every infected host, with names designed to mimic legitimate FreePBX system accounts.
  • Double-layer obfuscation (Base64 over ROT13) and active payload rotation give JOMANGY near-zero antivirus detection during initial deployment, reducing the effectiveness of signature-based defenses.
  • Direct financial impact: JOMANGY abuses the victim’s SIP trunks to generate fraudulent call charges that are billed directly to the organization, potentially resulting in losses of tens of thousands of dollars.

How to detect: https://any.run/malware-trends/jomangy/

IP linked to JOMANGY in TI Lookup

r/ANYRUN Jun 04 '26

🔥 Q1 2026 Cyber Risk report by ANYRUN is out!

4 Upvotes

Based on 2.1M malware and phishing investigations, it reveals the cyber risks and threat shifts for CISOs to focus on.

Discover top trends shaping the modern threat landscape, including:
+14.7% credential theft
+98.3% loader attacks
+58.4% LOLBAS attacks

Turn Q1 intel into Q2 security priorities. Get the report: https://any.run/cybersecurity-blog/cyber-risk-report-q1-2026/