Image 1 — 3DBlast: New Active Multibrand And Multiflow Phishkit Detected
Image 2 — 3DBlast: New Active Multibrand And Multiflow Phishkit Detected
Image 3 — 3DBlast: New Active Multibrand And Multiflow Phishkit Detected
Image 4 — 3DBlast: New Active Multibrand And Multiflow Phishkit Detected
Image 5 — 3DBlast: New Active Multibrand And Multiflow Phishkit Detected
▲ 4 r/ANYRUN

3DBlast: New Active Multibrand And Multiflow Phishkit Detected

Observed in the US, it impersonates Microsoft 365, Office 365, and Google while rotating infrastructure and phishing flows.   

We observed BitB, OAuth/Device Code phishing, AiTM, and DOM relay — techniques that let attackers mimic legitimate login experiences, abuse trusted authentication flows, intercept sessions, and relay victim interactions in real time. 

See the analysis sessions and collect IOCs to speed up detection and response:

 

Use this TI Lookup query to pivot from IOCs, review related activity, and validate your detection coverage.

IOCs:

llove-kitchens[.]com
createashape[.]com
ojpho7hhniua5lcd6jdgjpb161z[.]workers[.]dev
liguigas[.]com
ogqiatl1g63gs9oz1xyvufz5u[.]workers[.]dev
jarvissingaspore[.]com
dnavp5upvhaphzpbef8lf90p[.]workers[.]dev
visinomics[.]com
resultbusiness[.]com
w5fc40y5m7ehl190zcipbw[.]workers[.]dev
sansgiorgiosrl[.]com
2026-global-tender-collaborations[.]workers[.]dev
xxpn8dakpd8cr5pdt2ii[.]workers[.]dev

u/ANYRUN-team — 1 day ago
▲ 6 r/ANYRUN

SolarisLoader: How It Disables Defenses Before Dropping Payloads

What is SolarisLoader?

SolarisLoader is a malware loader designed to neutralize security infrastructure before deploying high-risk secondary payloads. It uses a "Bring Your Own Vulnerable Driver" technique to gain kernel-level access and terminate antivirus processes.

Key Takeaways

  • Kernel-Level Defense Dismantling: SolarisLoader uses BYOVD, exploiting a vulnerable Safetica endpoint protection driver (CVE-2026-0828) to gain kernel-level access and terminate security processes.
  • Telemetry Blinding: It patches AMSI and ETW in memory via direct opcode modification, preventing Windows from logging or reporting malicious activity.
  • Resilient Triple-Layer Persistence: It combines scheduled tasks, registry-backed backups (ICtrlData), and a watchdog process that injects code into legitimate system files like RuntimeBroker.exe.
  • Silent Privilege Elevation: ANY.RUN’s Interactive Sandbox analysis confirms a silent COM-elevation/UAC-bypass path via dllhost.exe, enabling administrative privileges without user-facing notifications or consent prompts.
  • Active MaaS Cycle: SolarisLoader is actively developed and delivers secondary payloads including StealC, Amadey, and REMCOS RAT.

Learn to detect this invisible threat early: https://any.run/malware-trends/solaris/

u/ANYRUN-team — 3 days ago

What's the biggest source of noise in your SOC right now?

You can tune detections and automate a lot of repetitive work, but some alerts still take up way too much time.

What kind of alerts are the hardest to deal with?

reddit.com
u/ANYRUN-team — 6 days ago

We “hired” Lazarus APT remote workers — and uncovered their toolkit

For weeks, researchers from BCA LTD & NorthScan used ANYRUN Sandbox to capture weeks of Famous Chollima activity inside a fake startup.

any.run
u/ANYRUN-team — 8 days ago
▲ 3 r/ANYRUN

What If You Could Search TI in Plain Language?

AI-powered queries in TI Lookup remove one of the most persistent friction points in threat investigation: figuring out the right syntax before you can get to the actual analysis.

Here's what it looks like in practice. A threat hunter describes the behavior they're looking for in plain language, and TI Lookup returns structured results: risk scores, threat names, associated indicators, and sandbox session links.

🎁 Using ANYRUN TI Lookup? Tell us how it fits into your workflow. Your answers help us build a better service. Take a short survey and get a reward

u/ANYRUN-team — 8 days ago
▲ 10 r/ANYRUN

OnyxC2 MaaS stealer targets 200+ apps to hijack session tokens and bypass MFA

What is OnyxC2?

OnyxC2 is a sophisticated Malware-as-a-Service platform sold on cybercrime forums for high-volume credential theft. It targets 200+ applications, stealing data from browsers, crypto wallets, FTP and email clients, while using DLL sideloading and browser fingerprinting to evade detection.

Key Features:

  • Advanced DLL sideloading: OnyxC2 uses legitimately signed applications to load malicious payloads disguised as system libraries. We observed signed ABRSubProcess.exe sideloading malicious borlndmm.dll to bypass traditional antivirus engines.
  • 200+ targeted applications: It steals data from Chromium-based browsers, crypto wallets, password managers, 2FA extensions, and session cookies, enabling MFA bypass and access that can survive password resets.
  • Remote access capabilities: The premium tier includes HVNC, LSASS memory dumping, and reverse shells, allowing attackers to inherit authenticated browser sessions and control compromised systems.
  • Vetted delivery: Phishing pages use Canvas fingerprinting to profile victims before delivering payloads. Password-protected ZIP archives such as Setup_File.zip help evade automated email scanning.
  • Industrialized MaaS model: OnyxC2 provides affiliates with ready-made lures, a centralized management panel, and a “service guarantee” against detection.

Update your SOC defenses against this evolving industrial threat: https://any.run/malware-trends/onyxc2/

u/ANYRUN-team — 9 days ago
▲ 9 r/ANYRUN

🔥 We “hired” Lazarus APT remote workers — and uncovered their toolkit.

For weeks, researchers from BCA LTD & NorthScan used ANYRUN Sandbox to capture weeks of Famous Chollima activity inside a fake startup.

How not to let a spy in?

See full story and videos

u/ANYRUN-team — 10 days ago
▲ 23 r/ANYRUN+1 crossposts

PhantomEnigma shows the difference between blocking today’s C2 and tracking the operation behind it.

We recovered a Node.js/Electron backdoor with /nbw/ beaconing, 180-second task checks, eval()-based JavaScript execution, EXE delivery, and login persistence — capabilities that can turn a clean-looking sample into longer access, follow-on payload delivery, and higher fraud or data-exposure risk.

The durable signal is the build and execution chain: Delphi/Inno installer ➡️ patched Electron/Boostnote app ➡️ malicious index.js ➡️ HTTP beaconing ➡️ JS/EXE tasking.

That pattern helped us connect 231 sandbox analyses to the same PhantomEnigma cluster, even as domains, IPs, and delivery infrastructure changed ❗️

Full investigation: https://any.run/cybersecurity-blog/phantomenigma-research/

u/ANYRUN-team — 14 days ago
▲ 7 r/ANYRUN

Kali365 hides its lure configuration, device-code session endpoints, and phishing flow inside encrypted JavaScript that only decrypts when the page runs in a real browser

The decrypted code exposes a kit built to scale: a design field selecting from 34 brand templates (OneDrive, SharePoint, Teams, DocuSign, and others), a flow_type field switching between Microsoft and Google device authorization flows, and dedicated endpoints for session creation and OAuth token polling.

Those backend patterns are more durable detection signals than lure content or domains that rotate between campaigns. And analysts need browser-level visibility to reach them.

Kali365 is active against US organizations. Its multi-brand templates make campaigns easy to adapt and scale across different industries. It increases the risk of account compromise, data exposure, fraud, and delayed response.

Everything on Kali365 — all 34 templates, API endpoints, detection steps and CISO recommendations: https://any.run/cybersecurity-blog/kali365-phishing-targeting-us/

u/ANYRUN-team — 15 days ago
▲ 11 r/ANYRUN

Major Cyber Attacks in July: US and EU Organizations Hit by Phishing, RATs, and Stealers

July’s major attacks put cloud accounts, financial activity, and sensitive data at risk.

Attackers abused 20+ government portals, used fake AI summit invitations, and manipulated Microsoft device code flows across the US, Europe, Brazil, and beyond.

See how your team can detect and respond faster: https://any.run/cybersecurity-blog/major-cyber-attacks-july-2026/

u/ANYRUN-team — 16 days ago
▲ 20 r/ANYRUN+2 crossposts

LNK Leads to DARTHVADER Stealer via LOLBins and AutoIt.

A malicious LNK disguised as a PDF launches a multi-stage chain with cmd.exe, LOLBins, AutoIt, and PowerShell, leading to stealer deployment and persistence. The risk is post-click compromise.

Observed behavior: hidden command execution with disabled output, curl.exe downloads, PowerShell ExecutionPolicy Bypass, mutex creation, and persistence setup.

cmd.exe /V:ON enables delayed environment variable expansion, while /D disables execution of AutoRun commands. Fewer artifacts make the chain harder to trace and can delay containment.

See the execution chain and collect IOCs to speed up detection & response: https://app.any.run/tasks/81e896a9-849b-491f-8dc4-edd51fed632b/

u/ANYRUN-team — 21 days ago
▲ 6 r/ANYRUN

Can your SOC investigate phishing that leaves no malicious files behind?

Traditional investigation workflows were built around malicious files and processes. Modern phishing attacks, especially Adversary-in-the-Middle (AiTM) campaigns, often leave neither.

As attacks increasingly unfold inside encrypted browser sessions, SOC teams need browser-level visibility to detect, investigate, and contain them faster.

Discover how to build resilience against modern phishing attacks: https://any.run/cybersecurity-blog/enterprise-phishing-resilience/

u/ANYRUN-team — 23 days ago
▲ 6 r/ANYRUN+1 crossposts

Kratos PhaaS: How Turnkey Phishing Scales Microsoft 365 Account Takeovers

What is Kratos?

Kratos is a PhaaS platform that evolved from Sneaky2FA to steal Microsoft 365 credentials using AiTM techniques. It provides affiliates with a ready-to-use phishing toolkit featuring an admin dashboard, anti-bot protections, and real-time data exfiltration via Telegram.

Key Takeaways

  • In July 2026, Operation Olympus Blade shut down over 200 servers and led to the arrest of the lead developer in Indonesia.
  • Before the takedown, the platform supported more than 1,800 subscribers running an estimated 15,000 phishing campaigns per month.
  • Kratos uses a decoupled architecture that exfiltrates stolen data to Telegram bots in real time, allowing attackers to retain access even if phishing pages are taken down.

Update defense against evolving session-theft threats: https://any.run/malware-trends/kratos/

u/ANYRUN-team — 24 days ago
▲ 28 r/threatintel+1 crossposts

Attacker C2 Control Caught on a Live System. Interactive analysis let us capture what static detonation misses.

During analysis of a PythonRAT sample, the operator connected to the infected system, uploaded the next-stage payload, and deployed OVERLORD RAT directly inside the analysis session. Observed targeting: Germany and UK

This gave us a rare opportunity to see the attack beyond the initial implant and reconstruct the full chain: live operator actions, DLL sideloading, in-memory execution, encrypted C2, and data exfiltration — the behaviors that make attacks like this difficult to confirm with static indicators alone. 

Execution chain: we.exe PythonRAT ➡️ Operator-uploaded next stage ➡️ exo.exe dropper ➡️ FnHotkeyUtility.exe legitimate Lenovo application ➡️ spkvol.dll DLL sideloading ➡️ Rust loader ➡️ In-memory OVERLORD RAT client 

Observe the full execution chain, validate malicious behavior faster, and collect IOCs for detection and response: https://app.any.run/tasks/926b4df0-e4c6-4250-be8f-6a4fdc845916

The initial PythonRAT connects to live[.]rnsn[.]live:8585 (rn/m visual impersonation) using a custom HTTP-like C2 protocol with commands delivered inside HTML comments and a spoofed porsche[.]com Host header. 

The OVERLORD dropper unpacks files into C:\ProgramData\DeepSkyBlueIndianRed\, launches the legitimate Lenovo application, and abuses spkvol.dll for DLL sideloading. The chain then delivers a fileless overlord-client Go agent through a Rust loader protected with UPX and Sentinel Envelope.

Observed OVERLORD capabilities include remote access, HVNC streaming, keylogging, audio recording, SOCKS proxying, file management, browser, messenger and crypto wallet data theft, and an automatic Solana drainer. 

OVERLORD establishes an mTLS-encrypted C2 connection to lord[.]kirkdridebridge[.]com:5173. During 45 minutes of analysis, the agent emitted ~86 MB of data, confirming active collection and exfiltration behavior. 

u/ANYRUN-team — 28 days ago
▲ 68 r/ANYRUN+1 crossposts

The malware arrives as a legal file from a police department email and passes SPF, DKIM, and DMARC.

What's inside: a Delphi/Inno Setup installer dropping PhantomEnigma's JS backdoor that beacons, persists, and executes on command.

Read the full report for a live detonation, IOCs, YARA rules, TI Lookup queries, Suricata signatures, and MITRE ATT&CK mapping: https://any.run/cybersecurity-blog/phantomenigma-research/

u/ANYRUN-team — 1 month ago
▲ 9 r/ANYRUN+1 crossposts

SnappyClient Exposed: Remote Access, Data Theft, and a Blind Spot for Defenders

What is SnappyClient?

SnappyClient is a sophisticated C++-based command-and-control (C2) implant first identified in December 2025. Delivered mainly via HijackLoader, it combines remote access capabilities with information theft, targeting cryptocurrency wallets, browser data, and system control.

Key Takeaways

  • Combines remote access (terminal, process control, file management) with data theft (keylogging, screenshots, browser and crypto wallet credentials) in a single tool.
  • Primarily targets cryptocurrency through credential theft and real-time clipboard hijacking that replaces wallet addresses with attacker-controlled ones.
  • Uses AMSI bypass, Heaven's Gate, direct system calls, and transacted hollowing to evade signature-based and API-hooking security tools.
  • Delivered mainly through social engineering, including a fake telecom website and a ClickFix-based chain, making user awareness a critical defense layer.
  • Supports reverse proxies for FTP, VNC, SOCKS5, and RLOGIN, allowing attackers to pivot from one compromised machine into the wider network.

Learn more and see the analysis session: https://any.run/malware-trends/snappyclient/

u/ANYRUN-team — 1 month ago
▲ 6 r/threatintel+1 crossposts

Hidden Infrastructure Exposed: ANY.RUN Reveals Hijacked Gov Websites Delivering Malware

ANY.RUN analysts have uncovered an active PhantomEnigma campaign abusing compromised government infrastructure and fake police-themed documents to target banking and public-sector organizations in Brazil. Trusted emails and legitimate .gov.br links are helping the operation stay hidden.

Discover how one operation abused trusted infrastructure to evade detection:

  • 20+ government websites hijacked
  • Banking and public-sector organizations targeted
  • Live backdoor activity still evading detection

Get free report

u/ANYRUN-team — 1 month ago
▲ 1 r/ANYRUN

Zoom Events Abused in Multi-Brand, Multi-Flow Phishing Campaign

Victims see a legitimate events[.]zoom[.]us page and a “partner summit” lure branded as Meta, OpenAI, or Anthropic. 

They are redirected to an external registration domain, where the phishing flow begins. Observed branches include Device Code phishing and AiTM flows.

Explore ANY.RUN Sandbox analysis sessions and collect IOCs to speed up detection and response: 
📌 Multi-flow example: https://app.any.run/tasks/e34b152b-8f61-4bde-b458-5af0bd2efe75/ 
📌 Anthropic lure: https://app.any.run/tasks/2098cd54-4fa8-414e-ada7-903a2f266631/ 
📌 ChatGPT lure: https://app.any.run/tasks/3a66250b-cb65-439c-8af0-b101d90a7e13/

IOCs: 
offcsso[.]com
zoomconnect[.]ssoworkportal[.]com 
zoomconnect[.]ssomeetingportal[.]com 
zoomconnect[.]workportalsso[.]com  

u/ANYRUN-team — 1 month ago