๐Ÿ”ฅ Q1 2026 Cyber Risk report by #ANYRUN is out!

Explore the cyber risks and threat shifts for CISOs, including:
โ—๏ธ +14.7% credential theft
โ—๏ธ +98.3% loader attacks
โ—๏ธ +58.4% LOLBAS attacks

Turn Q1 intel into Q2 security priorities. Get the report: https://any.run/cybersecurity-blog/cyber-risk-report-q1-2026/?utm_source=mastodon&utm_medium=post&utm_campaign=cyber_risk_report_q1_2026&utm_content=linktoreport&utm_term=040626

#cybersecurity #infosec

๐Ÿšจ ๐—™๐—ฎ๐—ธ๐—ฒ ๐—–๐—น๐—ฎ๐˜‚๐—ฑ๐—ฒ & ๐—–๐—ผ๐—ฑ๐—ฒ๐˜… ๐——๐—ฒ๐—น๐—ถ๐˜ƒ๐—ฒ๐—ฟ ๐—œ๐—ป-๐— ๐—ฒ๐—บ๐—ผ๐—ฟ๐˜† ๐—ฆ๐˜๐—ฒ๐—ฎ๐—น๐—ฒ๐—ฟ: ๐—–๐—น๐—ถ๐—ฐ๐—ธ๐—™๐—ถ๐˜… ๐˜ƒ๐—ถ๐—ฎ ๐—š๐—ผ๐—ผ๐—ด๐—น๐—ฒ ๐—ฆ๐—ถ๐˜๐—ฒ๐˜€
โš ๏ธ Weโ€™re tracking a #ClickFix campaign that mimics popular AI tools, including Codex and Claude, and abuses trusted Google Sites infrastructure to deliver stealer #malware.

With no standalone executable dropped to disk and network activity appearing as legitimate powershell.exe traffic, the attack can significantly reduce visibility during the early stages of compromise.

โ—๏ธ Victims are directed to trusted sites[.]google[.]com pages and instructed to execute an mshta command. The attack results in in-memory stealer execution, theft of browser, email, and cryptocurrency wallet data, and outbound communication with attacker-controlled C2 infrastructure, while leaving fewer traditional detection opportunities for SOC teams.

Execution chain:
Trusted Google Sites lure โžก๏ธ User-executed mshta command โžก๏ธ Multi-stage PowerShell delivery โžก๏ธ Steganographic payload extraction from image โžก๏ธ Shellcode deployment โžก๏ธ In-memory execution inside powershell.exe โžก๏ธ Browser, email & wallet data theft โžก๏ธ C2 exfiltration

๐Ÿ‘จโ€๐Ÿ’ป Using #ANYRUN Sandbox, investigate the full ClickFix execution chain, validate detection coverage, and observe PowerShell staging, steganographic payload delivery, and credential theft activity. Explore the analysis sessions and collect IOCs:
๐Ÿ”น Codex lure: https://app.any.run/tasks/151cfb30-5ef2-4962-a90e-58a59ecc43da/?utm_source=mastodon&utm_medium=post&utm_campaign=claude_codex_clickfix&utm_term=030626&utm_content=linktoservice
๐Ÿ”น Claude lure: https://app.any.run/tasks/698e0bd5-01b6-40fe-814c-5c0885cea645/?utm_source=mastodon&utm_medium=post&utm_campaign=claude_codex_clickfix&utm_term=030626&utm_content=linktoservice

๐Ÿ” Track related ClickFix activity in #ANYRUN TI Lookup, identify additional Codex and Claude lures, and uncover related AI-themed ClickFix activity and infrastructure:
๐Ÿ”น https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=claude_codex_clickfix&utm_content=030626&utm_term=linktotilookup#%7B%2522query%2522:%2522url:%255C%2522https:/sites.google.com/*/cdx%255C%2522%2520or%2520url:%255C%2522https:/sites.google.com/*/clau%255C%2522%2522,%2522dateRange%2522:7%7D
๐Ÿ”น https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=claude_codex_clickfix&utm_content=030626&utm_term=linktotilookup#%7B%22query%22:%22ruleName:%5C%22AI-themed%20ClickFix%20phishing%20page%20has%20been%20detected%5C%22%22,%22dateRange%22:14%7D

๐Ÿš€ Equip your SOC with stronger phishing detection and contain incidents faster: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=claude_codex_clickfix&utm_term=030626&utm_content=linktoenterprise

#cybersecurity #infosec

โšก Faster SOC decisions and stronger threat visibility with #ANYRUNโ€™s May updates.

Explore Tier 1 Reports, Elastic Security integration for fresh IOCs, and 1,400+ new detections ๐Ÿ›ก๏ธ

Learn more and strengthen your SOC response now ๐Ÿ‘‡
https://any.run/cybersecurity-blog/release-notes-may-2026/?utm_source=mastodon&utm_medium=post&utm_campaign=release-notes-may-2026&utm_term=030626&utm_content=linktoblog

Release Notes: Elastic Integration, Tier 1 Reports & 1,400+ Threat Updates

Explore ANY.RUNโ€™s May updates: Tier 1 Reports with AI Summary, Elastic Security integration, and new threat coverage updates for faster SOC response.

ANY.RUN's Cybersecurity Blog

Day 1 at Infosecurity Europe 2026 is a wrap ๐Ÿ‡ฌ๐Ÿ‡ง One theme kept coming up in conversations with security leaders today: investigation speed matters, but decision confidence matters even more.

We're showing how #ANYRUN helps enterprise SOCs & MSSPs shorten time to insight while giving teams the context needed to make faster, more confident response decisions โšก๏ธ

๐Ÿ“ Find our team at Stand C62 and learn how behavioral analysis and live threat intelligence help reduce uncertainty throughout the investigation process.

๐ŸŽŸ๏ธ Get your ticket: https://infosecurityeurope.com/en-gb/register.html?code=1666079269821849-VCP

๐Ÿšจ ๐—๐—ข๐— ๐—”๐—ก๐—š๐—ฌ ๐—ช๐—ฒ๐—ฏ๐˜€๐—ต๐—ฒ๐—น๐—น ๐—˜๐—ป๐—ฎ๐—ฏ๐—น๐—ฒ๐˜€ ๐—Ÿ๐—ผ๐—ป๐—ด-๐—ง๐—ฒ๐—ฟ๐—บ ๐—–๐—ผ๐—บ๐—ฝ๐—ฟ๐—ผ๐—บ๐—ถ๐˜€๐—ฒ ๐—ผ๐—ณ ๐—ฉ๐—ผ๐—œ๐—ฃ ๐—œ๐—ป๐—ณ๐—ฟ๐—ฎ๐˜€๐˜๐—ฟ๐˜‚๐—ฐ๐˜๐˜‚๐—ฟ๐—ฒ
โš ๏ธ #JOMANGY is an actively used PHP backdoor targeting FreePBX-based VoIP environments with stealth, self-recovery, and VoIP/SIP abuse capabilities.

Once deployed, it establishes persistent access, creates hidden root accounts, and abuses Asterisk/SIP services for toll fraud operations. Since VoIP systems are deeply integrated into enterprise environments, delayed detection can lead to prolonged unauthorized access, financial loss, and operational disruption.

โ—๏ธ The malware relies on stealth and defense-evasion techniques designed to survive cleanup attempts and complicate containment for SOC and IR teams once systems are compromised. MITRE ATT&CK techniques observed include:
๐Ÿ”น ๐—ฃ๐—ฒ๐—ฟ๐˜€๐—ถ๐˜€๐˜๐—ฒ๐—ป๐—ฐ๐—ฒ via Cron jobs and Unix shell configuration abuse
๐Ÿ”น ๐——๐—ฒ๐—ณ๐—ฒ๐—ป๐˜€๐—ฒ ๐—ฒ๐˜ƒ๐—ฎ๐˜€๐—ถ๐—ผ๐—ป through log clearing, timestomping, and firewall modification
๐Ÿ”น ๐—–๐—ฟ๐—ฒ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐—ฎ๐—น ๐—ฎ๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ targeting `/etc/passwd` and `/etc/shadow`
๐Ÿ”น ๐—–๐—ผ๐—บ๐—ฝ๐—ฒ๐˜๐—ถ๐˜๐—ถ๐˜ƒ๐—ฒ ๐—ฒ๐˜ƒ๐—ถ๐—ฐ๐˜๐—ถ๐—ผ๐—ป of other webshells from compromised systems
๐Ÿ”น ๐—ฉ๐—ผ๐—œ๐—ฃ/๐—ฆ๐—œ๐—ฃ ๐—ฎ๐—ฏ๐˜‚๐˜€๐—ฒ supporting toll fraud operations

Execution chain:
Vulnerable FreePBX instance โžก๏ธ Exploit public vulnerabilities โžก๏ธ Bash stager deployment โžก๏ธ JOMANGY webshell deployment โžก๏ธ Multiple persistence mechanisms โžก๏ธ Self-healing loop โžก๏ธ VoIP/SIP abuse

๐Ÿ‘จโ€๐Ÿ’ป Using #ANYRUN Sandbox, investigate JOMANGY behavior in real time, validate detection coverage, and observe webshell deployment, persistence mechanisms, and outbound C2 activity: https://app.any.run/tasks/6c779f0e-e422-4ef5-9bc7-6a799480cc20/?utm_source=mastodon&utm_medium=post&utm_campaign=jomangy_webshell&utm_content=linktoservice&utm_term=280526

Earlier visibility into persistence and webshell behavior helps SOC teams accelerate containment and reduce attacker dwell time. IOCs in the comments ๐Ÿ’ฌ

๐Ÿ” #ANYRUN TI Lookup reveals two active JOMANGY infrastructure clusters tied to attacker-controlled C2 servers, with activity traced back to April 2026. This visibility helps threat hunters uncover related activity, identify compromised environments, and track infrastructure reuse across campaigns: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=jomangy_webshell&utm_content=linktotilookup&utm_term=280526#%7B%2522query%2522:%2522destinationIP:%255C%2522160.119.69.4%255C%2522%2520OR%2520destinationIP:%255C%252245.95.147.178%255C%2522%2522,%2522dateRange%2522:180%7D

๐Ÿš€ Scale your SOCโ€™s triage and response with solutions trusted by 74 Fortune 100 companies and detect business risks earlier. Get an exclusive 10th anniversary deal for your team: https://app.any.run/plans/?utm_source=mastodon&utm_medium=post&utm_campaign=jomangy_webshell&utm_content=linktoplans&utm_term=280526

#cybersecurity #infosec

โšก Connect #ANYRUN with your SIEM, SOAR, or EDR, and make triage faster, response sharper, and threat hunting deeper, without disruption.

๐ŸŽฏ Maximize your security stack performance with special deals: https://any.run/plans/?utm_source=mastodon&utm_medium=post&utm_campaign=integrations_and_connectors&utm_term=280526&utm_content=linktoplans

Find your vendor: https://any.run/integrations/?utm_source=mastodon&utm_medium=post&utm_campaign=integrations_and_connectors&utm_term=280526&utm_content=linktointegrations

๐Ÿšจ #๐—ž๐—ฎ๐—น๐—ถ๐Ÿฏ๐Ÿฒ๐Ÿฑ ๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ถ๐˜๐˜† ๐—ฆ๐˜‚๐—ฟ๐—ด๐—ฒ๐˜€: ๐——๐—ฒ๐˜ƒ๐—ถ๐—ฐ๐—ฒ ๐—–๐—ผ๐—ฑ๐—ฒ ๐—ฃ๐—ต๐—ถ๐˜€๐—ต๐—ถ๐—ป๐—ด ๐—œ๐˜€ ๐—ฆ๐—ฐ๐—ฎ๐—น๐—ถ๐—ป๐—ด ๐—™๐—ฎ๐˜€๐˜
Weโ€™re seeing a growing Device Code #phishing activity, with Kali365 emerging as one of the most active PhaaS. In the last 24 hours alone, #ANYRUN recorded 100+ related analysis sessions.

โš ๏ธ The attack abuses legitimate Microsoft device authentication flows. Victims are shown a user code and instructed to enter it into a real Microsoft device auth page, allowing attackers to capture OAuth access tokens instead of passwords. The risk shifts from credential theft to token abuse, while significantly reducing the number of traditional phishing indicators typically used for detection and triage.

โ—๏ธ Deobfuscated Kali365 JavaScript revealed that after a verification gate, the lure deploys a phishing page, launches a legitimate Microsoft device authentication flow, and then polls /api/status/<session_id> for session states such as captured, expired, and declined.

๐Ÿ“Œ The code also contains lure-template generators for OneDrive, SharePoint, Teams, Outlook, and Voicemail, and a separate Google device-code authentication flow.

โšก๏ธ #ANYRUN lets analysts safely reconstruct the flow, validate suspicious OAuth activity faster, and identify related phishing infrastructure before campaigns scale further, helping SOC teams reduce investigation time, improve detection accuracy, and lower MTTR.

๐Ÿ‘จโ€๐Ÿ’ป See the full phishing flow, validate detection logic, and collect #IOCs: https://app.any.run/tasks/d078f430-c3cc-44e8-a809-5506205049c3?utm_source=mastodon&utm_medium=post&utm_campaign=kali365_activity_surges&utm_content=linktoservice&utm_term=270526

๐Ÿ” Track Kali365 activity using this TI Lookup search query: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=kali365_activity_surges&utm_content=linktotilookup&utm_term=270526#%7B%2522query%2522:%2522threatName:%255C%2522kali365%255C%2522%2522,%2522dateRange%2522:7%7D%20

๐Ÿš€ Scale your SOCโ€™s triage and response with solutions trusted by 74 Fortune 100 companies and detect business risks earlier. Get an exclusive 10th anniversary deal for your team: https://app.any.run/plans/?utm_source=mastodon&utm_medium=post&utm_campaign=kali365_activity_surges&utm_content=linktoplans&utm_term=270526

#cybersecurity #infosec

๐Ÿš€ 10 years ago, #ANYRUN started as one analystโ€™s attempt to make malware analysis faster.

Today, 10,000+ companies use it daily.

โšก๏ธ Read an exclusive interview with CEO Aleksey Lapshin on growth, AI, and why human expertise still matters: https://any.run/cybersecurity-blog/ceo-interview-anyrun-10-years/?utm_source=mastodon&utm_medium=post&utm_campaign=ceo_interview_anyrun_10_years&utm_content=linktoblog&utm_term=270526

What an amazing time at CONFidence 2026 ๐Ÿ‡ต๐Ÿ‡ฑ

Big thanks to the cybersecurity professionals who stopped by our stand, joined a demo, and shared their SOC challenges ๐Ÿ™Œ

โšก๏ธ The conversations donโ€™t stop here. Explore how #ANYRUN supports SOC workflows: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=confidence&utm_content=linktoenterprise&utm_term=270526

Enterprise security solutions to boost SOC performance with ANY.RUN

Enterprise companies cut costs, speed up investigations, and prevent breaches with ANY.RUNโ€™s malware analysis and threat intelligence, trusted by 15K+ orgs.

ANY.RUN