๐ฅ We โhiredโ Lazarus APT remote workers โ and uncovered their toolkit.
@BirminghamCyber & @north_scan used #ANYRUN Sandbox to capture weeks of Famous Chollima activity inside a fake startup.
๐ How not to let a spy in? See full story and videos: https://t.co/IOUZmZEjJQ
๐จ An RMM #phishing campaign spans 46 countries with 44% of activity in the US. Legitimate signed RMM software as payload: no malware verdict, no AV flag.
โก๏ธ #ANYRUN exposes the delivery chain and expands IOCs into the widerย campaign:ย https://t.co/Zmg1017iZd
โก Reactive security hurts resilience.
#ANYRUN givesย enterprise SOCs and MSSPsย a different operational model, where detection is continuously fueled by fresh intelligence.
See how to build intelligence-driven threat monitoring with #ANYRUN ๐
https://t.co/MO9gWmH7yp
๐ What changed in #ANYRUN this August?
A new Connections experience in TI Lookup helps analysts uncover related infrastructure faster โก
Plus, 656+ new rules and fresh research on active campaigns.
See how these updates strengthen your SOC response ๐
https://t.co/q1wv2HLrXr
๐จ Typosquatting packages on PyPI are targeting ๐ฟ๐ฒ๐พ๐๐ฒ๐๐๐, one of the most widely used Python packages. Catch them before compromise.
Attack timeline: 3 hours ago, a new PyPI account was registered. One hour later, four packages were published: 0requests, py-0requests, py-1requests, and py-2equests.
โ ๏ธ On import, each package:
โ collects env vars prefixed SECRET / API / TOKEN / KEY
โ sends them over a raw TCP socket
โ spawns a reverse shell hook
The callback currently points to 127.0.0.1, so the payload is staged, not armed, but the host is read from TS_HOST. One update could switch exfiltration to a live C2 channel and turn it into an active supply-chain threat โ๏ธ
๐จโ๐ป Full behavior analysis and IOCs in #ANYRUN Sandbox: https://t.co/wmT4bjqbo5
๐ All packages on PyPI: https[:]//pypi[.]org/user/preet780/
A mistyped dependency in a CI/CD pipeline can be enough to leak credentials. Catch it before the package becomes a real compromise with #ANYRUN: https://t.co/rc55Cne7cF
โ ๏ธ Infostealers circulate at high volume across US organizations and can feed into ransomware intrusions.
โย Law enforcement disruptionsย don'tย shrinkย demand. When Lumma Stealer was disrupted in 2025, Remus Stealerย emergedย as a direct technical successor within weeks. Criminal demand migrates, not diminishes,ย and the new generation adds session cookie theft that bypasses MFA outright.
Do not treat a stealer detection as a contained incident ๐จ
See how #ANYRUN's behavioral evidence and Threat Intelligence help prevent incidents:ย https://t.co/N7uj4zql1X
๐จ We uncovered #N0va, a new phishkit targeting organizations in North America and Europe across government, technology, consulting, and healthcare.
โ๏ธ It splits its infrastructure across compromised legitimate sites and shared/cloud hosting, including Cloudflare Workers and Linode Object Storage.
Observed lures: Microsoft Security, Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, Adobe Sign.
โ ๏ธ N0va uses Device Code phishing to obtain access and refresh tokens through legitimate Microsoft authentication, then moves toward PRT-based SSO access via token exchange and device registration. The risk is fragmented visibility: no single layer shows the full attack.
๐จโ๐ป #ANYRUN Sandbox helps reveal browser behavior, extract IOCs, and pivot to related activity faster. Review the analysis sessions and improve your detection coverage:
๐น Microsoft-themed lure: https://t.co/xaV5IuAjJS
๐น DocuSign-themed lure: https://t.co/cZB106qvpk
๐ฌ Find IOCs in the comments and let us know which detection layer would give you the earliest signal.
๐ Track N0va activity and uncover related infrastructure in TI Lookup: https://t.co/aVno9dNKoi
โก๏ธ Strengthen your SOC, detect complex threats faster, and boost team performance with #ANYRUN: https://t.co/FbaYwM84XU
โ ๏ธ Active in August 2026. Three widespreadย PhaaSย kits tracked by #ANYRUN:
๐นย #Sneaky2FAย intercepts M365 session cookies in real time acrossย nearly 100ย identified phishing domains:ย https://t.co/ar56XLpCaj
๐นย #Kali365ย captures OAuth tokens after genuine MFA, with AI-generated lures in 15 languages and 34 brand templates: https://t.co/gRco2LbhZd
๐นย #EvilTokensย uses compromised M365 accounts that pass SPF, DKIM & DMARC, then captures OAuth tokens valid for up toย 90 days: https://t.co/V5sE5eF1Ir
๐ See live data on each kit and keep your detections current.
๐ MSSP margins disappear one investigation at a time.
Manual enrichment, unnecessary escalations, and stale threat data add analyst time to every case โณ
How to cut friction, reduce MTTR by up to 21 min/case, and give your team room to scale ๐
https://t.co/xJhR4iUIhh
๐จ US & EU organizations faced a new wave of high-impact attacks in August.
From M365 session hijacking to remote-control malware and fake IT hires, attackers targeted trusted business systems and workflows.
Close the gaps these attacks exposed ๐
https://t.co/j4sG0enMo1
โ ๏ธ Phishing targeting US companies passes static analysis and produces clean verdicts, which is harder to detect.
#ANYRUN closes the visibility gap and builds a consistent investigation process โก
๐ฏ Improve phishing detection in your SOC: https://t.co/7kgKvqJOWK
๐จ #Makop Ransomware targets vulnerable perimeters, demanding an average $15,000 extortion payment.
Businesses face severe operational downtime and massive data recovery costs โ ๏ธ
Here's how SOC teams can detect and mitigate this threat: https://t.co/erzuutjL9p
โ ๏ธ Growth wasn't limited to a single malware category last week. RATs, stealers, loaders, and even ransomware all moved higher, led by #Medusa, #AsyncRAT, #XWorm, and #DCRat.
๐ Trend to watch: when multiple malware types accelerate together, defenders should expect a broader range of attack scenarios rather than a spike in one specific threat.
Monitor the malware driving todayโs attacks: https://t.co/GRZMEh5pi4
#Top10Malware
โ ๏ธ As attacker infrastructure changes, intelligence needs to reach detection just as fast.ย ย
โก #ANYRUN TI Feeds deliver fresh IOCs via STIX/TAXII to enrich alerts, trigger playbooks, and block threats faster.ย ย
๐ฅ Keep your detection current with TI Feeds: https://t.co/366sP6tMii
๐จA US-first phishing campaign is rotating domains, hosting, and RMM tools to evade detection.
The infrastructure changes, but the delivery chain is the same.
โก#ANYRUN exposed its patterns and linked persistent indicators to cases across 46 countries: https://t.co/3f0ScozkIZ
๐ช๐ฒ ๐๐ป๐ฐ๐ผ๐๐ฒ๐ฟ๐ฒ๐ฑ ๐ป๐ฒ๐ .๐ก๐๐ง ๐ฅ๐๐ง โ ๐ฆ๐ป๐ฎ๐ธ๐ฒ๐๐ถ๐๐ฒ๐๐ด๐ฒ๐ป๐. An implant pulled from a business-themed ZIP, which hands the attacker full remote control, credential access, and persistent surveillance.
โ ๏ธ 274 methods with no obfuscation and nothing encrypted on the wire.
C2 communication uses a TCP-based protocol. Each message is sent as a single line in the ๐ฆ๐๐ฒ๐ฐ|<๐ฏ๐ฎ๐๐ฒ๐ฒ๐ฐ(๐๐ฒ๐ ๐)> format. Responses from the C2 server contain the same text without the SB64 wrapper.
๐จโ๐ป Execution chain, C2 protocol and detection recommendations are listed in the visuals. See the analysis sessions:
๐ธ https://t.co/VB12zBgeyR
๐ธ https://t.co/DMwoGwbTXm
๐ Strengthen your SOC with #ANYRUN: https://t.co/BzFsf7Ho6h