๐ BIG NEWS: Full URL triage now takes a single click.
Domain data, dynamic DOM changes, hidden scripts โ all visible under Browser Data tab. No more slow investigations. Just see & decide to escalate or close the alert.
Try ultra-fast phishing analysis: https://t.co/StmzR446ad
๐ We're an official @torq_io AMP partner!
Together, we help security teams move from alerts to evidence-backed decisions faster, combining Torqโs automation with #ANYRUNโs real-time malware & phishing analysis and threat intelligence โก๏ธ
Learn more: https://t.co/3esMAaMb2H
โฑ๏ธ Lack of alert context costs your SOC time and money.
โก๏ธ #ANYRUNโs integration for @torq_io helps replace guesswork with high-confidence verdicts and intelligence to slash your MTTR by 21 mins per case.
Streamline your triage and response ๐
https://t.co/QQLMOjsLjD
โ ๏ธ Static detection has limited reachย intoย modern phishing.
#ANYRUN's in-browser data inspectionย catchesย everyย DOM mutation, script execution, redirect, and injected form.
๐จโ๐ป Discover the new standard for URLย analysis: https://t.co/t2FqXcTgdE
๐จ ๐ก๐ฒ๐ ๐ฅ๐ฒ๐ฑ๐ถ๐ฟ๐ฒ๐ฐ๐ ๐๐ฟ๐ฎ๐บ๐ฒ๐๐ผ๐ฟ๐ธ ๐ง๐๐ฟ๐ป๐ ๐๐ฒ๐ด๐ถ๐๐ถ๐บ๐ฎ๐๐ฒ ๐ช๐ฒ๐ฏ๐๐ถ๐๐ฒ๐ ๐๐ป๐๐ผ ๐ฃ๐ต๐ถ๐๐ต๐ถ๐ป๐ด ๐๐ป๐ณ๐ฟ๐ฎ๐๐๐ฟ๐๐ฐ๐๐๐ฟ๐ฒ
Weโre tracking a surge in activity linked to Bulletproof Redirect Engine, a previously unknown framework that helps attackers manage #phishing redirects through compromised legitimate websites.
โ๏ธ Since late April, #ANYRUN has recorded 170+ public submissions linked to this activity, with observed targets mainly in the US and Europe across manufacturing, consulting, and technology.
โ ๏ธ Hosted in hidden directories on compromised sites, the framework uses trusted domain names to generate phishing links and redirect users to pages built with known phishkits: #Sneaky2FA, #Tycoon, #EvilTokens, Greatness, and EvilProxy. Based on the observed activity, the tool is likely distributed as a PhaaS.
Reputation-based URL controls are not enough when phishing infrastructure hides behind trusted domains and obfuscated browser logic. This increases the chance of victim interaction and creates a SOC blind spot that may lead to missed compromise.
โก๏ธ Attack chains like this are now faster and easier to investigate in #ANYRUN Sandbox. In-browser data inspection shows exactly what happens inside the browser, exposing phishing behavior that static URL analysis can miss.
๐จโ๐ป Using the Browser Data tab, we can quickly review requests sent by the redirect page and locate the same activity in the HTML DOM Changes: https://t.co/pobLzcgv55
The code is heavily obfuscated, so the final phishing page is not directly visible in the DOM. But the HTTP Requests tab still exposes the next-stage redirect to an #EvilProxy phishing page impersonating Microsoft sign-in flow. This gives analysts a clear pivot point for detection, investigation, and response โ
๐ Expose phishing activity hidden behind trusted infrastructure and obfuscated browser logic, then turn it into faster triage, sharper response, and stronger detection rules. See how #ANYRUN closes phishing blind spots: https://t.co/nANS7uDw4I
#ExploreWithANYRUN
โ ๏ธ According to #ANYRUN Threat Intelligence data, recent EvilTokens activity is concentrated mainly in the United States and Europe. View the regions and industries at risk using this TI Lookup search query: https://t.co/hk1by5Wsjk
๐จ #EvilTokens can turn a missed browser event into a M365 account takeover. Its โghostโ code stays hidden from static analysis, extending exposure.
โก๏ธ 1 minute was enough to reveal the attack flow. Explore the analysis session: https://t.co/XuTTFM7LR2
๐จโ๐ป Discover how full browser visibility gave the SOC clear evidence to respond: https://t.co/BH2cvrD6KH
โ ๏ธย ๐๐ณ ๐๐ต๐ฒ ๐ด๐ฎ๐๐ฒ๐๐ฎ๐ ๐ณ๐น๐ฎ๐ด๐ด๐ฒ๐ฑ ๐ป๐ผ ๐ฝ๐ต๐ถ๐๐ต๐ถ๐ป๐ด, ๐ต๐ผ๐ ๐ฑ๐ถ๐ฑ ๐๐ต๐ฒ ๐๐๐ฒ๐ฟ ๐ฟ๐ฒ๐ฎ๐ฐ๐ต ๐๐ต๐ฒ ๐ฝ๐ฎ๐๐น๐ผ๐ฎ๐ฑ ๐ฝ๐ฎ๐ด๐ฒ?
Modern phishing attacks are engineered to pass static checks. The first link looks clean. The final page โ credential form, redirect chain, injected scripts โ never gets inspected.
๐ #ANYRUNโs in-browser data inspection closes the visibility gap by showing what happened inside the browser, helping analysts reach a verdict faster with evidence they can use toย contain, escalate, or build detection logic.
โก๏ธย #ANYRUN Sandbox is the verification layer for cases that sit in the gray zone.ย See how SOC teams investigate phishing inside the browser:ย https://t.co/dq2BcXuSxm
๐จ Greatness #PhaaS turns a fake Microsoft 365 login page into a potential BEC, data theft, and payment fraud incident.
๐จโ๐ป Learn how its branded lures, MFA bypass capabilities, and credential theft workflows put business identities at risk: https://t.co/r6venb6Drp
Phishing activity in the past 7 days ๐
Track latest #phishing threats in TI Lookup: https://t.co/LrZHmDvHHy
Here's what your SOC needs to know about rising #Sneaky2FA: https://t.co/CQ9uyWq5ls
#TopPhishingThreats
โ ๏ธ Credential-focused malware remained highly active last week. #Vidar and #Stealc continued to grow, while #AsyncRAT maintained its lead and newer families like #SilentNet and #DonutLoader gained momentum.
๐ Trend to watch: attackers aren't relying on a single access path. Growth across stealers, RATs, and loaders suggests multiple stages of the intrusion chain are being scaled at the same time. For SOC teams, that increases the need to connect isolated signals before they become incidents.
Monitor the malware families driving todayโs attacks: https://t.co/BB31YBdBW5
#Top10Malware
โ How often do your SOC reports drive action? We believe that a report should guide the next decision โก๏ธ
ย ย ย
Our SOC-ready Tier 1 reports, generated automatically after every sandbox analysis, are structured for triage, escalation, and leadership reporting.
Curious how it works in your team. Share your perspective in the comments ๐ฌ
๐จโ๐ป See how SOC teams provide a decision-support layer with standardized Tier 1 reports: https://t.co/oNrboF5GDW
๐ #ANYRUN is the Best Security Investigation Platform 2026 by @TheHackersNews!
This award reflects our mission to help teams act with confidence and make daily security operations smoother ๐
See which SOC-focused improvements helped secure the award ๐
https://t.co/wRwSxeHc2f
โก A single phishing page was used to build a YARA rule that uncovered 145 related samples.
With in-browser data inspection every URL carries pivot-ready evidence for hunting and detection.
๐ See how full browser visibility transforms investigation:ย https://t.co/4EOoQrmMFY
๐ฅ The Q1 2026 data reshaped what a strong security strategy looks like for CISOs.
One core principle: speed of understanding is a critical competitive advantage.
๐ฏ Get the strategic priorities where SOCs need to act faster than ever: https://t.co/0aR62TAHE3
๐จ ๐ช๐ต๐ฎ๐ ๐๐๐ถ๐น๐ง๐ผ๐ธ๐ฒ๐ป๐ ๐๐ถ๐ฑ๐ฒ๐ ๐ถ๐ป ๐๐ต๐ฒ ๐๐ฟ๐ผ๐๐๐ฒ๐ฟ: ๐ฆ๐ฒ๐ฒ ๐๐ฒ๐๐ผ๐ป๐ฑ ๐ฆ๐๐ฎ๐๐ถ๐ฐ ๐จ๐ฅ๐ ๐๐ป๐ฎ๐น๐๐๐ถ๐
#EvilTokens remains one of the most active phishkits in our reports, abusing MS Device Code authentication to gain access through OAuth workflows rather than direct credential theft.
โ๏ธ The landing page content is AES-GCM encrypted in the initial HTML response and becomes visible only after client-side decryption writes it into the browser DOM, making static URL analysis and network-only visibility incomplete.
๐จโ๐ป Review the full phishing flow: https://t.co/w5Q9GNw2gL
๐ #ANYRUN sets a new standard for URL analysis, leaving no blind spots for phishing to exploit. In-browser data inspection shows exactly what happens inside the browser, exposing every phishing URLโs behavior.
โก๏ธ ๐๐ผ๐ ๐๐ผ ๐๐๐ฒ ๐๐ต๐ฒ ๐๐ฟ๐ผ๐๐๐ฒ๐ฟ ๐๐ฎ๐๐ฎ ๐๐ฎ๐ฏ ๐ถ๐ป #๐๐ก๐ฌ๐ฅ๐จ๐ก ๐ฆ๐ฎ๐ป๐ฑ๐ฏ๐ผ๐ ๐ณ๐ผ๐ฟ ๐ณ๐๐น๐น ๐จ๐ฅ๐ ๐๐ถ๐๐ถ๐ฏ๐ถ๐น๐ถ๐๐ ๐๐ต๐ฎ๐ ๐๐ฝ๐ฒ๐ฒ๐ฑ๐ ๐๐ฝ ๐๐ฟ๐ถ๐ฎ๐ด๐ฒ ๐ฎ๐ป๐ฑ ๐ฟ๐ฒ๐๐ฝ๐ผ๐ป๐๐ฒ:
๐๐ง๐ ๐ ๐๐ข๐ ๐๐ต๐ฎ๐ป๐ด๐ฒ๐: Track DOM states over time with timeshift, compare page states, and review byte-level diffs.
๐ In this case, it reveals when the decrypted phishing page is rendered, exposing the user code and other artifacts hidden in the initial response.
๐จ๐ฅ๐ ๐๐ฒ๐๐ฎ๐ถ๐น๐: Review the final URL, domain, SSL certificate, DNS records, request statistics, and triggered signatures in one place.
๐ For device-code phishing, this helps quickly verify suspicious OAuth-related activity without manually correlating multiple data sources.
๐๐ง๐ง๐ฃ ๐ฅ๐ฒ๐พ๐๐ฒ๐๐๐: Inspect browser-level network activity across HTML, JS, Fetch/XHR, scripts, static files, binaries, archives, and other request categories.
๐ Here, requests to /api/device/start retrieve the userCode and sessionId, while /api/device/status/<sessionId> tracks authorization status, providing early confirmation of the phishing flow.
๐๐ป๐ฑ๐ถ๐ฐ๐ฎ๐๐ผ๐ฟ๐: Automatically collect page-level IOCs, including domains, URLs, hashes, IPs, and ASN data.
๐ These indicators provide immediate pivot points for threat hunting, helping analysts expand the investigation beyond the original URL.
โ This turns URL triage from long manual reconstruction into a fast decision path: what loaded, what changed, and whether the case should be contained, escalated, or turned into detection logic.
When phishing relies on dynamic browser behavior, this visibility doesn't just speed up triage โ it strengthens every downstream process: faster escalations, sharper response, stronger detection logic.
๐ See how #ANYRUN closes phishing blind spots: https://t.co/CrYREaljzk
#ExploreWithANYRUN
โ ๏ธ Every delayed triage decision adds pressure to the SOC.
More manual checks, escalations, and time spent before real threats move into response.
โก๏ธ See how #ANYRUN helps teams validate threats faste and reduce operational risk ๐
https://t.co/fwcgeBaGCQ