ANY.RUN

New Phishing Trends: How SOC Leaders Should Respond 

Modern phishing increasingly abuses legitimate authentication workflows, trusted infrastructure, and encrypted browser sessions.  This forces SOCs to rethink how they investigate, detect, and respond. Here are key...

When Trusted Gov Infrastructure Becomes an Attack Channel: PhantomEnigma Puts Banks at Risk 

A recent attack investigated by ANY.RUN experts revealed how attackers used more than 20 hijacked Brazilian government websites to support a campaign targeting banking organizations.  By...

Kratos Uses Cloudflare Turnstile, Obfuscated Login Pages, and PHP Endpoints to Exfiltrate Credentials

The kit combines trusted cloud services, Cloudflare Turnstile challenges, convincing Microsoft login clones, and PHP-based credential collection endpoints to evade detection and steal enterprise...

How Threat Intelligence Feeds Power SOC Automation Without Creating New Risks 

Security operations centers are automating faster than ever.  Alerts are enriched automatically. Domains are blocked without human approval. Endpoints are isolated. Tickets are created, prioritized,...

New Kratos PhaaS Campaign Attack Organizations with a Harder-to-Detect Phishing Flow

Kratos PhaaS activity is rising across Europe, with more than 100 related analysis sessions recorded in ANY.RUN’s Interactive Sandbox over the past week. The...

Popular

Subscribe