home.social

#anyrun — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #anyrun, aggregated by home.social.

fetched live
  1. Hackers Let Microsoft 365 Users Complete MFA, Then Steal Logged-In Sessions

    Indicators extracted from public reporting. Source: any.run/cybersecurity-blog/mir

    Pulse ID: 6a85e017727bae50935fe71a
    Pulse Link: otx.alienvault.com/pulse/6a85e
    Pulse Author: CyberHunter_NL
    Created: 2026-08-19 16:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #2FA #ANYRUN #CyberSecurity #HTTP #HTTPS #InfoSec #MFA #Microsoft #OTX #OpenThreatExchange #Phishing #RCE #bot #CyberHunter_NL

  2. MacSync Stealer: C2 Infrastructure Rotation

    On 5 May 2026, a Jamf Protect deployment blocked a download attempt from jacksonvillemma[.]com, four days after the operator's previous MacSync C2 was publicly disclosed. The new C2's TLS certificate was issued within 24 hours of that disclosure. Analysis revealed a Stage 2 zsh loader containing a static api-key value observed across four distinct C2 domains spanning December 2025 to May 2026. URI-pattern pivoting through any.run identified eleven additional candidate C2 domains dating back to February 2026, suggesting parallel infrastructure operation rather than sequential rotation. The loader exfiltrates macOS credentials, browser data, and cryptocurrency wallets, and transmits the victim's account password in cleartext via URL query strings, making it visible in web proxy logs.

    Pulse ID: 6a84bafb3c129cc2f9de2762
    Pulse Link: otx.alienvault.com/pulse/6a84b
    Pulse Author: AlienVault
    Created: 2026-08-18 20:05:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ANYRUN #Browser #CyberSecurity #InfoSec #Mac #MacOS #OTX #OpenThreatExchange #Password #Proxy #RAT #TLS #Word #bot #cryptocurrency #AlienVault

  3. North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring

    Indicators extracted from public reporting. Source: any.run/cybersecurity-blog/laz

    Pulse ID: 6a82e8d11134c2cd6f7e0e58
    Pulse Link: otx.alienvault.com/pulse/6a82e
    Pulse Author: CyberHunter_NL
    Created: 2026-08-17 10:56:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ANYRUN #CyberSecurity #Government #HTTP #HTTPS #InfoSec #Korea #Lazarus #NorthKorea #OTX #OpenThreatExchange #RAT #RCE #bot #CyberHunter_NL

  4. Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

    Indicators extracted from public reporting. Source: any.run/cybersecurity-blog/laz

    Pulse ID: 6a7b1bec6c53b12a73b05e32
    Pulse Link: otx.alienvault.com/pulse/6a7b1
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 12:56:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ANYRUN #CyberSecurity #HTTP #HTTPS #InfoSec #Korea #Lazarus #NorthKorea #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  5. Well, I guess I'm going to be suggesting #AnyRun to the company I work for as a new(first) sandbox detonation option.

    Anyone have any experience or insights they'd like to give me before I make a pitch?
    #SysAdmin #phishing #email

  6. Hackers Turned Microsoft Logins, Zoom Events, and Government Websites Into Attack Tools

    Indicators extracted from public reporting. Source: any.run/cybersecurity-blog/maj

    Pulse ID: 6a7379662864666304e8c4cf
    Pulse Link: otx.alienvault.com/pulse/6a737
    Pulse Author: CyberHunter_NL
    Created: 2026-08-05 17:56:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ANYRUN #CyberSecurity #Government #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #Zoom #bot #CyberHunter_NL

  7. GUI ценой приватности: разбор вредоносного форка Zapret 2 GUI

    Из за замедления YouTube, Discord и других популярных сервисов в РФ спровоцировало настоящий бум инструментов для обхода DPI. Флагманский проект zapret от @bol-van - мощное решение, но его консольный интерфейс пугает рядового пользователя. На этой почве выросли десятки GUI-оболочек «для домохозяек».. Однако за красивым интерфейсом и обещанием «обхода в один клик» может скрываться нечто большее, чем просто прокси-клиент. В этой статье я разберу форк «Zapret 2 GUI» (автор censorliber), который набрал сотни звезд на GitHub, но при детальном анализе оказался полноценным инструментом для шпионажа и компрометации системы..

    habr.com/ru/articles/1015380/

    #zapret #обход_блокировок #dpi #malware #trojan #mitm #аудит_кода #ANYRUN #reverse_engineering