#anyrun — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #anyrun, aggregated by home.social.
-
Hackers Let Microsoft 365 Users Complete MFA, Then Steal Logged-In Sessions
Indicators extracted from public reporting. Source: https://any.run/cybersecurity-blog/mirage2fa-phishing-targets-us-companies/?utm_source=eha&utm_medium=newsletter&utm_campaign=mirage2fa&utm_content=task&utm_term=200826
Pulse ID: 6a85e017727bae50935fe71a
Pulse Link: https://otx.alienvault.com/pulse/6a85e017727bae50935fe71a
Pulse Author: CyberHunter_NL
Created: 2026-08-19 16:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#2FA #ANYRUN #CyberSecurity #HTTP #HTTPS #InfoSec #MFA #Microsoft #OTX #OpenThreatExchange #Phishing #RCE #bot #CyberHunter_NL
-
MacSync Stealer: C2 Infrastructure Rotation
On 5 May 2026, a Jamf Protect deployment blocked a download attempt from jacksonvillemma[.]com, four days after the operator's previous MacSync C2 was publicly disclosed. The new C2's TLS certificate was issued within 24 hours of that disclosure. Analysis revealed a Stage 2 zsh loader containing a static api-key value observed across four distinct C2 domains spanning December 2025 to May 2026. URI-pattern pivoting through any.run identified eleven additional candidate C2 domains dating back to February 2026, suggesting parallel infrastructure operation rather than sequential rotation. The loader exfiltrates macOS credentials, browser data, and cryptocurrency wallets, and transmits the victim's account password in cleartext via URL query strings, making it visible in web proxy logs.
Pulse ID: 6a84bafb3c129cc2f9de2762
Pulse Link: https://otx.alienvault.com/pulse/6a84bafb3c129cc2f9de2762
Pulse Author: AlienVault
Created: 2026-08-18 20:05:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ANYRUN #Browser #CyberSecurity #InfoSec #Mac #MacOS #OTX #OpenThreatExchange #Password #Proxy #RAT #TLS #Word #bot #cryptocurrency #AlienVault
-
North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring
Indicators extracted from public reporting. Source: https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/
Pulse ID: 6a82e8d11134c2cd6f7e0e58
Pulse Link: https://otx.alienvault.com/pulse/6a82e8d11134c2cd6f7e0e58
Pulse Author: CyberHunter_NL
Created: 2026-08-17 10:56:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ANYRUN #CyberSecurity #Government #HTTP #HTTPS #InfoSec #Korea #Lazarus #NorthKorea #OTX #OpenThreatExchange #RAT #RCE #bot #CyberHunter_NL
-
Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers
Indicators extracted from public reporting. Source: https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/
Pulse ID: 6a7b1bec6c53b12a73b05e32
Pulse Link: https://otx.alienvault.com/pulse/6a7b1bec6c53b12a73b05e32
Pulse Author: CyberHunter_NL
Created: 2026-08-11 12:56:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ANYRUN #CyberSecurity #HTTP #HTTPS #InfoSec #Korea #Lazarus #NorthKorea #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Hackers Turned Microsoft Logins, Zoom Events, and Government Websites Into Attack Tools
Indicators extracted from public reporting. Source: https://any.run/cybersecurity-blog/major-cyber-attacks-july-2026/?utm_source=csn&utm_medium=article&utm_campaign=july_attacks_26&utm_content=blog&utm_term=050826
Pulse ID: 6a7379662864666304e8c4cf
Pulse Link: https://otx.alienvault.com/pulse/6a7379662864666304e8c4cf
Pulse Author: CyberHunter_NL
Created: 2026-08-05 17:56:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ANYRUN #CyberSecurity #Government #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #Zoom #bot #CyberHunter_NL
-
GUI ценой приватности: разбор вредоносного форка Zapret 2 GUI
Из за замедления YouTube, Discord и других популярных сервисов в РФ спровоцировало настоящий бум инструментов для обхода DPI. Флагманский проект zapret от @bol-van - мощное решение, но его консольный интерфейс пугает рядового пользователя. На этой почве выросли десятки GUI-оболочек «для домохозяек».. Однако за красивым интерфейсом и обещанием «обхода в один клик» может скрываться нечто большее, чем просто прокси-клиент. В этой статье я разберу форк «Zapret 2 GUI» (автор censorliber), который набрал сотни звезд на GitHub, но при детальном анализе оказался полноценным инструментом для шпионажа и компрометации системы..
https://habr.com/ru/articles/1015380/
#zapret #обход_блокировок #dpi #malware #trojan #mitm #аудит_кода #ANYRUN #reverse_engineering
-
How to Avoid Phishing Incidents in 2026: A CISO Guide https://hackread.com/how-to-avoid-phishing-incidents-2026-ciso-guide/ #Cybersecurity #PhishingScam #Security #Phishing #Sandbox #ANYRUN #CISO #Scam
-
Fixing a Slow SOC: Top 3 Solutions that Actually Work https://hackread.com/fixing-soc-top-3-solutions-that-work/ #ThreatIntelligence #Cybersecurity #Security #ANYRUN #SOC
-
How to Achieve Ultra-Fast Response Time in Your SOC https://hackread.com/how-to-achieve-ultra-fast-soc-response-time/ #ThreatIntelligence #ThreatDetection #ThreatAnalysis #Cybersecurity #Security #ANYRUN #SOC
-
Top 3 Malware Families in Q4: How to Keep Your SOC Ready https://hackread.com/top-3-malware-families-in-q4-how-to-keep-your-soc-ready/ #ThreatIntelligence #Cybersecurity #Vulnerability #LummaStealer #AgentTesla #Security #Malware #ANYRUN #XWorm #SOC