HomeMalware Analysis
Major Cyber Attacks in July 2026: US and EU Organizations Hit by Phishing, RATs, and Stealers
HomeMalware Analysis
Major Cyber Attacks in July 2026: US and EU Organizations Hit by Phishing, RATs, and Stealers

July 2026 showed how trusted business workflows can quickly turn into account takeover, data exposure, fraud, and persistent access. ANY.RUN observed attacks that put cloud accounts, financial processes, sensitive data, and business continuity at risk across the US, Europe, and Brazil.

Here are the major attacks from July, the business risks they exposed, and the actions security leaders should prioritize to contain them faster.

What July’s Attacks Revealed About Enterprise Risk

July’s attacks showed how easily routine business activity can become a path to account compromise, data exposure, fraud, and operational disruption. Attackers used trusted platforms, legitimate authentication flows, familiar documents, and built-in system tools to reduce suspicion and delay the moment when security teams could confirm the true scale of an incident.

Trusted business services created false confidence: SharePoint, OneDrive, Zoom Events, Microsoft authentication pages, and compromised government systems appeared in attack chains. Their presence made malicious activity look more credible and increased the chance that employees or security controls would allow it to continue.

Identity attacks threatened core business workflows: Kratos and Kali365 put Microsoft 365 accounts, corporate email, shared files, supplier communication, and payment conversations at risk. In cases involving active sessions, refresh tokens, or OAuth access, changing a password alone might not fully remove the attacker.

A single endpoint could expose access across the business: DestinyStealer, Banana RAT, DARTHVADER Stealer, and OVERLORD RAT collected or targeted browser credentials, cookies, Outlook data, VPN access, file-transfer accounts, cryptocurrency wallets, and other sensitive information. One infected device could therefore create exposure across several systems and require a much broader response than endpoint cleanup alone.

Legitimate tools made malicious activity harder to separate from normal operations: PowerShell, AutoIt, Windows utilities, trusted applications, and cloud services helped attackers hide inside familiar system activity. This increased the risk of delayed containment, unnecessary escalations, and longer investigations.

Changing infrastructure weakened indicator-only defenses: Several campaigns rotated domains, command-and-control servers, or delivery paths. Blocking one URL or IP address could stop only a small part of the operation, while related activity continued elsewhere.

Incomplete context increased response costs: A clean initial verdict, a legitimate first-stage URL, or one isolated alert did not always reveal the full compromise. Without a clear view of affected accounts, stolen data, persistence, and follow-on activity, leaders could underestimate business exposure or approve containment actions that were either too narrow or unnecessarily disruptive.

Strengthen your entire SOC to close blind spots.
Integrate ANY.RUN for faster MTTR and MTTD.

Stengthen SOC response

Who Attackers Targeted in July

July’s campaigns reached organizations across the United States, Europe, and Brazil, with activity affecting both private and public-sector environments.

Target Group  Campaigns and Observed Focus 
Microsoft 365 users  Kratos and Kali365 targeted cloud accounts across the US and Europe. 
US enterprises  Kali365 activity appeared across manufacturing, technology, healthcare, government, consulting, and MSSPs. 
European organizations  Kratos affected SMBs, law firms, schools, polytechnic institutions, and industrial organizations, with a strong concentration in Spain and Southern Europe. 
Banking organizations in Brazil  Banana RAT was associated with banking sessions and Pix-related fraud, while PhantomEnigma targeted the financial sector. 
Brazilian public-sector organizations  PhantomEnigma used police and legal themes and compromised government infrastructure during delivery. 
Employees handling business documents  Invoice, DocuSign, document-sharing, and fake PDF lures targeted users accustomed to opening external files. 
Staff engaging with partners and events  Fake Meta, OpenAI, and Anthropic summits targeted users through Zoom-themed event invitations. 
Users with stored account data  DestinyStealer focused on credentials and information held in browsers, Outlook, VPN clients, FileZilla, Wi-Fi profiles, and wallet extensions. 

The targeting was broad, but not random. Attackers focused on users and sectors with access to cloud accounts, financial activity, sensitive records, and trusted external communications.

1. Kratos Put Microsoft 365 Accounts and Business Workflows at Risk Across the US and Europe

In July, ANY.RUN researchers documented Kratos, a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the United States, Europe, and other regions. The campaign used document-sharing, DocuSign, and invoice lures, often routing victims through trusted services such as SharePoint, OneDrive, Microsoft Forms, Canva, and Tilda before displaying a fake Microsoft login page.

Check detailed breakdown

Kratos analysis
Attack chain of Kratos phishing campaign

For organizations, the risk extended beyond a stolen password. Compromised accounts could expose corporate email, cloud files, supplier communication, and payment workflows, supporting business email compromise, payment redirection, data exposure, and fraudulent requests from trusted accounts. Some sessions also established WebSocket connections, which may indicate possible adversary-in-the-middle activity or live credential relaying, although this alone does not confirm session theft.

Account takeover risk to address: A password reset may not fully contain the incident if attackers have already gained access to an active Microsoft 365 session. Organizations should review sign-in activity, revoke active sessions and refresh tokens when needed, and determine whether the account was used to access sensitive files, financial conversations, or external partner communications. Teams should also trace the full redirect chain rather than broadly blocking trusted services that may have served only as an intermediate step.

2. PhantomEnigma Abused Trusted Government Systems to Reach Banks and Public-Sector Targets

PhantomEnigma targeted banking and public-sector organizations in Brazil through fake Polícia Civil and digital power-of-attorney communications. At least 20 compromised .gov.br municipal and police portals were used to distribute malware, while compromised government mailboxes allowed some phishing emails to pass SPF, DKIM, and DMARC checks. These government systems were part of the delivery chain and were not confirmed as the campaign’s intended targets.

Check detailed breakdown

Phantomenigma timeline
Timeline of PhantomEnigma’s malicious activity

Once installed, the modular backdoor could collect system information, establish persistence, execute commands, and deliver additional payloads such as stealers, loaders, or remote management tools. Rotating command-and-control infrastructure and initial clean verdicts could also cause connected alerts to be investigated separately, delaying containment and increasing the risk of fraud, data exposure, operational disruption, and higher recovery costs.

Investigation gap to close: A single domain, file, or clean initial verdict may reveal only one part of the campaign. Teams need enough context to connect the phishing message, compromised government infrastructure, malware behavior, command-and-control activity, and any additional payloads delivered afterward. This broader view helps security leaders understand whether they are dealing with one isolated alert or a coordinated operation affecting multiple users or systems, so containment can begin before the business impact grows.

3. Kali365 Turned Legitimate Microsoft Sign-Ins into Cloud Access Risk for US Organizations

Kali365 targeted U.S. organizations with device code phishing that abused Microsoft’s legitimate authentication process. Instead of collecting passwords through a fake login page, the kit directed victims to Microsoft’s real device login page and persuaded them to enter an attacker-controlled code. More than 80 related public sandbox sessions were recorded each week, with activity observed across MSSPs, manufacturing, technology, government, healthcare, and consulting.

Check detailed breakdown

Kali industries it targets
US industries being targeted by Kali 365

Successful authentication could give attackers OAuth access and refresh tokens, potentially providing continued access to corporate email, documents, and cloud resources without directly stealing the victim’s password. Because the login took place on a legitimate Microsoft page, the activity could appear routine, delaying detection while attackers accessed sensitive data, altered business communications, or used trusted accounts for fraud.

Reduce the cost of delayed threat confirmation.
Give your SOC the evidence to contain attacks before exposure spreads.

Cut Response Time

Access control to strengthen: Device code authentication should be limited to users and workflows that genuinely require it. Organizations should also investigate unexpected authorization requests and unusual access to Microsoft 365 services. Because Kali365 sends victims through a legitimate Microsoft login page, ANY.RUN helps reveal the original lure, redirects, and device-code flow that may otherwise look safe.

4. Banana RAT Increased Fraud Risk by Evolving Its Remote Access Capabilities

Banana RAT is a banking-focused remote access trojan associated with Brazilian financial activity, including banking sessions and Pix-related fraud. Research published in July compared two branches tied to the same staging infrastructure. The older branch used fixed Microsoft-style filenames and installation paths, while the newer version introduced randomized identifiers, stronger persistence, and encrypted WebSocket communication through host-specific subdomains.

Banana RAT
TI Lookup quickly links an isolated hash to the full BananaRAT sample complete with a sandbox session

The newer branch could monitor screens and sessions, capture keyboard input, transfer files, control the infected system remotely, and maintain access through scheduled tasks or registry-based persistence. For banks and businesses handling payments, an infected endpoint could expose credentials, enable fraudulent transactions, and give attackers continued access even after the original malicious file is removed.

Evolving threat to track: Blocking one filename, path, or server may not stop Banana RAT as operators continue changing how the malware installs itself and communicates. Teams need behavioral context that connects hidden PowerShell activity, persistence, remote-control capabilities, and network communication across different variants. ANY.RUN helps compare related samples and reveal the stable behavior behind changing artifacts, allowing security teams to update detection and containment before a new branch affects more systems or financial workflows.

5. A Fake PDF Shortcut Turned One Click into Credential Theft and Persistent Access

A malicious LNK file disguised as a PDF launched a multi-stage infection chain using cmd.exe, legitimate Windows utilities, AutoIt, and PowerShell before deploying DARTHVADER Stealer. The attack also establishedpersistence, allowing the compromise to continue beyond the initial click.

Check technical details on Linkedin

ANY.RUN’s sandbox revealing all the hidden processes
ANY.RUN’s sandbox revealing all the hidden processes

The chain used hidden command execution, curl.exe downloads, PowerShell ExecutionPolicy Bypass, mutex creation, and persistence setup. The use of legitimate system tools and reduced command output created fewer obvious artifacts, making the activity harder to trace and potentially delaying containment while the stealer remained active.

Post-click risk to reduce: Security controls should not stop at checking whether a file looks like a PDF or whether a trusted Windows utility was used. Teams need visibility into what happens after the shortcut is opened, including hidden commands, downloaded components, PowerShell activity, AutoIt execution, and persistence. ANY.RUN helps expose this sequence in one analysis, giving teams the evidence needed to identify the stealer and contain affected systems before stolen data or persistent access creates wider business impact.

6. Live Attacker Control Exposed Organizations to Data Theft and Continued Access

While analyzing a PythonRAT infection, ANY.RUN observed the attacker connect to the compromised system, upload another payload, and deploy OVERLORD RAT in real time. The activity, seen targeting Germany and the UK, showed that the initial infection was only the first step in a broader compromise.

Check technical details on Linkedin

 OVERLORD is delivered via live C2 channel
ANY.RUN reveals how OVERLORD is delivered via live C2 channel

OVERLORD gave the attacker extensive control over the system, including access to files, browser data, messages, cryptocurrency wallets, keyboard input, and audio. During 45 minutes of analysis, the agent transmitted approximately 86 MB of data, highlighting how quickly one infected endpoint can turn into a serious data exposure and remote-access incident.

Stop initial infections from becoming active compromise.
Contain threats before sensitive data is exposed.

Contain Threats Earlier

Business exposure to confirm: An initial malware alert may not show whether an attacker is already active inside the environment. Interactive analysis in ANY.RUN revealed the operator’s actions and the additional payload as they appeared, helping teams understand the true scope of the compromise and move faster to isolate the system, protect exposed accounts, and prevent further access.

7. Fake Zoom Events Put Trusted Partner Communications at Risk

A multi-flow phishing campaign used legitimate Zoom event pages to promote fake virtual summits linked to Meta, OpenAI, and Anthropic. The invitations appeared to offer access to events such as the Meta Agency Summit 2026, OpenAI Partner Summit 2026, and Anthropic AI Marketing Summit 2026. After users selected “Continue to register,” they were redirected from events.zoom.us to attacker-controlled domains.

Check technical details on Linkedin

Meta, OpenAI and Anthropic lures
Meta, OpenAI and Anthropic lures used in a multi-flow phishing campaign

The campaign then followed different paths. Some samples used Microsoft device code phishing, while others used an adversary-in-the-middle flow impersonating Microsoft authentication. By starting on a trusted event platform and using familiar technology brands, the attackers reduced suspicion and made the early stages of the campaign less likely to stand out during triage.

Trusted redirect risk to reduce: Security teams should treat event invitations as complete journeys rather than judging only the first page or final destination. Redirects from legitimate SaaS platforms into unexpected authentication flows should be reviewed together, especially when an event registration suddenly asks users to authorize Microsoft access. ANY.RUN helps reproduce these transitions safely and reveal where a credible invitation turns into credential or session compromise.

8. DestinyStealer Put Credentials and Corporate Access Data at Risk Across the US and Europe

DestinyStealer activity increased across Europe and the United States, with the malware operating as an all-in-one data grabber. It collected browser data, cookies, passwords, cryptocurrency wallet extension storage, Outlook and VPN data, FileZilla credentials, Wi-Fi profiles, and desktop screenshots. Its code also showed clear continuity with StormKitty.

Check technical details on Linkedin

DestinyStealer targets US and EU
How DestinyStealer targets organizations across US and EU

Some samples were still undetected on VirusTotal at the time of analysis, while others lacked clear attribution. After checking the victim’s public IP address, the malware collected the stolen information in a temporary directory, packaged it into a ZIP archive, and exfiltrated it through two parallel channels: HTTP and raw TCP. This combination could allow valuable credentials and access data to leave the system before conventional detections provide teams with a clear verdict.

Exposure scope to determine: A DestinyStealer infection should not be treated as a problem limited to one endpoint. Teams need to establish which browsers, email accounts, VPN access, file-transfer credentials, cookies, and cryptocurrency wallets were exposed. Behavior-based analysis in ANY.RUN reveals what the malware collected and where it attempted to send the data, helping security teams identify affected accounts and contain the wider access risk.

Turn July’s Attack Evidence into Stronger SOC Defense

July’s campaigns changed domains, abused trusted services, hid behind legitimate activity, and expanded after the first alert. Reducing exposure requires more than blocking the indicator found in one incident. SOC teams need fresh intelligence for their controls, behavioral evidence for faster investigations, and campaign context for proactive hunting.

1. Keep Security Controls Updated with Fresh Threat Intelligence

Kratos, PhantomEnigma, Banana RAT, and other July threats changed infrastructure, delivery paths, or technical artifacts as their campaigns evolved. A domain or IP address taken from one confirmed incident may quickly lose value, while connected infrastructure remains active elsewhere.

TI Feeds
TI Feeds provides actionable IOCs to your existing stack

ANY.RUN’s Threat Intelligence Feeds deliver newly observed malicious IPs, domains, and URLs to SIEM, SOAR, TIP, firewalls, and other security controls through STIX/TAXII, API, and SDK. The intelligence is drawn from sandbox investigations submitted by more than 15,000 organizations and 600,000 security professionals worldwide, giving teams a continuously updated view of threats seen in real environments.

Each indicator links back to the sandbox session where it was observed, helping defenders validate it before taking action. This is especially important when attackers use compromised websites, shared cloud infrastructure, or legitimate platforms that should not be blocked without review.

2. Give SOC Teams the Evidence to Act Faster

July’s incidents showed how easily an alert can look harmless at first and become much more serious after execution. A trusted URL, familiar sign-in page, or clean initial verdict may reveal little about the access gained, data collected, or attacker activity that follows.

sandbox analysis
Complex phishing investigation inside ANY.RUN’s sandbox

Behavior-based analysis helps teams see what a file or URL actually does after it is opened. ANY.RUN’s Interactive Sandbox reveals redirects, authentication flows, hidden execution, persistence, downloaded payloads, remote-control activity, and data collection in one investigation. This gives Tier 1 the evidence needed to confirm malicious behavior and understand the potential business exposure behind an uncertain verdict.

Ready-made reports bring together the verdict, IOCs, TTPs, screenshots, and behavioral evidence in a shareable format. With the attack chain already documented, teams can make faster containment decisions and hand off complex cases without rebuilding the investigation across several sources.

Turn uncertain alerts into confident response decisions.
Reveal the true scope of threats before impact grows.

Accelerate Threat Response

3. Turn Isolated Alerts into Campaign-Level Intelligence

When related activity is investigated case by case, security teams may miss the scale of the threat and repeat the same work across multiple incidents. The result is slower attribution, weaker hunting, and less time to prepare for the next wave of the campaign.

Kali365 sandbox sessions
Relevant sandbox sessions displayed inside TI Lookup for full context

ANY.RUN’s Threat Intelligence Lookup helps teams connect suspicious files, URLs, infrastructure, behaviors, screenshots, and sandbox sessions across current and historical data. This makes it easier to determine whether an alert is isolated or part of activity already affecting other organizations, sectors, or regions.

Threat Intelligence Reports add analyst-led research on active malware, phishing operations, APTs, and cybercriminal groups. Each report includes investigation findings and ready-to-use TI Lookup queries that teams can apply to threat hunting, detection reviews, and incident enrichment.

TI reports
ANY.RUN’s analyst-led research on active malware, phishing operations, APTs, and cybercriminal groups

Together, TI Lookup and TI Reports help SOC teams move from reacting to one alert at a time to identifying wider campaign activity earlier, uncovering related exposure, and updating defenses before the same threat reaches more users or systems.

About ANY.RUN

ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions, helps SOCs, MSSPs, and enterprise security teams investigate threats faster and make response decisions based on clear behavioral evidence.

Its Interactive Sandbox allows teams to analyze malware, phishing pages, suspicious files, and URLs in a controlled environment while observing the full attack chain in real time. Threat Intelligence built on investigations from more than 15,000 organizations and 600,000 security professionals help teams enrich alerts, uncover related activity, and bring current threat context into detection, hunting, and response workflows.

ANY.RUN is SOC 2 Type II attested, reflecting its commitment to strong security controls and customer data protection. By combining behavior-based analysis with continuously updated threat intelligence, ANY.RUN helps security teams reduce investigation uncertainty, speed up triage, and contain threats before they create wider business impact.

What do you think about this post?

0 answers

  • Awful
  • Average
  • Great

No votes so far! Be the first to rate this post.

0 comments