HomeMalware Analysis
Major Cyber Attacks in August 2026: US and EU Businesses Hit by Session Hijacking, Remote Access, and Insider Risk
HomeMalware Analysis
Major Cyber Attacks in August 2026: US and EU Businesses Hit by Session Hijacking, Remote Access, and Insider Risk

August’s attacks showed how quickly trusted business activity can turn into risk. Across the US and Europe, attackers abused Microsoft 365 sessions, legitimate remote-management tools, business-themed files, and even hiring processes to reach corporate systems.

The result was a mix of account takeover, persistent attacker control, credential exposure, and insider risk that often looked legitimate at first.

Here’s what August’s biggest attacks reveal about where enterprise defenses are under pressure.

What August’s Attacks Revealed About Enterprise Risk

Taken together, August’s incidents point to a broader shift in enterprise risk. Attackers are increasingly targeting the points where organizations already place trust: identities, administrative tools, authentication flows, and employees.

Trusted tools created wider business exposure: Unauthorized RMM software and remote-control malware could give attackers control over credentials, files, and internal systems while blending into normal administration.

Identity compromise threatened core workflows: Mirage2FA and 3DBlast targeted Microsoft 365 sessions, OAuth, device-code authentication, and MFA flows, putting email, cloud files, supplier communication, and finance processes at risk.

MFA did not always end the attack: Stolen sessions could remain valid after authentication, meaning password resets alone might not remove the attacker from the account.

Remote hiring became a security concern: The Famous Chollima investigation showed how false identities could pass recruitment checks and receive legitimate permissions across source code repositories and internal systems, with exposure extending to intellectual property.

Changing infrastructure increased SOC workload: Several campaigns rotated domains, phishing flows, hosting, and remote-access tools, making single-IOC blocking less effective.

Limited context could lead to incomplete containment: A legitimate app, successful login, or familiar document may reveal only one part of the incident. Teams need enough context to understand what was compromised and how far the exposure extends.

Reduce the business impact of delayed threat detection.
Contain threats before they disrupt critical operations.

Strengthen Enterprise Defense

Who Attackers Targeted in August

August’s threat activity showed a strong focus on US organizations, cloud account users, and businesses relying on remote access and remote hiring.

Target Group  Campaigns and Observed Focus 
US organizations  Mirage2FA had its strongest victim concentration in the US, the RMM campaign was US-first, and 3DBlast was also observed in the country. 
Microsoft 365 and cloud users  Mirage2FA and 3DBlast targeted login flows, sessions, OAuth, device-code authentication, and MFA. 
Technology, manufacturing, and education  These sectors appeared prominently across Mirage2FA and RMM campaign data. 
Organizations hiring remote technical staff  Famous Chollima showed how false identities could gain legitimate access to code, systems, and intellectual property. 
Employees handling business files  SnakeBiteAgent and the RMM campaign used business-themed documents and archives as paths to remote access. 

1. A US-First RMM Campaign Turned Fake Business Documents into Remote Access Across 46 Countries

Research published by ANY.RUN in August exposed a phishing campaign spanning 46 countries, with 45% of observed activity associated with the United States. Attackers used tax documents, Social Security notices, invoices, Adobe PDFs, VAT notices, and shipping communications to convince victims to install legitimate remote management software.

Check detailed breakdown

RMM campaign targets US
US-first RMM campaign overview based on ANY.RUN research

The campaign abused signed RMM tools including GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, and ITarian to establish hands-on remote access. Because these applications are also used for legitimate IT administration, their activity can resemble normal remote administration and make malicious use harder to identify.

Remote-access risk to reduce: Security teams should be able to identify unexpected RMM installations regardless of the product used. Since the campaign changes domains, lures, and remote-access tools, blocking one URL or application is unlikely to stop the wider operation. ANY.RUN helps expose the full delivery chain and connect recurring campaign patterns across changing infrastructure.

2. Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup Exposed a Different Kind of Insider Threat

A joint investigation by BCA LTD, NorthScan, and ANY.RUN followed suspected Famous Chollima operatives beyond the interview stage by hiring them into a fake DeFi startup. After onboarding, the workers were given what they believed were company virtual desktops, while in reality they were operating inside specially prepared ANY.RUN sandbox environments that recorded their activity.

Check detailed breakdown

Discover detection IOCs and tactics for corporate SOCs

Lazarus APT’s IT workers caught on camera
Lazarus APT’s IT workers caught on camera

The investigation exposed the use of forged and stolen identities, mule bank accounts, VPNs, remote desktop software, and AI-assisted document manipulation. More importantly, it showed why these schemes go beyond recruitment fraud: once a false identity passes hiring checks, the worker can receive legitimate access to source code, internal systems, intellectual property, and trusted business processes without exploiting a vulnerability.

Give your SOC faster access to investigation context.
Cut MTTR by up to 21 minutes per case.

Accelerate Threat Investigations

Insider risk to reduce: Organizations hiring remotely should treat identity verification as an ongoing security control rather than a one-time HR check. Periodic verification, monitoring for unexpected VPN and remote-access activity, and closer review of privileged developer access can help reveal suspicious behavior after onboarding.

3. Mirage2FA Hijacked Microsoft 365 Sessions, Hitting Over 4K Victims in the US

Mirage2FA put US organizations at the center of a large Microsoft 365 phishing operation, with over 4,000 victims in the United States. The phishing-as-a-service toolkit used adversary-in-the-middle techniques to intercept credentials, 2FA codes, and authenticated session cookies, allowing attackers to hijack active Microsoft 365 sessions even after users completed MFA.

Check detailed breakdown

Mirage2FA in brief
Mirage2FA phishing targets US companies in technology and manufacturing

Technology, manufacturing, education, consulting, and telecommunications were among the industries exposed. Session theft was the most common compromise outcome, creating a path to corporate email, cloud services, internal documents, and trusted business accounts that attackers could use for impersonation, fraud, or further access.

Session theft risk to address: A password reset may not be enough once an authenticated session has been stolen. Security teams should revoke active sessions and tokens, investigate activity performed through the compromised identity, and strengthen high-risk accounts with phishing-resistant MFA. ANY.RUN helps reveal the complete browser-based attack flow and identify session theft before a compromised Microsoft 365 account creates wider business exposure.

4. SnakeBiteAgent Turned a Business-Themed ZIP into Full Remote Access

ANY.RUN uncovered a new .NET RAT, SnakeBiteAgent, delivered inside a business-themed ZIP archive. Once executed, the malware could give attackers full remote control, access to credentials, and persistent surveillance capabilities, turning a seemingly routine business file into a serious endpoint compromise.

View analysis session

Check details and gather IOCs

SnakeBiteAgent C2 protocol and observed capabilities
SnakeBiteAgent C2 protocol and observed capabilities

SnakeBiteAgent contains 274 methods with no obfuscation, while its command-and-control traffic is transmitted without encryption. Its capabilities include credential theft, keylogging, hidden desktop access, webcam and microphone capture, and silent installation of AnyDesk and MeshCentral for additional remote access.

Endpoint exposure to contain: A suspicious archive should be investigated beyond the initial file verdict. Security teams need to determine what executes after extraction, what information the malware can access, and whether remote control has already been established. ANY.RUN exposes the execution chain and C2 communication across the analysis sessions, helping analysts confirm the scope of compromise and contain persistent access before exposure spreads.

Cut the risk of persistent attacker access.
Help your SOC move from evidence to containment faster.

Contain Threats Earlier

5. 3DBlast Used Microsoft and Google Login Flows to Target US Organizations

A newly observed phishing kit, 3DBlast, targeted users in the United States while impersonating Microsoft 365, Office 365, and Google. Instead of relying on one fixed phishing flow, the kit could switch between BitB, OAuth/device code phishing, AiTM, and DOM relay techniques while rotating its infrastructure.

View analysis session

Check details and gather IOCs

3DBlast using Microsoft 365 BitB and AiTM phishing landing
3DBlast using Microsoft 365 BitB and AiTM phishing landing

These different flows allowed attackers to reproduce familiar login experiences, abuse legitimate authentication processes, intercept sessions, and relay victim interactions in real time. For organizations, that increases the risk of account takeover while making phishing harder to recognize from a single URL, page, or authentication event.

Analysts can use ANY.RUN’s Threat Intelligence Lookup to pivot from recurring campaign patterns and uncover related activity:

url:”/sw.js\?tab=t*_*” and threatName:”phishing”

TI Lookup showcases more context and related activity
TI Lookup showcases more context and related activity

Close Detection Gaps Exposed by August’s Attacks

August’s attacks showed how quickly malicious activity can change shape. Attackers rotated infrastructure, switched phishing flows, abused legitimate software and authentication processes, and used techniques that could look normal until the wider attack chain became visible.

For SOC teams, reducing risk means keeping defenses current, getting enough behavioral evidence to make faster decisions, and connecting individual alerts to the campaigns behind them.

1. Keep Detection Updated with Fresh Threat Intelligence

Domains, URLs, IP addresses, and delivery infrastructure can change long before a campaign disappears. Relying on indicators collected from previous incidents can leave gaps as attackers move to new infrastructure or modify their delivery methods.

ANY.RUN’s Threat Intelligence Feeds provide newly observed malicious IPs, domains, and URLs that teams can integrate into SIEM, SOAR, TIP, firewalls, and other security tools.

Fresh threat intelligence delivered directly to existing security controls
Fresh threat intelligence delivered directly to existing security controls

The intelligence comes from real-world sandbox investigations, helping security teams continuously update detection coverage instead of waiting for manually collected indicators. Each IOC can also be traced back to the sandbox session where it appeared, giving analysts additional context before they block or escalate it.

2. Give Analysts Behavioral Evidence Behind the Alert

A suspicious URL, attachment, or application does not always reveal the real level of risk on its own. The important evidence often appears after execution: redirects, scripts, credential collection, remote access, persistence, additional payloads, or network communication.

Full attack behavior revealed inside ANY.RUN’s Interactive Sandbox
Full attack behavior revealed inside ANY.RUN’s Interactive Sandbox

ANY.RUN’s Interactive Sandbox lets analysts safely observe what suspicious files and URLs actually do. Teams can follow browser activity, process execution, network traffic, authentication flows, persistence, credential access, and other behavior within the same investigation.

This gives analysts more evidence to confirm malicious activity, determine the potential scope of compromise, and make containment decisions without rebuilding the attack chain across several separate tools.

3. Expand Individual Alerts into Wider Threat Context

One confirmed malicious file, URL, or domain may represent only a small part of an active campaign. Investigating each indicator separately can make it harder to recognize related infrastructure, recurring behavior, or attacks already observed elsewhere.

ANY.RUN’s Threat Intelligence Lookup helps teams pivot from files, URLs, domains, IP addresses, behaviors, and sandbox sessions to related threat activity across current and historical data.

ANY.RUN Threat Intelligence Lookup
Related threat activity connected through ANY.RUN Threat Intelligence Lookup

Analysts can use individual IOCs or recurring campaign patterns as starting points for threat hunting, uncover connected infrastructure, and check whether similar activity has already appeared in other investigations.

Together, TI Lookup and sandbox evidence help teams move beyond one alert at a time and understand the broader threat context sooner, while TI Feeds bring newly observed indicators back into existing security controls to strengthen detection against the next attempt.

Turn stronger threat visibility into faster business protection.
Enable faster detection, investigation, and containment.

Strengthen Your SOC

About ANY.RUN

ANY.RUN provides interactive malware analysis and threat intelligence solutions used by more than 16,000 organizations and 700,000 security professionals worldwide.

Its Interactive Sandbox helps SOC teams, MSSPs, and enterprise security teams safely analyze suspicious files, URLs, phishing pages, and malware while observing the full attack chain in real time. Analysts can inspect browser activity, processes, network traffic, persistence, credential access, and other behavior to make faster and more confident response decisions.

ANY.RUN’s Threat Intelligence turns data from real-world sandbox investigations into actionable context for detection, threat hunting, and incident response. Teams can uncover related infrastructure, connect individual alerts to wider campaigns, and bring newly observed threat data into existing security controls.

ANY.RUN is SOC 2 Type II attested, reflecting its commitment to strong security controls and customer data protection. By combining behavioral analysis with current threat intelligence, ANY.RUN helps security teams reduce investigation uncertainty, improve detection coverage, and contain threats before they create wider business impact.

What do you think about this post?

0 answers

  • Awful
  • Average
  • Great

No votes so far! Be the first to rate this post.

0 comments