HomeService Updates
Threat Coverage Digest: New TI Report, Threat Research and 750+ Detection Rules
HomeService Updates
Threat Coverage Digest: New TI Report, Threat Research and 750+ Detection Rules

July brought another set of threat coverage updates designed to help security teams work faster and with more confidence. ANY.RUN added 42 behavior signatures, 11 YARA rules, and 703 Suricata rules, giving SOCs broader visibility across files, malware behavior, and network activity. 

We also published new threat intelligence and technical research on active malware and phishing campaigns. Together, these updates help teams validate alerts sooner, reduce manual investigation work, and make faster response decisions. 

Here is a closer look at July’s threat coverage and research updates. 

Threat Intelligence Report 

In July, we published a new Threat Intelligence Report covering ORACLESPY, Rokarolla, and ZOHOMURK. 

Available to TI Lookup Premium users, the report includes IOCs, detection guidance, MITRE ATT&CK mappings, and TI Lookup queries for exploring related activity and sandbox sessions. 

TI Reports on malware and phishing attacks
TI Reports on malware and phishing attacks for deeper investigations

The report covers: 

  • ORACLESPY: Windows spyware that collects system and storage information before preparing it for exfiltration. 
  • Rokarolla: An Android banking trojan targeting more than 200 banking and cryptocurrency applications through fake apps, overlays, and Accessibility Services abuse. 
  • ZOHOMURK: A Windows backdoor linked to Mustang Panda that uses Zoho WorkDrive for command-and-control communication and data exfiltration. 

Turn threat intelligence into faster response decisions.
Give your team the context needed to act sooner.

Stengthen SOC response

Behavior Signatures 

The latest behavior coverage expansion brings 42 new signatures to ANY.RUN’s Interactive Sandbox. The new detections include:

Malicious activity is highlighted directly in sandbox sessions, allowing SOC teams to validate alerts faster, avoid unnecessary escalations, and move toward response with clearer evidence.

YARA Rules 

The latest update expands YARA coverage with 11 rules designed to identify malicious patterns in files and processes

Together with behavior signatures and network detections, they add another layer of evidence for classifying samples and reaching faster investigation decisions.

Suricata Rules 

703 new Suricata rules were added to ANY.RUN’s Interactive Sandbox. The new rules cover malicious connections, phishing-related requests, and command-and-control traffic. 

Latest Threat Research 

ANY.RUN researchers also published four new investigations into active malware and phishing campaigns. The findings provide practical indicators and detection insights that can be used to investigate related activity and strengthen their response. 

  • Kratos PhaaS: An investigation into three generations of the Microsoft 365 phishing kit that uncovered 1,484 previously unattributed sandbox sessions and new fingerprints for threat hunting. 
  • PhantomEnigma: Research into an active campaign abusing more than 20 compromised Brazilian government websites to deliver malware to banking and public-sector targets. 
  • Kali365: An analysis of a device code phishing kit that abuses legitimate Microsoft authentication to gain access to Microsoft 365 accounts without directly stealing passwords. 
  • Banana RAT Evolution: A comparison of two malware branches connected to the same infrastructure, revealing changes in persistence, command-and-control communication, and other behavior. 

Strengthen threat detection across your SOC.
Turn suspicious activity into clear investigation evidence.

Integrate ANY.RUN now

About ANY.RUN 

ANY.RUN is a leading provider of interactive malware analysis and threat intelligence solutions for SOCs, MSSPs, and security teams. 

The Interactive Sandbox helps teams safely analyze suspicious files, URLs, and phishing attacks while observing real-time behavior across processes, network connections, files, registry activity, and browser interactions. Threat Intelligence adds further context, helping teams connect findings, investigate related activity, and improve detection coverage. 

More than 600,000 security professionals across 15,000 organizations use ANY.RUN to validate alerts faster, reduce manual investigation work, and respond to threats with greater confidence. 

What do you think about this post?

0 answers

  • Awful
  • Average
  • Great

No votes so far! Be the first to rate this post.

0 comments