{"id":22417,"date":"2026-08-04T08:30:51","date_gmt":"2026-08-04T08:30:51","guid":{"rendered":"https:\/\/any.run\/cybersecurity-blog\/?p=22417"},"modified":"2026-08-04T09:08:00","modified_gmt":"2026-08-04T09:08:00","slug":"major-cyber-attacks-july-2026","status":"publish","type":"post","link":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-july-2026\/","title":{"rendered":"Major Cyber Attacks in July 2026: US and EU Organizations Hit by Phishing, RATs, and Stealers"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">July 2026 showed how trusted business workflows can quickly turn into account takeover, data exposure, fraud, and persistent access. <a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-july-2026&amp;utm_term=040826&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN<\/a> observed attacks that put cloud accounts, financial processes, sensitive data, and business continuity at risk across the US, Europe, and Brazil. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here are the major attacks from July, the business risks they exposed, and the actions security leaders should prioritize to contain them faster. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What July\u2019s Attacks Revealed About Enterprise Risk <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">July\u2019s attacks showed how easily routine business activity can become a path to account compromise, data exposure, fraud, and operational disruption. Attackers used trusted platforms, legitimate authentication flows, familiar documents, and built-in system tools to reduce suspicion and delay the moment when security teams could confirm the true scale of an incident. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Trusted business services created false confidence:<\/strong> SharePoint, OneDrive, Zoom Events, Microsoft authentication pages, and compromised government systems appeared in attack chains. Their presence made malicious activity look more credible and increased the chance that employees or security controls would allow it to continue. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Identity attacks threatened core business workflows:<\/strong> Kratos and Kali365 put Microsoft 365 accounts, corporate email, shared files, supplier communication, and payment conversations at risk. In cases involving active sessions, refresh tokens, or OAuth access, changing a password alone might not fully remove the attacker. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>A single endpoint could expose access across the business:<\/strong> DestinyStealer, Banana RAT, DARTHVADER Stealer, and OVERLORD RAT collected or targeted browser credentials, cookies, Outlook data, VPN access, file-transfer accounts, cryptocurrency wallets, and other sensitive information. One infected device could therefore create exposure across several systems and require a much broader response than endpoint cleanup alone. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Legitimate tools made malicious activity harder to separate from normal operations:<\/strong> PowerShell, AutoIt, Windows utilities, trusted applications, and cloud services helped attackers hide inside familiar system activity. This increased the risk of delayed containment, unnecessary escalations, and longer investigations. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Changing infrastructure weakened indicator-only defenses:<\/strong> Several campaigns rotated domains, command-and-control servers, or delivery paths. Blocking one URL or IP address could stop only a small part of the operation, while related activity continued elsewhere. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Incomplete context increased response costs:<\/strong> A clean initial verdict, a legitimate first-stage URL, or one isolated alert did not always reveal the full compromise. Without a clear view of affected accounts, stolen data, persistence, and follow-on activity, leaders could underestimate business exposure or approve containment actions that were either too narrow or unnecessarily disruptive. <\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\n<span class=\"highlight\">Strengthen your entire SOC to close blind spots.\n <\/span><br>Integrate ANY.RUN for faster MTTR and MTTD.\n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=major-cyber-attacks-july-2026&#038;utm_term=040826&#038;utm_content=linktoenterprise#contact-sales\" target=\"_blank\" rel=\"noopener\">\nStengthen SOC response \n<\/a>\n<!-- CTA Link -->\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n.regular-banner__link:hover {\nbackground-color: #FFFFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h2 class=\"wp-block-heading\">Who Attackers Targeted in July <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">July\u2019s campaigns reached organizations across the United States, Europe, and Brazil, with activity affecting both private and public-sector environments. <\/p>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-353\"\n           style=\"border-collapse:collapse;\n                   border-spacing:0px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"2\"\n           data-rows=\"9\"\n           data-wpID=\"353\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell wpdt-bold\"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:50%;                    padding:10px;\n                    \"\n                    >\n                                        Target Group\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold\"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:50%;                    padding:10px;\n                    \"\n                    >\n                                        Campaigns and Observed Focus\u00a0                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Microsoft 365 users\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Kratos and\u00a0Kali365 targeted cloud accounts across the US and Europe.\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        US enterprises\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Kali365 activity appeared across manufacturing, technology, healthcare, government, consulting, and MSSPs.\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A4\"\n                    data-col-index=\"0\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        European organizations\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"B4\"\n                    data-col-index=\"1\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Kratos affected SMBs, law firms, schools, polytechnic institutions, and industrial organizations, with a strong concentration in Spain and Southern Europe.\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A5\"\n                    data-col-index=\"0\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Banking organizations in Brazil\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"B5\"\n                    data-col-index=\"1\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Banana RAT was associated with banking sessions and\u00a0Pix-related fraud, while\u00a0PhantomEnigma\u00a0targeted the financial sector.\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A6\"\n                    data-col-index=\"0\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Brazilian public-sector organizations\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"B6\"\n                    data-col-index=\"1\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        PhantomEnigma\u00a0used police and legal themes and compromised government infrastructure during delivery.\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A7\"\n                    data-col-index=\"0\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Employees handling business documents\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"B7\"\n                    data-col-index=\"1\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Invoice,\u00a0DocuSign, document-sharing, and fake PDF lures targeted users accustomed to opening external files.\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A8\"\n                    data-col-index=\"0\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Staff engaging with partners and events\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"B8\"\n                    data-col-index=\"1\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Fake Meta, OpenAI, and Anthropic summits targeted users\u00a0through Zoom-themed event invitations.\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A9\"\n                    data-col-index=\"0\"\n                    data-row-index=\"8\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Users with stored account data\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"B9\"\n                    data-col-index=\"1\"\n                    data-row-index=\"8\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        DestinyStealer\u00a0focused on credentials and information held in browsers, Outlook, VPN clients, FileZilla, Wi-Fi profiles, and wallet extensions.\u00a0                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-353'>\ntable#wpdtSimpleTable-353{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-353 td, table.wpdtSimpleTable353 th { white-space: normal !important; }\n<\/style>\n\n\n\n\n<p class=\"wp-block-paragraph\">The targeting was broad, but not random. Attackers focused on users and sectors with access to cloud accounts, financial activity, sensitive records, and trusted external communications.  <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">1. Kratos Put Microsoft 365 Accounts and Business Workflows at Risk Across the US and Europe <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In July, ANY.RUN researchers documented Kratos, a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the United States, Europe, and other regions. The campaign used document-sharing, DocuSign, and invoice lures, often routing victims through trusted services such as SharePoint, OneDrive, Microsoft Forms, Canva, and Tilda before displaying a fake Microsoft login page. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/cybersecurity-blog\/kratos-phaas-account-takeover\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Check detailed breakdown<\/strong><\/a> <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"709\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Kratos-Phishing-Attacks-US-and-EU-Companies-1024x709.png\" alt=\"Kratos analysis\" class=\"wp-image-22336\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Kratos-Phishing-Attacks-US-and-EU-Companies-1024x709.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Kratos-Phishing-Attacks-US-and-EU-Companies-300x208.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Kratos-Phishing-Attacks-US-and-EU-Companies-768x532.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Kratos-Phishing-Attacks-US-and-EU-Companies-1536x1064.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Kratos-Phishing-Attacks-US-and-EU-Companies-370x256.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Kratos-Phishing-Attacks-US-and-EU-Companies-270x187.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Kratos-Phishing-Attacks-US-and-EU-Companies-435x300.png 435w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Kratos-Phishing-Attacks-US-and-EU-Companies-740x512.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Kratos-Phishing-Attacks-US-and-EU-Companies.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Attack chain of Kratos phishing campaign<\/em> <\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">For organizations, the risk extended beyond a stolen password. Compromised accounts could expose corporate email, cloud files, supplier communication, and payment workflows, supporting business email compromise, payment redirection, data exposure, and fraudulent requests from trusted accounts. Some sessions also established WebSocket connections, which may indicate possible adversary-in-the-middle activity or live credential relaying, although this alone does not confirm session theft. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Account takeover risk to address:<\/strong> A password reset may not fully contain the incident if attackers have already gained access to an active Microsoft 365 session. Organizations should review sign-in activity, revoke active sessions and refresh tokens when needed, and determine whether the account was used to access sensitive files, financial conversations, or external partner communications. Teams should also trace the full redirect chain rather than broadly blocking trusted services that may have served only as an intermediate step. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">2. PhantomEnigma Abused Trusted Government Systems to Reach Banks and Public-Sector Targets <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/malware-trends\/PhantomEnigma\/\" target=\"_blank\" rel=\"noreferrer noopener\">PhantomEnigma<\/a> targeted banking and public-sector organizations in Brazil through fake Pol\u00edcia Civil and digital power-of-attorney communications. At least 20 compromised .gov.br municipal and police portals were used to distribute malware, while compromised government mailboxes allowed some phishing emails to pass SPF, DKIM, and DMARC checks. These government systems were part of the delivery chain and were not confirmed as the campaign\u2019s intended targets. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/cybersecurity-blog\/phantomenigma-research\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Check detailed breakdown<\/strong><\/a> <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/timeline-1024x576.png\" alt=\"Phantomenigma timeline\" class=\"wp-image-22132\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/timeline-1024x576.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/timeline-300x169.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/timeline-768x432.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/timeline-1536x864.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/timeline-2048x1152.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/timeline-370x208.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/timeline-270x152.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/timeline-740x416.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Timeline of PhantomEnigma\u2019s malicious activity<\/em> <\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Once installed, the modular backdoor could collect system information, establish persistence, execute commands, and deliver additional payloads such as stealers, loaders, or remote management tools. Rotating command-and-control infrastructure and initial clean verdicts could also cause connected alerts to be investigated separately, delaying containment and increasing the risk of fraud, data exposure, operational disruption, and higher recovery costs. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Investigation gap to close:<\/strong> A single domain, file, or clean initial verdict may reveal only one part of the campaign. Teams need enough context to connect the phishing message, compromised government infrastructure, malware behavior, command-and-control activity, and any additional payloads delivered afterward. This broader view helps security leaders understand whether they are dealing with one isolated alert or a coordinated operation affecting multiple users or systems, so containment can begin before the business impact grows. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">3. Kali365 Turned Legitimate Microsoft Sign-Ins into Cloud Access Risk for US Organizations <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/malware-trends\/kali365\/\" target=\"_blank\" rel=\"noreferrer noopener\">Kali365<\/a> targeted U.S. organizations with device code phishing that abused Microsoft\u2019s legitimate authentication process. Instead of collecting passwords through a fake login page, the kit directed victims to Microsoft\u2019s real device login page and persuaded them to enter an attacker-controlled code. More than 80 related public sandbox sessions were recorded each week, with activity observed across MSSPs, manufacturing, technology, government, healthcare, and consulting. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/cybersecurity-blog\/kali365-phishing-targeting-us\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Check detailed breakdown<\/strong><\/a> <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"490\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Kali-industries-1024x490.webp\" alt=\"Kali industries it targets\" class=\"wp-image-22418\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Kali-industries-1024x490.webp 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Kali-industries-300x143.webp 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Kali-industries-768x367.webp 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Kali-industries-1536x734.webp 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Kali-industries-370x177.webp 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Kali-industries-270x129.webp 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Kali-industries-740x354.webp 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Kali-industries.webp 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>US industries being targeted by Kali 365<\/em> <\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Successful authentication could give attackers OAuth access and refresh tokens, potentially providing continued access to corporate email, documents, and cloud resources without directly stealing the victim\u2019s password. Because the login took place on a legitimate Microsoft page, the activity could appear routine, delaying detection while attackers accessed sensitive data, altered business communications, or used trusted accounts for fraud. <\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\n<span class=\"highlight\">Reduce the cost of delayed threat confirmation.\n <\/span><br>Give your SOC the evidence to contain attacks before exposure spreads.\n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=major-cyber-attacks-july-2026&#038;utm_term=040826&#038;utm_content=linktoenterprise#contact-sales\" target=\"_blank\" rel=\"noopener\">\nCut Response Time\n<\/a>\n<!-- CTA Link -->\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n.regular-banner__link:hover {\nbackground-color: #FFFFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Access control to strengthen:<\/strong> Device code authentication should be limited to users and workflows that genuinely require it. Organizations should also investigate unexpected authorization requests and unusual access to Microsoft 365 services. Because Kali365 sends victims through a legitimate Microsoft login page, ANY.RUN helps reveal the original lure, redirects, and device-code flow that may otherwise look safe.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">4. Banana RAT Increased Fraud Risk by Evolving Its Remote Access Capabilities <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Banana RAT is a banking-focused remote access trojan associated with Brazilian financial activity, including banking sessions and Pix-related fraud. Research published in July compared two branches tied to the same staging infrastructure. The older branch used fixed Microsoft-style filenames and installation paths, while the newer version introduced randomized identifiers, stronger persistence, and encrypted WebSocket communication through host-specific subdomains. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"589\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/bananarat_lookup-1024x589.webp\" alt=\"Banana RAT\" class=\"wp-image-22419\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/bananarat_lookup-1024x589.webp 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/bananarat_lookup-300x173.webp 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/bananarat_lookup-768x442.webp 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/bananarat_lookup-1536x883.webp 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/bananarat_lookup-370x213.webp 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/bananarat_lookup-270x155.webp 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/bananarat_lookup-740x426.webp 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/bananarat_lookup.webp 1826w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>TI Lookup quickly links an isolated hash to the full BananaRAT sample complete with a sandbox session<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">The newer branch could monitor screens and sessions, capture keyboard input, transfer files, control the infected system remotely, and maintain access through scheduled tasks or registry-based persistence. For banks and businesses handling payments, an infected endpoint could expose credentials, enable fraudulent transactions, and give attackers continued access even after the original malicious file is removed. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Evolving threat to track:<\/strong> Blocking one filename, path, or server may not stop Banana RAT as operators continue changing how the malware installs itself and communicates. Teams need behavioral context that connects hidden PowerShell activity, persistence, remote-control capabilities, and network communication across different variants. ANY.RUN helps compare related samples and reveal the stable behavior behind changing artifacts, allowing security teams to update detection and containment before a new branch affects more systems or financial workflows. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">5. A Fake PDF Shortcut Turned One Click into Credential Theft and Persistent Access <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A malicious LNK file disguised as a PDF launched a multi-stage infection chain using cmd.exe, legitimate Windows utilities, AutoIt, and PowerShell before deploying DARTHVADER Stealer. The attack also establishedpersistence, allowing the compromise to continue beyond the initial click. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/posts\/any-run_anyrun-explorewithanyrun-activity-7488581811447668736-AsbM\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Check technical details on Linkedin<\/strong><\/a> <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"848\" height=\"1024\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/sandbox-analysis-details-848x1024.jpeg\" alt=\"ANY.RUN\u2019s sandbox revealing all the hidden processes \" class=\"wp-image-22420\" style=\"aspect-ratio:0.8281343869864596;width:464px;height:auto\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/sandbox-analysis-details-848x1024.jpeg 848w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/sandbox-analysis-details-248x300.jpeg 248w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/sandbox-analysis-details-768x928.jpeg 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/sandbox-analysis-details-370x447.jpeg 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/sandbox-analysis-details-270x326.jpeg 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/sandbox-analysis-details-740x894.jpeg 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/sandbox-analysis-details.jpeg 995w\" sizes=\"auto, (max-width: 848px) 100vw, 848px\" \/><figcaption class=\"wp-element-caption\"><em>ANY.RUN\u2019s sandbox revealing all the hidden processes<\/em> <\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">The chain used hidden command execution, curl.exe downloads, PowerShell ExecutionPolicy Bypass, mutex creation, and persistence setup. The use of legitimate system tools and reduced command output created fewer obvious artifacts, making the activity harder to trace and potentially delaying containment while the stealer remained active. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Post-click risk to reduce:<\/strong> Security controls should not stop at checking whether a file looks like a PDF or whether a trusted Windows utility was used. Teams need visibility into what happens after the shortcut is opened, including hidden commands, downloaded components, PowerShell activity, AutoIt execution, and persistence. ANY.RUN helps expose this sequence in one analysis, giving teams the evidence needed to identify the stealer and contain affected systems before stolen data or persistent access creates wider business impact. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">6. Live Attacker Control Exposed Organizations to Data Theft and Continued Access <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">While analyzing a PythonRAT infection, ANY.RUN observed the attacker connect to the compromised system, upload another payload, and deploy OVERLORD RAT in real time. The activity, seen targeting Germany and the UK, showed that the initial infection was only the first step in a broader compromise. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/posts\/any-run_anyrun-overlord-anyrun-activity-7485698702142099457-tRRC\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Check technical details on Linkedin<\/strong><\/a> <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"678\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/OVERLORD-exposed-1024x678.jpeg\" alt=\" OVERLORD is delivered via live C2 channel \" class=\"wp-image-22422\" style=\"aspect-ratio:1.5103358783233243;width:554px;height:auto\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/OVERLORD-exposed-1024x678.jpeg 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/OVERLORD-exposed-300x199.jpeg 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/OVERLORD-exposed-768x508.jpeg 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/OVERLORD-exposed-370x245.jpeg 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/OVERLORD-exposed-270x179.jpeg 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/OVERLORD-exposed-740x490.jpeg 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/OVERLORD-exposed.jpeg 1280w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>ANY.RUN reveals how OVERLORD is delivered via live C2 channel<\/em> <\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">OVERLORD gave the attacker extensive control over the system, including access to files, browser data, messages, cryptocurrency wallets, keyboard input, and audio. During 45 minutes of analysis, the agent transmitted approximately 86 MB of data, highlighting how quickly one infected endpoint can turn into a serious data exposure and remote-access incident. <\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\n<span class=\"highlight\">Stop initial infections from becoming active compromise.\n <\/span><br>Contain threats before sensitive data is exposed. \n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=major-cyber-attacks-july-2026&#038;utm_term=040826&#038;utm_content=linktoenterprise#contact-sales\" target=\"_blank\" rel=\"noopener\">\nContain Threats Earlier \n<\/a>\n<!-- CTA Link -->\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n.regular-banner__link:hover {\nbackground-color: #FFFFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Business exposure to confirm:<\/strong> An initial malware alert may not show whether an attacker is already active inside the environment. Interactive analysis in ANY.RUN revealed the operator\u2019s actions and the additional payload as they appeared, helping teams understand the true scope of the compromise and move faster to isolate the system, protect exposed accounts, and prevent further access. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">7. Fake Zoom Events Put Trusted Partner Communications at Risk <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A multi-flow phishing campaign used legitimate Zoom event pages to promote fake virtual summits linked to Meta, OpenAI, and Anthropic. The invitations appeared to offer access to events such as the Meta Agency Summit 2026, OpenAI Partner Summit 2026, and Anthropic AI Marketing Summit 2026. After users selected \u201cContinue to register,\u201d they were redirected from events.zoom.us to attacker-controlled domains. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/posts\/any-run_anyrun-explorewithanyrun-activity-7483136027788906496-1goQ\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Check technical details on Linkedin<\/strong><\/a> <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"768\" height=\"1024\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Zoom-events-abused-1-768x1024.jpeg\" alt=\"Meta, OpenAI and Anthropic lures \" class=\"wp-image-22424\" style=\"width:502px;height:auto\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Zoom-events-abused-1-768x1024.jpeg 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Zoom-events-abused-1-225x300.jpeg 225w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Zoom-events-abused-1-1152x1536.jpeg 1152w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Zoom-events-abused-1-370x493.jpeg 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Zoom-events-abused-1-270x360.jpeg 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Zoom-events-abused-1-740x986.jpeg 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Zoom-events-abused-1.jpeg 1280w\" sizes=\"auto, (max-width: 768px) 100vw, 768px\" \/><figcaption class=\"wp-element-caption\"><em>Meta, OpenAI and Anthropic lures used in a multi-flow phishing campaign<\/em> <\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">The campaign then followed different paths. Some samples used Microsoft device code phishing, while others used an adversary-in-the-middle flow impersonating Microsoft authentication. By starting on a trusted event platform and using familiar technology brands, the attackers reduced suspicion and made the early stages of the campaign less likely to stand out during triage. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Trusted redirect risk to reduce:<\/strong> Security teams should treat event invitations as complete journeys rather than judging only the first page or final destination. Redirects from legitimate SaaS platforms into unexpected authentication flows should be reviewed together, especially when an event registration suddenly asks users to authorize Microsoft access. ANY.RUN helps reproduce these transitions safely and reveal where a credible invitation turns into credential or session compromise. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">8. DestinyStealer Put Credentials and Corporate Access Data at Risk Across the US and Europe <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">DestinyStealer activity increased across Europe and the United States, with the malware operating as an all-in-one data grabber. It collected browser data, cookies, passwords, cryptocurrency wallet extension storage, Outlook and VPN data, FileZilla credentials, Wi-Fi profiles, and desktop screenshots. Its code also showed clear continuity with StormKitty. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/posts\/destinystealer-anyrun-share-7480976690031149056-jlJD\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Check technical details on Linkedin<\/strong><\/a> <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"768\" height=\"1024\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DestinyStealer-execution-768x1024.jpeg\" alt=\"DestinyStealer targets US and EU \" class=\"wp-image-22425\" style=\"width:540px;height:auto\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DestinyStealer-execution-768x1024.jpeg 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DestinyStealer-execution-225x300.jpeg 225w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DestinyStealer-execution-1152x1536.jpeg 1152w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DestinyStealer-execution-370x493.jpeg 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DestinyStealer-execution-270x360.jpeg 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DestinyStealer-execution-740x986.jpeg 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/DestinyStealer-execution.jpeg 1280w\" sizes=\"auto, (max-width: 768px) 100vw, 768px\" \/><figcaption class=\"wp-element-caption\"><em>How DestinyStealer targets organizations across US and EU<\/em> <\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Some samples were still undetected on VirusTotal at the time of analysis, while others lacked clear attribution. After checking the victim\u2019s public IP address, the malware collected the stolen information in a temporary directory, packaged it into a ZIP archive, and exfiltrated it through two parallel channels: HTTP and raw TCP. This combination could allow valuable credentials and access data to leave the system before conventional detections provide teams with a clear verdict. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Exposure scope to determine:<\/strong> A DestinyStealer infection should not be treated as a problem limited to one endpoint. Teams need to establish which browsers, email accounts, VPN access, file-transfer credentials, cookies, and cryptocurrency wallets were exposed. <a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-july-2026&amp;utm_term=040826&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\">Behavior-based analysis<\/a> in ANY.RUN reveals what the malware collected and where it attempted to send the data, helping security teams identify affected accounts and contain the wider access risk. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Turn July\u2019s Attack Evidence into Stronger SOC Defense <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">July\u2019s campaigns changed domains, abused trusted services, hid behind legitimate activity, and expanded after the first alert. Reducing exposure requires more than blocking the indicator found in one incident. SOC teams need fresh intelligence for their controls, behavioral evidence for faster investigations, and campaign context for proactive hunting. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. Keep Security Controls Updated with Fresh Threat Intelligence <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Kratos, PhantomEnigma, Banana RAT, and other July threats changed infrastructure, delivery paths, or technical artifacts as their campaigns evolved. A domain or IP address taken from one confirmed incident may quickly lose value, while connected infrastructure remains active elsewhere. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"464\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Threat-Intelligence-Feed-ANY.RUN_-1024x464.png\" alt=\"TI Feeds\" class=\"wp-image-22275\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Threat-Intelligence-Feed-ANY.RUN_-1024x464.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Threat-Intelligence-Feed-ANY.RUN_-300x136.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Threat-Intelligence-Feed-ANY.RUN_-768x348.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Threat-Intelligence-Feed-ANY.RUN_-1536x695.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Threat-Intelligence-Feed-ANY.RUN_-2048x927.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Threat-Intelligence-Feed-ANY.RUN_-370x167.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Threat-Intelligence-Feed-ANY.RUN_-270x122.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Threat-Intelligence-Feed-ANY.RUN_-740x335.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>TI Feeds provides actionable IOCs to your existing stack<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">ANY.RUN\u2019s <a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-july-2026&amp;utm_term=040826&amp;utm_content=linktotifeedslanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence Feeds<\/a> deliver newly observed malicious IPs, domains, and URLs to SIEM, SOAR, TIP, firewalls, and other security controls through STIX\/TAXII, API, and SDK. The intelligence is drawn from sandbox investigations submitted by more than 15,000 organizations and 600,000 security professionals worldwide, giving teams a continuously updated view of threats seen in real environments. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Each indicator links back to the sandbox session where it was observed, helping defenders validate it before taking action. This is especially important when attackers use compromised websites, shared cloud infrastructure, or legitimate platforms that should not be blocked without review. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. Give SOC Teams the Evidence to Act Faster <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">July\u2019s incidents showed how easily an alert can look harmless at first and become much more serious after execution. A trusted URL, familiar sign-in page, or clean initial verdict may reveal little about the access gained, data collected, or attacker activity that follows. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"566\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Kratos-sandbox-analysis-1024x566.webp\" alt=\"sandbox analysis\" class=\"wp-image-22337\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Kratos-sandbox-analysis-1024x566.webp 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Kratos-sandbox-analysis-300x166.webp 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Kratos-sandbox-analysis-768x425.webp 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Kratos-sandbox-analysis-1536x849.webp 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Kratos-sandbox-analysis-370x205.webp 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Kratos-sandbox-analysis-270x149.webp 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Kratos-sandbox-analysis-740x409.webp 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/Kratos-sandbox-analysis.webp 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Complex phishing investigation inside ANY.RUN\u2019s sandbox <\/em> <\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Behavior-based analysis helps teams see what a file or URL actually does after it is opened. ANY.RUN\u2019s <a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-july-2026&amp;utm_term=040826&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\">Interactive Sandbox<\/a> reveals redirects, authentication flows, hidden execution, persistence, downloaded payloads, remote-control activity, and data collection in one investigation. This gives Tier 1 the evidence needed to confirm malicious behavior and understand the potential business exposure behind an uncertain verdict. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ready-made reports bring together the verdict, IOCs, TTPs, screenshots, and behavioral evidence in a shareable format. With the attack chain already documented, teams can make faster containment decisions and hand off complex cases without rebuilding the investigation across several sources. <\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\n<span class=\"highlight\">Turn uncertain alerts into confident response decisions. \n <\/span><br>Reveal the true scope of threats before impact grows. \n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=major-cyber-attacks-july-2026&#038;utm_term=040826&#038;utm_content=linktoenterprise#contact-sales\" target=\"_blank\" rel=\"noopener\">\nAccelerate Threat Response  \n<\/a>\n<!-- CTA Link -->\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n.regular-banner__link:hover {\nbackground-color: #FFFFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h3 class=\"wp-block-heading\">3. Turn Isolated Alerts into Campaign-Level Intelligence <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When related activity is investigated case by case, security teams may miss the scale of the threat and repeat the same work across multiple incidents. The result is slower attribution, weaker hunting, and less time to prepare for the next wave of the campaign. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"550\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Kali365-sandbox-sessions-1024x550.webp\" alt=\"Kali365 sandbox sessions\" class=\"wp-image-22426\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Kali365-sandbox-sessions-1024x550.webp 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Kali365-sandbox-sessions-300x161.webp 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Kali365-sandbox-sessions-768x413.webp 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Kali365-sandbox-sessions-1536x825.webp 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Kali365-sandbox-sessions-370x199.webp 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Kali365-sandbox-sessions-270x145.webp 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Kali365-sandbox-sessions-740x397.webp 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Kali365-sandbox-sessions.webp 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Relevant sandbox sessions displayed inside TI Lookup for full context<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">ANY.RUN\u2019s <a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-july-2026&amp;utm_term=040826&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence Lookup<\/a> helps teams connect suspicious files, URLs, infrastructure, behaviors, screenshots, and sandbox sessions across current and historical data. This makes it easier to determine whether an alert is isolated or part of activity already affecting other organizations, sectors, or regions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/intelligence.any.run\/reports?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-july-2026&amp;utm_term=040826&amp;utm_content=linktotireports\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence Reports<\/a> add analyst-led research on active malware, phishing operations, APTs, and cybercriminal groups. Each report includes investigation findings and ready-to-use TI Lookup queries that teams can apply to threat hunting, detection reviews, and incident enrichment. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"539\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/TI-Reports-1024x539.png\" alt=\"TI reports\" class=\"wp-image-22390\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/TI-Reports-1024x539.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/TI-Reports-300x158.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/TI-Reports-768x404.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/TI-Reports-1536x808.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/TI-Reports-2048x1078.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/TI-Reports-370x195.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/TI-Reports-270x142.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/07\/TI-Reports-740x389.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>ANY.RUN\u2019s analyst-led research on active malware, phishing operations, APTs, and cybercriminal groups<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Together, TI Lookup and TI Reports help SOC teams move from reacting to one alert at a time to identifying wider campaign activity earlier, uncovering related exposure, and updating defenses before the same threat reaches more users or systems.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">About ANY.RUN <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-july-2026&amp;utm_term=040826&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN<\/a>, a leading provider of interactive malware analysis and threat intelligence solutions, helps SOCs, MSSPs, and enterprise security teams investigate threats faster and make response decisions based on clear behavioral evidence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Its <a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-july-2026&amp;utm_term=040826&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\">Interactive Sandbox<\/a> allows teams to analyze malware, phishing pages, suspicious files, and URLs in a controlled environment while observing the full attack chain in real time. <a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-july-2026&amp;utm_term=040826&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence<\/a> built on investigations from more than 15,000 organizations and 600,000 security professionals help teams enrich alerts, uncover related activity, and bring current threat context into detection, hunting, and response workflows.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ANY.RUN is <a href=\"https:\/\/any.run\/compliance\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-july-2026&amp;utm_term=040826&amp;utm_content=linktocompliance\" target=\"_blank\" rel=\"noreferrer noopener\">SOC 2 Type II attested<\/a>, reflecting its commitment to strong security controls and customer data protection. By combining behavior-based analysis with continuously updated threat intelligence, ANY.RUN helps security teams reduce investigation uncertainty, speed up triage, and contain threats before they create wider business impact.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>July 2026 showed how trusted business workflows can quickly turn into account takeover, data exposure, fraud, and persistent access. ANY.RUN observed attacks that put cloud accounts, financial processes, sensitive data, and business continuity at risk across the US, Europe, and Brazil. Here are the major attacks from July, the business risks they exposed, and the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":22430,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[8],"tags":[57,10,34],"class_list":["post-22417","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware-analysis","tag-anyrun","tag-cybersecurity","tag-malware-analysis"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Major Cyber Attacks in July 2026: US and Europe Targeted<\/title>\n<meta name=\"description\" content=\"Explore the major cyber attacks of July 2026, the risks they created across the US and Europe, and the steps security leaders can take to reduce exposure.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-july-2026\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"ANY.RUN\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"16 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-july-2026\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-july-2026\\\/\"},\"author\":{\"name\":\"ANY.RUN\",\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"headline\":\"Major Cyber Attacks in July 2026: US and EU Organizations Hit by Phishing, RATs, and Stealers\",\"datePublished\":\"2026-08-04T08:30:51+00:00\",\"dateModified\":\"2026-08-04T09:08:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-july-2026\\\/\"},\"wordCount\":2883,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-july-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Major-Cyber-Attacks-in-July-2026-scaled.png\",\"keywords\":[\"ANYRUN\",\"cybersecurity\",\"malware analysis\"],\"articleSection\":[\"Malware Analysis\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-july-2026\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-july-2026\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-july-2026\\\/\",\"name\":\"Major Cyber Attacks in July 2026: US and Europe Targeted\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-july-2026\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-july-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Major-Cyber-Attacks-in-July-2026-scaled.png\",\"datePublished\":\"2026-08-04T08:30:51+00:00\",\"dateModified\":\"2026-08-04T09:08:00+00:00\",\"description\":\"Explore the major cyber attacks of July 2026, the risks they created across the US and Europe, and the steps security leaders can take to reduce exposure.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-july-2026\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-july-2026\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-july-2026\\\/#primaryimage\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Major-Cyber-Attacks-in-July-2026-scaled.png\",\"contentUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Major-Cyber-Attacks-in-July-2026-scaled.png\",\"width\":2560,\"height\":1243,\"caption\":\"Major Cyber Attacks in July 2026\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-july-2026\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Malware Analysis\",\"item\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/category\\\/malware-analysis\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Major Cyber Attacks in July 2026: US and EU Organizations Hit by Phishing, RATs, and Stealers\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN&#039;s Cybersecurity Blog\",\"description\":\"Cybersecurity Blog covers topics for experienced professionals as well as for those new to it.\",\"publisher\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/any.run\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN\",\"url\":\"https:\\\/\\\/any.run\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/ANYRUN-Icon.svg\",\"contentUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/ANYRUN-Icon.svg\",\"width\":1,\"height\":1,\"caption\":\"ANY.RUN\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/www.any.run\\\/\",\"https:\\\/\\\/x.com\\\/anyrun_app\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/30692044\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCOgCPho7lzmH7m6fPNlukrQ\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"caption\":\"ANY.RUN\"},\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/author\\\/a-bespalova\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Major Cyber Attacks in July 2026: US and Europe Targeted","description":"Explore the major cyber attacks of July 2026, the risks they created across the US and Europe, and the steps security leaders can take to reduce exposure.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-july-2026\/","twitter_misc":{"Written by":"ANY.RUN","Est. reading time":"16 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-july-2026\/#article","isPartOf":{"@id":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-july-2026\/"},"author":{"name":"ANY.RUN","@id":"https:\/\/any.run\/"},"headline":"Major Cyber Attacks in July 2026: US and EU Organizations Hit by Phishing, RATs, and Stealers","datePublished":"2026-08-04T08:30:51+00:00","dateModified":"2026-08-04T09:08:00+00:00","mainEntityOfPage":{"@id":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-july-2026\/"},"wordCount":2883,"commentCount":0,"publisher":{"@id":"https:\/\/any.run\/"},"image":{"@id":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-july-2026\/#primaryimage"},"thumbnailUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Major-Cyber-Attacks-in-July-2026-scaled.png","keywords":["ANYRUN","cybersecurity","malware analysis"],"articleSection":["Malware Analysis"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-july-2026\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-july-2026\/","url":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-july-2026\/","name":"Major Cyber Attacks in July 2026: US and Europe Targeted","isPartOf":{"@id":"https:\/\/any.run\/"},"primaryImageOfPage":{"@id":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-july-2026\/#primaryimage"},"image":{"@id":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-july-2026\/#primaryimage"},"thumbnailUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Major-Cyber-Attacks-in-July-2026-scaled.png","datePublished":"2026-08-04T08:30:51+00:00","dateModified":"2026-08-04T09:08:00+00:00","description":"Explore the major cyber attacks of July 2026, the risks they created across the US and Europe, and the steps security leaders can take to reduce exposure.","breadcrumb":{"@id":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-july-2026\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-july-2026\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-july-2026\/#primaryimage","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Major-Cyber-Attacks-in-July-2026-scaled.png","contentUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/08\/Major-Cyber-Attacks-in-July-2026-scaled.png","width":2560,"height":1243,"caption":"Major Cyber Attacks in July 2026"},{"@type":"BreadcrumbList","@id":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-july-2026\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/any.run\/cybersecurity-blog\/"},{"@type":"ListItem","position":2,"name":"Malware Analysis","item":"https:\/\/any.run\/cybersecurity-blog\/category\/malware-analysis\/"},{"@type":"ListItem","position":3,"name":"Major Cyber Attacks in July 2026: US and EU Organizations Hit by Phishing, RATs, and Stealers"}]},{"@type":"WebSite","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/","name":"ANY.RUN&#039;s Cybersecurity Blog","description":"Cybersecurity Blog covers topics for experienced professionals as well as for those new to it.","publisher":{"@id":"https:\/\/any.run\/"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/any.run\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/any.run\/","name":"ANY.RUN","url":"https:\/\/any.run\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg","contentUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg","width":1,"height":1,"caption":"ANY.RUN"},"image":{"@id":"https:\/\/any.run\/"},"sameAs":["https:\/\/www.facebook.com\/www.any.run\/","https:\/\/x.com\/anyrun_app","https:\/\/www.linkedin.com\/company\/30692044","https:\/\/www.youtube.com\/channel\/UCOgCPho7lzmH7m6fPNlukrQ"]},{"@type":"Person","@id":"https:\/\/any.run\/","name":"ANY.RUN","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","caption":"ANY.RUN"},"url":"https:\/\/any.run\/cybersecurity-blog\/author\/a-bespalova\/"}]}},"_links":{"self":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/22417","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/comments?post=22417"}],"version-history":[{"count":13,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/22417\/revisions"}],"predecessor-version":[{"id":22446,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/22417\/revisions\/22446"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/media\/22430"}],"wp:attachment":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/media?parent=22417"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/categories?post=22417"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/tags?post=22417"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}