{"id":23458,"date":"2026-09-29T08:32:51","date_gmt":"2026-09-29T08:32:51","guid":{"rendered":"https:\/\/any.run\/cybersecurity-blog\/?p=23458"},"modified":"2026-09-29T08:37:44","modified_gmt":"2026-09-29T08:37:44","slug":"major-cyber-attacks-september-2026","status":"publish","type":"post","link":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-september-2026\/","title":{"rendered":"Major Cyber Attacks in September 2026: US and EU Face Session Theft, Remote Access, and Payment Fraud"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Cyberattacks observed in September showed how difficult it has become to separate malicious activity from legitimate business workflows. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Attackers used trusted cloud services, familiar document-sharing platforms, legitimate authentication flows, remote-management software, and rapidly changing infrastructure to hide different stages of their operations. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For SOC teams, this creates a visibility problem: one alert rarely shows the full attack. For security leaders, it increases the risk that identity compromise, endpoint access, or payment fraud develops before the real scope of the incident is understood. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What September\u2019s Attacks Reveal About US Enterprise Risk <\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Identity compromise is becoming harder to contain<\/strong>: N0va and CSuite targeted sessions, tokens, and Microsoft 365 access, extending the impact beyond a stolen password.<\/li>\n\n\n\n<li><strong>Automated detection can miss the final phishing stage<\/strong>: Wazza used routing and anti-bot checks to keep its Device Code phishing page hidden until the right conditions were met.<\/li>\n\n\n\n<li><strong>Trusted software can make malicious activity harder to distinguish<\/strong>: CSuite and TerminalFix relied on legitimate tools and processes, which can slow down early validation.<\/li>\n\n\n\n<li><strong>Single IOCs provide limited protection on their own<\/strong>: IronToll rotated disposable infrastructure while keeping recognizable backend patterns in place.<\/li>\n\n\n\n<li><strong>A successful compromise can quickly widen in scope<\/strong>: Across these campaigns, access to accounts, endpoints, payments, and internal workflows could overlap within the same incident.<\/li>\n\n\n\n<li><strong>The full picture is often spread across several systems<\/strong>: Identity, browser, endpoint, and network evidence may need to be connected before teams can see how far an attack has progressed.<\/li>\n<\/ul>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\n<span class=\"highlight\">Investigate Faster. Limit Business Impact.\n\n<\/span> \n<br>\nGive Analysts the Context to Act Sooner.\n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktoenterprise#contact-sales\" rel=\"noopener\" target=\"_blank\">\nStrengthen Enterprise Defense<\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h2 class=\"wp-block-heading\">Who Attackers Targeted in September <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">September\u2019s threat activity showed a strong focus on US and EU organizations, Microsoft 365 users, and businesses exposed to phishing, remote access, and payment fraud.<\/p>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-399\"\n           style=\"border-collapse:collapse;\n                   border-spacing:0px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"2\"\n           data-rows=\"6\"\n           data-wpID=\"399\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell \"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:50%;                    padding:10px;\n                    \"\n                    >\n                                        Target Group\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell \"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:50%;                    padding:10px;\n                    \"\n                    >\n                                        What We Observed\u00a0                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        US organizations and employees\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        CSuite\u00a0had a strong US footprint, while\u00a0TerminalFix\u00a0and N0va also targeted North America.\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Technology, manufacturing, government,\u00a0healthcare\u00a0and consulting organizations\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        These sectors appeared prominently in\u00a0CSuite\u00a0activity.\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A4\"\n                    data-col-index=\"0\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Microsoft 365 users\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"B4\"\n                    data-col-index=\"1\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        CSuite\u00a0captured active sessions, while N0va targeted access and refresh tokens.\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A5\"\n                    data-col-index=\"0\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Employees using common business platforms\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"B5\"\n                    data-col-index=\"1\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Attackers impersonated Adobe,\u00a0DocuSign, Zoom, Dropbox, SharePoint, OneDrive, and similar services.\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A6\"\n                    data-col-index=\"0\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Users exposed to payment and delivery lures\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"B6\"\n                    data-col-index=\"1\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        IronToll\u00a0used postal, banking, government, parking, and travel-themed phishing.\u00a0                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-399'>\ntable#wpdtSimpleTable-399{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-399 td, table.wpdtSimpleTable399 th { white-space: normal !important; }\n<\/style>\n\n\n\n\n<h2 class=\"wp-block-heading\">CSuite Targets US and EU with Session Theft and RMM Abuse, Expanding Fraud and Access Risk <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">CSuite is a multi-stage phishing operation that combines Microsoft 365 session theft with remote access through legitimate management tools. ANY.RUN researchers linked 351 sandbox analyses to the campaign, with 51% of submissions coming from the United States.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/app.any.run\/tasks\/10ecee38-5f29-421a-9d6a-9e516ba4deeb\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">View sandbox session<\/a> <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/cybersecurity-blog\/csuite-attack-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">Check details and gather IOCs<\/a> <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Submissions-by-Country-1024x768.png\" alt=\"Sandbox submissions by country\" class=\"wp-image-23229\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Submissions-by-Country-1024x768.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Submissions-by-Country-300x225.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Submissions-by-Country-768x576.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Submissions-by-Country-1536x1152.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Submissions-by-Country-2048x1536.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Submissions-by-Country-370x278.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Submissions-by-Country-270x203.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Submissions-by-Country-740x555.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Submissions-by-Country-80x60.png 80w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>CSuite sandbox submissions by country<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">The attack starts with business-themed lures impersonating services such as Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365, then routes victims through filtering and counterfeit document pages. Depending on the path, attackers either capture credentials and authenticated sessions or deliver files that install tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"649\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/CSuite-Attack-Chain-1-1024x649.png\" alt=\"The attack chain of CSuite campaign\" class=\"wp-image-23223\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/CSuite-Attack-Chain-1-1024x649.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/CSuite-Attack-Chain-1-300x190.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/CSuite-Attack-Chain-1-768x486.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/CSuite-Attack-Chain-1-1536x973.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/CSuite-Attack-Chain-1-2048x1297.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/CSuite-Attack-Chain-1-370x234.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/CSuite-Attack-Chain-1-270x171.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/CSuite-Attack-Chain-1-740x469.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>CSuite attack chain discovered by ANY.RUN<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><strong>Account and endpoint risk to reduce:<\/strong> Organizations should treat CSuite as more than a phishing or credential-theft incident. A single compromise can expose Microsoft 365 sessions, business email, and employee endpoints at the same time, creating paths to mailbox abuse, payment fraud, persistent remote access, and follow-on phishing. Containment should include session revocation, mailbox review, checks for unexpected management agents, and investigation of affected endpoints. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">N0va Targets Microsoft 365 Users with Device Code Phishing, Extending Access Beyond Password Theft <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">N0va is a phishing kit targeting organizations across North America and Europe with lures impersonating Microsoft Security, Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign. The campaign uses Device Code phishing to obtain access and refresh tokens through legitimate Microsoft authentication flows, allowing attackers to bypass the need for stolen passwords alone. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/app.any.run\/tasks\/26360cd2-8f2d-4de0-af60-2ec3cf60497c\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">View sandbox session with Microsoft-themed lure<\/a> <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/x.com\/anyrun_app\/status\/2095142285486821549\" target=\"_blank\" rel=\"noreferrer noopener\">Check details and gather IOCs<\/a> <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"819\" height=\"1024\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/N0va-phishkit-attack-details-819x1024.jpeg\" alt=\"N0va phishkit attack details \" class=\"wp-image-23459\" style=\"width:625px;height:auto\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/N0va-phishkit-attack-details-819x1024.jpeg 819w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/N0va-phishkit-attack-details-240x300.jpeg 240w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/N0va-phishkit-attack-details-768x960.jpeg 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/N0va-phishkit-attack-details-1229x1536.jpeg 1229w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/N0va-phishkit-attack-details-1638x2048.jpeg 1638w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/N0va-phishkit-attack-details-370x463.jpeg 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/N0va-phishkit-attack-details-270x338.jpeg 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/N0va-phishkit-attack-details-740x925.jpeg 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/N0va-phishkit-attack-details-scaled.jpeg 2048w\" sizes=\"auto, (max-width: 819px) 100vw, 819px\" \/><figcaption class=\"wp-element-caption\"><em>N0va phishkit attack details<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Observed activity also includes token exchange and device registration that can support broader SSO access, while campaign infrastructure is distributed across compromised websites and cloud services such as Cloudflare Workers and Linode Object Storage. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Identity risk to reduce:<\/strong> Organizations should treat suspicious device-code authentication as a potential token and session compromise, not just a credential issue. Security teams should review active sessions, device registrations, token activity, and follow-on access to confirm whether the attacker still has a valid path into the account. <\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\n<span class=\"highlight\">Turn investigation context into faster action.\n<\/span> \n<br>\nCut MTTR by up to 21 minutes per case.\n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktoenterprise#contact-sales\" rel=\"noopener\" target=\"_blank\">\nSpeed Up Threat Response<\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h2 class=\"wp-block-heading\">IronToll Steals Card Data and OTPs Across 12+ Countries <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">IronToll is a large multi-country phishing platform, identified with high confidence as the <strong>IronToll (\u201cIron Man System\u201d)<\/strong> kit. ANY.RUN researchers connected <strong>114 malicious domains across 71 non-Cloudflare origins<\/strong> through recurring backend patterns.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/app.any.run\/tasks\/205d78f7-4e84-4210-a0fc-8b1a4044b4d2\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Check full attack chain<\/a> <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"657\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/IronToll-1024x657.jpeg\" alt=\"IronToll Steals Card Data and OTPs Across 12+ Countries\" class=\"wp-image-23460\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/IronToll-1024x657.jpeg 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/IronToll-300x193.jpeg 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/IronToll-768x493.jpeg 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/IronToll-1536x986.jpeg 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/IronToll-2048x1314.jpeg 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/IronToll-370x237.jpeg 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/IronToll-270x173.jpeg 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/IronToll-740x475.jpeg 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>A fake payment step exposed inside ANY.RUN sandbox<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">The platform impersonates government, postal, courier, tax, banking, and transport services across <strong>12+ countries<\/strong>, including USPS in the US, and uses cloned pages to steal payment-card data and OTPs in real time. A WebSocket-based operator panel gives attackers live visibility into victim sessions and lets them request additional card details or one-time passwords. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For a deeper technical breakdown of IronToll\u2019s infrastructure, backend paths, campaign generations, and hunting indicators, see our <a href=\"https:\/\/intelligence.any.run\/reports\/09-10-2026-irontoll\" target=\"_blank\" rel=\"noreferrer noopener\">Premium TI Report<\/a>, available to Premium Threat Intelligence users. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Fraud risk to reduce:<\/strong> IronToll shows why real-time phishing requires fast detection and response. Live operator involvement can turn stolen card data and OTPs into an immediate payment-fraud opportunity, while disposable domains can rotate quickly. Security teams should combine domain blocking with detection of recurring backend paths and other patterns that persist as infrastructure changes. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Wazza Uses Multi-Stage Routing to Evade Automated Detection<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Wazza is a phishing kit targeting banking, manufacturing, and government organizations, with observed activity in the US, Europe, and Australia. Victims first pass through campaign routing and anti-bot filters before reaching an Adobe Document Cloud-themed Device Code phishing page. The flow uses campaign validation, client markers, short-lived session tokens, browser telemetry checks, and multiple redirects to keep the final phishing page hidden until the visitor passes the required checks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/app.any.run\/tasks\/be1f83a0-742a-42de-afe4-c20110ef667f\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Check sandbox session<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/x.com\/anyrun_app\/status\/2102745165915996562\" target=\"_blank\" rel=\"noreferrer noopener\">Check details and gather IOCs<\/a><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"819\" height=\"1024\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Wazza-819x1024.png\" alt=\"Wazza phishing kit details\" class=\"wp-image-23474\" style=\"width:579px;height:auto\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Wazza-819x1024.png 819w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Wazza-240x300.png 240w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Wazza-768x960.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Wazza-1229x1536.png 1229w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Wazza-1638x2048.png 1638w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Wazza-370x463.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Wazza-270x338.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Wazza-740x925.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Wazza-scaled.png 2048w\" sizes=\"auto, (max-width: 819px) 100vw, 819px\" \/><figcaption class=\"wp-element-caption\"><em>Wazza phishing kit details<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><strong>Detection risk to reduce:<\/strong> Wazza is designed to make automated detection less reliable by hiding the final phishing destination behind filtering and staged redirects. Security teams should analyze the full browser flow, not just the first URL, to uncover the final authentication page and confirm malicious activity earlier.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TerminalFix Targets US and Canadian Users with Multi-Stage Delivery and Evasive Payload Execution <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">TerminalFix is a multi-stage campaign targeting users in the US and Canada through compromised WordPress sites. The attack chain uses several techniques to make malicious activity harder to recognize, including JavaScript that represents binary payloads as sequences of ordinary English words and a legitimate Node.js runtime to decode them.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/app.any.run\/tasks\/00d12fa2-c9da-44fc-848f-7481a520762a\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">View sandbox session<\/a> <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/x.com\/anyrun_app\/status\/2097679034033324161\" target=\"_blank\" rel=\"noreferrer noopener\">Check details and gather IOCs<\/a> <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"819\" height=\"1024\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Full-TerminalFix-attack-chain-819x1024.png\" alt=\"Full TerminalFix attack chain\" class=\"wp-image-23461\" style=\"width:587px;height:auto\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Full-TerminalFix-attack-chain-819x1024.png 819w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Full-TerminalFix-attack-chain-240x300.png 240w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Full-TerminalFix-attack-chain-768x960.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Full-TerminalFix-attack-chain-1229x1536.png 1229w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Full-TerminalFix-attack-chain-1638x2048.png 1638w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Full-TerminalFix-attack-chain-370x463.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Full-TerminalFix-attack-chain-270x338.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Full-TerminalFix-attack-chain-740x925.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Full-TerminalFix-attack-chain-scaled.png 2048w\" sizes=\"auto, (max-width: 819px) 100vw, 819px\" \/><figcaption class=\"wp-element-caption\"><em>Full TerminalFix attack chain<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Later stages execute through a signed Microsoft binary, while the campaign also uses a Polygon smart contract to retrieve lure infrastructure and a public forum profile to obtain its final C2 list. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Detection risk to reduce:<\/strong> TerminalFix shows how malicious activity can be spread across trusted processes, legitimate services, and several execution stages instead of appearing as one clearly malicious file. Security teams should correlate browser activity, script execution, unusual child processes, and outbound connections to catch the full chain before the attacker reaches later-stage C2 communication.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Close Detection Gaps Exposed by September\u2019s Attacks <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">September\u2019s attacks showed that the hardest part is often not spotting something suspicious, but understanding what it means quickly enough to act. CSuite crossed identity and endpoint access, N0va abused legitimate authentication flows, Wazza used routing and anti-bot checks to evade automated detection, TerminalFix hid malicious execution behind trusted components, and IronToll kept changing infrastructure while reusing recognizable backend patterns.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For security leaders, that puts more pressure on investigation speed and context. Analysts need to move from alert to evidence, then from evidence to campaign-level understanding, without spending too much time rebuilding the same picture manually. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. See What the Alert Does Next <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Many of these attacks only become clearly malicious after the first interaction. A document lure, login request, signed process, or remote-management tool may look legitimate on its own. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"552\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/september-attacks-1024x552.png\" alt=\"Fake verification code displayed inside ANY.RUN sandbox\" class=\"wp-image-23462\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/september-attacks-1024x552.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/september-attacks-300x162.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/september-attacks-768x414.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/september-attacks-1536x829.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/september-attacks-2048x1105.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/september-attacks-370x200.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/september-attacks-270x146.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/september-attacks-740x399.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Fake verification code displayed inside ANY.RUN sandbox<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">ANY.RUN\u2019s <a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\">Interactive Sandbox<\/a> lets analysts observe the full behavior behind suspicious files and URLs, including redirects, scripts, process execution, payload delivery, network activity, and other actions that appear later in the chain. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That visibility helps teams validate incidents faster and make containment decisions with less manual investigation. Organizations using ANY.RUN have reported <strong>94% faster threat triage<\/strong> and a <strong>21-minute reduction in MTTR<\/strong>. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. Turn One Indicator into Wider Threat Context <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">September\u2019s campaigns showed how easily a single IOC can hide a much larger operation. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ANY.RUN\u2019s <a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence Lookup<\/a> helps analysts pivot from domains, IPs, URLs, files, and sandbox findings to related infrastructure, previous activity, and connected threats. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"622\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/CSuite-TI-lookup-query.png-1024x622.webp\" alt=\"ANY.RUN\u2019s Threat Intelligence gives full context into CSuite suspicious activity\" class=\"wp-image-23463\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/CSuite-TI-lookup-query.png-1024x622.webp 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/CSuite-TI-lookup-query.png-300x182.webp 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/CSuite-TI-lookup-query.png-768x466.webp 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/CSuite-TI-lookup-query.png-1536x933.webp 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/CSuite-TI-lookup-query.png-370x225.webp 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/CSuite-TI-lookup-query.png-270x164.webp 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/CSuite-TI-lookup-query.png-740x449.webp 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/CSuite-TI-lookup-query.png.webp 1744w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>ANY.RUN\u2019s Threat Intelligence gives full context into CSuite suspicious activity<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">This gives teams more context before they escalate or contain a case, helping reduce time spent on manual enrichment and repeated lookups. In practice, that can mean <strong>30% fewer Tier 1-to-Tier 2 escalations<\/strong>, giving senior analysts more time to focus on the cases that truly need deeper investigation. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. Bring Confirmed Threat Data Back into Detection <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Once malicious activity is confirmed that context should reach the rest of the security stack quickly. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ANY.RUN\u2019s <a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktotifeedslanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence Feeds<\/a> deliver fresh malicious IPs, domains, URLs, and other IOCs into SIEM, SOAR, TIP, firewalls, and other security tools. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"462\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-feeds-1-1024x462.png\" alt=\"SOC teams implement TI Feeds for fresh and actionable IOCs into their existing stack\" class=\"wp-image-23271\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-feeds-1-1024x462.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-feeds-1-300x135.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-feeds-1-768x346.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-feeds-1-1536x692.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-feeds-1-2048x923.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-feeds-1-370x167.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-feeds-1-270x122.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-feeds-1-740x334.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>SOC teams implement TI Feeds for fresh and actionable IOCs into their existing stack<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">The feeds are backed by real-world analysis from a global community of <strong>700,000+ security professionals across 16,000+ organizations<\/strong>, helping teams keep detection coverage current as campaigns rotate infrastructure and change delivery methods. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That reduces manual IOC collection, broadens visibility into active threats, and helps security controls react faster to newly observed malicious infrastructure. <\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\n<span class=\"highlight\">Turn faster investigations into faster containment.\n<\/span> \n<br>\nReduce workload and strengthen response across entire SOC.\n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=major-cyber-attacks-september-2026&#038;utm_term=290926&#038;utm_content=linktoenterprise#contact-sales\" rel=\"noopener\" target=\"_blank\">\nStrengthen Your SOC Response<\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h2 class=\"wp-block-heading\">About ANY.RUN <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN<\/a> provides interactive malware analysis and threat intelligence solutions for SOC teams, threat hunters, incident responders, and enterprise security teams. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Its <a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\">Interactive Sandbox<\/a> helps analysts safely investigate suspicious files, URLs, phishing pages, and malware while observing the full attack chain in real time. Teams can inspect browser activity, processes, network traffic, persistence, credential access, and other behavior to validate threats faster and make better-informed response decisions. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ANY.RUN\u2019s <a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence<\/a> turns data from real-world sandbox investigations into context for detection, threat hunting, and incident response. Analysts can connect individual indicators to related infrastructure and wider campaigns, while <a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=major-cyber-attacks-september-2026&amp;utm_term=290926&amp;utm_content=linktotifeedslanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence Feeds<\/a> bring newly observed threat data into existing security controls. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cyberattacks observed in September showed how difficult it has become to separate malicious activity from legitimate business workflows. Attackers used trusted cloud services, familiar document-sharing platforms, legitimate authentication flows, remote-management software, and rapidly changing infrastructure to hide different stages of their operations. For SOC teams, this creates a visibility problem: one alert rarely shows the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":23466,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[8],"tags":[57,10,34],"class_list":["post-23458","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware-analysis","tag-anyrun","tag-cybersecurity","tag-malware-analysis"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Major Cyber Attacks in September 2026: US &amp; EU Threats<\/title>\n<meta name=\"description\" content=\"See how September\u2019s major cyber attacks exposed US and EU organizations to account takeover, remote access, payment fraud, and wider operational risk.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-september-2026\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"ANY.RUN\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-september-2026\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-september-2026\\\/\"},\"author\":{\"name\":\"ANY.RUN\",\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"headline\":\"Major Cyber Attacks in September 2026: US and EU Face Session Theft, Remote Access, and Payment Fraud\",\"datePublished\":\"2026-09-29T08:32:51+00:00\",\"dateModified\":\"2026-09-29T08:37:44+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-september-2026\\\/\"},\"wordCount\":1724,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-september-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Major-Cyber-Attacks-in-September-2026-scaled.png\",\"keywords\":[\"ANYRUN\",\"cybersecurity\",\"malware analysis\"],\"articleSection\":[\"Malware Analysis\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-september-2026\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-september-2026\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-september-2026\\\/\",\"name\":\"Major Cyber Attacks in September 2026: US & EU Threats\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-september-2026\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-september-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Major-Cyber-Attacks-in-September-2026-scaled.png\",\"datePublished\":\"2026-09-29T08:32:51+00:00\",\"dateModified\":\"2026-09-29T08:37:44+00:00\",\"description\":\"See how September\u2019s major cyber attacks exposed US and EU organizations to account takeover, remote access, payment fraud, and wider operational risk.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-september-2026\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-september-2026\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-september-2026\\\/#primaryimage\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Major-Cyber-Attacks-in-September-2026-scaled.png\",\"contentUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Major-Cyber-Attacks-in-September-2026-scaled.png\",\"width\":2560,\"height\":1243,\"caption\":\"Major Cyber Attacks in September 2026\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/major-cyber-attacks-september-2026\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Malware Analysis\",\"item\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/category\\\/malware-analysis\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Major Cyber Attacks in September 2026: US and EU Face Session Theft, Remote Access, and Payment Fraud\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN&#039;s Cybersecurity Blog\",\"description\":\"Cybersecurity Blog covers topics for experienced professionals as well as for those new to it.\",\"publisher\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/any.run\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN\",\"url\":\"https:\\\/\\\/any.run\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/ANYRUN-Icon.svg\",\"contentUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/ANYRUN-Icon.svg\",\"width\":1,\"height\":1,\"caption\":\"ANY.RUN\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/www.any.run\\\/\",\"https:\\\/\\\/x.com\\\/anyrun_app\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/30692044\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCOgCPho7lzmH7m6fPNlukrQ\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"caption\":\"ANY.RUN\"},\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/author\\\/a-bespalova\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Major Cyber Attacks in September 2026: US & EU Threats","description":"See how September\u2019s major cyber attacks exposed US and EU organizations to account takeover, remote access, payment fraud, and wider operational risk.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-september-2026\/","twitter_misc":{"Written by":"ANY.RUN","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-september-2026\/#article","isPartOf":{"@id":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-september-2026\/"},"author":{"name":"ANY.RUN","@id":"https:\/\/any.run\/"},"headline":"Major Cyber Attacks in September 2026: US and EU Face Session Theft, Remote Access, and Payment Fraud","datePublished":"2026-09-29T08:32:51+00:00","dateModified":"2026-09-29T08:37:44+00:00","mainEntityOfPage":{"@id":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-september-2026\/"},"wordCount":1724,"commentCount":0,"publisher":{"@id":"https:\/\/any.run\/"},"image":{"@id":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-september-2026\/#primaryimage"},"thumbnailUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Major-Cyber-Attacks-in-September-2026-scaled.png","keywords":["ANYRUN","cybersecurity","malware analysis"],"articleSection":["Malware Analysis"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-september-2026\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-september-2026\/","url":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-september-2026\/","name":"Major Cyber Attacks in September 2026: US & EU Threats","isPartOf":{"@id":"https:\/\/any.run\/"},"primaryImageOfPage":{"@id":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-september-2026\/#primaryimage"},"image":{"@id":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-september-2026\/#primaryimage"},"thumbnailUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Major-Cyber-Attacks-in-September-2026-scaled.png","datePublished":"2026-09-29T08:32:51+00:00","dateModified":"2026-09-29T08:37:44+00:00","description":"See how September\u2019s major cyber attacks exposed US and EU organizations to account takeover, remote access, payment fraud, and wider operational risk.","breadcrumb":{"@id":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-september-2026\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-september-2026\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-september-2026\/#primaryimage","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Major-Cyber-Attacks-in-September-2026-scaled.png","contentUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Major-Cyber-Attacks-in-September-2026-scaled.png","width":2560,"height":1243,"caption":"Major Cyber Attacks in September 2026"},{"@type":"BreadcrumbList","@id":"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-september-2026\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/any.run\/cybersecurity-blog\/"},{"@type":"ListItem","position":2,"name":"Malware Analysis","item":"https:\/\/any.run\/cybersecurity-blog\/category\/malware-analysis\/"},{"@type":"ListItem","position":3,"name":"Major Cyber Attacks in September 2026: US and EU Face Session Theft, Remote Access, and Payment Fraud"}]},{"@type":"WebSite","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/","name":"ANY.RUN&#039;s Cybersecurity Blog","description":"Cybersecurity Blog covers topics for experienced professionals as well as for those new to it.","publisher":{"@id":"https:\/\/any.run\/"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/any.run\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/any.run\/","name":"ANY.RUN","url":"https:\/\/any.run\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg","contentUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg","width":1,"height":1,"caption":"ANY.RUN"},"image":{"@id":"https:\/\/any.run\/"},"sameAs":["https:\/\/www.facebook.com\/www.any.run\/","https:\/\/x.com\/anyrun_app","https:\/\/www.linkedin.com\/company\/30692044","https:\/\/www.youtube.com\/channel\/UCOgCPho7lzmH7m6fPNlukrQ"]},{"@type":"Person","@id":"https:\/\/any.run\/","name":"ANY.RUN","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","caption":"ANY.RUN"},"url":"https:\/\/any.run\/cybersecurity-blog\/author\/a-bespalova\/"}]}},"_links":{"self":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/23458","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/comments?post=23458"}],"version-history":[{"count":19,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/23458\/revisions"}],"predecessor-version":[{"id":23489,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/23458\/revisions\/23489"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/media\/23466"}],"wp:attachment":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/media?parent=23458"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/categories?post=23458"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/tags?post=23458"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}