{"id":23546,"date":"2026-10-01T13:13:27","date_gmt":"2026-10-01T13:13:27","guid":{"rendered":"https:\/\/any.run\/cybersecurity-blog\/?p=23546"},"modified":"2026-10-01T13:13:28","modified_gmt":"2026-10-01T13:13:28","slug":"september-threat-coverage-2026","status":"publish","type":"post","link":"https:\/\/any.run\/cybersecurity-blog\/september-threat-coverage-2026\/","title":{"rendered":"Threat Coverage Digest: New Malware Reports and 1,100+ Detection Rules"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">September saw an expansion of detection coverage across network, file, and behavioral activity, providing analysts with additional visibility into suspicious activity. <a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN<\/a> added 76 behavior signatures, 16 YARA detections, and 1,098 Suricata rules, strengthening coverage across malware activity, suspicious files, and network communications. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These updates provide <a href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoenterprise\" target=\"_blank\" rel=\"noreferrer noopener\">SOC<\/a> and <a href=\"https:\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktomssp\" target=\"_blank\" rel=\"noreferrer noopener\">MSSP<\/a> teams with additional evidence during investigations, helping analysts identify malicious activity faster, validate alerts with greater confidence, and streamline the investigation of suspicious behavior. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s take a closer look at the latest threat coverage and research from September. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Threat Intelligence Reports <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In September, we published two new <a href=\"https:\/\/intelligence.any.run\/reports?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_content=ti_reports&amp;utm_term=01102026\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence Reports<\/a> covering the IronToll Phishing-as-a-Service (PhaaS) platform and the CSuite phishing operation. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Available to <a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktotiplans\" target=\"_blank\" rel=\"noreferrer noopener\">TI Lookup Premium<\/a> subscribers, the reports provide security teams with actionable intelligence, including indicators of compromise, detection insights, behavioral characteristics, and techniques that can support threat hunting and incident response. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"532\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/tireportsnew-1024x532.png\" alt=\"\" class=\"wp-image-23547\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/tireportsnew-1024x532.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/tireportsnew-300x156.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/tireportsnew-768x399.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/tireportsnew-1536x798.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/tireportsnew-2048x1064.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/tireportsnew-370x192.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/tireportsnew-270x140.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/tireportsnew-740x385.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Recent malware and phishing campaigns analyzed by ANY.RUN threat intelligence experts<\/em> <\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The September reports cover: <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>IronToll:<\/strong> A phishing platform used across multiple countries that imitates government websites for fines and fees to capture payment-card information. The platform connects victims with a live operator through a WebSocket-based panel, allowing attackers to interact with sessions in real time and request additional information, such as OTP codes or card details, when needed. <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>CSuite:<\/strong> A multi-stage phishing and remote-access campaign targeting organizations across the US and Europe. The operation uses familiar business services and platforms, including Adobe, DocuSign, Zoom, SharePoint, and Microsoft 365 voicemail, to make its campaigns appear legitimate and engage potential victims. <\/li>\n<\/ul>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\n<span class=\"highlight\">95% of SOC teams speed up investigations with ANY.RUN.\u00a0\n\n<\/span> \n<br>\nTurn threat intelligence into faster investigations.\u00a0 \n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=september-threat-coverage-2026&#038;utm_term=011026&#038;utm_content=linktoenterprise#contact-sales\" rel=\"noopener\" target=\"_blank\">\n Explore for Your SOC<\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h2 class=\"wp-block-heading\">New Behavior Signatures <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">September\u2019s 76 new behavior signatures cover a range of threats that can appear during day-to-day malware investigations, including loaders, stealers, RATs, ransomware, and mobile threats.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The expanded coverage spans Windows, Linux, macOS, and Android, giving analysts additional context from behavior observed during <a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\">Interactive Sandbox<\/a> analysis. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The new detonations include:  <\/p>\n\n\n\n<div class=\"wp-block-group is-layout-grid wp-container-core-group-is-layout-9d260ee2 wp-block-group-is-layout-grid\">\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/6b8ea7ae-f96f-400b-b3e2-b24348ccf8fa\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Nyan<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/a67f6cf1-dc75-4cd7-8e3f-46c557f26479\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">ShadowProject<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/009f8518-5a16-4d05-8a28-ca99c6759fd5\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">TokyoCore<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/398ba7c2-9416-494a-b3c4-8b93e9fa94c3\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">RustyStealer<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/0558ccba-356c-4da8-b9d2-a23d2e94c22a\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">XWorm<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/32652c50-8844-40ee-9651-2402659dfb7e\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">NanoCore<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/92474194-7442-4b99-b0aa-6f8f7bceb6c5\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Zeus<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/57432c3a-1aa1-4000-b4c0-51dafe72829a\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">NodeRemote<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/d3155ef8-3670-4795-aca3-a793a23e3771\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">SparkRAT<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/b275be18-9bde-4b18-a480-39a107989086\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">IronChain<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/a057916b-9166-49e9-9b9d-48776a63aa92\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Apex3<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/3c4209c5-2300-4c8f-8887-986be63eb973\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">ShinySp1der<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/603e2d0e-585c-4e7c-9aa6-628dbd330e6b\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">ThrowCrypt<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/795a8b22-4d39-4176-b46c-e1292b00748a\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">VertexNet<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/b93a968e-3122-4a9f-a175-a818f483e8b5\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Vidar<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/90ac57d7-50ff-4235-83a5-0a3cc2518785\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Ker<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/1c4b3a10-f5b1-44f1-9315-715675fa5f8e\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">XVClipper<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/c2e6843b-210d-434e-9746-c7788b165bcc\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">KawaiiUnicorn<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/e4dc3d86-2450-40c5-8508-c50b451cdcef\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Cookie<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/37c6316c-643f-4eda-91a6-82c85e0c29d7\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">JRan<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/9c3acbe3-e233-499b-87c5-cbf184decbbf\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">SevenLock<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/85f89f81-98a7-446d-bd57-5bcf3e88e466\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">RansomDoors<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/512f34ed-689f-4e54-8623-984970086621\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Nebula<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/f0bab50b-04f5-4f73-810c-63b3722ff80e\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">NullHexxx<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/27145bb2-38d3-45af-afa9-83be0d59ab7c\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Guram<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/a4640caf-9113-42f1-aa6d-eb948a2aa8ac\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Umbra<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/07f9a7c3-eb41-411d-990a-9000cd1a2c9e\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">LockBit<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/588490b9-974d-4360-b3e4-d5e9fd2d6b77\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">Chara<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/60bf01f5-53d3-4d2f-a613-145f21129d26\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">CryptoMix<\/a> <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/0d1c2bfe-a8e5-4b3b-aa53-76828e7bbf07\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">JunDesk<\/a> <\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">By highlighting malicious behavior directly in sandbox sessions, these signatures help <a href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoenterprise\" target=\"_blank\" rel=\"noreferrer noopener\">SOC<\/a> and <a href=\"https:\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktomssp\" target=\"_blank\" rel=\"noreferrer noopener\">MSSP<\/a> teams validate alerts, investigate suspicious samples, and move toward response with clearer evidence.  <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"544\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/nyan01-1024x544.png\" alt=\"\" class=\"wp-image-23549\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/nyan01-1024x544.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/nyan01-300x159.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/nyan01-768x408.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/nyan01-1536x816.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/nyan01-2048x1088.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/nyan01-370x197.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/nyan01-270x143.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/nyan01-740x393.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Nyan detected in ANY.RUN&#8217;s Interactive Sandbox<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">New YARA Rules <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The September update adds 16 new YARA detections designed to identify malicious patterns across files and processes. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Together with behavior signatures and network-based detections, the new YARA coverage provides another layer of evidence for classifying suspicious samples and supporting faster malware investigations. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">New Suricata Rules <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">September also added 1,098 new Suricata rules, extending network-level detection across malicious traffic, phishing activity, and command-and-control communications. The new rules include detections for several recent threats and campaigns, such as: <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/6989942b-2509-4e8f-b7ea-045a776ae589\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Gh0stRAT inbound TCP activity<\/strong><\/a> (SID: 84004588): Detects live C2 responses from Gh0stRAT following an implant\u2019s TCP check-in. <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/f6b85a8c-6601-477a-80b4-845de33e3aa5\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Wazza Phishkit HTTP activity<\/strong><\/a> (SID: 84004715): Tracks HTTP activity associated with a recently emerged phishing kit that uses the Device Code flow. <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/app.any.run\/tasks\/62b1a0f7-1e8b-4325-ba79-f0ef547f3428\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Sailor PhaaS related URL pattern<\/strong><\/a> (SID: 85008428): Detects URL patterns associated with an active, Chinese-backed PhaaS framework used for large-scale payment information theft and credential harvesting. <\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Together, these rules provide additional network-level indicators that can help analysts identify suspicious communications and connect them to specific malware and phishing activity during analysis. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"523\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/wazza01-1024x523.png\" alt=\"\" class=\"wp-image-23550\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/wazza01-1024x523.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/wazza01-300x153.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/wazza01-768x392.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/wazza01-1536x784.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/wazza01-2048x1046.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/wazza01-370x189.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/wazza01-270x138.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/wazza01-585x300.png 585w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/wazza01-740x378.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Wazza observed in ANY.RUN&#8217;s Interactive Sandbox<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Latest Threat Research <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN<\/a> researchers also published new investigations into active malware and phishing campaigns during September. The research provides practical detection insights, behavioral observations, and indicators that can support threat hunting and incident response. <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/any.run\/cybersecurity-blog\/csuite-attack-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>CSuite<\/strong><\/a><strong>:<\/strong> An investigation into a multi-stage phishing and remote-access operation targeting organizations across the US and Europe, combining Microsoft 365 session theft, device-code phishing, and legitimate remote-management tools to compromise accounts and endpoints. <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/any.run\/cybersecurity-blog\/hvnc-backdoor-targets-latam\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>HVNC Backdoor<\/strong><\/a><strong>: <\/strong>An investigation into a custom HVNC backdoor targeting organizations across Latin America through fake tax documents, DocuSign lures, and banking-themed phishing, revealing capabilities for hidden remote access, persistence, keystroke monitoring, and browser data theft. <\/li>\n<\/ul>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\n<span class=\"highlight\">30% fewer Tier 1-to-Tier 2 escalations.\n\n<\/span> \n<br>\nHelp analysts move from investigation to response with less manual work.\n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktoenterprise#contact-sales\" rel=\"noopener\" target=\"_blank\">\n Integrate ANY.RUN<\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h2 class=\"wp-block-heading\">About ANY.RUN <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN<\/a> provides interactive malware analysis and threat intelligence solutions used by more than 16,000 organizations worldwide, including 74% of the Fortune 100. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The company\u2019s <a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\">Interactive Sandbox<\/a> enables security teams to examine suspicious files, URLs, and phishing activity in real time, while <a href=\"https:\/\/intelligence.any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=september-threat-coverage-2026&amp;utm_term=011026&amp;utm_content=linktothreatintelligence\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence<\/a> helps analysts investigate related threats, identify connections between campaigns, and add context to their findings. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Together, these capabilities help security teams investigate suspicious activity more efficiently, improve detection and response workflows, and act on threats with greater confidence. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>September saw an expansion of detection coverage across network, file, and behavioral activity, providing analysts with additional visibility into suspicious activity. ANY.RUN added 76 behavior signatures, 16 YARA detections, and 1,098 Suricata rules, strengthening coverage across malware activity, suspicious files, and network communications. These updates provide SOC and MSSP teams with additional evidence during investigations, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":23557,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[9],"tags":[57,10,56],"class_list":["post-23546","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-service-updates","tag-anyrun","tag-cybersecurity","tag-update"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>ANY.RUN&#039;s Threat Coverage Digest: September 2026<\/title>\n<meta name=\"description\" content=\"Explore September&#039;s malware research, threat intelligence updates, and 1,190+ new detection rules from ANY.RUN.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/any.run\/cybersecurity-blog\/september-threat-coverage-2026\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"ANY.RUN\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/september-threat-coverage-2026\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/september-threat-coverage-2026\\\/\"},\"author\":{\"name\":\"ANY.RUN\",\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"headline\":\"Threat Coverage Digest: New Malware Reports and 1,100+ Detection Rules\",\"datePublished\":\"2026-10-01T13:13:27+00:00\",\"dateModified\":\"2026-10-01T13:13:28+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/september-threat-coverage-2026\\\/\"},\"wordCount\":777,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/september-threat-coverage-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/Threat_coverage_updates-scaled.png\",\"keywords\":[\"ANYRUN\",\"cybersecurity\",\"update\"],\"articleSection\":[\"Service Updates\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/september-threat-coverage-2026\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/september-threat-coverage-2026\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/september-threat-coverage-2026\\\/\",\"name\":\"ANY.RUN's Threat Coverage Digest: September 2026\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/september-threat-coverage-2026\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/september-threat-coverage-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/Threat_coverage_updates-scaled.png\",\"datePublished\":\"2026-10-01T13:13:27+00:00\",\"dateModified\":\"2026-10-01T13:13:28+00:00\",\"description\":\"Explore September's malware research, threat intelligence updates, and 1,190+ new detection rules from ANY.RUN.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/september-threat-coverage-2026\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/september-threat-coverage-2026\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/september-threat-coverage-2026\\\/#primaryimage\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/Threat_coverage_updates-scaled.png\",\"contentUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/Threat_coverage_updates-scaled.png\",\"width\":2560,\"height\":1243,\"caption\":\"ANY.RUN's Threat Coverage Digest: September 2026\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/september-threat-coverage-2026\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Service Updates\",\"item\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/category\\\/service-updates\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Threat Coverage Digest: New Malware Reports and 1,100+ Detection Rules\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN&#039;s Cybersecurity Blog\",\"description\":\"Cybersecurity Blog covers topics for experienced professionals as well as for those new to it.\",\"publisher\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/any.run\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN\",\"url\":\"https:\\\/\\\/any.run\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/ANYRUN-Icon.svg\",\"contentUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/ANYRUN-Icon.svg\",\"width\":1,\"height\":1,\"caption\":\"ANY.RUN\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/www.any.run\\\/\",\"https:\\\/\\\/x.com\\\/anyrun_app\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/30692044\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCOgCPho7lzmH7m6fPNlukrQ\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"caption\":\"ANY.RUN\"},\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/author\\\/a-bespalova\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"ANY.RUN's Threat Coverage Digest: September 2026","description":"Explore September's malware research, threat intelligence updates, and 1,190+ new detection rules from ANY.RUN.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/any.run\/cybersecurity-blog\/september-threat-coverage-2026\/","twitter_misc":{"Written by":"ANY.RUN","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/any.run\/cybersecurity-blog\/september-threat-coverage-2026\/#article","isPartOf":{"@id":"https:\/\/any.run\/cybersecurity-blog\/september-threat-coverage-2026\/"},"author":{"name":"ANY.RUN","@id":"https:\/\/any.run\/"},"headline":"Threat Coverage Digest: New Malware Reports and 1,100+ Detection Rules","datePublished":"2026-10-01T13:13:27+00:00","dateModified":"2026-10-01T13:13:28+00:00","mainEntityOfPage":{"@id":"https:\/\/any.run\/cybersecurity-blog\/september-threat-coverage-2026\/"},"wordCount":777,"commentCount":0,"publisher":{"@id":"https:\/\/any.run\/"},"image":{"@id":"https:\/\/any.run\/cybersecurity-blog\/september-threat-coverage-2026\/#primaryimage"},"thumbnailUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Threat_coverage_updates-scaled.png","keywords":["ANYRUN","cybersecurity","update"],"articleSection":["Service Updates"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/any.run\/cybersecurity-blog\/september-threat-coverage-2026\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/any.run\/cybersecurity-blog\/september-threat-coverage-2026\/","url":"https:\/\/any.run\/cybersecurity-blog\/september-threat-coverage-2026\/","name":"ANY.RUN's Threat Coverage Digest: September 2026","isPartOf":{"@id":"https:\/\/any.run\/"},"primaryImageOfPage":{"@id":"https:\/\/any.run\/cybersecurity-blog\/september-threat-coverage-2026\/#primaryimage"},"image":{"@id":"https:\/\/any.run\/cybersecurity-blog\/september-threat-coverage-2026\/#primaryimage"},"thumbnailUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Threat_coverage_updates-scaled.png","datePublished":"2026-10-01T13:13:27+00:00","dateModified":"2026-10-01T13:13:28+00:00","description":"Explore September's malware research, threat intelligence updates, and 1,190+ new detection rules from ANY.RUN.","breadcrumb":{"@id":"https:\/\/any.run\/cybersecurity-blog\/september-threat-coverage-2026\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/any.run\/cybersecurity-blog\/september-threat-coverage-2026\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/any.run\/cybersecurity-blog\/september-threat-coverage-2026\/#primaryimage","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Threat_coverage_updates-scaled.png","contentUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Threat_coverage_updates-scaled.png","width":2560,"height":1243,"caption":"ANY.RUN's Threat Coverage Digest: September 2026"},{"@type":"BreadcrumbList","@id":"https:\/\/any.run\/cybersecurity-blog\/september-threat-coverage-2026\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/any.run\/cybersecurity-blog\/"},{"@type":"ListItem","position":2,"name":"Service Updates","item":"https:\/\/any.run\/cybersecurity-blog\/category\/service-updates\/"},{"@type":"ListItem","position":3,"name":"Threat Coverage Digest: New Malware Reports and 1,100+ Detection Rules"}]},{"@type":"WebSite","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/","name":"ANY.RUN&#039;s Cybersecurity Blog","description":"Cybersecurity Blog covers topics for experienced professionals as well as for those new to it.","publisher":{"@id":"https:\/\/any.run\/"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/any.run\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/any.run\/","name":"ANY.RUN","url":"https:\/\/any.run\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg","contentUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg","width":1,"height":1,"caption":"ANY.RUN"},"image":{"@id":"https:\/\/any.run\/"},"sameAs":["https:\/\/www.facebook.com\/www.any.run\/","https:\/\/x.com\/anyrun_app","https:\/\/www.linkedin.com\/company\/30692044","https:\/\/www.youtube.com\/channel\/UCOgCPho7lzmH7m6fPNlukrQ"]},{"@type":"Person","@id":"https:\/\/any.run\/","name":"ANY.RUN","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","caption":"ANY.RUN"},"url":"https:\/\/any.run\/cybersecurity-blog\/author\/a-bespalova\/"}]}},"_links":{"self":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/23546","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/comments?post=23546"}],"version-history":[{"count":7,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/23546\/revisions"}],"predecessor-version":[{"id":23558,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/23546\/revisions\/23558"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/media\/23557"}],"wp:attachment":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/media?parent=23546"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/categories?post=23546"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/tags?post=23546"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}