ANY.RUN Exposes August 2025โ€™s Top Cyber Threats Targeting Global Industries

NEW Logo

DUBAI, DUBAI, UNITED ARAB EMIRATES, August 26, 2025 /EINPresswire.com/ — ANY.RUN, a leading provider of interactive malware analysis and threat intelligence, has released its August 2025 threat roundup, exposing three major attacks targeting enterprises and critical industries worldwide.

Phishing kits and stealers dominated the month with new tactics to bypass defenses and overwhelm analysts, but the research team showed how these campaigns can be safely uncovered before causing costly business damage.

๐“๐ฒ๐œ๐จ๐จ๐ง๐Ÿ๐…๐€: ๐€ ๐Ÿ•-๐’๐ญ๐š๐ ๐ž ๐๐ก๐ข๐ฌ๐ก๐ข๐ง๐  ๐€๐ญ๐ญ๐š๐œ๐ค ๐๐ฎ๐ข๐ฅ๐ญ ๐ญ๐จ ๐๐ž๐š๐ญ ๐ƒ๐ž๐Ÿ๐ž๐ง๐ฌ๐ž๐ฌ

ANY.RUN uncovered Tycoon2FAโ€™s new multi-stage campaign; a seven-step chain of CAPTCHAs, button-hold checks, and validation screens to stay hidden from automated tools. Unlike mass phishing kits, it targets ๐—ด๐—ผ๐˜ƒ๐—ฒ๐—ฟ๐—ป๐—บ๐—ฒ๐—ป๐˜, ๐—บ๐—ถ๐—น๐—ถ๐˜๐—ฎ๐—ฟ๐˜†, ๐—ฎ๐—ป๐—ฑ ๐—ณ๐—ถ๐—ป๐—ฎ๐—ป๐—ฐ๐—ถ๐—ฎ๐—น ๐—ถ๐—ป๐˜€๐˜๐—ถ๐˜๐˜‚๐˜๐—ถ๐—ผ๐—ป๐˜€, ๐˜„๐—ถ๐˜๐—ต ๐Ÿฎ๐Ÿฒ% ๐—ผ๐—ณ ๐—ผ๐—ฏ๐˜€๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฑ ๐—ฐ๐—ฎ๐˜€๐—ฒ๐˜€ ๐—ต๐—ถ๐˜๐˜๐—ถ๐—ป๐—ด ๐˜๐—ต๐—ฒ ๐—ฏ๐—ฎ๐—ป๐—ธ๐—ถ๐—ป๐—ด ๐˜€๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ.

๐‘๐ก๐š๐๐š๐ฆ๐š๐ง๐ญ๐ก๐ฒ๐ฌ ๐’๐ญ๐ž๐š๐ฅ๐ž๐ซ ๐ฏ๐ข๐š ๐‚๐ฅ๐ข๐œ๐ค๐…๐ข๐ฑ

Attackers combined ๐—–๐—น๐—ถ๐—ฐ๐—ธ๐—™๐—ถ๐˜… ๐—ณ๐—น๐—ผ๐˜„๐˜€ ๐˜„๐—ถ๐˜๐—ต ๐—ฅ๐—ต๐—ฎ๐—ฑ๐—ฎ๐—บ๐—ฎ๐—ป๐˜๐—ต๐˜†๐˜€ ๐—ฆ๐˜๐—ฒ๐—ฎ๐—น๐—ฒ๐—ฟ, ๐—ฎ ๐—–++ ๐—บ๐—ฎ๐—น๐˜„๐—ฎ๐—ฟ๐—ฒ designed for large-scale data theft. Delivered through MSI payloads running in memory, it uses ๐—ฎ๐—ป๐˜๐—ถ-๐—ฉ๐—  ๐—ฐ๐—ต๐—ฒ๐—ฐ๐—ธ๐˜€, ๐—ง๐—Ÿ๐—ฆ ๐—ฎ๐—ป๐—ผ๐—บ๐—ฎ๐—น๐—ถ๐—ฒ๐˜€, ๐—ฎ๐—ป๐—ฑ ๐—ฃ๐—ก๐—š ๐˜€๐˜๐—ฒ๐—ด๐—ฎ๐—ป๐—ผ๐—ด๐—ฟ๐—ฎ๐—ฝ๐—ต๐˜† to stay under the radar.

๐’๐š๐ฅ๐ญ๐ฒ๐Ÿ๐…๐€: ๐€ ๐๐ž๐ฐ ๐๐ก๐š๐š๐’ ๐‹๐ข๐ง๐ค๐ž๐ ๐ญ๐จ ๐’๐ญ๐จ๐ซ๐ฆ-๐Ÿ๐Ÿ“๐Ÿ•๐Ÿ“

Experts also exposed Salty2FA, a Phishing-as-a-Service kit capable of bypassing nearly all MFA methods. Already active in ๐—ณ๐—ถ๐—ป๐—ฎ๐—ป๐—ฐ๐—ฒ, ๐—ฒ๐—ป๐—ฒ๐—ฟ๐—ด๐˜†, ๐˜๐—ฒ๐—น๐—ฒ๐—ฐ๐—ผ๐—บ, ๐—ต๐—ฒ๐—ฎ๐—น๐˜๐—ต๐—ฐ๐—ฎ๐—ฟ๐—ฒ, ๐—ฎ๐—ป๐—ฑ ๐—ด๐—ผ๐˜ƒ๐—ฒ๐—ฟ๐—ป๐—บ๐—ฒ๐—ป๐˜, it poses severe risks where one compromised account can disrupt entire operations.

For full technical details, live analyses, IOCs, and guidance on faster detection, visit the ANY.RUN blog.

๐€๐›๐จ๐ฎ๐ญ ๐€๐๐˜.๐‘๐”๐

ANY.RUN helps more than 15,000 organizations worldwide, from banking and healthcare to telecom, retail, and technology, strengthen cybersecurity operations and respond to threats with confidence.

Solutions include the Interactive Sandbox for live malware analysis, Threat Intelligence Lookup for IOC enrichment, and TI Feeds that deliver high-fidelity data directly into SOC workflows.

Built for speed and clarity, ANY.RUN gives teams the visibility they need to uncover hidden attacks, cut investigation time, and stop intrusions earlier.

The ANY.RUN team
ANYRUN FZCO
+1 657-366-5050
email us here
Visit us on social media:
LinkedIn
YouTube
X

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.