ZeroHour

Source: ANY.RUN

3 stories in the last 30d

US Finance Under Phishing Pressure: What the SOC Data Reveals?

ANY.RUN SOC telemetry shows escalating phishing campaigns against US finance, including Vercel-hosted RMM attacks abusing legitimate services.

ANY.RUN analyzed SOC telemetry data on phishing targeting the US financial sector, concluding that the scale and security impact should not be understated. The analysis highlights modern campaigns such as Vercel-hosted attacks that deliver remote monitoring and management (RMM) tools. It notes that attackers increasingly abuse legitimate services and everyday workflow tools to deliver phishing, making detection harder for SOC teams.

ANY.RUN · 20d agoPhishing & fraud in the wild

A Single Canadian Tax Lure Spread into a 46-Country, US-First RMM Campaign

A phishing campaign using fake Canada Revenue Agency tax documents has expanded to 46 countries, with 45% of activity targeting the US via RMM tools.

ANY.RUN analysis traced a campaign that began with fake Canada Revenue Agency (CRA) T4 tax documents and grew into a broader remote-access operation spanning 46 countries. The United States accounts for 45% of observed activity. Attackers impersonate trusted organizations and document types to trick victims into installing remote monitoring and management (RMM) tools.

ANY.RUN · 21d agoPhishing & fraud in the wild

Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US

Mirage2FA phishing-as-a-service kit uses AiTM attacks to hijack Microsoft 365 sessions, with over 4,000 US victims.

ANY.RUN analyzed Mirage2FA, an active phishing-as-a-service toolkit that steals Microsoft 365 credentials and authenticated sessions through Adversary-in-the-Middle phishing pages. About 63.7% of identified victims are in the US, with Technology, Manufacturing, and Education the most targeted industries. Thousands of compromise events were recorded between 2024 and 2026.

ANY.RUN · 28d agoPhishing & fraud in the wild1