US Finance Under Phishing Pressure: What the SOC Data Reveals?
ANY.RUN SOC telemetry shows escalating phishing campaigns against US finance, including Vercel-hosted RMM attacks abusing legitimate services.
ANY.RUN analyzed SOC telemetry data on phishing targeting the US financial sector, concluding that the scale and security impact should not be understated. The analysis highlights modern campaigns such as Vercel-hosted attacks that deliver remote monitoring and management (RMM) tools. It notes that attackers increasingly abuse legitimate services and everyday workflow tools to deliver phishing, making detection harder for SOC teams.
North Korean IT Workers Scheme: Detection IOCs and Tactics for Government and Corporate SOCs
ANY.RUN details the expanding North Korean IT worker infiltration scheme using forged identities and AI-assisted workflows, sharing detection IOCs for SOCs.
ANY.RUN describes how North Korean IT workers infiltrate American and European organizations using forged identities and AI-assisted workflows to become trusted insiders. The operation bypasses traditional security perimeters and has expanded beyond the private sector to government targets. The post provides detection IOCs and tactics for government and corporate SOCs.