ANY.RUN says the Wazza phishkit routes visitors through a multi-stage filtering chain before serving an Adobe-themed device-code phishing page. The chain screens out automated traffic, so the first link gives banking, government and manufacturing defenders little to analyze.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives80
- Confidence50
ANY.RUN tied 351 sandbox analyses to CSuite, a phishing operation that steals Microsoft 365 sessions or installs ScreenConnect or Action1 for remote access. Resetting credentials leaves the remote-access half of an intrusion in place.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives80
- Confidence45
Any.Run's researchers found a phishing kit running in 46 countries whose final payload is a signed copy of ScreenConnect or GoTo Resolve, which moves the defensive question from malware signatures to which remote-access tools may execute at all.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+10
- Incentives70
- Confidence60
EfficientIP put ten .cyou domains on its threat feed June 9, 23 days before they went live as redirects to a fake AliExpress site. The chain was designed to outrun reputation scoring, though its landing page had carried a phishing verdict since May 22.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence50
Island says the adversary-in-the-middle service runs on at least 755 domains against hundreds of organizations. The session it steals arrives after an authentication the identity provider records as entirely normal.
Reality
- Evidence45
- Adoption58
- Hype gap+18
- Incentives65
- Confidence55
ANY.RUN says the kit lures staff with Teams, DocuSign and Dropbox pages, walks them through a genuine device code sign-in, and then takes the access and refresh tokens to register a device of its own.
Reality
- Evidence25
- Adoption20
- Hype gap+45
- Incentives85
- Confidence60
Check Point says a Chinese-speaking crew has been running custom Apache modules on compromised Brazilian federal, state and municipal web servers since mid-2025, so the address bar and the TLD tell a visitor nothing useful.
Perspective Coverage
3 publishers
- Builder
- Builder 23%
- Operator
- Operator 58%
- Investor
- Investor 19%
Reality
- Evidence67
- Adoption58
- Hype gap+26
- Incentives66
- Confidence65
ANY.RUN says a commercial phishing kit ran against Microsoft 365 login flows from 2024 to 2026, harvesting session cookies. The control that matters now is what happens to the token.
Reality
- Evidence30
- Adoption38
- Hype gap+40
- Incentives85
- Confidence52
A researcher says an unreported campaign used a fake GSTR-3B overdue notice ahead of the 20 August filing deadline, delivering a patched DLL that a genuinely signed Microsoft binary loads.
Publishers:blog.himanshuanand.com
Reality
- Evidence62
- Adoption28
- Hype gap+18
- Incentives55
- Confidence54