August’s attacks showed how quickly trusted business activity can turn into risk. Across the US and Europe, attackers abused Microsoft 365 sessions, legitimate remote-management tools, business-themed files, and even hiring processes to reach corporate systems.
The result was a mix of account takeover, persistent attacker control, credential exposure, and insider risk that often looked legitimate at first.
Here’s what August’s biggest attacks reveal about where enterprise defenses are under pressure.
What August’s Attacks Revealed About Enterprise Risk
Taken together, August’s incidents point to a broader shift in enterprise risk. Attackers are increasingly targeting the points where organizations already place trust: identities, administrative tools, authentication flows, and employees.
Trusted tools created wider business exposure:Unauthorized RMM software and remote-control malware could give attackers control over credentials, files, and internal systems while blending into normal administration.
Identity compromise threatened core workflows:Mirage2FA and 3DBlast targeted Microsoft 365 sessions, OAuth, device-code authentication, and MFA flows, putting email, cloud files, supplier communication, and finance processes at risk.
MFA did not always end the attack:Stolen sessions could remain valid after authentication, meaning password resets alone might not remove the attacker from the account.
Remote hiring became a security concern:The Famous Chollima investigation showed how false identities could pass recruitment checks and receive legitimate permissions acrossing to intellectual property
Changing infrastructure increased SOC workload:Several campaigns rotated domains, phishing flows, hosting, and remote-access tools, making single-IOC blocking less effective.
Limited context could lead to incomplete containment:A legitimate app, successful login, or familiar document may reveal only one part of the incident. Teams need enough context to understand what was compromised and how far the exposure extends.
Reduce the business impact of delayed threat detection. Contain threats before they disrupt critical operations >>Strengthen Enterprise Defense
Who Attackers Targeted in August
August’s threat activity showed a strong focus on US organizations, cloud account users, and businesses relying on remote access and remote hiring.
1. A US-First RMM Campaign Turned Fake Business Documents into Remote Access Across 46 Countries
Research published byANY.RUNin August exposed a phishing campaign spanning46 countries, with 45% of observed activity associated with the United States. Attackers used tax documents, Social Security notices, invoices, Adobe PDFs, VAT notices, and shipping communications to convince victims to install legitimate remote management software.
US-first RMM campaign overview based onANY.RUNresearch
The campaign abused signed RMM tools including GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, and ITarian to establish hands-on remote access. Because these applications are also used for legitimate IT administration, their activity can resemble normal remote administration and make malicious use harder to identify.
Remote-access risk to reduce: Security teams should be able to identify unexpected RMM installations regardless of the product used. Since the campaign changes domains, lures, and remote-access tools, blocking one URL or application is unlikely to stop the wider operation.ANY.RUNhelps expose the full delivery chain and connect recurring campaign patterns across changing infrastructure.
2. Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup Exposed a Different Kind of Insider Threat
A joint investigation by BCA LTD, NorthScan, andANY.RUNfollowed suspected Famous Chollima operatives beyond the interview stage by hiring them into a fake DeFi startup. After onboarding, the workers were given what they believed were company virtual desktops, while in reality they were operating inside specially preparedANY.RUNsandbox environments that recorded their activity.
Discover detection IOCs and tactics for corporate SOCs
Lazarus APT’s IT workers caught on camera
The investigation exposed the use offorged and stolen identities, mule bank accounts, VPNs, remote desktop software, and AI-assisted document manipulation.More importantly, it showed why these schemes go beyond recruitment fraud: once a false identity passes hiring checks, the worker can receive legitimate access tousiness processes without exploiting a vulnerability
Give your SOC faster access to investigation context.Cut MTTR by up to 21 minutes per case >>Accelerate Threat Investigations
Insider risk to reduce:Organizations hiring remotely should treat identity verification as an ongoing security control rather than a one-time HR check. Periodic verification, monitoring for unexpected VPN and remote-access activity, and closer review of privileged developer access can help reveal suspicious behavior after onboarding.
3. Mirage2FA Hijacked Microsoft 365 Sessions, Hitting Over 4K Victims in the US
Mirage2FA put US organizations at the center of a large Microsoft 365 phishing operation, with over 4,000 victims in the United States. The phishing-as-a-service toolkit used adversary-in-the-middle techniques to intercept credentials, 2FA codes, and authenticated session cookies, allowing attackers to hijack active Microsoft 365 sessions even after users completed MFA.
Mirage2FA phishing targets US companies in technology and manufacturing
Technology, manufacturing, education, consulting, and telecommunications were among the industries exposed. Session theft was the most common compromise outcome, creating a path to corporate email, cloud services, internal documents, and trusted business accounts that attackers could use for impersonation, fraud, or further access.
Session theft risk to address: A password reset may not be enough once an authenticated session has been stolen. Security teams should revoke active sessions and tokens, investigate activity performed through the compromised identity, and strengthen high-risk accounts with phishing-resistant MFA.ANY.RUNhelps reveal the complete browser-based attack flow and identify session theft before a compromised Microsoft 365 account creates wider business exposure.
4. SnakeBiteAgent Turned a Business-Themed ZIP into Full Remote Access
ANY.RUNuncovered a new .NET RAT, SnakeBiteAgent, delivered inside a business-themed ZIP archive. Once executed, the malware could give attackers full remote control, access to credentials, and persistent surveillance capabilities, turning a seemingly routine business file into a serious endpoint compromise.
SnakeBiteAgent C2 protocol and observed capabilities
SnakeBiteAgent contains 274 methods with no obfuscation, while its command-and-control traffic is transmitted without encryption. Its capabilities include credential theft, keylogging, hidden desktop access, webcam and microphone capture, and silent installation of AnyDesk and MeshCentral for additional remote access.
Endpoint exposure to contain:A suspicious archive should be investigated beyond the initial file verdict. Security teams need to determine what executes after extraction, what information the malware can access, and whether remote control has already been established.ANY.RUNexposes the execution chain and C2 communication across the analysis sessions, helping analysts confirm the scope of compromise and contain persistent access before exposure spreads.
Cut the risk of persistent attacker access.Help your SOC move from evidence to containment faster >>Contain Threats Earlier
5. 3DBlast Used Microsoft and Google Login Flows to Target US Organizations
A newly observed phishing kit, 3DBlast, targeted users in theUnited Stateswhile impersonating Microsoft 365, Office 365, and Google. Instead of relying on one fixed phishing flow, the kit could switch between BitB, OAuth/device code phishing, AiTM, and DOM relay techniques while rotating its infrastructure.
3DBlast using Microsoft 365 BitB and AiTM phishing landing
These different flows allowed attackers to reproduce familiar login experiences, abuse legitimate authentication processes, intercept sessions, and relay victim interactions in real time. For organizations, that increases the risk of account takeover while makingphishingharder to recognize from a single URL, page, or authentication event.
Analysts can useANY.RUN’sThreat Intelligence Lookupto pivot from recurring campaign patterns and uncover related activity:
url:”/sw.js?tab=t*_*” and threatName:”phishing”
TI Lookup showcases more context and related activity
Close Detection Gaps Exposed by August’s Attacks
August’s attacks showed how quickly malicious activity can change shape. Attackers rotated infrastructure, switched phishing flows, abused legitimate software and authentication processes, and used techniques that could look normal until the wider attack chain became visible.
For SOC teams, reducing risk means keeping defenses current, getting enough behavioral evidence to make faster decisions, and connecting individual alerts to the campaigns behind them.
1. Keep Detection Updated with Fresh Threat Intelligence
Domains, URLs, IP addresses, and delivery infrastructure can change long before a campaign disappears. Relying on indicators collected from previous incidents can leave gaps as attackers move to new infrastructure or modify their delivery methods.
ANY.RUN’sThreat Intelligence Feedsprovide newly observed malicious IPs, domains, and URLs that teams can integrate into SIEM, SOAR, TIP, firewalls, and other security tools.
Fresh threat intelligence delivered directly to existing security controls
The intelligence comes from real-world sandbox investigations, helping security teams continuously update detection coverage instead of waiting for manually collected indicators. Each IOC can also be traced back to the sandbox session where it appeared, giving analysts additional context before they block or escalate it.
2. Give Analysts Behavioral Evidence Behind the Alert
A suspicious URL, attachment, or application does not always reveal the real level of risk on its own. The important evidence often appears after execution: redirects, scripts, credential collection, remote access, persistence, additional payloads, or network communication.
Full attack behavior revealed insideANY.RUN’s Interactive Sandbox
ANY.RUN’sInteractive Sandboxlets analysts safely observe what suspicious files and URLs actually do. Teams can follow browser activity, process execution, network traffic, authentication flows, persistence, credential access, and other behavior within the same investigation.
This gives analysts more evidence to confirm malicious activity, determine the potential scope of compromise, and make containment decisions without rebuilding the attack chain across several separate tools.
3. Expand Individual Alerts into Wider Threat Context
One confirmed malicious file, URL, or domain may represent only a small part of an active campaign. Investigating each indicator separately can make it harder to recognize related infrastructure, recurring behavior, or attacks already observed elsewhere.
ANY.RUN’sThreat Intelligence Lookuphelps teams pivot from files, URLs, domains, IP addresses, behaviors, and sandbox sessions to related threat activity across current and historical data.
Related threat activity connected throughANY.RUNThreat Intelligence Lookup
Analysts can use individual IOCs or recurring campaign patterns as starting points for threat hunting, uncover connected infrastructure, and check whether similar activity has already appeared in other investigations.
Together, TI Lookup and sandbox evidence help teams move beyond one alert at a time and understand the broader threat context sooner, while TI Feeds bring newly observed indicators back into existing security controls to strengthen detection against the next attempt.
Turn stronger threat visibility into faster business protection. Enable faster detection, investigation, and containment.