
ANY.RUN Reveals Major Cyber Attacks in July: Fake 7-Zip App, New DeerStealer Campaign, and More
DUBAI, DUBAI, UNITED ARAB EMIRATES, July 30, 2025 /EINPresswire.com/ -- ANY.RUN has released its July 2025 cyber threat report. The study highlights the most active malware families, infection techniques, and a growing trend: cybercriminals are increasingly using legitimate Remote Monitoring and Management (RMM) software to attack corporate systems.
๐๐๐ฒ ๐๐ข๐ง๐๐ข๐ง๐ ๐ฌ ๐๐ซ๐จ๐ฆ ๐๐ฎ๐ฅ๐ฒ ๐๐๐๐
โ DeerStealer campaign: spread via obfuscated .LNK shortcuts. Execution goes through mshta.exe and PowerShell, allowing malware to bypass basic defenses and deliver payloads silently.
โ Fake 7โZip installer: downloads a malicious archive that extracts Active Directory files, including ntds.dit and the SYSTEM hive. Attackers can use this data for privilege escalation and full domain compromise.
โ Snake Keylogger activity: increased attacks against banking and financial services. The malware uses multiple layers of obfuscation, LOLBins, and registry changes for persistence.
๐๐ซ๐จ๐๐๐๐ซ ๐ญ๐ซ๐๐ง๐๐ฌ ๐ข๐ง ๐๐๐๐
โ ๐๐๐ฎ๐ฌ๐ ๐จ๐ ๐๐๐ ๐ญ๐จ๐จ๐ฅ๐ฌ: attackers often rely on tools normally used by IT teams to gain remote access and move inside networks.
โ ๐๐จ๐ฉ ๐ ๐๐๐ฎ๐ฌ๐๐ ๐๐๐ ๐ฌ๐จ๐ฅ๐ฎ๐ญ๐ข๐จ๐ง๐ฌ (๐๐ ๐๐๐๐): ScreenConnect, UltraVNC, NetSupport, PDQ Connect, Atera.
โ ๐๐ข๐ฏ๐ข๐ง๐ -๐จ๐๐-๐ญ๐ก๐-๐ฅ๐๐ง๐ ๐ญ๐๐๐ญ๐ข๐๐ฌ: cybercriminals increasingly use built-in Windows tools to stay undetected.
โ ๐๐ญ๐๐๐ฅ๐๐ซ ๐ฆ๐๐ฅ๐ฐ๐๐ซ๐ ๐ ๐ซ๐จ๐ฐ๐ญ๐ก: campaigns distributing informationโstealers remain among the most common threats, often delivered through phishing emails or fake software installers.
Visit the ANY.RUN blog for more details.
๐๐จ๐ฐ ๐๐๐.๐๐๐ ๐ก๐๐ฅ๐ฉ๐ฌ ๐๐ฎ๐ฌ๐ข๐ง๐๐ฌ๐ฌ๐๐ฌ ๐๐๐ญ๐๐๐ญ ๐ง๐๐ฐ ๐๐ญ๐ญ๐๐๐ค๐ฌ ๐๐๐ซ๐ฅ๐ฒ
All the threats were identified using ANY.RUNโs malware analysis and threat intelligence solutions that empower companies across finance, healthcare, IT, government, and other industries to catch attacks before they cause damage.
Hereโs how ANY.RUN helps companies stay safer:
โ Faster detection of threats and reduced Mean Time to Detect (MTTD)
โ Full visibility into what threats do on the system without any guesswork
โ Immediate access to IOCs for SIEM enrichment and faster response
โ Less manual effort for analysts, thanks to automated analysis
โ Lower risk of breaches, data loss, and business disruption
โ Shareable, detailed reports for internal teams, clients, or compliance needs
๐๐๐จ๐ฎ๐ญ ๐๐๐.๐๐๐
ANY.RUN is a provider of cybersecurity solutions. Among its products are Interactive sandbox for analysis of malicious behavior in real time and threat intelligence solutions TI Lookup and TI Feeds suitable for browsing and monitoring emerging and evolving threats targeting over 15,000 companies in sectors like finance, manufacturing, and healthcare.
The ANY.RUN team
ANYRUN FZCO
+1 657-366-5050
email us here
Visit us on social media:
LinkedIn
YouTube
X

Distribution channels: Banking, Finance & Investment Industry, Companies, Electronics Industry, IT Industry, Technology
Legal Disclaimer:
EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.
Submit your press release