September saw an expansion of detection coverage across network, file, and behavioral activity, providing analysts with additional visibility into suspicious activity. ANY.RUN added 76 behavior signatures, 16 YARA detections, and 1,098 Suricata rules, strengthening coverage across malware activity, suspicious files, and network communications.
These updates provide SOC and MSSP teams with additional evidence during investigations, helping analysts identify malicious activity faster, validate alerts with greater confidence, and streamline the investigation of suspicious behavior.
Let’s take a closer look at the latest threat coverage and research from September.
Threat Intelligence Reports
In September, we published two new Threat Intelligence Reports covering the IronToll Phishing-as-a-Service (PhaaS) platform and the CSuite phishing operation.
Available to TI Lookup Premium subscribers, the reports provide security teams with actionable intelligence, including indicators of compromise, detection insights, behavioral characteristics, and techniques that can support threat hunting and incident response.

The September reports cover:
- IronToll: A phishing platform used across multiple countries that imitates government websites for fines and fees to capture payment-card information. The platform connects victims with a live operator through a WebSocket-based panel, allowing attackers to interact with sessions in real time and request additional information, such as OTP codes or card details, when needed.
- CSuite: A multi-stage phishing and remote-access campaign targeting organizations across the US and Europe. The operation uses familiar business services and platforms, including Adobe, DocuSign, Zoom, SharePoint, and Microsoft 365 voicemail, to make its campaigns appear legitimate and engage potential victims.
New Behavior Signatures
September’s 76 new behavior signatures cover a range of threats that can appear during day-to-day malware investigations, including loaders, stealers, RATs, ransomware, and mobile threats.
The expanded coverage spans Windows, Linux, macOS, and Android, giving analysts additional context from behavior observed during Interactive Sandbox analysis.
The new detonations include:
By highlighting malicious behavior directly in sandbox sessions, these signatures help SOC and MSSP teams validate alerts, investigate suspicious samples, and move toward response with clearer evidence.

New YARA Rules
The September update adds 16 new YARA detections designed to identify malicious patterns across files and processes.
Together with behavior signatures and network-based detections, the new YARA coverage provides another layer of evidence for classifying suspicious samples and supporting faster malware investigations.
New Suricata Rules
September also added 1,098 new Suricata rules, extending network-level detection across malicious traffic, phishing activity, and command-and-control communications. The new rules include detections for several recent threats and campaigns, such as:
- Gh0stRAT inbound TCP activity (SID: 84004588): Detects live C2 responses from Gh0stRAT following an implant’s TCP check-in.
- Wazza Phishkit HTTP activity (SID: 84004715): Tracks HTTP activity associated with a recently emerged phishing kit that uses the Device Code flow.
- Sailor PhaaS related URL pattern (SID: 85008428): Detects URL patterns associated with an active, Chinese-backed PhaaS framework used for large-scale payment information theft and credential harvesting.
Together, these rules provide additional network-level indicators that can help analysts identify suspicious communications and connect them to specific malware and phishing activity during analysis.

Latest Threat Research
ANY.RUN researchers also published new investigations into active malware and phishing campaigns during September. The research provides practical detection insights, behavioral observations, and indicators that can support threat hunting and incident response.
- CSuite: An investigation into a multi-stage phishing and remote-access operation targeting organizations across the US and Europe, combining Microsoft 365 session theft, device-code phishing, and legitimate remote-management tools to compromise accounts and endpoints.
- HVNC Backdoor: An investigation into a custom HVNC backdoor targeting organizations across Latin America through fake tax documents, DocuSign lures, and banking-themed phishing, revealing capabilities for hidden remote access, persistence, keystroke monitoring, and browser data theft.
About ANY.RUN
ANY.RUN provides interactive malware analysis and threat intelligence solutions used by more than 16,000 organizations worldwide, including 74% of the Fortune 100.
The company’s Interactive Sandbox enables security teams to examine suspicious files, URLs, and phishing activity in real time, while Threat Intelligence helps analysts investigate related threats, identify connections between campaigns, and add context to their findings.
Together, these capabilities help security teams investigate suspicious activity more efficiently, improve detection and response workflows, and act on threats with greater confidence.