Major Cyber Attacks in July 2026: US and EU Organizations Hit by Phishing, RATs, and Stealers

Major Cyber Attacks in July 2026: US and EU Organizations Hit by Phishing, RATs, and Stealers
July 2026 attacks showed how trusted business workflows, legitimate platforms, and built-in tools were abused to drive account takeover, data theft, fraud, and persistent access across the US, Europe, and Brazil. ANY.RUN highlighted campaigns involving Kratos, PhantomEnigma, Kali365, Banana RAT, DARTHVADER Stealer, OVERLORD RAT, DestinyStealer, and fake Zoom event lures that exposed Microsoft 365, banking, and public-sector environments. #Kratos #PhantomEnigma #Kali365 #BananaRAT #DARTHVADERStealer #OVERLORDRAT #DestinyStealer #ZoomEvents

Keypoints

  • July attacks exploited trusted services like SharePoint, OneDrive, Zoom Events, Microsoft authentication pages, and compromised government systems to appear legitimate.
  • Kratos targeted Microsoft 365 users with phishing lures that could lead to account takeover, email compromise, payment redirection, and data exposure.
  • PhantomEnigma abused compromised .gov.br portals and mailboxes to deliver malware to Brazilian banking and public-sector targets.
  • Kali365 used device code phishing against U.S. organizations to gain OAuth access and refresh tokens through legitimate Microsoft login pages.
  • Banana RAT focused on Brazilian financial activity, including banking sessions and Pix-related fraud, while evolving persistence and communication methods.
  • Fake PDFs, LNK files, PowerShell, AutoIt, and Windows utilities were used to deploy stealer and RAT payloads while reducing visible indicators.
  • ANY.RUN emphasized that broader behavioral context, not single indicators, is needed to contain campaigns and identify affected accounts, data, and infrastructure.

MITRE Techniques

  • [T1566.002 ] Phishing: Link – Attackers used document-sharing, invoice, and event-invitation lures to drive victims to malicious flows (‘document-sharing, DocuSign, and invoice lures’; ‘fake Zoom event pages’).
  • [T1189 ] Drive-by Compromise – Trusted platforms and redirects were used to move users from benign-looking pages into malicious authentication or delivery steps (‘routing victims through trusted services such as SharePoint, OneDrive, Microsoft Forms, Canva, and Tilda’).
  • [T1078 ] Valid Accounts – Compromised Microsoft 365, government, and other legitimate accounts were used to continue access and pass checks (‘compromised government mailboxes allowed some phishing emails to pass SPF, DKIM, and DMARC checks’).
  • [T1550.001 ] Use Alternate Authentication Material: Application Access Token – Kali365 abused device code flow to obtain OAuth access and refresh tokens (‘could give attackers OAuth access and refresh tokens’).
  • [T1090 ] Proxy – Redirect chains and intermediary services were used to hide the real destination (‘trace the full redirect chain rather than broadly blocking trusted services’).
  • [T1059.001 ] Command and Scripting Interpreter: PowerShell – PowerShell was used in multi-stage infections and to bypass execution controls (‘PowerShell ExecutionPolicy Bypass’; ‘hidden PowerShell activity’).
  • [T1059.003 ] Command and Scripting Interpreter: Windows Command Shell – cmd.exe was used to launch the staged infection chain (‘launched a multi-stage infection chain using cmd.exe’).
  • [T1218 ] System Binary Proxy Execution – Legitimate Windows utilities and trusted applications were used to blend with normal activity (‘legitimate Windows utilities’; ‘Windows utilities, AutoIt, and PowerShell’).
  • [T1027 ] Obfuscated Files or Information – Reduced output, encrypted communication, randomization, and hidden execution made detection harder (‘randomized identifiers, stronger persistence, and encrypted WebSocket communication’).
  • [T1105 ] Ingress Tool Transfer – Attackers downloaded additional payloads and delivered second-stage tools (‘downloaded components’; ‘upload another payload’).
  • [T1547.001 ] Registry Run Keys / Startup Folder – Persistence was maintained through registry-based mechanisms (‘registry-based persistence’).
  • [T1053.005 ] Scheduled Task/Job: Scheduled Task – Banana RAT maintained access through scheduled tasks (‘maintain access through scheduled tasks’).
  • [T1112 ] Modify Registry – Registry changes were used to establish persistence (‘registry-based persistence’).
  • [T1041 ] Exfiltration Over C2 Channel – Stolen data was sent out through HTTP, raw TCP, and malicious remote channels (‘exfiltrated it through two parallel channels: HTTP and raw TCP’).
  • [T1056.001 ] Input Capture: Keylogging – Malware captured keyboard input during remote control and stealing operations (‘capture keyboard input’; ‘keyboard input’).
  • [T1219 ] Remote Access Software – RATs and remote management tools provided interactive control (‘remote management tools’; ‘direct control over the system’).
  • [T1005 ] Data from Local System – Stealers collected browser data, Outlook data, VPN data, screenshots, and files from the device (‘collected browser data, cookies, passwords… Outlook and VPN data’).
  • [T1113 ] Screen Capture – Malware captured desktop screenshots and monitored sessions (‘desktop screenshots’; ‘monitor screens and sessions’).
  • [T1567 ] Exfiltration to Cloud Storage – Data was packaged and moved out through attacker-controlled channels after collection (‘packaged it into a ZIP archive, and exfiltrated it’).
  • [T1095 ] Non-Application Layer Protocol – Raw TCP was used as an exfiltration path (‘through two parallel channels: HTTP and raw TCP’).
  • [T1102 ] Web Service – Trusted web services and SaaS platforms were leveraged in delivery and redirection (‘SharePoint, OneDrive, Zoom Events’).
  • [T1552.001 ] Unsecured Credentials: Credentials In Files – Browser and file-transfer credentials were targeted and stolen from local applications (‘FileZilla credentials’; ‘browser credentials’).

Indicators of Compromise

  • [Domains/URLs ] Legitimate and attacker-controlled delivery paths used in phishing and redirects – events.zoom.us, compromised .gov.br municipal and police portals, and attacker-controlled domains
  • [File names ] Disguised or malicious files used to start infection chains – PDF-disguised LNK file, Microsoft-style filenames, and installer/dropper names tied to Banana RAT
  • [Hashes ] Sample identification and sandbox correlation – isolated hash, related Banana RAT sample, and other hashes referenced in TI Lookup
  • [Network infrastructure ] Command-and-control and exfiltration channels – rotating command-and-control servers, host-specific subdomains, HTTP, and raw TCP endpoints
  • [Email/web artifacts ] Phishing lures and authentication pages – fake Microsoft login page, Microsoft device login page, DocuSign lure, invoice lure, and Zoom-themed event invitations


Read more: https://any.run/cybersecurity-blog/major-cyber-attacks-july-2026/