Cyberattacks observed in September showed how difficult it has become to separate malicious activity from legitimate business workflows.
Attackers used trusted cloud services, familiar document-sharing platforms, legitimate authentication flows, remote-management software, and rapidly changing infrastructure to hide different stages of their operations.
For SOC teams, this creates a visibility problem: one alert rarely shows the full attack. For security leaders, it increases the risk that identity compromise, endpoint access, or payment fraud develops before the real scope of the incident is understood.
What September’s Attacks Reveal About US Enterprise Risk
- Identity compromise is becoming harder to contain: N0va and CSuite targeted sessions, tokens, and Microsoft 365 access, extending the impact beyond a stolen password.
- Automated detection can miss the final phishing stage: Wazza used routing and anti-bot checks to keep its Device Code phishing page hidden until the right conditions were met.
- Trusted software can make malicious activity harder to distinguish: CSuite and TerminalFix relied on legitimate tools and processes, which can slow down early validation.
- Single IOCs provide limited protection on their own: IronToll rotated disposable infrastructure while keeping recognizable backend patterns in place.
- A successful compromise can quickly widen in scope: Across these campaigns, access to accounts, endpoints, payments, and internal workflows could overlap within the same incident.
- The full picture is often spread across several systems: Identity, browser, endpoint, and network evidence may need to be connected before teams can see how far an attack has progressed.
Who Attackers Targeted in September
September’s threat activity showed a strong focus on US and EU organizations, Microsoft 365 users, and businesses exposed to phishing, remote access, and payment fraud.
| Target Group | What We Observed |
|---|---|
| US organizations and employees | CSuite had a strong US footprint, while TerminalFix and N0va also targeted North America. |
| Technology, manufacturing, government, healthcare and consulting organizations | These sectors appeared prominently in CSuite activity. |
| Microsoft 365 users | CSuite captured active sessions, while N0va targeted access and refresh tokens. |
| Employees using common business platforms | Attackers impersonated Adobe, DocuSign, Zoom, Dropbox, SharePoint, OneDrive, and similar services. |
| Users exposed to payment and delivery lures | IronToll used postal, banking, government, parking, and travel-themed phishing. |
CSuite Targets US and EU with Session Theft and RMM Abuse, Expanding Fraud and Access Risk
CSuite is a multi-stage phishing operation that combines Microsoft 365 session theft with remote access through legitimate management tools. ANY.RUN researchers linked 351 sandbox analyses to the campaign, with 51% of submissions coming from the United States.

The attack starts with business-themed lures impersonating services such as Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365, then routes victims through filtering and counterfeit document pages. Depending on the path, attackers either capture credentials and authenticated sessions or deliver files that install tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect.

Account and endpoint risk to reduce: Organizations should treat CSuite as more than a phishing or credential-theft incident. A single compromise can expose Microsoft 365 sessions, business email, and employee endpoints at the same time, creating paths to mailbox abuse, payment fraud, persistent remote access, and follow-on phishing. Containment should include session revocation, mailbox review, checks for unexpected management agents, and investigation of affected endpoints.
N0va Targets Microsoft 365 Users with Device Code Phishing, Extending Access Beyond Password Theft
N0va is a phishing kit targeting organizations across North America and Europe with lures impersonating Microsoft Security, Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign. The campaign uses Device Code phishing to obtain access and refresh tokens through legitimate Microsoft authentication flows, allowing attackers to bypass the need for stolen passwords alone.
View sandbox session with Microsoft-themed lure

Observed activity also includes token exchange and device registration that can support broader SSO access, while campaign infrastructure is distributed across compromised websites and cloud services such as Cloudflare Workers and Linode Object Storage.
Identity risk to reduce: Organizations should treat suspicious device-code authentication as a potential token and session compromise, not just a credential issue. Security teams should review active sessions, device registrations, token activity, and follow-on access to confirm whether the attacker still has a valid path into the account.
IronToll Steals Card Data and OTPs Across 12+ Countries
IronToll is a large multi-country phishing platform, identified with high confidence as the IronToll (“Iron Man System”) kit. ANY.RUN researchers connected 114 malicious domains across 71 non-Cloudflare origins through recurring backend patterns.

The platform impersonates government, postal, courier, tax, banking, and transport services across 12+ countries, including USPS in the US, and uses cloned pages to steal payment-card data and OTPs in real time. A WebSocket-based operator panel gives attackers live visibility into victim sessions and lets them request additional card details or one-time passwords.
For a deeper technical breakdown of IronToll’s infrastructure, backend paths, campaign generations, and hunting indicators, see our Premium TI Report, available to Premium Threat Intelligence users.
Fraud risk to reduce: IronToll shows why real-time phishing requires fast detection and response. Live operator involvement can turn stolen card data and OTPs into an immediate payment-fraud opportunity, while disposable domains can rotate quickly. Security teams should combine domain blocking with detection of recurring backend paths and other patterns that persist as infrastructure changes.
Wazza Uses Multi-Stage Routing to Evade Automated Detection
Wazza is a phishing kit targeting banking, manufacturing, and government organizations, with observed activity in the US, Europe, and Australia. Victims first pass through campaign routing and anti-bot filters before reaching an Adobe Document Cloud-themed Device Code phishing page. The flow uses campaign validation, client markers, short-lived session tokens, browser telemetry checks, and multiple redirects to keep the final phishing page hidden until the visitor passes the required checks.

Detection risk to reduce: Wazza is designed to make automated detection less reliable by hiding the final phishing destination behind filtering and staged redirects. Security teams should analyze the full browser flow, not just the first URL, to uncover the final authentication page and confirm malicious activity earlier.
TerminalFix Targets US and Canadian Users with Multi-Stage Delivery and Evasive Payload Execution
TerminalFix is a multi-stage campaign targeting users in the US and Canada through compromised WordPress sites. The attack chain uses several techniques to make malicious activity harder to recognize, including JavaScript that represents binary payloads as sequences of ordinary English words and a legitimate Node.js runtime to decode them.

Later stages execute through a signed Microsoft binary, while the campaign also uses a Polygon smart contract to retrieve lure infrastructure and a public forum profile to obtain its final C2 list.
Detection risk to reduce: TerminalFix shows how malicious activity can be spread across trusted processes, legitimate services, and several execution stages instead of appearing as one clearly malicious file. Security teams should correlate browser activity, script execution, unusual child processes, and outbound connections to catch the full chain before the attacker reaches later-stage C2 communication.
Close Detection Gaps Exposed by September’s Attacks
September’s attacks showed that the hardest part is often not spotting something suspicious, but understanding what it means quickly enough to act. CSuite crossed identity and endpoint access, N0va abused legitimate authentication flows, Wazza used routing and anti-bot checks to evade automated detection, TerminalFix hid malicious execution behind trusted components, and IronToll kept changing infrastructure while reusing recognizable backend patterns.
For security leaders, that puts more pressure on investigation speed and context. Analysts need to move from alert to evidence, then from evidence to campaign-level understanding, without spending too much time rebuilding the same picture manually.
1. See What the Alert Does Next
Many of these attacks only become clearly malicious after the first interaction. A document lure, login request, signed process, or remote-management tool may look legitimate on its own.

ANY.RUN’s Interactive Sandbox lets analysts observe the full behavior behind suspicious files and URLs, including redirects, scripts, process execution, payload delivery, network activity, and other actions that appear later in the chain.
That visibility helps teams validate incidents faster and make containment decisions with less manual investigation. Organizations using ANY.RUN have reported 94% faster threat triage and a 21-minute reduction in MTTR.
2. Turn One Indicator into Wider Threat Context
September’s campaigns showed how easily a single IOC can hide a much larger operation.
ANY.RUN’s Threat Intelligence Lookup helps analysts pivot from domains, IPs, URLs, files, and sandbox findings to related infrastructure, previous activity, and connected threats.

This gives teams more context before they escalate or contain a case, helping reduce time spent on manual enrichment and repeated lookups. In practice, that can mean 30% fewer Tier 1-to-Tier 2 escalations, giving senior analysts more time to focus on the cases that truly need deeper investigation.
3. Bring Confirmed Threat Data Back into Detection
Once malicious activity is confirmed that context should reach the rest of the security stack quickly.
ANY.RUN’s Threat Intelligence Feeds deliver fresh malicious IPs, domains, URLs, and other IOCs into SIEM, SOAR, TIP, firewalls, and other security tools.

The feeds are backed by real-world analysis from a global community of 700,000+ security professionals across 16,000+ organizations, helping teams keep detection coverage current as campaigns rotate infrastructure and change delivery methods.
That reduces manual IOC collection, broadens visibility into active threats, and helps security controls react faster to newly observed malicious infrastructure.
About ANY.RUN
ANY.RUN provides interactive malware analysis and threat intelligence solutions for SOC teams, threat hunters, incident responders, and enterprise security teams.
Its Interactive Sandbox helps analysts safely investigate suspicious files, URLs, phishing pages, and malware while observing the full attack chain in real time. Teams can inspect browser activity, processes, network traffic, persistence, credential access, and other behavior to validate threats faster and make better-informed response decisions.
ANY.RUN’s Threat Intelligence turns data from real-world sandbox investigations into context for detection, threat hunting, and incident response. Analysts can connect individual indicators to related infrastructure and wider campaigns, while Threat Intelligence Feeds bring newly observed threat data into existing security controls.