Major Cyber Attacks in September 2026: US and EU Face Session Theft, Remote Access, and Payment Fraud
Cyberattacks observed 2026-9-29 08:46:24 Author: any.run(查看原文) 阅读量:20 收藏

Cyberattacks observed in September showed how difficult it has become to separate malicious activity from legitimate business workflows.

Attackers used trusted cloud services, familiar document-sharing platforms, legitimate authentication flows, remote-management software, and rapidly changing infrastructure to hide different stages of their operations.

For SOC teams, this creates a visibility problem: one alert rarely shows the full attack. For security leaders, it increases the risk that identity compromise, endpoint access, or payment fraud develops before the real scope of the incident is understood.

What September’s Attacks Reveal About US Enterprise Risk

  • Identity compromise is becoming harder to contain: N0va and CSuite targeted sessions, tokens, and Microsoft 365 access, extending the impact beyond a stolen password.
  • Automated detection can miss the final phishing stage: Wazza used routing and anti-bot checks to keep its Device Code phishing page hidden until the right conditions were met.
  • Trusted software can make malicious activity harder to distinguish: CSuite and TerminalFix relied on legitimate tools and processes, which can slow down early validation.
  • Single IOCs provide limited protection on their own: IronToll rotated disposable infrastructure while keeping recognizable backend patterns in place.
  • A successful compromise can quickly widen in scope: Across these campaigns, access to accounts, endpoints, payments, and internal workflows could overlap within the same incident.
  • The full picture is often spread across several systems: Identity, browser, endpoint, and network evidence may need to be connected before teams can see how far an attack has progressed.

Who Attackers Targeted in September

September’s threat activity showed a strong focus on US and EU organizations, Microsoft 365 users, and businesses exposed to phishing, remote access, and payment fraud.

Target Group  What We Observed 
US organizations and employees  CSuite had a strong US footprint, while TerminalFix and N0va also targeted North America. 
Technology, manufacturing, government, healthcare and consulting organizations  These sectors appeared prominently in CSuite activity. 
Microsoft 365 users  CSuite captured active sessions, while N0va targeted access and refresh tokens. 
Employees using common business platforms  Attackers impersonated Adobe, DocuSign, Zoom, Dropbox, SharePoint, OneDrive, and similar services. 
Users exposed to payment and delivery lures  IronToll used postal, banking, government, parking, and travel-themed phishing. 

CSuite Targets US and EU with Session Theft and RMM Abuse, Expanding Fraud and Access Risk

CSuite is a multi-stage phishing operation that combines Microsoft 365 session theft with remote access through legitimate management tools. ANY.RUN researchers linked 351 sandbox analyses to the campaign, with 51% of submissions coming from the United States.

View sandbox session

Check details and gather IOCs

Sandbox submissions by country
CSuite sandbox submissions by country

The attack starts with business-themed lures impersonating services such as Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365, then routes victims through filtering and counterfeit document pages. Depending on the path, attackers either capture credentials and authenticated sessions or deliver files that install tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect.

The attack chain of CSuite campaign
CSuite attack chain discovered by ANY.RUN

Account and endpoint risk to reduce: Organizations should treat CSuite as more than a phishing or credential-theft incident. A single compromise can expose Microsoft 365 sessions, business email, and employee endpoints at the same time, creating paths to mailbox abuse, payment fraud, persistent remote access, and follow-on phishing. Containment should include session revocation, mailbox review, checks for unexpected management agents, and investigation of affected endpoints.

N0va Targets Microsoft 365 Users with Device Code Phishing, Extending Access Beyond Password Theft

N0va is a phishing kit targeting organizations across North America and Europe with lures impersonating Microsoft Security, Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign. The campaign uses Device Code phishing to obtain access and refresh tokens through legitimate Microsoft authentication flows, allowing attackers to bypass the need for stolen passwords alone.

View sandbox session with Microsoft-themed lure

Check details and gather IOCs

N0va phishkit attack details
N0va phishkit attack details

Observed activity also includes token exchange and device registration that can support broader SSO access, while campaign infrastructure is distributed across compromised websites and cloud services such as Cloudflare Workers and Linode Object Storage.

Identity risk to reduce: Organizations should treat suspicious device-code authentication as a potential token and session compromise, not just a credential issue. Security teams should review active sessions, device registrations, token activity, and follow-on access to confirm whether the attacker still has a valid path into the account.

IronToll Steals Card Data and OTPs Across 12+ Countries

IronToll is a large multi-country phishing platform, identified with high confidence as the IronToll (“Iron Man System”) kit. ANY.RUN researchers connected 114 malicious domains across 71 non-Cloudflare origins through recurring backend patterns.

Check full attack chain

IronToll Steals Card Data and OTPs Across 12+ Countries
A fake payment step exposed inside ANY.RUN sandbox

The platform impersonates government, postal, courier, tax, banking, and transport services across 12+ countries, including USPS in the US, and uses cloned pages to steal payment-card data and OTPs in real time. A WebSocket-based operator panel gives attackers live visibility into victim sessions and lets them request additional card details or one-time passwords.

For a deeper technical breakdown of IronToll’s infrastructure, backend paths, campaign generations, and hunting indicators, see our Premium TI Report, available to Premium Threat Intelligence users.

Fraud risk to reduce: IronToll shows why real-time phishing requires fast detection and response. Live operator involvement can turn stolen card data and OTPs into an immediate payment-fraud opportunity, while disposable domains can rotate quickly. Security teams should combine domain blocking with detection of recurring backend paths and other patterns that persist as infrastructure changes.

Wazza Uses Multi-Stage Routing to Evade Automated Detection

Wazza is a phishing kit targeting banking, manufacturing, and government organizations, with observed activity in the US, Europe, and Australia. Victims first pass through campaign routing and anti-bot filters before reaching an Adobe Document Cloud-themed Device Code phishing page. The flow uses campaign validation, client markers, short-lived session tokens, browser telemetry checks, and multiple redirects to keep the final phishing page hidden until the visitor passes the required checks.

Check sandbox session

Check details and gather IOCs

Wazza phishing kit details
Wazza phishing kit details

Detection risk to reduce: Wazza is designed to make automated detection less reliable by hiding the final phishing destination behind filtering and staged redirects. Security teams should analyze the full browser flow, not just the first URL, to uncover the final authentication page and confirm malicious activity earlier.

TerminalFix Targets US and Canadian Users with Multi-Stage Delivery and Evasive Payload Execution

TerminalFix is a multi-stage campaign targeting users in the US and Canada through compromised WordPress sites. The attack chain uses several techniques to make malicious activity harder to recognize, including JavaScript that represents binary payloads as sequences of ordinary English words and a legitimate Node.js runtime to decode them.

View sandbox session

Check details and gather IOCs

Full TerminalFix attack chain
Full TerminalFix attack chain

Later stages execute through a signed Microsoft binary, while the campaign also uses a Polygon smart contract to retrieve lure infrastructure and a public forum profile to obtain its final C2 list.

Detection risk to reduce: TerminalFix shows how malicious activity can be spread across trusted processes, legitimate services, and several execution stages instead of appearing as one clearly malicious file. Security teams should correlate browser activity, script execution, unusual child processes, and outbound connections to catch the full chain before the attacker reaches later-stage C2 communication.

Close Detection Gaps Exposed by September’s Attacks

September’s attacks showed that the hardest part is often not spotting something suspicious, but understanding what it means quickly enough to act. CSuite crossed identity and endpoint access, N0va abused legitimate authentication flows, Wazza used routing and anti-bot checks to evade automated detection, TerminalFix hid malicious execution behind trusted components, and IronToll kept changing infrastructure while reusing recognizable backend patterns.

For security leaders, that puts more pressure on investigation speed and context. Analysts need to move from alert to evidence, then from evidence to campaign-level understanding, without spending too much time rebuilding the same picture manually.

1. See What the Alert Does Next

Many of these attacks only become clearly malicious after the first interaction. A document lure, login request, signed process, or remote-management tool may look legitimate on its own.

Fake verification code displayed inside ANY.RUN sandbox
Fake verification code displayed inside ANY.RUN sandbox

ANY.RUN’s Interactive Sandbox lets analysts observe the full behavior behind suspicious files and URLs, including redirects, scripts, process execution, payload delivery, network activity, and other actions that appear later in the chain.

That visibility helps teams validate incidents faster and make containment decisions with less manual investigation. Organizations using ANY.RUN have reported 94% faster threat triage and a 21-minute reduction in MTTR.

2. Turn One Indicator into Wider Threat Context

September’s campaigns showed how easily a single IOC can hide a much larger operation.

ANY.RUN’s Threat Intelligence Lookup helps analysts pivot from domains, IPs, URLs, files, and sandbox findings to related infrastructure, previous activity, and connected threats.

ANY.RUN’s Threat Intelligence gives full context into CSuite suspicious activity
ANY.RUN’s Threat Intelligence gives full context into CSuite suspicious activity

This gives teams more context before they escalate or contain a case, helping reduce time spent on manual enrichment and repeated lookups. In practice, that can mean 30% fewer Tier 1-to-Tier 2 escalations, giving senior analysts more time to focus on the cases that truly need deeper investigation.

3. Bring Confirmed Threat Data Back into Detection

Once malicious activity is confirmed that context should reach the rest of the security stack quickly.

ANY.RUN’s Threat Intelligence Feeds deliver fresh malicious IPs, domains, URLs, and other IOCs into SIEM, SOAR, TIP, firewalls, and other security tools.

SOC teams implement TI Feeds for fresh and actionable IOCs into their existing stack
SOC teams implement TI Feeds for fresh and actionable IOCs into their existing stack

The feeds are backed by real-world analysis from a global community of 700,000+ security professionals across 16,000+ organizations, helping teams keep detection coverage current as campaigns rotate infrastructure and change delivery methods.

That reduces manual IOC collection, broadens visibility into active threats, and helps security controls react faster to newly observed malicious infrastructure.

About ANY.RUN

ANY.RUN provides interactive malware analysis and threat intelligence solutions for SOC teams, threat hunters, incident responders, and enterprise security teams.

Its Interactive Sandbox helps analysts safely investigate suspicious files, URLs, phishing pages, and malware while observing the full attack chain in real time. Teams can inspect browser activity, processes, network traffic, persistence, credential access, and other behavior to validate threats faster and make better-informed response decisions.

ANY.RUN’s Threat Intelligence turns data from real-world sandbox investigations into context for detection, threat hunting, and incident response. Analysts can connect individual indicators to related infrastructure and wider campaigns, while Threat Intelligence Feeds bring newly observed threat data into existing security controls.


文章来源: https://any.run/cybersecurity-blog/major-cyber-attacks-september-2026/
如有侵权请联系:admin#unsafe.sh