logo

From Tycoon2FA to Lazarus Group – Inside ANY.RUN’s Biggest Discoveries of 2025

ID: 5570e735-c993-5ae8-b0ff-585b240b27a1

STIX ID: report--5570e735-c993-5ae8-b0ff-585b240b27a1

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2026-01-07

Date Updated: 2026-04-21

Author: Balaji N

...
...

ANY.RUN's 2025 annual report details platform growth and new analysis capabilities (Android and Debian/ARM support, Detonation Actions, AI Sigma Rules) and describes notable threat intelligence activity: detection and analysis of phishing-as-a-service frameworks (Salty2FA, Tycoon2FA), Android banking stealers (Salvador Stealer, Pentagon Stealer), credential stealers (Tykit), a hybrid Salty2FA/Tycoon2FA cross-kit, and published research on a Lazarus Group infiltration scheme — alongside ecosystem integrations and plans for 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.