logo

Major Cyber Attacks in February 2026: BQTLock, Thread-Hijack Phishing, and MFA Bypass Evolution

ID: 141c22cb-5c85-533d-b2a6-9ad1540b1355

STIX ID: report--141c22cb-5c85-533d-b2a6-9ad1540b1355

Feed Name: ANY.RUN's Cybersecurity Blog

Threat Score
80/100

Date Published: 2026-03-04

Date Updated: 2026-04-26

Author: ANY.RUN

...
...

ANY.RUN analysts report multiple high-risk developments in February 2026: two fast, extortion-capable ransomware families (GREENBLOOD, BQTLock); two stealthy, zero-detection RATs (Moonrise, Karsto) with credential-theft and persistence capabilities; and advanced phishing playbooks—including thread-hijack attacks and PhaaS kits (EvilProxy, Tycoon2FA, Sneaky2FA) hosted on major cloud/CDN providers that evade reputation-based defenses and can bypass MFA. The piece provides sandbox-observed behaviors, sample IOCs, and recommends behavioral detonation and continuous TI feeds to detect and hunt these evasive threats.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.