September 2026 Cyber Campaigns Target US and EU With Session Theft, Phishing and Payment Fraud

Summary
ANY.RUN describes five September campaigns targeting US and EU users and organizations, involving Microsoft 365 session and token theft, remote-access tools, payment-card and OTP theft, evasive phishing, and multi-stage payload delivery.
Key points
- CSuite used business-service lures to steal credentials or authenticated Microsoft 365 sessions and, in some cases, install legitimate remote-management tools.
- N0va used Device Code phishing to obtain Microsoft access and refresh tokens; observed activity also included token exchange and device registration.
- IronToll impersonated services in more than 12 countries to steal payment-card data and one-time passwords, with a live operator panel and recurring backend patterns.
- Wazza used routing, anti-bot checks and multiple redirects to conceal its final Device Code phishing page from automated detection.
- TerminalFix used compromised WordPress sites, encoded payloads, a legitimate Node.js runtime and a signed Microsoft binary; later stages retrieved infrastructure details through a smart contract and public forum profile.
- The article recommends investigating full browser and execution chains, reviewing sessions and device registrations, checking for unexpected remote-management agents, and correlating identity, endpoint and network evidence.
Article Details
- Attack Vectors
- CSuite uses business-themed phishing lures and counterfeit document pages to capture Microsoft 365 credentials and authenticated sessions or deliver files that install remote-management software.
- N0va uses device-code phishing through legitimate Microsoft authentication flows to obtain access and refresh tokens; observed activity also includes device registration.
- IronToll uses cloned service pages to steal payment-card data and one-time passwords, with operators able to request additional details during a victim session.
- Wazza routes visitors through campaign validation, anti-bot checks, and redirects before showing an Adobe Document Cloud-themed device-code phishing page.
- TerminalFix targets users through compromised WordPress sites. Its JavaScript represents binary payloads as English-word sequences that a legitimate Node.js runtime decodes; later stages execute through a signed Microsoft binary.
- Defensive Notes
- For CSuite incidents, revoke sessions, review mailboxes, check for unexpected remote-management agents, and investigate affected endpoints.
- For suspected N0va device-code phishing, review active sessions, device registrations, token activity, and follow-on account access.
- For IronToll, combine domain blocking with detection of recurring backend paths and other patterns that persist as domains change.
- For Wazza, inspect the complete browser flow rather than only the initial URL.
- For TerminalFix, correlate browser activity, script execution, unusual child processes, and outbound connections.
MITRE ATT&CK
T1027 · Obfuscated Files or InformationTerminalFix JavaScript represents binary payloads as sequences of ordinary English words before decoding them.T1059.007 · JavaScriptTerminalFix uses JavaScript in its payload-delivery chain.T1098.005 · Device RegistrationObserved N0va activity includes device registration that could support broader SSO access.T1102.001 · Dead Drop ResolverTerminalFix obtains its final C2 list from a public forum profile.T1219 · Remote Access ToolsOne CSuite path delivers files that install legitimate remote-management tools, including ScreenConnect, Action1, Atera, Syncro, and PDQ Connect.T1528 · Steal Application Access TokenN0va uses device-code phishing to obtain Microsoft access and refresh tokens.T1566.002 · Spearphishing LinkThe described phishing operations route victims from business or service-themed lures to counterfeit document, authentication, or payment pages.
Malware
IronTollSingle IOCs provide limited protection on their own: IronToll rotated disposable infrastructure while keeping recognizable backend patterns in place.N0vaIdentity compromise is becoming harder to contain: N0va and CSuite targeted sessions, tokens, and Microsoft 365 access, extending the impact beyond a stolen password.WazzaAutomated detection can miss the final phishing stage: Wazza used routing and anti-bot checks to keep its Device Code phishing page hidden until the right conditions were met.
Vendors
Products
Action1Depending on the path, attackers either capture credentials and authenticated sessions or deliver files that install tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect.AteraDepending on the path, attackers either capture credentials and authenticated sessions or deliver files that install tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect.Microsoft 365Identity compromise is becoming harder to contain: N0va and CSuite targeted sessions, tokens, and Microsoft 365 access, extending the impact beyond a stolen password.Node.jsJavaScript that represents binary payloads as sequences of ordinary English words and a legitimate Node.js runtime to decode them.PDQ ConnectDepending on the path, attackers either capture credentials and authenticated sessions or deliver files that install tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect.ScreenConnectDepending on the path, attackers either capture credentials and authenticated sessions or deliver files that install tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect.SyncroDepending on the path, attackers either capture credentials and authenticated sessions or deliver files that install tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect.WordPressTerminalFix is a multi-stage campaign targeting users in the US and Canada through compromised WordPress sites.
Tools
Countries
AustraliaWazza is a phishing kit targeting banking, manufacturing, and government organizations, with observed activity in the US, Europe, and Australia.CanadaTerminalFix is a multi-stage campaign targeting users in the US and Canada through compromised WordPress sites.United StatesANY.RUN researchers linked 351 sandbox analyses to the campaign, with 51% of submissions coming from the United States.
Industries
BankingIronToll used postal, banking, government, parking, and travel-themed phishing.ConsultingTechnology, manufacturing, government, healthcare and consulting organizations GovernmentTechnology, manufacturing, government, healthcare and consulting organizations HealthcareTechnology, manufacturing, government, healthcare and consulting organizations ManufacturingTechnology, manufacturing, government, healthcare and consulting organizations TechnologyTechnology, manufacturing, government, healthcare and consulting organizations