From Tycoon2FA to Lazarus Group – Inside ANY.RUN’s Biggest Discoveries of 2025
ANY.RUN, a prominent interactive malware analysis platform, concluded 2025 with substantial growth and notable contributions to the cybersecurity sector. The platform's annual report highlights significant achievements and technological advancements.
ANY.RUN, a prominent interactive malware analysis platform, concluded 2025 with substantial growth and notable contributions to the cybersecurity sector. The platform's annual report highlights significant achievements and technological advancements.
In 2025, ANY.RUN's global user base dedicated over 400,000 hours to threat analysis, equivalent to more than 45 years of continuous research. The platform processed 5.7 million analyses across 195 countries, identifying 1.1 million threats. The user community expanded to over 500,000, with 81,000 new members joining during the year. Additionally, 74 of the Fortune 100 companies utilized ANY.RUN’s sandbox for security operations.
Platform Evolution and New Capabilities
ANY.RUN introduced significant updates to its Interactive Sandbox in 2025, enhancing analysis capabilities beyond traditional Windows environments. The platform now supports Android OS, enabling security teams to analyze APK files in virtual machines that mimic real Android devices. Linux Debian OS support was also added, allowing the detonation of ARM-based threats targeting IoT devices and other ARM systems. These enhancements increase the sandbox's versatility in addressing diverse threat landscapes.
To streamline analysis, ANY.RUN launched Detonation Actions, offering guided hints to help analysts uncover hidden threats efficiently. Additionally, AI Sigma Rules were introduced to automate the generation of deployment-ready rules for SIEM, SOAR, and EDR systems.
ANY.RUN, a prominent interactive malware analysis platform, concluded 2025 with substantial growth and notable contributions to the cybersecurity sector.
ANY.RUN's Threat Intelligence Lookup received nearly 195,000 requests in 2025, identifying Tycoon2FA as a prominent threat. The platform democratized access to threat intelligence with a free plan offering verified context at no cost. New features, such as TI Reports and Industry & Geo Threat Landscape data, provided analysts with insights into campaign-specific threats and their relevance to particular sectors and countries. The Threat Intelligence Feeds product expanded through STIX/TAXII integration and new connectors, including partnerships with ThreatQ and major security platforms.
ANY.RUN researchers identified several significant threats before the broader security community, including Salty 2FA, a Phishing-as-a-Service framework, and various Android banking malware variants like Salvador Stealer and Pentagon Stealer. The detection of a hybrid malware combining Salty2FA and Tycoon2FA frameworks marked a notable achievement. The company also published research on Lazarus Group's infiltration schemes involving North Korean IT workers.
In 2025, ANY.RUN received multiple industry accolades, including awards at the Globee Awards, Cybersecurity Excellence Awards, and CyberSecurity Breakthrough Awards. The platform expanded its ecosystem with an SDK release and integrations with security platforms such as Palo Alto Networks Cortex XSOAR, Microsoft Sentinel, Microsoft Defender, and IBM Security QRadar SOAR.
ANY.RUN's 2026 plans include enhanced collaboration features for SOC teams, AI-powered reporting capabilities, and SSL decryption without MITM for improved network threat detection. The platform will also expand VM support to include macOS and Windows Server environments for Enterprise users. User feedback indicates improvements in detection and response times, with a decrease in mean time to detect and respond, and increased investigation efficiency in 95% of security operations centers.
Based on reporting by Cyber Security News.
