ANY.RUN A.I CyberSecurity Scoring
ANY.RUN
Company Information
Website:https://any.run/?utm_source=linkedin&utm_campaign=bio
Employees number:375
Number of followers:22,119
NAICS:541514
Industry Type:Computer and Network Security
Homepage:any.run
ANY.RUN Risk Score (AI oriented)
Between 600 and 649
ANY.RUNComputer and Network Security
Updated:
28/02/2026
28/02/2026
644/1000
Poor
Caa
ANY.RUN Global Score (TPRM)
xxxx
ANY.RUNComputer and Network Security
Score locked

ANY.RUNPoor
Current Score
644Caa (POOR)
01000
1 incidents
-110 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
653
MAY 2026
649
APRIL 2026
649
MARCH 2026
647
FEBRUARY 2026
753
Ransomware
11 Feb 2026 • ANY.RUN
ANY.RUN: BQTLock & GREENBLOOD Ransomware Attacking Organizations to Encrypt and Exfiltrate Data
Emergence of BQTLock and GREENBLOOD Ransomware Strains
643
MEDIUM-110
ANY1770832431
New Ransomware Strains BQTLock and GREENBLOOD Showcase Evolving Threat Tactics
Two advanced ransomware families, BQTLock and GREENBLOOD, have emerged with distinct strategies, complicating detection and response for cybersecurity teams.
BQTLock operates as a stealthy espionage tool, embedding itself within legitimate system processes such as explorer.exe to evade detection. Using a Remcos payload, it bypasses traditional antivirus by masquerading as trusted Windows activity. The malware then executes a UAC bypass via *fodhelper.exe*, gaining elevated privileges without user interaction. Once persistent, it harvests credentials and screenshots, delaying encryption to maximize data theft before extortion.
In contrast, GREENBLOOD prioritizes speed, leveraging Go-based ChaCha8 encryption to lock systems within minutes. It employs a "smash-and-grab" approach, deleting forensic evidence and pressuring victims via a TOR-based leak site. Unlike BQTLock’s slow infiltration, GREENBLOOD’s rapid execution leaves little time for intervention.
Analysts at ANY.RUN uncovered these behaviors in sandbox environments, where real-time execution chains revealed critical early indicators such as unexpected process injections and rapid file modifications. Detecting these signs before encryption is key to containment, as both strains exploit gaps in traditional signature-based defenses.
BQTLock’s persistence mechanisms and GREENBLOOD’s destructive speed highlight the need for behavioral monitoring and updated threat intelligence to counter these evolving threats. Organizations are advised to watch for anomalous interactions between explorer.exe and fodhelper.exe, along with the unique command-line patterns associated with these strains.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
753
DECEMBER 2025
753
NOVEMBER 2025
753
OCTOBER 2025
753
SEPTEMBER 2025
753
AUGUST 2025
753
JULY 2025
753
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for ANY.RUN ??
What was ANY.RUN's A.I Rankiteo Cyber Score in May 2026 ??
What was ANY.RUN's A.I Rankiteo Cyber Score in April 2026 ??
What was ANY.RUN's A.I Rankiteo Cyber Score in March 2026 ??
What was ANY.RUN's A.I Rankiteo Cyber Score in February 2026 ??
What was ANY.RUN's A.I Rankiteo Cyber Score in January 2026 ??
What was ANY.RUN's A.I Rankiteo Cyber Score in December 2025 ??
What was ANY.RUN's A.I Rankiteo Cyber Score in November 2025 ??
What was ANY.RUN's A.I Rankiteo Cyber Score in October 2025 ??
What was ANY.RUN's A.I Rankiteo Cyber Score in September 2025 ??
What was ANY.RUN's A.I Rankiteo Cyber Score in August 2025 ??
What was ANY.RUN's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on ANY.RUN's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with ANY.RUN ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view ANY.RUN's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?