Webinar Description
Key Takeaways
- Monthly briefing on VMRay Labs detection updates, including 50+ new YARA rules and two new configuration extractors.
- Covers phishing detection improvements for EvilProxy credential discovery, CAPTCHA-based phishing, tracking pixels and deceptive email links.
- Examines evasion techniques including file masquerading, staged PowerShell and batch script delivery, and Phorpiex beaconing.
- Features threat research case study linking RedLine stealer analysis to maritime business email compromise infrastructure.
- Designed for SOC analysts, threat hunters and security engineers.
About the Webinar
This September 2026 edition of VMRay’s Detection Highlights series presents the latest threat detection updates from VMRay Labs. Fatih Akar, Senior Security Product Manager at VMRay, will walk through new VMRay Threat Identifiers (VTIs), Smart Link Detonation improvements, two new configuration extractors and more than 50 new YARA rules.
Phishing Detection Updates
The session addresses several phishing techniques that threat actors are using to bypass security controls. Topics include EvilProxy credential discovery, CAPTCHA-based phishing designed to evade automated analysis, tracking pixel detection and identification of deceptive email links. These detections reflect the continued evolution of credential phishing campaigns that rely on user interaction and obfuscation to succeed.
Evasion Techniques and Malware Behavior
The webinar covers detection capabilities for common evasion and delivery methods. This includes file masquerading, staged PowerShell and batch script delivery, Phorpiex beaconing activity and suspicious scripting behavior. The presentation will also explain how Smart Link Detonation analyzes misleading links to determine their actual destinations, addressing a technique frequently used in phishing and malware delivery chains.
Expanded YARA Coverage
The 50+ new YARA rules expand detection coverage across multiple threat categories, including stealers, remote access trojans (RATs), ransomware and phishing infrastructure. Two new configuration extractors have also been added to support automated analysis of malware samples.
Threat Research: RedLine to Maritime BEC
Following the detection updates, the session includes a threat research spotlight demonstrating how analysis of a RedLine stealer sample led to the discovery of a broader infrastructure cluster associated with maritime business email compromise. This case study illustrates how malware analysis can reveal connections beyond the initial sample under investigation.
Who Should Attend
This webinar is intended for SOC analysts, threat hunters and security engineers who want to understand current phishing and malware delivery techniques and how detection capabilities are evolving to address them.

