

We curate threat intelligence to provide situational awareness and actionable insights
Threat Identifier Detections
Atomic detections that serve as the foundation of our detection framework.
Threat Scenario Detections
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
Reports Hot Off the Forge
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024




All Threat Reports
Cuba Ransomware Discovered to Abuse OWASSRF Flaw
Microsoft alerts that the Cuba ransomware gang is exploiting the OWASSRF flaw using CVE-2022-41080. This exploit elevates privileges on Microsoft Exchange servers, bypassing ProxyNotShell mitigations. Similar tactics were used in the recent Rackspace breach by the Play ransomware group.
Gootkit Malware Campaign Expands SEO Poisoning To Target Australian Healthcare Sector
Trend Micro reveals Gootkit malware targeting Australian healthcare via SEO poisoning. Using keywords related to healthcare and cities, users are tricked into downloading malicious ZIP files. The infection chain involves PowerShell scripts and DLL sideloading to deploy Cobalt Strike.
PyPI Malware Campaign Adds a Cloudflare Tunnel to Bypass Firewall Restrictions
Phylum reports a PyPI malware campaign using a Cloudflare tunnel to bypass firewalls, distributing info-stealing and RAT malware. The attack involves encoded PowerShell scripts, data exfiltration, and remote access via WScript.exe and Cloudflare. Malicious packages have been removed from PyPI.
From An IcedID Infection to Domain Compromise in Under 24hrs
Cybereason's research details an IcedID infection that led to domain compromise and data exfiltration within 24 hours. The attack used Cobalt Strike for lateral movement, Rubeus/DCSync for credential access, and involved techniques linked to Conti, Lockbit, and FiveHands, demonstrating cross-group TTP sharing.
CircleCI Discloses A Security Incident, Urges Customers to Rotate Secrets
CircleCI discloses a security incident, advising customers to rotate secrets, review logs for suspicious activity, and replace Project API tokens. The company reassures that no unauthorized actors are active in their systems but encourages precautionary measures.
LockBit Backtracks Attack on SickKids Hospital
LockBit ransomware group provided a free decryptor to SickKids Hospital after a member violated their rules by targeting healthcare. The attack caused delays in patient care and imaging services. LockBit apologized and blocked the member responsible, while the hospital restored 50% of impacted systems by December 29th.

About the Forge & Threat Reports
Our mission is to assess the operational behaviors of all threats to provide the community, and our customers, with actionable information and enterprise-ready detections in order to defend themselves in an ever- changing threat landscape.

Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
Whitepapers

The World's Best SOC Teams Use Anvilogic
Build Detections You Want, Where You Want






.png)