Anvilogic Forge Threat Research Reports

Here you can find an accumulation of trending threats published weekly by the Anvilogic team.

We curate threat intelligence to provide situational awareness and actionable insights

Forge Threat Report

Forge Report: First Half Threat Trends of 2024

Anvilogic Forge's latest report offers essential insights into key threat trends and adversarial tactics observed in the first half of 2024. From the pervasive use of PowerShell and remote access tools to sophisticated social engineering and attacks on the healthcare sector, this comprehensive analysis provides actionable intelligence and detection rules to bolster your defenses. Explore our key findings and access ready-to-deploy detection content to enhance your security posture.

All Threat Reports

Levels

All
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
This is some text inside of a div block.
12
-
14
-
2022

Vice Society A Threat Group of Opportunity

Palo Alto Unit42 profiles Vice Society, a ransomware group targeting various industries, notably education and healthcare, since 2021. Known for exploiting the PrintNightmare vulnerability and using HelloKitty and Zeppelin ransomware, Vice Society times attacks with the school year calendar. California, Texas, and Pennsylvania are among the most affected states.

Construction
Education
Energy
Finance
Health
Level:
Tactical
|
Source:
This is some text inside of a div block.
12
-
14
-
2022

Iranian Threat Actor Launches New 'Fantasy' Data Wiper

ESET reveals that Iranian threat group Agrius has deployed a new data wiper named 'Fantasy' in supply-chain attacks targeting organizations in Hong Kong, Israel, and South Africa. The 'Fantasy' wiper overwrites files and the master record, but recovery has been possible for some victims, with damages reversed within hours.

Consulting
Retail
Global
Level:
Tactical
|
Source:
This is some text inside of a div block.
12
-
14
-
2022

Activities from a Truebot Infections

Cisco Talos reports a rise in Truebot malware infections since August 2022. Distributed via phishing, botnets, USB infections, and Raspberry Robin, Truebot acts as a downloader for data exfiltration tools like Teleport and deploys Clop ransomware. Truebot infections link to Silence Group and TA505, with post-compromise activities including data theft.

Global
Level:
Tactical
|
Source:
This is some text inside of a div block.
12
-
14
-
2022

DEV-0139 Tailors Attack Against Cryptocurrency Organizations

Microsoft reports DEV-0139 targeting cryptocurrency organizations via Telegram, using weaponized Office documents to deliver malicious payloads. Posing as legitimate representatives, they gain trust before launching attacks. Techniques include DLL sideloading and backdoor deployment, similar to Lazarus group's AppleJesus malware.

Finance
Level:
Tactical
|
Source:
This is some text inside of a div block.
12
-
14
-
2022

Cloud Attacks in AWS and GCP from Compromised Credentials

Palo Alto Unit 42 reports compromised credentials causing security breaches in AWS and GCP. Threat actors launch phishing and cryptomining attacks, quickly exploiting cloud environments. Key actions include enumerating environments, tampering with IAM configurations, and deploying new cloud instances, underscoring the importance of robust cloud security and monitoring.

Global
Level:
Tactical
|
Source:
This is some text inside of a div block.
12
-
06
-
2022

High Demand for Signal App Exploits

Russian company OpZero offers $1.5 million for Signal app RCE exploits, tripling Zerodium's offer. The company's high offer and connections to Russian private and government organizations raise concerns about espionage efforts, particularly targeting Ukraine. OpZero's recent online presence adds to the intrigue.

Global
Level:
Strategic
|
Source:

About the Forge & Threat Reports

Deploy and maintain detections and threat hunt across all of your logging platforms and security tools without centralizing your data or deploying new agents.

Our mission is to assess the operational behaviors of all threats to provide the community, and our customers, with actionable information and enterprise-ready detections in order to defend themselves in an ever- changing threat landscape.
Sign Up For Weekly Threat Reports

Intelligence Levels for Threat Reports

Tactical

Detectable threat behaviors for response with threat scenarios or threat identifiers.

Strategic

General information security news, for awareness.

Whitepapers

No items found.

The World's Best SOC Teams Use Anvilogic

Paypal Logo
Sprinklr Logo
SAP Logo
SAP Logo
Regeneron Logo
Regeneron Logo
SurveyMonkey Logo
TradeWeb Logo
Alteryx Logo
First Citizens Bank Logo
Crypto.com Logo
Rakuten Mobile Logo
St. George's University Logo
Navan Logo
ADP Logo
ADP Logo
Labcorp Logo
Dyson Logo
siemens Logo
Research to keep you up-to-date on threats
Learn More
Interested in joining the Anvilogic team?
See Careers

Build Detections You Want, Where You Want