

We curate threat intelligence to provide situational awareness and actionable insights
Threat Identifier Detections
Atomic detections that serve as the foundation of our detection framework.
Threat Scenario Detections
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
Reports Hot Off the Forge
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024




All Threat Reports
The Severity of Cyberattacks Elevated for Latvia
Latvia experiences a 30% rise in cyberattacks linked to its support for Ukraine during the Russia-Ukraine war. Key targets include government, critical infrastructure, and private businesses, with hacktivist group Killnet leading the assaults, primarily through DDoS attacks, though often missing intended targets.
APT36 Impersonates MFA Software to Infect the Indian Government
Zscaler reports APT36's (Transparent Tribe) campaign against the Indian government, using malvertising to distribute backdoored MFA software. The group registers fake domains mimicking official download portals to deploy a python downloader, backdoors, and data exfiltration tools, targeting users running in India's time zone for espionage purposes.
The Threat of IcedID Still Looming
Elastic researchers report that the IcedID banking trojan's infrastructure is still active. Initially targeting financial institutions, IcedID now delivers complex payloads like Cobalt Strike. Using obfuscation techniques with zip files and ISO images, IcedID establishes persistence and enables credential stealing, command execution, and data collection.
APT10 Attacks Japanese Organizations w. LODEINFO Malware
Kaspersky reports that APT10, a Chinese threat group, uses LODEINFO malware to target Japanese organizations since 2019. Employing phishing and DLL side-loading techniques, APT10 focuses on diplomatic, government, media, and think tank sectors. LODEINFO malware evolves frequently to evade detection, supporting cyber espionage objectives.
SentinelLabs Finds Connection Between Black Basta and FIN7
SentinelLabs researchers have identified a connection between the Black Basta ransomware group and FIN7, based on shared custom tools and techniques. Key findings include the use of BIRDDOG backdoor and similarities in tools like Cobalt Strike and SocksBot. Black Basta's tactics include exploiting Microsoft vulnerabilities and using Qakbot for initial access.
A Email Hack Leaks Iranian Nuclear Intel
Iran's Bushehr Nuclear Power Plant was breached by the hacktivist group Black Reward, who claimed responsibility for an email hack. Despite denials from the Atomic Energy Organization of Iran about the exposure of sensitive data, the group claims to have obtained and threatened to release financial reports, administrative documents, and personal information.

About the Forge & Threat Reports
Our mission is to assess the operational behaviors of all threats to provide the community, and our customers, with actionable information and enterprise-ready detections in order to defend themselves in an ever- changing threat landscape.

Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
Whitepapers

The World's Best SOC Teams Use Anvilogic
Build Detections You Want, Where You Want






.png)