

We curate threat intelligence to provide situational awareness and actionable insights
Threat Identifier Detections
Atomic detections that serve as the foundation of our detection framework.
Threat Scenario Detections
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
Reports Hot Off the Forge
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024




All Threat Reports
Connecting Ransom Cartel Ransomware with REvil
Unit42 researchers report potential connections between Ransom Cartel and REvil ransomware, noting similarities in TTPs and encryption code. Ransom Cartel, emerging in December 2021, uses advanced techniques like PrintNightmare for privilege escalation and DonPAPI for credential harvesting, suggesting a revival of REvil's capabilities.
TeamTNT Resurfaces?
Trend Micro researchers uncover potential new activity from TeamTNT, exploiting misconfigured Docker APIs to deploy coinminers. The activity involves using ZGrab network scanner, malicious shell scripts, and deploying XMRIG cryptocurrency miner. The recent actions suggest TeamTNT may still be active or imitated by a copycat group.
Ukraine and Poland Targeted by New 'Prestige' Ransomware
Microsoft's Threat Intelligence Center reports 'Prestige' ransomware targeting organizations in Ukraine and Poland. The DEV-0960 group uses tools like RemoteExec and Impacket's WMIexec for deployment, with techniques including scheduled tasks, PowerShell commands, and group policy. The campaign is distinct from recent destructive attacks in Ukraine.
Russian Missile Attacks Disrupt Ukraine Telecommunication And Energy Infrastructure
Russian missile strikes on October 10th and 11th caused power outages and disrupted internet and mobile communications in Ukraine, reducing internet traffic by 35%. Critical infrastructure and services were impacted, prompting authorities to urge restricted use of mobile and electrical services. Ukraine relies on backup solutions and Starlink for connectivity.
COVID-19 Phishing Schemes Persist with Google Forms
Inky researchers report a spike in COVID-19 phishing schemes using Google Forms to steal credentials from small business owners. Attackers impersonate the SBA, tricking victims into disclosing sensitive information. With the upcoming winter months, expect an increase in such phishing emails. Verify communications from official sources only.
Pro-Russian Group Calls for Help in Launching DDoS Attacks
BleepingComputer reveals a pro-Russian group crowdsourcing DDoS attacks against Western countries, with financial incentives for participants. The project targets military and educational organizations in Ukraine and has over 400 members. Payouts range from 20,000 to 80,000 rubles for top contributors, highlighting the growing threat of organized cyberattacks.

About the Forge & Threat Reports
Our mission is to assess the operational behaviors of all threats to provide the community, and our customers, with actionable information and enterprise-ready detections in order to defend themselves in an ever- changing threat landscape.

Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
Whitepapers

The World's Best SOC Teams Use Anvilogic
Build Detections You Want, Where You Want






.png)