

We curate threat intelligence to provide situational awareness and actionable insights
Threat Identifier Detections
Atomic detections that serve as the foundation of our detection framework.
Threat Scenario Detections
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
Reports Hot Off the Forge
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024




All Threat Reports
MicroBackdoor Attacks Ukraine
On March 9, 2022, Ukraine's Computer Emergency Response Team (CERT-UA) warned that MicroBackdoor malware is targeting Ukrainian government agencies. The malware, distributed via phishing emails, contains a zip file with files that execute malicious VBScript code. CERT-UA's intelligence indicates that the malware was created in January 2022.
HermeticRansom Ransomware Decryptor Released by Avast
Avast has released a decryptor for HermeticRansom, a ransomware component of HermeticWiper. CrowdStrike found a weakness in its encryption schema, allowing files to be decrypted. The ransomware, written in Go, serves as a decoy for the wiper and encrypts files in various paths. The flaw indicates possible inexperience or limited effort by the malware author.
Hacked Sites Spreads Fake "Capitulation" News
On March 3rd, 2022, the Ukrainian State Service of Special Communication and Information Protection (SSSCIP) identified hacked government sites spreading fake news about Ukraine's surrender to Russia. The SSSCIP actively shares updates and warnings about these compromised sites on Twitter, emphasizing that the surrender claims are false.
Anonymous Attacks Russian Government Sites
On March 15th, 2022, the Anonymous group launched DDoS attacks taking down multiple Russian government sites, including FSB and the Stock Exchange. The attacks caused a seven-hour outage, with some sites remaining inaccessible.
DoubleZero Wiper
On March 22, 2022, Symantec reported on the DoubleZero wiper, written in .NET and designed to obfuscate code and zero out critical system files and registry keys. This latest addition joins other wipers like WhisperGate, HermeticWiper, IsaacWiper, and CaddyWiper.
Anonymous Hacker Group Potentially Hacks Nestlé
On March 22nd, 2022, Anonymous claimed to have hacked 10GB of data from Nestlé due to their continued operations in Russia. Nestlé denies the hack, stating the data was accidentally released in February. The company has since limited its offerings in Russia.

About the Forge & Threat Reports
Our mission is to assess the operational behaviors of all threats to provide the community, and our customers, with actionable information and enterprise-ready detections in order to defend themselves in an ever- changing threat landscape.

Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
Whitepapers

The World's Best SOC Teams Use Anvilogic
Build Detections You Want, Where You Want






.png)