

We curate threat intelligence to provide situational awareness and actionable insights
Threat Identifier Detections
Atomic detections that serve as the foundation of our detection framework.
Threat Scenario Detections
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
Reports Hot Off the Forge
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024




All Threat Reports
Lazarus Group Leverages ManageEngine RCE for Breaches to US & UK Orgs
Cisco Talos identifies Lazarus Group, a North Korean state-sponsored actor, exploiting a ManageEngine ServiceDesk vulnerability (CVE-2022-47966) to target US and UK organizations in healthcare and telecommunications. Utilizing the new QuiteRAT malware for reconnaissance, the group demonstrates enhanced capabilities, though it lacks self-persistence. The use of the Qt framework increases the malware's defense evasion. Lazarus's evolving tactics are further highlighted with another malware variant, CollectionRAT, enhancing their cyber arsenal.
Vast Potential of a New Chinese Espionage Group Targeting Taiwanese Organizations
Microsoft's Threat Intelligence highlights Flax Typhoon, a new Chinese espionage group primarily targeting Taiwanese organizations since mid-2021. Using stealthy techniques, the group exploits public-facing servers and utilizes tools like China Chopper, Juicy Potato, and SoftEther VPN. Interestingly, while they establish long-term access, no concrete actions beyond unauthorized access are noted. The group's activities parallel those of Ethereal Panda, another actor with a focus on Taiwan. Microsoft's report seeks to boost awareness and detection of Flax Typhoon's tactics.
FBI: Attributes Spike of Cryptocurrency Thefts to Lazarus
The Lazarus Group, also known as APT38 and affiliated with the Democratic People's Republic of Korea (DPRK), is being linked by the FBI to a series of high-profile cryptocurrency heists. These cyberattacks have targeted several major platforms, leading to the theft of cryptocurrencies valued at millions of dollars. Recent examples include thefts from Alphapo, CoinsPaid, and Atomic Wallet. As the DPRK actors might attempt to convert more than $40 million worth of stolen bitcoin, the FBI is alerting cryptocurrency companies to exercise heightened vigilance and enforce stringent security measures to safeguard their digital assets.
A Large QR Code Phishing Campaigns Favor Energy Companies
In 2023, Cofense sheds light on a substantial QR code phishing campaign with the energy sector at its epicenter. The campaign experienced a massive email distribution surge in June and July, aiming to snatch user credentials by masquerading as a Microsoft security alert. The attackers cleverly employ QR codes to potentially bypass security mechanisms, with further deceptions using trusted domains like Bing and Salesforce.
Perilous Times for LinkedIn Users: Malicious Account Takeovers on the Rise
Cyberint's report underscores an alarming rise in LinkedIn account compromises in 2023. Users worldwide grapple with two primary breach types: temporary locks from suspicious activities like brute-forcing, and full account takeovers with altered access details. Additionally, many face ransom demands and threats of account deletion. The research advises users to strengthen their account security, especially by activating MFA.
Unraveling A New South Asia-Based APT Group
Knownsec 404 and Kaspersky expose a new South Asia-based APT group named 'Mysterious Elephant' or 'APT-K-47'. Active since March 2022, the group targets Pakistani entities through weaponized attachments in phishing emails, deploying the ORPCBackdoor for C2 communication. Their tactics and tools show notable similarities to other regional APTs like BITTER, suggesting potential overlaps or collaborations among these threat actors. The intricate connections among these groups underline the complexity of cyber attribution.

About the Forge & Threat Reports
Our mission is to assess the operational behaviors of all threats to provide the community, and our customers, with actionable information and enterprise-ready detections in order to defend themselves in an ever- changing threat landscape.

Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
Whitepapers

The World's Best SOC Teams Use Anvilogic
Build Detections You Want, Where You Want






.png)