Anvilogic Forge Threat Research Reports

Here you can find an accumulation of trending threats published weekly by the Anvilogic team.

We curate threat intelligence to provide situational awareness and actionable insights

Forge Threat Report

Forge Report: First Half Threat Trends of 2024

Anvilogic Forge's latest report offers essential insights into key threat trends and adversarial tactics observed in the first half of 2024. From the pervasive use of PowerShell and remote access tools to sophisticated social engineering and attacks on the healthcare sector, this comprehensive analysis provides actionable intelligence and detection rules to bolster your defenses. Explore our key findings and access ready-to-deploy detection content to enhance your security posture.

All Threat Reports

Levels

All
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
This is some text inside of a div block.
08
-
24
-
2023

Rhysida Ransomware On the Rise & Aims Sights on Healthcare Industry

Trend Micro's 2023 report delves into the activities of the Rhysida ransomware group, particularly its disruption of 16 hospitals in August. The gang, while primarily targeting healthcare, has also been seen impacting a range of industries from education to technology. With a global footprint, Rhysida’s prominent presence in countries like Indonesia and the US is evident. The ransomware’s techniques, including phishing and PowerShell script utilization, have been discussed in detail, with a peculiar note on their strategy of presenting themselves as a "cybersecurity team" in their ransom communications.

Education
Financial
Government
Healthcare
Insurance
Level:
Tactical
|
Source:
This is some text inside of a div block.
08
-
24
-
2023

Exploring the Latest Tools & Tactics of Cuba Ransomware

BlackBerry's 2023 report delves into the ever-evolving tactics and tools of the Cuba ransomware group, highlighting their continuous threat, especially to Western targets, and their new strategies like exploiting Veeam servers.

Critical Infrastructure
Global
Level:
Tactical
|
Source:
This is some text inside of a div block.
08
-
17
-
2023

Colorado Department of Higher Education Reveals Data Incident Affects Students As Far Back As 2004

The Colorado Department of Higher Education (CDHE) has issued a notice of a network intrusion occurring between June 11th and 19th, 2023, which led to a ransomware attack. The breach potentially impacts a wide array of individuals, including those who attended public educational institutions in Colorado between specific years, stretching as far back as 2004. The compromised data includes full names, social security numbers, student identification numbers, and education records, with affected parties set to receive two years of credit monitoring through Experian once the investigation concludes.

Education
Level:
Strategic
|
Source:
This is some text inside of a div block.
08
-
17
-
2023

Rhysida Ransomware Caused Outages to 16 Hospitals?

In the aftermath of the ransomware attack on August 3rd, 2023, that impacted Prospect Medical hospitals, it has been confirmed that 16 hospitals across four states were affected. This major incident, attributed to the relatively new Rhysida ransomware group, has led to hospital closures, the rescheduling of patient appointments, and the rerouting of patients to other facilities. Both the FBI and the U.S. Department of Health and Human Services have remained silent on the details of the attack, while an HC3 advisory suggests a potential link between Rhysida and the Vice Society ransomware gang.

Healthcare
Level:
Strategic
|
Source:
This is some text inside of a div block.
08
-
17
-
2023

eSentire Unveils Operation PhantomControl

In July 2023, eSentire researchers uncovered a malicious campaign dubbed Operation PhantomControl, identified through suspicious PowerShell commands. The attackers utilized the ScreenConnect remote access tool, delivered through compromised websites, including a domain associated with 'Teachflix', a classroom learning and video-sharing site. After gaining access, the attackers deployed various files and scripts, including a notable PowerShell script disguised as an SVG file, to deploy AsyncRAT, harvest user data and credentials, and establish persistence on infected systems.

Global
Level:
Tactical
|
Source:
This is some text inside of a div block.
08
-
17
-
2023

TargetCompany Ransomware Layers Intrusions with Remcos

The TargetCompany ransomware operators are enhancing their intrusion strategies by employing Fully Undetectable (FUD) packers and the Remcos Remote Access Trojan (RAT), aiming to conduct evasive infections. According to Trend Micro analysts Don Ovid Ladores and Nathaniel Morales, the attackers initially gain access through vulnerable SQL servers. They then execute a PowerShell script to download executable files into the TEMP directory, eventually leading to the successful download and installation of the Remcos RAT. The FUD packer style used resembles that used by BatCloak, involving batch files and PowerShell for Living-Off-The-Land Binaries (LOLBins) execution. Metasploit is also utilized in the attack chain. Trend Micro emphasizes TargetCompany's adoption since February 2022 of a 'cmd x PowerShell' loader technique, likely inspired by OneNote campaigns using PowerLoad. Unlike other malware, the loaders for Remcos and TargetCompany focus on integrating decompression into their binaries, likely altering the payload to evade detection.

Global
Level:
Tactical
|
Source:

About the Forge & Threat Reports

Deploy and maintain detections and threat hunt across all of your logging platforms and security tools without centralizing your data or deploying new agents.

Our mission is to assess the operational behaviors of all threats to provide the community, and our customers, with actionable information and enterprise-ready detections in order to defend themselves in an ever- changing threat landscape.
Sign Up For Weekly Threat Reports

Intelligence Levels for Threat Reports

Tactical

Detectable threat behaviors for response with threat scenarios or threat identifiers.

Strategic

General information security news, for awareness.

Whitepapers

No items found.

The World's Best SOC Teams Use Anvilogic

Paypal Logo
Sprinklr Logo
SAP Logo
SAP Logo
Regeneron Logo
Regeneron Logo
SurveyMonkey Logo
TradeWeb Logo
Alteryx Logo
First Citizens Bank Logo
Crypto.com Logo
Rakuten Mobile Logo
St. George's University Logo
Navan Logo
ADP Logo
ADP Logo
Labcorp Logo
Dyson Logo
siemens Logo
Research to keep you up-to-date on threats
Learn More
Interested in joining the Anvilogic team?
See Careers

Build Detections You Want, Where You Want