

We curate threat intelligence to provide situational awareness and actionable insights
Threat Identifier Detections
Atomic detections that serve as the foundation of our detection framework.
Threat Scenario Detections
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
Reports Hot Off the Forge
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024




All Threat Reports
Pyarmor Pro Shields Batloader for Stealthier Intrusions
The Water Minyades threat actors have refined the Batloader initial access malware, incorporating Pyarmor Pro for stealth, as reported by Trend Micro. Since December 2022, Pyarmor, particularly its professional variant, has been utilized to obfuscate Batloader, complicating detection due to most antivirus engines lacking an unpacker for Pyarmor. Batloader’s attack chain uses Windows Installer package files, the Windows command-line interface, and batch files. Once executed, it leverages native Windows tools for host enumeration and sends the data to a command and control server. It can then facilitate the installation of further malware payloads, such as Ursnif, Vidar, or Redline Stealer, with potential escalation to dangerous ransomware deployments, including those associated with the Royal and BlackSuit ransomware gangs.
Dragos Measures a 2x Increase in Ransomware Attacks Against Industrial Orgs in Q2 2023
In Q2 2023, ransomware attacks on industrial sectors doubled, as revealed by Dragos. North America was the primary target, with manufacturing facing the majority of threats. Prominent gangs like Lockbit 3.0 spearheaded these attacks, and given the current geopolitical climate, a further surge in Q3 is anticipated.
APT29: Actively Running Phishing Attacks Centered on Microsoft Teams
Russian threat group APT29 has been actively running phishing campaigns on Microsoft Teams to steal user credentials since May 2023. Posing as technical support, they target entities in government, manufacturing, media, NGOs, and tech sectors, furthering Russia's espionage objectives.
BATLoader Assists the Spread of XWorm
Cyble uncovers a complex infection chain where the BATLoader malware facilitates the spread of the versatile XWorm malware. Starting with deceptive spam emails, the infection uses multiple binaries and scripts to ensure delivery. XWorm boasts capabilities like data theft, DDoS attacks, and ransomware deployment, emphasizing its multifaceted threat potential.
Qakbot: A Reliable Malware of Adaptability
Since 2007, the Qakbot banking trojan has evolved, recently adapting OneNote into its attack strategy. Zscaler's analysis points to Qakbot's myriad of infiltration methods, from phishing emails with malicious HTML and PDF documents to innovative evasion using conhost.exe. Activity peaked in March and April 2023, with significant targeting in Germany, the US, and Brazil. Despite a recent lull, experts anticipate a resurgence in Qakbot attacks.
FIN8 Compromised an EMEA Retailer
The financially-driven threat group, FIN8, targeted an EMEA retailer on April 30th, 2023, leading to the exfiltration of 61GB of data. Darktrace identifies SSL connections, lateral movements, and potential DCSync attacks as key indicators. The initial breach point remains unidentified, but phishing, a known strategy of FIN8, is suspected. Nine devices, including five administrative ones, played roles in this breach.

About the Forge & Threat Reports
Our mission is to assess the operational behaviors of all threats to provide the community, and our customers, with actionable information and enterprise-ready detections in order to defend themselves in an ever- changing threat landscape.

Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
Whitepapers

The World's Best SOC Teams Use Anvilogic
Build Detections You Want, Where You Want






.png)