Anvilogic Forge Threat Research Reports

Here you can find an accumulation of trending threats published weekly by the Anvilogic team.

We curate threat intelligence to provide situational awareness and actionable insights

Forge Threat Report

Forge Report: First Half Threat Trends of 2024

Anvilogic Forge's latest report offers essential insights into key threat trends and adversarial tactics observed in the first half of 2024. From the pervasive use of PowerShell and remote access tools to sophisticated social engineering and attacks on the healthcare sector, this comprehensive analysis provides actionable intelligence and detection rules to bolster your defenses. Explore our key findings and access ready-to-deploy detection content to enhance your security posture.

All Threat Reports

Levels

All
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
This is some text inside of a div block.
07
-
27
-
2023

A Series of Post-Exploitation Activities from an Ursnif Infection

In early July 2023, a security researcher known as Kostas investigated an Ursnif malware infection. The study provides valuable insight into the malware's post-exploitation activities, including automated tasks, deliberate inactivity indicating a coordinated criminal effort, and hands-on-keyboard activity. The initial infection was through a phishing email containing a malicious PDF file. Upon execution, the malware performed a series of tasks for host enumeration, persistence establishment, and process injection. After 30 minutes, further hands-on-keyboard actions were observed, along with additional discovery commands, PowerShell execution, and Cobalt Strike use. This activity suggests a hand-over between different criminal groups during the infection process, further highlighting the coordinated effort behind these attacks.

Global
Level:
Tactical
|
Source:
This is some text inside of a div block.
07
-
27
-
2023

Turla Sets Aim on Collect Data from Defense Industries

The Russian threat group Turla (also known as Secret Blizzard, KRYPTON, and UAC-0003) is conducting an active cyber campaign aimed at gathering sensitive data from defense organizations in Ukraine and Eastern Europe. The campaign, as identified by a joint effort from CERT-UA and Microsoft, utilizes Capibar and Kazuar spyware. The attack begins with phishing emails containing weaponized Excel attachments, and the malware establishes persistence through a scheduled task disguised as a Firefox update. The group also abuses legitimate and compromised Exchange servers, transforming them into malware control centers. Despite detection efforts, as of July 20, 2023, the detection score for a sample of Capibar malware remains relatively low at 20/70 on VirusTotal.

Defense
Level:
Tactical
|
Source:
This is some text inside of a div block.
07
-
27
-
2023

FIN8 Bolsters its Arsenal with BlackCat and Updated Backdoor

In a significant development, the FIN8 threat group has amplified its cybercrime toolkit, introducing the BlackCat ransomware and an updated Sardonic backdoor, according to Symantec's Threat Hunter Team. Previously associated with point-of-sale (POS) attacks, FIN8's shift towards ransomware activities indicates a strategic move to exploit more profitable opportunities. The group's activities primarily impact a wide array of industries, including chemicals, entertainment, financial services, healthcare, hospitality, insurance, retail, and technology.

Chemical
Entertainment
Financial
Healthcare
Hospitality
Level:
Tactical
|
Source:
This is some text inside of a div block.
07
-
20
-
2023

A Splinter of Royal Ransomware Strikes Tampa Bay Zoo

ZooTampa, a nonprofit zoo located in Tampa, Florida, has been targeted in a security breach, possibly by a splinter cell of the Royal ransomware gang known as BlackSuit. The incident has sparked an investigation involving law enforcement. A spokesperson for ZooTampa assured visitors that the zoo does not store any personal or financial information. The breach could potentially be indicative of a new trend in the activities of the Royal ransomware gang. Researchers speculate that Royal is undergoing a rebranding effort in response to increasing law enforcement pressure.

Non-Profit
Level:
Strategic
|
Source:
This is some text inside of a div block.
07
-
20
-
2023

APT29 Adopts Car Sales Persona for Phishing Campaign

The Russian threat group APT29, also known as Cloaked Ursa, has initiated a new phishing campaign disguising as car sales to deliver malware to pro-Ukrainian diplomats. The campaign, which started in May 2023, revolves around distributing weaponized car flyers, primarily to public email addresses. When an unsuspecting diplomat clicks on the car images within the email, a series of malicious execution flow commences. This involves downloading an ISO container file containing shortcut files, and leading to the injection of a malicious DLL into a Windows process, resulting in the execution of a decrypted final payload. This payload then establishes a connection to both Dropbox and the Microsoft Graph API, serving as its command and control (C2) for further communication. Researchers from Unit 42 note that the campaign focuses more on the diplomats themselves than the countries they represent.

Government
Level:
Strategic
|
Source:
This is some text inside of a div block.
07
-
20
-
2023

Mandiant Spoils Russia's Military Playbook on Ukraine

Mandiant's recent analysis exposes a six-phase cyber operation by Russia's military intelligence (GRU) against Ukraine, starting in 2019. The six phases include strategic cyber espionage, initial destructive cyber operations, sustained attacks, maintaining footholds, renewed disruptive attacks, and refocus on strategic cyber espionage. The operation targets critical Ukrainian organizations in government, telecommunications, financial services, energy, and transportation. The GRU employs various techniques, including compromising edge infrastructure, stealthy reconnaissance, persistence maintenance, and deployment of disruptive tools like wipers and ransomware. Additionally, the threat actors promote their campaigns on social media channels to boast about their narratives. The Mandiant report highlights the sophistication and strategic planning of these cyber attacks, indicating a deliberate effort by the GRU to increase the speed, scale, and intensity of offensive cyber operations while minimizing detection chances.

Critical Infrastructure
Government
Energy
Financial
Telecommunications
Level:
Tactical
|
Source:

About the Forge & Threat Reports

Deploy and maintain detections and threat hunt across all of your logging platforms and security tools without centralizing your data or deploying new agents.

Our mission is to assess the operational behaviors of all threats to provide the community, and our customers, with actionable information and enterprise-ready detections in order to defend themselves in an ever- changing threat landscape.
Sign Up For Weekly Threat Reports

Intelligence Levels for Threat Reports

Tactical

Detectable threat behaviors for response with threat scenarios or threat identifiers.

Strategic

General information security news, for awareness.

Whitepapers

No items found.

The World's Best SOC Teams Use Anvilogic

Paypal Logo
Sprinklr Logo
SAP Logo
SAP Logo
Regeneron Logo
Regeneron Logo
SurveyMonkey Logo
TradeWeb Logo
Alteryx Logo
First Citizens Bank Logo
Crypto.com Logo
Rakuten Mobile Logo
St. George's University Logo
Navan Logo
ADP Logo
ADP Logo
Labcorp Logo
Dyson Logo
siemens Logo
Research to keep you up-to-date on threats
Learn More
Interested in joining the Anvilogic team?
See Careers

Build Detections You Want, Where You Want