

We curate threat intelligence to provide situational awareness and actionable insights
Threat Identifier Detections
Atomic detections that serve as the foundation of our detection framework.
Threat Scenario Detections
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
Reports Hot Off the Forge
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024




All Threat Reports
BlackCat Abuses Search Ads with Malicious WinSCP Downloads
The BlackCat ransomware gang is exploiting search ads to trick users into downloading a malicious version of the WinSCP file transfer application. The victims were lured in through a fraudulent tutorial which led them to a compromised WordPress site. Despite gaining high-level administrative privileges, the attackers were prevented from executing their final payload by Trend Micro's intervention. The group's tactics involved an array of tools including Python scripts, batch scripts, AdFind, Cobalt Strike, PowerShell, PowerView, PsExec, BitsAdmin, and AnyDesk.
Killnet Grows & Hones Their Attack Potency
The infamous Russian-linked Killnet threat group has been growing and evolving its attack tactics since 2022. Initially emerging amidst Russia's invasion of Ukraine, the group has been known for executing significant DDoS attacks against targets in Ukraine and its supporters. A recent report from Mandiant reveals that while there is no direct evidence linking Killnet to Russia, the group's operations consistently mirror Russian strategic objectives. Killnet's capabilities have expanded thanks to affiliates like REvil, Zarya Splinters, and notably Anonymous Sudan. With over 500 victims since the beginning of 2023, the threat group has shown no signs of slowing down, targeting numerous industries, mainly technology, social media, and transportation. Following their recent disruptive attack on Microsoft services, it's expected that Killnet will continue to bolster its attack potency.
Novel Attack Techniques from Threat Actor Targeting Middle East and African Government Orgs
Palo Alto's Cortex team uncovers CL-STA-0043, a suspected nation-state threat actor, deploying innovative espionage techniques against Middle East and African government organizations. With an objective of acquiring sensitive political and military data, this actor exhibits broad capabilities, including zero-day exploits and a variety of penetration tools.
Attacks from 8Base Ransomware Gang Surges
8Base ransomware gang's attacks increased significantly between May and June 2023, targeting various industries. The group uses double extortion tactics and claims to target only companies neglecting data privacy. VMware's analysis suggests that 8Base might be an off-shoot of RansomHouse or a copycat due to significant similarities in their ransom notes and data leak websites.
DDoS Participation Rises for Pro-Russian Hackers
The pro-Russian hacking group, NoName057(16), has experienced a significant surge in participation in its DDoS toolkit, DDoSia, which targets primarily Ukrainian and NATO country websites. With the group's influence and monetary compensation, DDoSia's Telegram channel has accumulated a user base of over 10,000 individuals, supporting at least 400 active users.
The Range of Trigona Ransomware
Since its emergence in October 2022, Trigona ransomware has been evolving and targeting organizations worldwide. With its most significant impact on technology, healthcare, and financial sectors, it leverages vulnerabilities such as CVE-2021-40539 and uses double extortion to exploit its victims.

About the Forge & Threat Reports
Our mission is to assess the operational behaviors of all threats to provide the community, and our customers, with actionable information and enterprise-ready detections in order to defend themselves in an ever- changing threat landscape.

Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
Whitepapers

The World's Best SOC Teams Use Anvilogic
Build Detections You Want, Where You Want






.png)