

We curate threat intelligence to provide situational awareness and actionable insights
Threat Identifier Detections
Atomic detections that serve as the foundation of our detection framework.
Threat Scenario Detections
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
Reports Hot Off the Forge
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024




All Threat Reports
BumbleBee Malware Found in Disguised Software
BumbleBee malware is being distributed through trojanized installers for popular software such as Zoom and Cisco AnyConnect, exploiting Google Ads and SEO poisoning. Secureworks discovered the campaign involves fake download pages and malicious PowerShell scripts, leading to additional payloads for data collection and ransomware. Threat actors use remote access software to move laterally and deploy ransomware.
UK Cyber Agency Warns of the Rise of 'Ideologically' Motivated Russian Cyber Threat
The NCSC has warned of emerging ideologically motivated Russian cyber threat groups. Unlike traditional cyber criminals, these groups are driven by sympathies towards Russia's invasion and are less predictable. Their attacks include DDoS, web defacements, and misinformation, with a potential focus on Western critical national infrastructure.
Russia Maintains its Sights on Ukraine
Russia continues to pressure Ukraine with cyber operations, including espionage, data-wiping attacks, and misinformation. Google TAG's Q1 2023 report highlights APT28's focus on Ukrainian government, defense, energy, and other sectors. Over 60% of observed Russian phishing campaigns target Ukraine, using emails, SMS, and Telegram to distribute malware and steal credentials.
Upstream Supply Chain Issues Caused 3XC Software Compromise
The 3CX desktop application compromise, affecting over 600,000 companies, was linked to a malicious installer from Trading Technologies. Investigations by Mandiant reveal North Korean actors, potentially from the Lazarus group, as the main suspects. The attack, involving malware backdoors and sophisticated lateral movements, highlights significant supply chain vulnerabilities impacting financial services and telecommunications sectors.
Daggerfly APT Sets Its Sights on African Telecoms Corporation
The Daggerfly advanced persistent threat group, (aka Evasive Panda or Bronze Highland) was observed to have a telecommunications organization in Africa as part of its latest campaign.
Legion: Malware Circulates with Capabilities for Credential Theft and Email Compromise
Legion, a Python-based malware, is circulating on Telegram with capabilities for credential theft, remote code execution, and email hijacking. It targets AWS services and web servers, especially those running CMS and PHP frameworks. The malware's extensive features and widespread guides pose a significant threat to organizations and individuals relying on AWS and web-based systems.

About the Forge & Threat Reports
Our mission is to assess the operational behaviors of all threats to provide the community, and our customers, with actionable information and enterprise-ready detections in order to defend themselves in an ever- changing threat landscape.

Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
Whitepapers

The World's Best SOC Teams Use Anvilogic
Build Detections You Want, Where You Want






.png)