

We curate threat intelligence to provide situational awareness and actionable insights
Threat Identifier Detections
Atomic detections that serve as the foundation of our detection framework.
Threat Scenario Detections
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
Reports Hot Off the Forge
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024




All Threat Reports
Malware with “radio silence” Mode Sneaks into Southeast Asian Entities
Sharp Panda, a Chinese cyber-espionage group, targets Southeast Asian government entities using the 'Soul' malware framework. This malware features a 'radio silence' mode, enabling stealthy communication with the C2 server. The campaign focuses on strategic nations, exploiting Equation Editor vulnerabilities in DOCX attachments.
Lazarus Abused an Unknown Software To Breach a Financial South Korea Organization
The Lazarus Group breached a South Korean financial institution twice in 2022 by exploiting vulnerabilities in an undisclosed software. The attacks involved disabling security measures and installing backdoors to establish remote control, demonstrating sophisticated tactics and persistence.
How Healthcare is a Prime Target for Cybercriminals
Healthcare is a prime target for cybercriminals, accounting for 6% of attacks. Patient data is highly valuable, making hospitals vulnerable to ransomware and DDoS attacks. Recent attacks by groups like Killnet highlight the sector's susceptibility to disruption and ransom demands.
LastPass: New Details Emerge from Second Security Breach of 2022
LastPass disclosed a secondary breach in 2022, where attackers accessed AWS cloud storage from August to October. Data exfiltrated included partially encrypted password vaults and customer information. Attackers targeted a DevOps engineer to gain access. LastPass has since enhanced its security measures.
'Blind Eagle' Sets Sights on Latin American Organizations
Blind Eagle, a South American cyber espionage group, targets financial, government, and healthcare organizations in Colombia and Ecuador. Using phishing emails and RATs, they aim for information theft and espionage. Protect your organization from this emerging threat.
Evasive LockBit Campaign
The latest LockBit ransomware campaign, observed in December 2022 and January 2023, uses advanced evasion techniques to bypass AV and EDR solutions. Employing social engineering and sophisticated scripting, this campaign poses a serious threat to global industries.

About the Forge & Threat Reports
Our mission is to assess the operational behaviors of all threats to provide the community, and our customers, with actionable information and enterprise-ready detections in order to defend themselves in an ever- changing threat landscape.

Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
Whitepapers

The World's Best SOC Teams Use Anvilogic
Build Detections You Want, Where You Want






.png)