

We curate threat intelligence to provide situational awareness and actionable insights
Threat Identifier Detections
Atomic detections that serve as the foundation of our detection framework.
Threat Scenario Detections
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
Reports Hot Off the Forge
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024




All Threat Reports
Tax Season Brings News Tax-themed Phishing Campaigns
Tax-themed phishing campaigns are increasing during tax season, distributing GuLoader malware and remote access trojans like Remcos. Malicious attachments masquerade as tax-related documents to deceive victims. Stay vigilant and protect against these attacks.
#StopRansomware Headlines Royal Ransomware
The FBI and CISA report on Royal ransomware activities since September 2022. Targeting critical infrastructure, education, and healthcare sectors, Royal ransomware uses phishing, RDP, and valid accounts to gain access and execute double extortion tactics, encrypting and exfiltrating data.
Russian Influence Campaigns Losing Steam on Meta Platforms
Meta reports a decline in Russian influence campaigns on Facebook and Instagram. The shift from sophisticated tactics to spam-like behavior has resulted in lower engagement, as new security measures thwart nefarious accounts.
Russian Threat Actor Had Access to Ukraine Government Site Since 2021
Ukrainian agencies revealed that Russian hackers, linked to Ember Bear, compromised government websites since December 2021. Discovered in February 2023, the attackers deployed multiple backdoors, affecting several sites but causing no significant operational disruptions.
Wiper Malware Poses Increasing Threat to Cybersecurity
Fortinet's research shows a 53% increase in wiper malware usage, particularly since the Russia-Ukraine conflict began. Initially used by nation-states, these destructive tools are now widespread among cybercriminals, posing a severe threat to global cybersecurity.
An Odd Certutil Download Spurs Investigation from Huntress
Huntress investigates a suspicious certutil download, uncovering a malicious DLL linked to Truebot malware and TA505 threat group. The payload exploited GoAnywhere MFT software vulnerabilities, creating persistence with scheduled tasks. Immediate patching is urged.

About the Forge & Threat Reports
Our mission is to assess the operational behaviors of all threats to provide the community, and our customers, with actionable information and enterprise-ready detections in order to defend themselves in an ever- changing threat landscape.

Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
Whitepapers

The World's Best SOC Teams Use Anvilogic
Build Detections You Want, Where You Want






.png)