Anvilogic Forge Threat Research Reports

Here you can find an accumulation of trending threats published weekly by the Anvilogic team.

We curate threat intelligence to provide situational awareness and actionable insights

Threat Identifier Detections

Atomic detections that serve as the foundation of our detection framework.

Threat Scenario Detections

Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.

Reports Hot Off the Forge

Threat News Reports
Trending Threat Reports
ResearchArticles

Forge Threat Report

Forge Report: First Half Threat Trends of 2024

Anvilogic Forge's latest report offers essential insights into key threat trends and adversarial tactics observed in the first half of 2024. From the pervasive use of PowerShell and remote access tools to sophisticated social engineering and attacks on the healthcare sector, this comprehensive analysis provides actionable intelligence and detection rules to bolster your defenses. Explore our key findings and access ready-to-deploy detection content to enhance your security posture.

All Threat Reports

Levels

All
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
This is some text inside of a div block.
07
-
20
-
2023
Level:
Strategic
|
Source:

APT29 Adopts Car Sales Persona for Phishing Campaign

The Russian threat group APT29, also known as Cloaked Ursa, has initiated a new phishing campaign disguising as car sales to deliver malware to pro-Ukrainian diplomats. The campaign, which started in May 2023, revolves around distributing weaponized car flyers, primarily to public email addresses. When an unsuspecting diplomat clicks on the car images within the email, a series of malicious execution flow commences. This involves downloading an ISO container file containing shortcut files, and leading to the injection of a malicious DLL into a Windows process, resulting in the execution of a decrypted final payload. This payload then establishes a connection to both Dropbox and the Microsoft Graph API, serving as its command and control (C2) for further communication. Researchers from Unit 42 note that the campaign focuses more on the diplomats themselves than the countries they represent.

Government
This is some text inside of a div block.
07
-
20
-
2023
Level:
Tactical
|
Source:

Mandiant Spoils Russia's Military Playbook on Ukraine

Mandiant's recent analysis exposes a six-phase cyber operation by Russia's military intelligence (GRU) against Ukraine, starting in 2019. The six phases include strategic cyber espionage, initial destructive cyber operations, sustained attacks, maintaining footholds, renewed disruptive attacks, and refocus on strategic cyber espionage. The operation targets critical Ukrainian organizations in government, telecommunications, financial services, energy, and transportation. The GRU employs various techniques, including compromising edge infrastructure, stealthy reconnaissance, persistence maintenance, and deployment of disruptive tools like wipers and ransomware. Additionally, the threat actors promote their campaigns on social media channels to boast about their narratives. The Mandiant report highlights the sophistication and strategic planning of these cyber attacks, indicating a deliberate effort by the GRU to increase the speed, scale, and intensity of offensive cyber operations while minimizing detection chances.

Critical Infrastructure
Government
Energy
Financial
Telecommunications
This is some text inside of a div block.
07
-
20
-
2023
Level:
Tactical
|
Source:

Mandiant Sees An Increase of USB Infections in 2023

Mandiant researchers have observed a significant rise in USB infections during the first half of 2023, with their metrics indicating a threefold increase. The campaign targets a wide range of industry sectors, including print shops and hotels, and aims to steal data and provide a foothold for future attacks. The malware used in these attacks, SOGU and SNOWYDRIVE, serve to hijack DLLs and establish a foothold in the victim's systems. The attacker's lifecycle includes implementing persistence mechanisms, escalating privileges, conducting reconnaissance, propagating through the network, and exfiltrating sensitive data. The report highlights the importance of cybersecurity vigilance and the urgent need for preventive measures against such attacks.

Global
This is some text inside of a div block.
07
-
20
-
2023
Level:
Tactical
|
Source:

TeamTNT Scans Relentlessly to Compromise Targets

In a new aggressive cloud campaign, TeamTNT is aiming to expand its botnet by relentlessly scanning the internet for misconfigurations and exposed services on various platforms. AquaSec researchers Ofek Itach and Assaf Morag, having infiltrated the TeamTNT's command and control (C2) server, discovered that the botnet perpetually scans the entirety of the internet, creating at least two new victims per hour. The increased efficiency of TeamTNT's scanning mechanisms, coupled with its extensive toolbox of scripts, poses a significant global threat that underlines the critical importance of proper configuration and security for cloud instances.

Global
This is some text inside of a div block.
07
-
13
-
2023
Level:
Strategic
|
Source:

Nickelodeon Admits a Data Breach

Nickelodeon, an American television channel owned by Paramount Media Networks, has admitted to a data breach that resulted in approximately 500GB of compromised document and media files from its animation department. Despite reports of the data leak, Nickelodeon claims the breached data is "decades old." Investigations into the incident are ongoing, and the company has assured the public that the files do not appear to be from a recent system breach. The breach emphasizes the importance of stringent data security measures in the entertainment and media industry.

Entertainment
Media
This is some text inside of a div block.
07
-
13
-
2023
Level:
Strategic
|
Source:

Major Japanese Port Resume Operations

The Port of Nagoya, one of the largest ports in Japan, has resumed operations after a significant ransomware attack on July 4th, 2023. The attack, linked to the LockBit 3.0 ransomware gang, resulted in major disruptions in cargo handling due to system failures. Despite the delays in restoring operations due to the need for extensive backup data inspections, the port managed to recover without paying a ransom. The incident underscores the vulnerability of vital trading infrastructure to cyber threats.

Logistics
Shipping

Intelligence Levels for Threat Reports

Tactical

Detectable threat behaviors for response with threat scenarios or threat identifiers.

Strategic

General information security news, for awareness.

Whitepapers

No items found.

Trusted by leading teams at

Paypal Logo
Rubrik Logo
Deloitte Logo
Ebay Logo
Regeneron Logo
SurveyMonkey Logo
TradeWeb Logo
Alteryx Logo
First Citizens Bank Logo
Crypto.com Logo
Rakuten Mobile Logo
St. George's University Logo
St. George's University Logo
St. George's University Logo
St. George's University Logo
St. George's University Logo
St. George's University Logo
St. George's University Logo
St. George's University Logo
Paypal Logo
Sprinklr Logo
SAP Logo
Ebay Logo
Regeneron Logo
SurveyMonkey Logo
TradeWeb Logo
Alteryx Logo
First Citizens Bank Logo
Crypto.com Logo
Rakuten Mobile Logo
St. George's University Logo
Navan Logo
ADP Logo
Labcorp Logo
Dyson Logo
siemens Logo

Build Detections You Want,
Where You Want

Build Detections You Want,
Where You Want