Anvilogic Forge Threat Research Reports
Here you can find an accumulation of trending threats published weekly by the Anvilogic team.
We curate threat intelligence to provide situational awareness and actionable insights
Atomic detections that serve as the foundation of our detection framework.
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024



Featured Threat Reports


All Threat Reports
UK Cyber Agency Warns of the Rise of 'Ideologically' Motivated Russian Cyber Threat
The NCSC has warned of emerging ideologically motivated Russian cyber threat groups. Unlike traditional cyber criminals, these groups are driven by sympathies towards Russia's invasion and are less predictable. Their attacks include DDoS, web defacements, and misinformation, with a potential focus on Western critical national infrastructure.
Russia Maintains its Sights on Ukraine
Russia continues to pressure Ukraine with cyber operations, including espionage, data-wiping attacks, and misinformation. Google TAG's Q1 2023 report highlights APT28's focus on Ukrainian government, defense, energy, and other sectors. Over 60% of observed Russian phishing campaigns target Ukraine, using emails, SMS, and Telegram to distribute malware and steal credentials.
Upstream Supply Chain Issues Caused 3XC Software Compromise
The 3CX desktop application compromise, affecting over 600,000 companies, was linked to a malicious installer from Trading Technologies. Investigations by Mandiant reveal North Korean actors, potentially from the Lazarus group, as the main suspects. The attack, involving malware backdoors and sophisticated lateral movements, highlights significant supply chain vulnerabilities impacting financial services and telecommunications sectors.
Daggerfly APT Sets Its Sights on African Telecoms Corporation
The Daggerfly advanced persistent threat group, (aka Evasive Panda or Bronze Highland) was observed to have a telecommunications organization in Africa as part of its latest campaign.
Legion: Malware Circulates with Capabilities for Credential Theft and Email Compromise
Legion, a Python-based malware, is circulating on Telegram with capabilities for credential theft, remote code execution, and email hijacking. It targets AWS services and web servers, especially those running CMS and PHP frameworks. The malware's extensive features and widespread guides pose a significant threat to organizations and individuals relying on AWS and web-based systems.
Heightened Threat from Iranian State-Sponsored Hackers
A subgroup of the Iranian state-sponsored Magic Hound, tracked by Microsoft, is escalating data theft campaigns against high-value targets. These hackers rapidly weaponize new vulnerabilities and conduct sophisticated attacks using PowerShell scripts, Impacket, and custom implants. Their activities align with Iran's national priorities, targeting sectors like defense, energy, and government.
Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
.png)
Whitepapers
Trusted by leading teams at

.png)


