Anvilogic Forge Threat Research Reports
Here you can find an accumulation of trending threats published weekly by the Anvilogic team.
We curate threat intelligence to provide situational awareness and actionable insights
Atomic detections that serve as the foundation of our detection framework.
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024



Featured Threat Reports


All Threat Reports
Gamaredon Group Organizes Attacks Through Telegram
The Gamaredon Group is increasing cyberattacks on Ukraine, using Telegram to evade detection. BlackBerry reports they target government and critical infrastructure entities with weaponized documents via spear-phishing, exploiting remote template injection vulnerabilities to bypass Microsoft macro protections.
The Manufacturing Industry a Frequent Target of Vice Society
Vice Society ransomware is expanding its attacks beyond education and healthcare to the manufacturing industry, according to Trend Micro. Using compromised credentials and exploiting vulnerabilities, the group has impacted manufacturing in Brazil, Argentina, Switzerland, and Israel.
A Refusal to Pay Ransom Sinks Ransomware Profits in 2022
Ransomware profits dropped 40% in 2022 to $457 million as victims increasingly refused to pay. Factors include unreliable cybercriminals, changing public perceptions, and better backup management. Despite this, ransomware threats from gangs like LockBit and Hive persist.
CERT-UA Prevents Service Disruption to Ukraine News Agency from Russian Threat Actor
CERT-UA foiled a Russian cyberattack on the National News Agency of Ukraine (Ukrinform), preventing operational disruptions. The attack, suspected to involve CaddyWiper malware by the Sandworm group, aimed at undermining Ukrainian media.
PyPI Author 'Lolip0p' Distributes Info-stealing Malware
Fortinet discovers PyPI author 'Lolip0p' distributing info-stealing malware via Python packages 'colorslib,' 'httpslib,' and 'libhttps.' The packages use PowerShell commands to download and run malicious binaries from DropBox, affecting global users.
Malicious Payloads with Batloader Malware in 2022
Trend Micro reports Batloader malware's heightened activity in Q4 2022, distributing threats like Ursnif, Vidar, and Royal ransomware. Batloader uses SEO poisoning and obfuscated JavaScript to evade detection and deliver payloads, affecting global industries.
Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
.png)
Whitepapers
The World's Best SOC Teams Use Anvilogic

.png)


