Anvilogic Forge Threat Research Reports
Here you can find an accumulation of trending threats published weekly by the Anvilogic team.
We curate threat intelligence to provide situational awareness and actionable insights
Atomic detections that serve as the foundation of our detection framework.
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024



Featured Threat Reports


All Threat Reports
IceXLoader Makes an Impact After the Latest Update
Minerva Labs reports a surge in IceXLoader infections after the update to version 3.3.3. The malware now uses advanced evasion techniques, including AMSI bypass and Windows Defender disabling. It gains persistence through the Run registry and collects host information, making it a significant threat globally.
Microsoft Attributes Prestige Ransomware to a Russian Threat Actor
Microsoft attributes the Prestige ransomware attacks on Ukraine and Poland to Russian threat actor IRIDIUM, linked to the GRU's Sandworm. Targeting humanitarian and military programs, IRIDIUM uses tools like RemoteExec and Impacket WMIexec in post-exploitation. The campaign highlights unique enterprise-wide ransomware deployment in Ukraine.
SocGholish Drops JavaScript File from Compromised News Sites
Proofpoint and BleepingComputer report SocGholish distributing malware through compromised news sites, injecting malicious JavaScript into assets accessed by over 250 regional and national outlets. The attack, tracked to TA569, uses fake browser updates to deliver its payload, impacting major markets like New York, Chicago, and Miami.
Unraveling the Yanluowang Ransomware Group from Chat Leaks
Leaked chat logs analyzed by KELA reveal the inner workings of the Yanluowang ransomware group, suggesting ties to former REvil members. Discussions show active development of an ESXi version of their malware. This marks the second significant ransomware group data leak of 2022, following the Conti leak.
The Severity of Cyberattacks Elevated for Latvia
Latvia experiences a 30% rise in cyberattacks linked to its support for Ukraine during the Russia-Ukraine war. Key targets include government, critical infrastructure, and private businesses, with hacktivist group Killnet leading the assaults, primarily through DDoS attacks, though often missing intended targets.
APT36 Impersonates MFA Software to Infect the Indian Government
Zscaler reports APT36's (Transparent Tribe) campaign against the Indian government, using malvertising to distribute backdoored MFA software. The group registers fake domains mimicking official download portals to deploy a python downloader, backdoors, and data exfiltration tools, targeting users running in India's time zone for espionage purposes.
Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
.png)
Whitepapers
The World's Best SOC Teams Use Anvilogic

.png)




.png)