Anvilogic Forge Threat Research Reports
Here you can find an accumulation of trending threats published weekly by the Anvilogic team.
We curate threat intelligence to provide situational awareness and actionable insights
Atomic detections that serve as the foundation of our detection framework.
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024



Featured Threat Reports


All Threat Reports
Gwisin Ransomware Targeting Korean Entities
ASEC has identified Gwisin ransomware targeting Korean organizations. The malware uses MSI Installers and requires a specific value to execute. It evades detection by injecting its DLL into Windows processes. Gwisin's unique characteristics include tailored ransom notes per organization and the ability to encrypt files in safe mode.
Russian Organizations Targeted by Woody RAT
Malwarebytes identified Woody RAT targeting Russian organizations, including a major aerospace and defense entity. Distributed through phishing emails and exploiting the Follina vulnerability, this remote access trojan captures host data, executes commands, and uploads files. While attribution remains uncertain, speculation points to threat actors from China and North Korea.
Popular Crypto Wallet Used to Spread Mars Stealer Malware
A fake Atomic Wallet website is spreading Mars Stealer malware. Discovered by researcher Dee (@ViriBack), the site uses Atomic Wallet branding to deceive users. Victims are targeted through malvertising, spam, and SEO poisoning. The malware hides within a zip file and modifies Windows Defender to exfiltrate host information.
Initial Access Broker Using Bumblebee Malware
Palo Alto Unit42 reports Exotic Lily using Bumblebee malware for initial access. Active since February 2022, Bumblebee has replaced Bazarloader and is deployed via spear phishing to deliver Cobalt Strike beacons. The malware is linked to ransomware groups Conti and Quantum.
Hackers Arrested from Tampering with Radiation Alert System
Spanish police arrested two former contractors for hacking Spain's radioactivity alert network (RAR) between March and June 2021. The attackers disrupted 300 sensors and targeted the control center's web application. The National Police traced the activity to a public network in Madrid.
Ukrainian IT Army Disrupting Russian Online Services
The Ukrainian IT Army disrupted 750 Russian online resources, including the Foreign Ministry and military agencies, between July 11-24. The Ministry of Digital Transformation stated the attacks were in retaliation for Russian missile and gunfire assaults on Ukrainian cities.
Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
.png)
Whitepapers
The World's Best SOC Teams Use Anvilogic

.png)




.png)