Anvilogic Forge Threat Research Reports

Here you can find an accumulation of trending threats published weekly by the Anvilogic team.

We curate threat intelligence to provide situational awareness and actionable insights

Threat Identifier Detections

Atomic detections that serve as the foundation of our detection framework.

Threat Scenario Detections

Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.

Reports Hot Off the Forge

Threat News Reports
Trending Threat Reports
ResearchArticles

Forge Threat Report

Forge Report: First Half Threat Trends of 2024

Anvilogic Forge's latest report offers essential insights into key threat trends and adversarial tactics observed in the first half of 2024. From the pervasive use of PowerShell and remote access tools to sophisticated social engineering and attacks on the healthcare sector, this comprehensive analysis provides actionable intelligence and detection rules to bolster your defenses. Explore our key findings and access ready-to-deploy detection content to enhance your security posture.

All Threat Reports

Levels

All
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
This is some text inside of a div block.
08
-
17
-
2023
Level:
Tactical
|
Source:

eSentire Unveils Operation PhantomControl

In July 2023, eSentire researchers uncovered a malicious campaign dubbed Operation PhantomControl, identified through suspicious PowerShell commands. The attackers utilized the ScreenConnect remote access tool, delivered through compromised websites, including a domain associated with 'Teachflix', a classroom learning and video-sharing site. After gaining access, the attackers deployed various files and scripts, including a notable PowerShell script disguised as an SVG file, to deploy AsyncRAT, harvest user data and credentials, and establish persistence on infected systems.

Global
This is some text inside of a div block.
08
-
17
-
2023
Level:
Tactical
|
Source:

TargetCompany Ransomware Layers Intrusions with Remcos

The TargetCompany ransomware operators are enhancing their intrusion strategies by employing Fully Undetectable (FUD) packers and the Remcos Remote Access Trojan (RAT), aiming to conduct evasive infections. According to Trend Micro analysts Don Ovid Ladores and Nathaniel Morales, the attackers initially gain access through vulnerable SQL servers. They then execute a PowerShell script to download executable files into the TEMP directory, eventually leading to the successful download and installation of the Remcos RAT. The FUD packer style used resembles that used by BatCloak, involving batch files and PowerShell for Living-Off-The-Land Binaries (LOLBins) execution. Metasploit is also utilized in the attack chain. Trend Micro emphasizes TargetCompany's adoption since February 2022 of a 'cmd x PowerShell' loader technique, likely inspired by OneNote campaigns using PowerLoad. Unlike other malware, the loaders for Remcos and TargetCompany focus on integrating decompression into their binaries, likely altering the payload to evade detection.

Global
This is some text inside of a div block.
08
-
17
-
2023
Level:
Tactical
|
Source:

Pyarmor Pro Shields Batloader for Stealthier Intrusions

The Water Minyades threat actors have refined the Batloader initial access malware, incorporating Pyarmor Pro for stealth, as reported by Trend Micro. Since December 2022, Pyarmor, particularly its professional variant, has been utilized to obfuscate Batloader, complicating detection due to most antivirus engines lacking an unpacker for Pyarmor. Batloader’s attack chain uses Windows Installer package files, the Windows command-line interface, and batch files. Once executed, it leverages native Windows tools for host enumeration and sends the data to a command and control server. It can then facilitate the installation of further malware payloads, such as Ursnif, Vidar, or Redline Stealer, with potential escalation to dangerous ransomware deployments, including those associated with the Royal and BlackSuit ransomware gangs.

Global
This is some text inside of a div block.
08
-
11
-
2023
Level:
Strategic
|
Source:

Dragos Measures a 2x Increase in Ransomware Attacks Against Industrial Orgs in Q2 2023

In Q2 2023, ransomware attacks on industrial sectors doubled, as revealed by Dragos. North America was the primary target, with manufacturing facing the majority of threats. Prominent gangs like Lockbit 3.0 spearheaded these attacks, and given the current geopolitical climate, a further surge in Q3 is anticipated.

Aerospace
Automotive
Chemical
Consumer Goods & Services
Construction
This is some text inside of a div block.
08
-
10
-
2023
Level:
Strategic
|
Source:

APT29: Actively Running Phishing Attacks Centered on Microsoft Teams

Russian threat group APT29 has been actively running phishing campaigns on Microsoft Teams to steal user credentials since May 2023. Posing as technical support, they target entities in government, manufacturing, media, NGOs, and tech sectors, furthering Russia's espionage objectives.

Government
Manufacturing
Media
Non-Governmental Organization
Technology
This is some text inside of a div block.
08
-
10
-
2023
Level:
Tactical
|
Source:

BATLoader Assists the Spread of XWorm

Cyble uncovers a complex infection chain where the BATLoader malware facilitates the spread of the versatile XWorm malware. Starting with deceptive spam emails, the infection uses multiple binaries and scripts to ensure delivery. XWorm boasts capabilities like data theft, DDoS attacks, and ransomware deployment, emphasizing its multifaceted threat potential.

Global

Intelligence Levels for Threat Reports

Tactical

Detectable threat behaviors for response with threat scenarios or threat identifiers.

Strategic

General information security news, for awareness.

Whitepapers

No items found.

Trusted by leading teams at

Paypal Logo
Rubrik Logo
Deloitte Logo
Ebay Logo
Regeneron Logo
SurveyMonkey Logo
TradeWeb Logo
Alteryx Logo
First Citizens Bank Logo
Crypto.com Logo
Rakuten Mobile Logo
St. George's University Logo
St. George's University Logo
St. George's University Logo
St. George's University Logo
St. George's University Logo
St. George's University Logo
St. George's University Logo
St. George's University Logo
Paypal Logo
Sprinklr Logo
SAP Logo
Ebay Logo
Regeneron Logo
SurveyMonkey Logo
TradeWeb Logo
Alteryx Logo
First Citizens Bank Logo
Crypto.com Logo
Rakuten Mobile Logo
St. George's University Logo
Navan Logo
ADP Logo
Labcorp Logo
Dyson Logo
siemens Logo

Build Detections You Want,
Where You Want

Build Detections You Want,
Where You Want