Anvilogic Forge Threat Research Reports

Here you can find an accumulation of trending threats published weekly by the Anvilogic team.

We curate threat intelligence to provide situational awareness and actionable insights

Threat Identifier Detections

Atomic detections that serve as the foundation of our detection framework.

Threat Scenario Detections

Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.

Reports Hot Off the Forge

Threat News Reports
Trending Threat Reports
ResearchArticles

Forge Threat Report

Forge Report: First Half Threat Trends of 2024

Anvilogic Forge's latest report offers essential insights into key threat trends and adversarial tactics observed in the first half of 2024. From the pervasive use of PowerShell and remote access tools to sophisticated social engineering and attacks on the healthcare sector, this comprehensive analysis provides actionable intelligence and detection rules to bolster your defenses. Explore our key findings and access ready-to-deploy detection content to enhance your security posture.

All Threat Reports

Levels

All
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
This is some text inside of a div block.
08
-
10
-
2023
Level:
Strategic
|
Source:

APT29: Actively Running Phishing Attacks Centered on Microsoft Teams

Russian threat group APT29 has been actively running phishing campaigns on Microsoft Teams to steal user credentials since May 2023. Posing as technical support, they target entities in government, manufacturing, media, NGOs, and tech sectors, furthering Russia's espionage objectives.

Government
Manufacturing
Media
Non-Governmental Organization
Technology
This is some text inside of a div block.
08
-
10
-
2023
Level:
Tactical
|
Source:

BATLoader Assists the Spread of XWorm

Cyble uncovers a complex infection chain where the BATLoader malware facilitates the spread of the versatile XWorm malware. Starting with deceptive spam emails, the infection uses multiple binaries and scripts to ensure delivery. XWorm boasts capabilities like data theft, DDoS attacks, and ransomware deployment, emphasizing its multifaceted threat potential.

Global
This is some text inside of a div block.
08
-
10
-
2023
Level:
Tactical
|
Source:

Qakbot: A Reliable Malware of Adaptability

Since 2007, the Qakbot banking trojan has evolved, recently adapting OneNote into its attack strategy. Zscaler's analysis points to Qakbot's myriad of infiltration methods, from phishing emails with malicious HTML and PDF documents to innovative evasion using conhost.exe. Activity peaked in March and April 2023, with significant targeting in Germany, the US, and Brazil. Despite a recent lull, experts anticipate a resurgence in Qakbot attacks.

Global
This is some text inside of a div block.
08
-
10
-
2023
Level:
Tactical
|
Source:

FIN8 Compromised an EMEA Retailer

The financially-driven threat group, FIN8, targeted an EMEA retailer on April 30th, 2023, leading to the exfiltration of 61GB of data. Darktrace identifies SSL connections, lateral movements, and potential DCSync attacks as key indicators. The initial breach point remains unidentified, but phishing, a known strategy of FIN8, is suspected. Nine devices, including five administrative ones, played roles in this breach.

Retail
This is some text inside of a div block.
08
-
03
-
2023
Level:
Strategic
|
Source:

CISA: Valid Accounts A Prevailing Technique for Attacks in 2022

CISA's risk and vulnerability assessment has identified "Valid Accounts" as the most prominent attack technique in 2022 against government and critical infrastructure organizations. Accounting for over half of initial access attacks and a significant portion of other tactic categories, this technique is a key concern. Other top techniques include PowerShell for execution, LLMNR/NBT-NS Poisoning & SMB Relay for credential access, and Exfiltration Over C2 Channel for data exfiltration. The report emphasizes that even minor changes to technology controls can enhance security, as threat actors largely continue to follow established patterns without significant deviation.

Critical Infrastructure
Government
This is some text inside of a div block.
08
-
03
-
2023
Level:
Tactical
|
Source:

Wiz Discovers Two Vulnerabilities in Ubuntu's OverlayFS module

Wiz researchers Sagi Tzadik and Shir Tamari have discovered two privilege escalation vulnerabilities (CVE-2023-2640, CVE-2023-32629) in Ubuntu's OverlayFS module, potentially affecting 40% of Ubuntu users. These vulnerabilities arose from conflicts between Ubuntu's custom configurations and subsequent modifications to the module by the Linux kernel project. Ubuntu has released patches to rectify the vulnerabilities, and users are urged to apply them immediately, as proof-of-concept exploits have been made public.

Global

Intelligence Levels for Threat Reports

Tactical

Detectable threat behaviors for response with threat scenarios or threat identifiers.

Strategic

General information security news, for awareness.

Whitepapers

No items found.

The World's Best SOC Teams Use Anvilogic

Paypal Logo
Rubrik Logo
Deloitte Logo
Ebay Logo
Regeneron Logo
SurveyMonkey Logo
TradeWeb Logo
Alteryx Logo
First Citizens Bank Logo
Crypto.com Logo
Rakuten Mobile Logo
St. George's University Logo
St. George's University Logo
St. George's University Logo
St. George's University Logo
St. George's University Logo
St. George's University Logo
St. George's University Logo
St. George's University Logo
Paypal Logo
Sprinklr Logo
SAP Logo
Ebay Logo
Regeneron Logo
SurveyMonkey Logo
TradeWeb Logo
Alteryx Logo
First Citizens Bank Logo
Crypto.com Logo
Rakuten Mobile Logo
St. George's University Logo
Navan Logo
ADP Logo
Labcorp Logo
Dyson Logo
siemens Logo

Build Detections You Want,
Where You Want

Build Detections You Want,
Where You Want