Anvilogic Forge Threat Research Reports
Here you can find an accumulation of trending threats published weekly by the Anvilogic team.
We curate threat intelligence to provide situational awareness and actionable insights
Atomic detections that serve as the foundation of our detection framework.
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024



Featured Threat Reports


All Threat Reports
Novel Attack Techniques from Threat Actor Targeting Middle East and African Government Orgs
Palo Alto's Cortex team uncovers CL-STA-0043, a suspected nation-state threat actor, deploying innovative espionage techniques against Middle East and African government organizations. With an objective of acquiring sensitive political and military data, this actor exhibits broad capabilities, including zero-day exploits and a variety of penetration tools.
Attacks from 8Base Ransomware Gang Surges
8Base ransomware gang's attacks increased significantly between May and June 2023, targeting various industries. The group uses double extortion tactics and claims to target only companies neglecting data privacy. VMware's analysis suggests that 8Base might be an off-shoot of RansomHouse or a copycat due to significant similarities in their ransom notes and data leak websites.
DDoS Participation Rises for Pro-Russian Hackers
The pro-Russian hacking group, NoName057(16), has experienced a significant surge in participation in its DDoS toolkit, DDoSia, which targets primarily Ukrainian and NATO country websites. With the group's influence and monetary compensation, DDoSia's Telegram channel has accumulated a user base of over 10,000 individuals, supporting at least 400 active users.
The Range of Trigona Ransomware
Since its emergence in October 2022, Trigona ransomware has been evolving and targeting organizations worldwide. With its most significant impact on technology, healthcare, and financial sectors, it leverages vulnerabilities such as CVE-2021-40539 and uses double extortion to exploit its victims.
Human Error Highlights a North Korean Intrusion
A network intrusion attributed to Andariel, a sub-group of North Korea's Lazarus group, exposed operational errors, including typos and misunderstanding of the system's language. This incident has led to the discovery of a new remote access trojan known as "EarlyRAT", showing further ties to the Lazarus group.
Canadian Energy Supplies Under Threat by Russian Actors
As per Canadian intelligence, Russian threat actors may target the country's energy sectors in a bid to disrupt supplies and retaliate against Ukraine allies. A potentially significant cybersecurity issue, it highlights the importance of securing operational technology networks in energy-related industries.
Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
.png)
Whitepapers
The World's Best SOC Teams Use Anvilogic

.png)




.png)