Anvilogic Forge Threat Research Reports
Here you can find an accumulation of trending threats published weekly by the Anvilogic team.
We curate threat intelligence to provide situational awareness and actionable insights
Atomic detections that serve as the foundation of our detection framework.
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024



Featured Threat Reports


All Threat Reports
OCX#HARVESTER Campaign Unleashes More_eggs Suite on Financial Service Organizations
Since December 2022, the OCX#HARVESTER campaign has targeted financial service organizations using the More_eggs malware suite. Phishing emails deliver malicious shortcuts, leading to code execution and persistence via living off-the-land binaries like msxsl.exe. The malware collects system data, captures desktop images, and connects to the attackers' C2 for further exploitation.
BumbleBee Malware Found in Disguised Software
BumbleBee malware is being distributed through trojanized installers for popular software such as Zoom and Cisco AnyConnect, exploiting Google Ads and SEO poisoning. Secureworks discovered the campaign involves fake download pages and malicious PowerShell scripts, leading to additional payloads for data collection and ransomware. Threat actors use remote access software to move laterally and deploy ransomware.
UK Cyber Agency Warns of the Rise of 'Ideologically' Motivated Russian Cyber Threat
The NCSC has warned of emerging ideologically motivated Russian cyber threat groups. Unlike traditional cyber criminals, these groups are driven by sympathies towards Russia's invasion and are less predictable. Their attacks include DDoS, web defacements, and misinformation, with a potential focus on Western critical national infrastructure.
Russia Maintains its Sights on Ukraine
Russia continues to pressure Ukraine with cyber operations, including espionage, data-wiping attacks, and misinformation. Google TAG's Q1 2023 report highlights APT28's focus on Ukrainian government, defense, energy, and other sectors. Over 60% of observed Russian phishing campaigns target Ukraine, using emails, SMS, and Telegram to distribute malware and steal credentials.
Upstream Supply Chain Issues Caused 3XC Software Compromise
The 3CX desktop application compromise, affecting over 600,000 companies, was linked to a malicious installer from Trading Technologies. Investigations by Mandiant reveal North Korean actors, potentially from the Lazarus group, as the main suspects. The attack, involving malware backdoors and sophisticated lateral movements, highlights significant supply chain vulnerabilities impacting financial services and telecommunications sectors.
Daggerfly APT Sets Its Sights on African Telecoms Corporation
The Daggerfly advanced persistent threat group, (aka Evasive Panda or Bronze Highland) was observed to have a telecommunications organization in Africa as part of its latest campaign.
Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
.png)
Whitepapers
The World's Best SOC Teams Use Anvilogic

.png)




.png)