Anvilogic Forge Threat Research Reports
Here you can find an accumulation of trending threats published weekly by the Anvilogic team.
We curate threat intelligence to provide situational awareness and actionable insights
Atomic detections that serve as the foundation of our detection framework.
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024



Featured Threat Reports


All Threat Reports
Four-Month Espionage Campaign Hits U.S. Organization, Compromising Five Workstations
Symantec uncovered a four-month espionage campaign targeting a U.S. organization, attributed to China-based actors. The attackers compromised five workstations, employing WMI, DLL sideloading, and credential dumping. Advanced techniques enabled lateral movement, email theft, and evasion, underscoring the persistence and sophistication of the threat.
FBI Warns of Rising AI-Driven Financial Fraud Schemes
The FBI warns of rising AI-driven fraud schemes exploiting generative AI for phishing, deepfakes, and scams. Criminals use AI-generated text, images, and audio to deceive victims at scale. Vigilance against suspicious messages, verifying identities, and reducing personal social media exposure are key defenses against this growing cybercrime threat.
White House Warns of Salt Typhoon Hacker Threat Greater Than Anticipated
Salt Typhoon, a Chinese state-sponsored hacking group, has infiltrated eight U.S. telecom companies in a global espionage campaign. Exploiting network vulnerabilities, the group targets sensitive communications. Federal agencies urge stronger cybersecurity measures as the White House stresses the urgency of combating this persistent and severe threat.
Credential Dumping Campaign with Atera Agent Linked to MuddyWater
MuddyWater, an Iranian cyber espionage group, is linked to a credential theft campaign targeting global organizations. Using phishing emails, malicious Onehub links, and Atera RMM tools, the group executes PowerShell scripts for registry backups and network domain enumeration. Sophos reports similar attacks in Israel and the U.S., signaling a broader threat.
Akira Ransomware Gains Momentum, Favoring U.S. Targets Across Critical Sectors
The Akira ransomware gang is escalating attacks on U.S. critical sectors using advanced, cross-platform tactics. Leveraging a double-extortion RaaS model, Akira exploits compromised credentials, vulnerable systems, and advanced evasion techniques. Its connections to Conti, LockBit, and new Rust-based Akira_v2 variants signal a growing cyber threat demanding urgent attention from organizations.
Black Basta’s Strategic Shift Combines Technical Precision with Human Exploitation
Black Basta advances ransomware tactics, blending social engineering with technical precision. Impersonation campaigns exploit Microsoft Teams and email platforms, while tools like DarkGate and Knotrock facilitate attacks on high-value sectors. RedSense notes their disciplined operations, raising concerns about possible collaboration with Russian state actors and escalating cyber threats.
Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
.png)
Whitepapers
The World's Best SOC Teams Use Anvilogic




