Anvilogic Forge Threat Research Reports
Here you can find an accumulation of trending threats published weekly by the Anvilogic team.
We curate threat intelligence to provide situational awareness and actionable insights
Atomic detections that serve as the foundation of our detection framework.
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024



Featured Threat Reports


All Threat Reports
A Growing Trend of BEC Attacks Misusing Legitimate File Sharing Platforms
Microsoft reports a surge in BEC attacks using legitimate platforms like SharePoint and OneDrive. These attacks evade detection by sending legitimate file-sharing notifications, luring victims into re-authenticating and exposing credentials. Threat actors then use compromised accounts to expand their reach and conduct further attacks.
Royal Mail Impersonated in Latest Prince Ransomware Phishing Scam
Proofpoint researchers unveil a phishing campaign that impersonates Royal Mail to deliver Prince ransomware. Active in the UK and US, the campaign uses public contact forms and direct emails, leveraging ZIP files with malicious scripts. Despite no clear attribution, the ransomware is available on GitHub for free.
Perfctl Malware Adapts and Evades Detection Targeting Linux Servers
Aqua Security researchers uncover the perfctl malware targeting Linux servers by exploiting misconfigurations and vulnerabilities like CVE-2021-4034. The malware adapts to evade detection, impacts server operations, and is linked to cryptomining. It uses stealth tactics, including masking processes and leveraging user-agent filtering to deliver payloads.
A more_eggs Malware Infection From Recruitment Scams
The more_eggs malware, part of the Golden Chickens malware-as-a-service (MaaS) toolkit, continues to spread through fake job recruitment scams. Threat actors like FIN6 and the Cobalt Group are leveraging this toolkit to target industries involved in hiring, particularly finance and retail, using deceptive social engineering techniques.
Memory Manipulation Vulnerability in ChatGPT Raises Concerns for Data Exfiltration
A memory manipulation vulnerability in ChatGPT, discovered by security researcher Johann Rehberger, could allow attackers to implant false memories and exfiltrate data. Despite OpenAI's fixes, risks remain. Ars Technica highlights the importance of vigilance when using AI models to prevent potential security breaches.
Hackers Could Exploit ATG Flaws to Cause Environmental and Economic Havoc
Researchers from Bitsight have identified critical vulnerabilities in Automatic Tank Gauges (ATGs) that could enable attackers to manipulate fuel storage systems, causing environmental damage and economic disruption. CISA advises immediate security measures to mitigate the risks as some vendors delay patches.
Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
.png)
The World's Best SOC Teams Use Anvilogic




