Anvilogic Forge Threat Research Reports
Here you can find an accumulation of trending threats published weekly by the Anvilogic team.
We curate threat intelligence to provide situational awareness and actionable insights
Atomic detections that serve as the foundation of our detection framework.
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024
Featured Threat Reports
All Threat Reports
Royal Mail Impersonated in Latest Prince Ransomware Phishing Scam
Proofpoint researchers unveil a phishing campaign that impersonates Royal Mail to deliver Prince ransomware. Active in the UK and US, the campaign uses public contact forms and direct emails, leveraging ZIP files with malicious scripts. Despite no clear attribution, the ransomware is available on GitHub for free.
Storm-0501’s Impact on On-Prem and Cloud Infrastructure
Storm-0501, a financially motivated threat actor, exploits vulnerabilities in on-prem and cloud environments. Linked to major ransomware groups, it uses credential theft and hybrid infrastructure attacks. Microsoft highlights Storm-0501’s tactics, including leveraging Microsoft Entra ID and synchronization processes, and recommends implementing MFA and other security measures.
SnipBot, A New RomCom Malware Variant Targets Broad Industries for Espionage
SnipBot, a newly discovered variant of RomCom malware, is targeting global industries with advanced obfuscation and stealth techniques. Unit 42 researchers suspect the malware, previously linked to ransomware, now focuses on espionage. This multi-stage attack utilizes legitimate certificates, PowerShell commands, and data exfiltration tools to compromise networks.
Hackers Could Exploit ATG Flaws to Cause Environmental and Economic Havoc
Researchers from Bitsight have identified critical vulnerabilities in Automatic Tank Gauges (ATGs) that could enable attackers to manipulate fuel storage systems, causing environmental damage and economic disruption. CISA advises immediate security measures to mitigate the risks as some vendors delay patches.
Memory Manipulation Vulnerability in ChatGPT Raises Concerns for Data Exfiltration
A memory manipulation vulnerability in ChatGPT, discovered by security researcher Johann Rehberger, could allow attackers to implant false memories and exfiltrate data. Despite OpenAI's fixes, risks remain. Ars Technica highlights the importance of vigilance when using AI models to prevent potential security breaches.
North Korea’s Recruitment-Themed Cyberattacks for Spreading RustDoor Malware
North Korean hackers deploy RustDoor malware through LinkedIn recruitment scams, targeting the financial and cryptocurrency sectors. Victims are deceived into running malicious scripts, enabling persistent backdoor access. FBI and Jamf Threat Labs uncover this state-sponsored campaign, urging caution against unsolicited job offers and coding tests online.
Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.