Threat Research from The Forge by Anvilogic
Anvilogic Forge Threat Research Reports
Weekly threat intelligence and detection guidance from the Anvilogic Forge team — trending threats, actor campaigns, and detections to catch them.
All Threat Reports
The most recent research from The Forge. New reports publish weekly.
March 4, 2026
Iranian Cyber Threats Against U.S. Critical Infrastructure & Supply Chain
Following U.S. and Israeli strikes against Iran, Iranian cyber actors and aligned hacktivist groups have intensified operations targeting U.S. critical infrastructure and supply chains. This advisory details active campaigns, APT capabilities, exploited entry points, and urgent defensive actions to help security teams harden edge devices and detect emerging threats.
Read the report → iranian-cyber-threats-against-u-s-critical-infrastructure-supply-chain
Level: Strategic
Source: Unit 42
February 19, 2026
MacSync Infostealer via ClickFix & Claude Artifact Abuse
Anvilogic uncovered a ClickFix campaign abusing Google Ads and Claude AI artifacts to deliver the MacSync infostealer to over 15,600 macOS users. By combining trusted platforms with base64-encoded shell commands, attackers bypassed traditional defenses. Behavioral detection and LLM-based URL scoring stopped the threat before public indicators emerged.
Read the report → macsync-infostealer-via-clickfix-claude-artifact-abuse
Level: Operational
Source: Moonlock Lab
February 16, 2026
Notepad++ updater turned delivery vehicle
A Rapid7 investigation reveals an espionage campaign leveraging the Notepad++ updater as a malware delivery mechanism. Attackers deploy update.exe via GUP.exe, stage payloads with NSIS, sideload a malicious DLL, and activate the Chrysalis backdoor. The campaign features encrypted C2 traffic, API hashing, and modular post-exploitation capabilities.
Read the report → how-they-get-in-notepad-updater-turned-delivery-vehicle
Level: Operational
Source: Rapid7
January 22, 2026
VBS scripts masquerading as legitimate updates
SHADOW#REACTOR is an opportunistic attack chain starting with VBS scripts posing as updates. It escalates to PowerShell execution, pulling payloads disguised as .txt files. Using LOLBins like MSBuild, it maintains stealthy persistence through a cross-language script chain that avoids disk-based binaries and resists static detection.
Read the report → vbs-powershell-attack
Level: Tactical
Source: Securonix
December 18, 2025
Makob Ransomware at it again
Makop ransomware primarily enters through exposed RDP using brute-force tools like NLBrute. Once inside, it disables security via BYOVD techniques, escalates privileges with known Windows LPE flaws, steals credentials using Mimikatz and LaZagne, and increasingly delivers payloads through GuLoader-based staged execution.
Read the report → makop-ransomware-rdp-guload
Level: Tactical
Source: Acronis
November 27, 2025
Systems Trust Controls are under active, repeated attack
macOS systems face a sharp rise in attacks that bypass Gatekeeper, XProtect, and quarantine by manipulating user trust rather than exploiting vulnerabilities. Threat actors abuse AppleScript and social engineering to disable protections, leading to credential theft, crypto loss, and major supply chain risks across cryptocurrency, fintech, government, and technology sectors.
Read the report → macos-trust-control-attacks
Level: Strategic
Source:
November 27, 2025
Supply chain + dev tooling is also a real macOS vector now
Attackers are increasingly compromising macOS systems by poisoning developer tooling—npm packages, build scripts, and CI/CD pipelines. With 73% of developers using macOS, threat actors exploit postinstall scripts, LaunchAgents, and deceptive dev utilities. Campaigns like AdaptixC2 and Shai-Hulud show the growing scale and impact of macOS supply chain compromise.
Read the report → macos-dev-supplychain-risks
Level: Strategic
Source:
November 27, 2025
Legit tools + simple primitives are weaponized everywhere
Threat actors increasingly weaponize trusted macOS tools such as curl, bash, Script Editor, and Terminal to deliver blind, fileless execution that bypasses Gatekeeper. Social engineering and fake installers drive rapid compromise, exemplified by ClickFix campaigns targeting healthcare, finance, government, telecom, and tech with Atomic Stealer and similar payloads.
Read the report → macos-blind-execution-attacks
Level: Strategic
Source:
November 27, 2025
Big-Picture MacOS Threat Climate
DBIR 2024 and M-Trends 2025 highlight a shifting macOS threat landscape dominated by exploits, credential theft, and social engineering. Cross-platform malware families increasingly bypass Apple’s defenses while human error drives most breaches. macOS now mirrors global trends, from vulnerability exploitation to identity compromise and extortion workflows.
Read the report → macos-threat-climate-2025
Level: Tactical
Source:
October 16, 2025
W-9 Lure Kicks Off 28-Day Intrusion Ending in Exfiltration With No Ransomware
A May 2024 intrusion beginning with a malicious W-9 JavaScript downloader developed into a patient 28-day operation. Operators used Brute Ratel, Cobalt Strike, Zerologon, and living-off-the-land techniques to harvest credentials, move laterally, and exfiltrate data. The campaign ended with eviction—no ransomware was deployed.
Read the report → w9-lure-28day-intrusion
Level: Tactical
Source: The DFIR Report
October 16, 2025
OpenAI Tracks Phish, Malware Tooling, And Low-Reach Influence Campaigns
OpenAI’s October 2025 report reveals threat actors integrating large language models into phishing, malware maintenance, scams, and small-scale influence operations. Despite disruptions of over 40 networks, investigators found no evidence of new offensive capabilities, emphasizing iterative abuse of AI tools, multilingual lure generation, and adaptive social engineering.
Read the report → openai-tracks-ai-abuse-2025
Level: Strategic
Source: OpenAI
October 16, 2025
From CL-STA-0043 to Phantom Taurus: Multi-Year Hunt Reveals New PRC Cyber Playbook
Unit 42 formally identifies Phantom Taurus, a PRC-aligned APT evolved from cluster CL-STA-0043. Active since 2023, it targets government and telecom networks across Africa, the Middle East, and Asia. The group employs the .NET-based NET-STAR suite, IIS in-memory persistence, timestomping, and SQL-focused data exfiltration for espionage objectives.
Read the report → phantom-taurus-prc-apt
Level: Tactical
Source: Unit 42
October 9, 2025
TA415 Targets U.S.–China Policy Circles with VS Code Tunnel Intrusions
Proofpoint attributes a 2025 phishing campaign to TA415 / APT41, targeting U.S.–China policy, academic, and government sectors. Lures spoofed trade organizations and officials, dropping a Python loader that abuses Visual Studio Code’s Tunnel feature for remote command execution. The operation replaces traditional malware with living-off-the-land persistence.
Read the report → ta415-vscode-tunnel-2025
Level: Tactical
Source: Proofpoint
October 9, 2025
Okta: 130+ DPRK Identities Linked to 6,500 Interviews at 5,000 Companies
Okta research reveals North Korea’s IT-worker program spans 130+ false identities tied to over 6,500 job interviews at 5,000 companies worldwide. The scheme targets technology, finance, healthcare, and government sectors, generating revenue and potential insider access. Okta warns of a mature, global threat using deception to gain remote roles.
Read the report → okta-dprk-itworker-scheme
Level: Strategic
Source: Okta
October 9, 2025
Akira’s SonicWall Blitz: CVE-2024-40766 to Ransomware in Under 4 Hours
Arctic Wolf reports Akira campaigns (July 2025) exploiting SonicWall CVE-2024-40766 SSL VPN access to authenticate from VPS hosts, harvest credentials, and rapidly stage exfiltration and ransomware. Attacks compressed lateral movement and impact into minutes–hours. Arctic Wolf urges resetting VPN and AD credentials, revoking exposed keys, and tightening remote-access controls.
Read the report → akira-sonicwall-cve-2024-40766
Level: Tactical
Source: Arctic Wolf
October 2, 2025
SEO-poisoned GitHub Repos Push Atomic Stealer to macOS
LastPass researchers uncovered SEO-optimized GitHub repositories masquerading as Mac desktop apps to distribute the Atomic (AMOS) stealer. Victims are tricked into running a Terminal one-liner that downloads and executes a malicious installer, planting “/tmp/update.” The campaign spans dozens of fake repos targeting finance and technology users.
Read the report → atomic-stealer-macos-seo
Level: Tactical
Source: LastPass
October 2, 2025
CISA Warns of ‘Shai-Hulud’ npm Worm: Review Dependencies, Rotate Developer Secrets
CISA warns that the “Shai-Hulud” npm worm compromised over 500 packages by stealing developer credentials and republishing tainted versions. The malware harvested GitHub tokens and cloud keys, spreading automatically across the npm ecosystem. CISA urges rotating secrets, enforcing MFA, and auditing dependencies to contain potential supply-chain impact.
Read the report → cisa-shai-hulud-npm-worm
Level: Strategic
Source: CISA & The Record
October 2, 2025
CISA Outlines Lessons Learned from the 2024 FCEB intrusion
CISA’s analysis of a 2024 FCEB intrusion attributes initial access to GeoServer CVE-2024-36401 exploitation, followed by China Chopper web shells, Stowaway proxy tunneling, and multi-platform reconnaissance. The incident highlights delayed patching, missing endpoint protection, and weak incident response coordination across a federal agency’s infrastructure.
Read the report → cisa-fceb-intrusion-2024
Level: Tactical
Source: CISA
September 25, 2025
When Chat Becomes Compromise: Building Defenses Around Prompt-Centric Risk
Security researcher Thomas Roccia warns that prompts are the newest attack surface in enterprise AI systems. His Indicators of Prompt Compromise (IoPCs) model categorizes manipulative or malicious prompt behaviors and guides defenders in hunting, detecting, and mitigating prompt-based threats within chat, agent, and retrieval workflows.
Read the report → prompt-compromise-defense
Level: Strategic
Source: Medium - Thomas Roccia
September 25, 2025
Weaponized Documents and Cloud C2 underpin APT28’s Active 2025 Campaign
Sekoia details APT28’s 2025 campaign against Ukrainian defense personnel using spear-phished Word lures delivered via Signal. The macro-enabled documents install a COM-hijacked DLL loader that extracts Covenant and BeardShell payloads, leveraging Koofr and icedrive cloud APIs for C2. Additional spyware, SlimAgent, extends surveillance and data theft functions.
Read the report → apt28-weaponized-docs-2025
Level: Tactical
Source: Sekoia
September 25, 2025
DragonForce, Play, and RansomHub Collide in One Intrusion
The DFIR Report documents a six-day 2024 intrusion showing tradecraft overlap among DragonForce, Play, and RansomHub ransomware groups. Shared tools—AdFind, PsExec, SystemBC, and Betruger—enabled lateral movement, credential theft, and exfiltration without encryption. The incident highlights affiliate cross-pollination complicating attribution and strengthening pre-ransomware detection needs.
Read the report → dragonforce-play-ransomhub
Level: Tactical
Source: The DFIR Report
September 18, 2025
The Gentlemen Ransomware Group Emerges with Custom Tools and Global Impact
Trend Micro attributes a sophisticated new ransomware group, “The Gentlemen,” to attacks on 27 victims in 17 countries. Operators adapt tooling to bypass defenses, abuse privileged credentials and FortiGate accounts, stage encrypted exfiltration via WinSCP, and deploy ransomware domain-wide via NETLOGON—followed by cleanup routines to frustrate recovery and forensics.
Read the report → gentlemen-ransomware
Level: Tactical
Source: Trend Micro
September 18, 2025
Talos Finds Swift Response Key to Blocking Ransomware Deployment
Cisco Talos Incident Response’s analysis of pre-ransomware cases (2023–2025) shows rapid incident handling and tight privilege restrictions as the most effective defenses against ransomware. Common precursors included RDP, PsExec, AnyDesk, and LSASS dumping. Talos recommends MFA, Sysmon, offline backups, and segmentation to prevent full deployment.
Read the report → talos-ransomware-response
Level: Strategic
Source: Cisco Talos
September 18, 2025
Social Engineering via Microsoft Teams Expands With Remote Access and PowerShell Payloads
Permiso identifies a global social engineering campaign exploiting Microsoft Teams to impersonate IT support and deploy PowerShell payloads. Attackers leverage AnyDesk and QuickAssist for remote access, credential theft prompts, and persistence through scheduled tasks or registry keys—showing evolving tactics linked to ransomware and threat clusters like Scattered Spider.
Read the report → msteams-social-engineering
Level: Tactical
Source: Permiso