July was another very active month for Augur, with 43.5K IP addresses flagged by Augur's patented predictive threat intelligence verified as malicious by independent third-party sources.
That is 43.5K IP addresses that were identified and blocked months, sometimes years, in advance of weaponization, providing unique preemptive protection against fast-moving threats.
While some preemptive security vendors focus only on lower-level risks such as domain lookalikes and basic spoofing, Augur does all of this via our Brand Protection Module while also targeting the operational backbone of more sophisticated cyber campaigns. It identifies the command-and-control servers, exfiltration staging nodes, and delivery infrastructure that advanced threat actors depend on. This includes infrastructure established by nation-state groups, ransomware operators, and organized cybercriminal networks, well before their activities escalate into public-facing incidents
Let’s take a look at what Augur saw in July:
Most Active Threat Actors
UNC5537 (financial, targeting Snowflake) - 26 IPs confirmed
Primitivebear (espionage, aka Gamaredon, Actinium, Aqua Blizzard) - 25 IPs confirmed
Shinyhunters (data theft, aka The Com, UNC6040 read more) - 19 IPs confirmed
UNC6395 (financial targeting, Salesforce) - 15 IPs confirmed
Threats Seen in July
The following examples highlight the kinds of malicious operations Augur uncovers and disrupts.
We highly recommend blocking these IP addresses.
If your SOC team is stuck in emergency mode responding to fast-moving threats like AdaptixC2, PureRAT, and Havoc and the others above, the Augur preemptive cybersecurity platform can help. Reach out at preempt@augursecurity.com to find out about how we can predictively identify threats, automate response, improve security posture and give your SOC hours back.
Augur Highlights
Over the past few months, Augur has uncovered IPs and domains that were later leveraged in high-profile attacks. From nation-state theats to sophisticated phishing ops to supply-chain exploits, here are just a few recent examples of the type of high-impact attacks Augur has predicted and prevented
Not every IP we uncover ends up in the headlines, but the overwhelming majority of the IPs and domains we identify are ultimately weaponized by threat actors to launch real-world attacks.
If your SOC team is stuck in emergency mode responding to fast-moving threats like AdaptixC2, PureRAT, and Havoc and the others above, the Augur preemptive cybersecurity platform can help. Reach out at preempt@augursecurity.com to find out about how we can predictively identify threats, automate response, improve security posture and give your SOC hours back.
How Does Augur Work?
Augur uses ML-powered behavioral modeling to detect the buildup of cybercriminal infrastructure online before attacks. We identify thousands of malicious IPs, IP ranges, and domains every month. Augur identifies threats on average 60 days before they’re first reported by traditional sources. Our predictions are highly accurate, with a near-zero false-positive rate (0.01%), providing organizations using Augur with preemptive protection against cyberattacks, zero-days, and novel threats.



