predictive threat intelligence

THREAT FLASH:

43.5K NEW CONFIRMATIONS IN JULY

Threat Research Team

July was another very active month for Augur, with 43.5K IP addresses flagged by Augur's patented predictive threat intelligence verified as malicious by independent third-party sources. 

That is 43.5K IP addresses that were identified and blocked months, sometimes years, in advance of weaponization, providing unique preemptive protection against fast-moving threats.

While some preemptive security vendors focus only on lower-level risks such as domain lookalikes and basic spoofing, Augur does all of this via our Brand Protection Module while also targeting the operational backbone of more sophisticated cyber campaigns. It identifies the command-and-control servers, exfiltration staging nodes, and delivery infrastructure that advanced threat actors depend on. This includes infrastructure established by nation-state groups, ransomware operators, and organized cybercriminal networks, well before their activities escalate into public-facing incidents

Let’s take a look at what Augur saw in July:

Most Active Threat Actors

UNC5537 (financial, targeting Snowflake) - 26 IPs confirmed

Primitivebear (espionage, aka Gamaredon, Actinium, Aqua Blizzard) - 25 IPs confirmed

Shinyhunters (data theft, aka The Com, UNC6040 read more) - 19 IPs confirmed

UNC6395 (financial targeting, Salesforce) - 15 IPs confirmed

Threats Seen in July

The following examples highlight the kinds of malicious operations Augur uncovers and disrupts.

Name Type IP Lead Time
AdaptixC2 Post-exploitation toolkit 95[.]216.94.101 +365 days
PureRAT Remote access tool 31[.]77.57.7 90 days
Jackskid IoT DDoS botnet 185[.]104.63.90 +365 days
Havoc Command & Control (C2) 185[.]115.161.32 65 days
ClearFake Malware 213[.]232.235.51 +200 days

We highly recommend blocking these IP addresses.

If your SOC team is stuck in emergency mode responding to fast-moving threats like AdaptixC2, PureRAT, and Havoc and the others above, the Augur preemptive cybersecurity platform can help. Reach out at preempt@augursecurity.com to find out about how we can predictively identify threats, automate response, improve security posture and give your SOC hours back.

Augur Highlights

Over the past few months, Augur has uncovered IPs and domains that were later leveraged in high-profile attacks. From nation-state theats to sophisticated phishing ops to supply-chain exploits, here are just a few recent examples of the type of high-impact attacks Augur has predicted and prevented

Attack Threat Group Lead Time
Iran Targets US Critical Infrastructure (Learn more) PYROXENE (Iran state-affiliated) 201 days
DragonForce Ransomware Campaign (Learn more) Scattered Spider 300 days
WIN-Fingerprint Exploit (Learn more) Lazarus Group / Conti 360+ days

Not every IP we uncover ends up in the headlines, but the overwhelming majority of the IPs and domains we identify are ultimately weaponized by threat actors to launch real-world attacks.

If your SOC team is stuck in emergency mode responding to fast-moving threats like AdaptixC2, PureRAT, and Havoc and the others above, the Augur preemptive cybersecurity platform can help. Reach out at preempt@augursecurity.com to find out about how we can predictively identify threats, automate response, improve security posture and give your SOC hours back.

How Does Augur Work?

Augur uses ML-powered behavioral modeling to detect the buildup of cybercriminal infrastructure online before attacks. We identify thousands of malicious IPs, IP ranges, and domains every month. Augur identifies threats on average 60 days before they’re first reported by traditional sources. Our predictions are highly accurate, with a near-zero false-positive rate (0.01%), providing organizations using Augur with preemptive protection against cyberattacks, zero-days, and novel threats.

The Augur Difference. Let Us Prove It To You.

Experience firsthand the benefits of preemptive cyber defense with a quick proof of value (POV). We can have you up and running in less than a day, and after 30 days, get an Augur report detailing:

  • Threats Augur identified
  • Advance warning timelines
  • Data-driven insight on alert reduction and improved SOC efficiency

Click here to talk to an Augur specialist now.