Top 10 Malware Q2 2025
ID: 4490664e-da74-5db1-bc10-43cd9caa6504
STIX ID: report--4490664e-da74-5db1-bc10-43cd9caa6504
Feed Name: CISecurity.org Insights Blog
CIS/MS-ISAC’s Q2 2025 Top 10 Malware report notes an 18% decrease in detections but continued dominance of SocGholish (31%), with notable activity from ZPHP, Agent Tesla, VenomRAT, CoinMiner, Mirai, NanoCore, ArechClient2, ClearFake, and LandUpdate808. Malvertisement led initial access vectors (driven by SocGholish, ZPHP, ClearFake, LandUpdate808), alongside malspam and dropped payloads. The report provides extensive IOCs (domains, IPs, SHA256 hashes) to support detection and hunting, and outlines malware capabilities including RAT functions, credential theft, data exfiltration, and botnet/DDoS operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
