logo

IR Trends Q2 2025: Phishing attacks persist as actors leverage compromised valid accounts to enhance legitimacy

ID: 4b56472a-9a9d-559c-a857-42e02571b7fe

STIX ID: report--4b56472a-9a9d-559c-a857-42e02571b7fe

Feed Name: Cisco Talos

Threat Score
78/100

Date Published: 2025-07-31

Date Updated: 2026-04-27

Author: Lexi DiScola

...
...

Cisco Talos IR Q2 2025 finds phishing (often from compromised internal/trusted accounts) as the top initial access technique—frequently used for credential harvesting—and that ransomware or pre-ransomware incidents comprised half of engagements; the report documents first-time Qilin ransomware activity with novel TTPs (hardcoded encryptor credentials, Backblaze-hosted C2, CyberDuck for exfiltration), frequent use of PowerShell 1.0 for defense evasion, education as the most targeted sector this quarter, and recommends enforcing modern MFA, centralized logging/SIEM, and protecting EDR configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.