IR Trends Q2 2025: Phishing attacks persist as actors leverage compromised valid accounts to enhance legitimacy
ID: 4b56472a-9a9d-559c-a857-42e02571b7fe
STIX ID: report--4b56472a-9a9d-559c-a857-42e02571b7fe
Feed Name: Cisco Talos
Cisco Talos IR Q2 2025 finds phishing (often from compromised internal/trusted accounts) as the top initial access technique—frequently used for credential harvesting—and that ransomware or pre-ransomware incidents comprised half of engagements; the report documents first-time Qilin ransomware activity with novel TTPs (hardcoded encryptor credentials, Backblaze-hosted C2, CyberDuck for exfiltration), frequent use of PowerShell 1.0 for defense evasion, education as the most targeted sector this quarter, and recommends enforcing modern MFA, centralized logging/SIEM, and protecting EDR configurations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
