logo

Talos IR trends Q4 2024: Web shell usage and exploitation of public-facing applications spike

ID: 781752bd-cf3c-5e94-b3e3-4f2b1f1d2091

STIX ID: report--781752bd-cf3c-5e94-b3e3-4f2b1f1d2091

Feed Name: Cisco Talos

Threat Score
75/100

Date Published: 2025-01-30

Date Updated: 2026-04-27

Author: Lexi DiScola

...
...

**Executive summary:** Talos Incident Response observed a significant shift in Q4 toward exploitation of public-facing applications and web shells (35% of incidents), a continued presence of ransomware and pre-ransomware activity (including BlackBasta, RansomHub, and newly observed Interlock), extensive use of remote access tooling and compromised valid accounts, long attacker dwell times (17–44 days), and large-scale password-spraying activity; the report maps these behaviors to MITRE ATT&CK techniques and provides mitigation recommendations such as enforcing MFA, patching, segmentation, and properly configured EDR.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.