logo

IR Trends Q1 2025: Phishing soars as identity-based attacks persist

ID: c736ecd6-2ad8-583b-8bf9-087f1aa6916f

STIX ID: report--c736ecd6-2ad8-583b-8bf9-087f1aa6916f

Feed Name: Cisco Talos

Threat Score
75/100

Date Published: 2025-04-28

Date Updated: 2026-04-27

Author: Lexi DiScola

...
...

This Talos IR quarterly report highlights a sharp increase in phishing—particularly vishing—used to gain valid account access, followed by persistence and lateral movement leading to a notable rise in ransomware and pre-ransomware incidents (notably BlackBasta, Cactus, and Crytox). The report details attack chains (Quick Assist remote sessions, token theft, TitanPlus registry persistence, HRSword to disable EDR), sector targeting (manufacturing), effective defensive actions that stopped many incidents before encryption, and mapped MITRE ATT&CK techniques and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.