IR Trends Q1 2025: Phishing soars as identity-based attacks persist
ID: c736ecd6-2ad8-583b-8bf9-087f1aa6916f
STIX ID: report--c736ecd6-2ad8-583b-8bf9-087f1aa6916f
Feed Name: Cisco Talos
This Talos IR quarterly report highlights a sharp increase in phishing—particularly vishing—used to gain valid account access, followed by persistence and lateral movement leading to a notable rise in ransomware and pre-ransomware incidents (notably BlackBasta, Cactus, and Crytox). The report details attack chains (Quick Assist remote sessions, token theft, TitanPlus registry persistence, HRSword to disable EDR), sector targeting (manufacturing), effective defensive actions that stopped many incidents before encryption, and mapped MITRE ATT&CK techniques and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
