logo

Expel Quarterly Threat Report, Q3 2025: Threat intel recap

ID: 4fce7c85-503c-5254-9417-5899718b39a3

STIX ID: report--4fce7c85-503c-5254-9417-5899718b39a3

Feed Name: Expel Blog

Threat Score
72/100

Date Published: 2025-11-06

Date Updated: 2026-04-27

Author: Ben Nahorney; Aaron Walton

...
...

Q3 2025 recap describing BaoLoader and similar trojanized applications that masquerade as useful utilities (PDF editors, recipe and calendar apps) but install backdoors and abuse code-signing certificates; BaoLoader comprised 13% of non-targeted commodity malware and related families (e.g., TamperedChef) saw tens of thousands of downloads. Although primarily monetized via affiliate fraud rather than credential theft or ransomware, the presence of arbitrary backdoors and PowerShell-based AV enumeration increases enterprise risk, so stricter application control and sanctioned tooling are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.