Expel Quarterly Threat Report, Q2 2025: Threat intel recap
ID: df870bed-af25-580d-8bda-82fa1441f1c0
STIX ID: report--df870bed-af25-580d-8bda-82fa1441f1c0
Feed Name: Expel Blog
This Q2 2025 quarterly threat report summarizes observed attacker activity: identity-targeting social engineering (credential theft, help-desk MFA bypass, and the novel Atlas Lion tactic of enrolling malicious VMs), increasing ransomware-focused social engineering via Microsoft Teams (attributed to Black Basta and affiliates), and distribution of loaders/malware such as Latrodectus and OysterLoader via infected websites and malicious ads; it highlights code-signing abuse and shifts in attacker tactics across thousands of incidents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
