logo

Expel Quarterly Threat Report, Q2 2025: Threat intel recap

ID: df870bed-af25-580d-8bda-82fa1441f1c0

STIX ID: report--df870bed-af25-580d-8bda-82fa1441f1c0

Feed Name: Expel Blog

Threat Score
75/100

Date Published: 2025-07-24

Date Updated: 2026-04-27

Author: Ben Nahorney; Aaron Walton

...
...

This Q2 2025 quarterly threat report summarizes observed attacker activity: identity-targeting social engineering (credential theft, help-desk MFA bypass, and the novel Atlas Lion tactic of enrolling malicious VMs), increasing ransomware-focused social engineering via Microsoft Teams (attributed to Black Basta and affiliates), and distribution of loaders/malware such as Latrodectus and OysterLoader via infected websites and malicious ads; it highlights code-signing abuse and shifts in attacker tactics across thousands of incidents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.