logo

Expel Quarterly Threat Report, Q1 2025: Endpoint threats

ID: e0c1f2e5-7a28-5e85-99c3-343629077b06

STIX ID: report--e0c1f2e5-7a28-5e85-99c3-343629077b06

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2025-04-24

Date Updated: 2026-04-27

Author: Aaron Walton; Ben Nahorney

...
...

This Q1 2025 endpoint-focused threat report summarizes SOC-observed trends: drive-by downloads were the leading initial access vector (users tricked into executing malicious files), phishing and removable media were smaller contributors, and infostealing malware remained the dominant malware type—making up 61.9% of malware incidents—while adversaries increasingly exploit stolen credentials to enable ransomware and other crimes; the report also recommends mitigations such as enforcing password managers and restricting PowerShell and the Windows Run program via Group Policy.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.