Expel Quarterly Threat Report, Q1 2025: Endpoint threats
ID: e0c1f2e5-7a28-5e85-99c3-343629077b06
STIX ID: report--e0c1f2e5-7a28-5e85-99c3-343629077b06
Feed Name: Expel Blog
This Q1 2025 endpoint-focused threat report summarizes SOC-observed trends: drive-by downloads were the leading initial access vector (users tricked into executing malicious files), phishing and removable media were smaller contributors, and infostealing malware remained the dominant malware type—making up 61.9% of malware incidents—while adversaries increasingly exploit stolen credentials to enable ransomware and other crimes; the report also recommends mitigations such as enforcing password managers and restricting PowerShell and the Windows Run program via Group Policy.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
