2025 Year in Review: Malicious, Infrastructure
ID: 4672e0f0-4c32-5ac9-9618-f0edb726250d
STIX ID: report--4672e0f0-4c32-5ac9-9618-f0edb726250d
Feed Name: Recorded Future Blog
This Insikt Group 2025 malicious infrastructure report expands tracking across malware families and infrastructure types, finding that infostealers (notably Vidar and Lumma) and malware-as-a-service remain primary infection vectors, Cobalt Strike continues to dominate offensive security tool detections even as competitors (RedGuard, Ligolo, Supershell) gain share, and the ecosystem shows high turnover in loaders/droppers (eg. CastleLoader) with sustained use of traffic distribution systems and threat activity enablers; the report urges improved detection (YARA/Sigma/Snort), continuous monitoring, and careful handling of legitimate infrastructure services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
