logo

A 2025 Threat Trends Analysis

ID: b1b390d5-c406-5485-9e5c-c3aafe8d7497

STIX ID: report--b1b390d5-c406-5485-9e5c-c3aafe8d7497

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
80/100

Date Published: 2025-12-22

Date Updated: 2026-04-28

Author: Andrea Martinez and Peter Connolly

...
...

LevelBlue’s 2025 DFIR trends report documents three major threats: (1) Luna Moth’s callback-phishing and IT-impersonation campaigns that gain remote access (Zoho Assist/Atera), exfiltrate data (WinSCP/Rclone), and extort victims; (2) Akira’s exploitation of SonicWall CVEs and use of SEO-poisoned spoofed domains to deliver Bumblebee, leading to lateral movement and Akira ransomware; and (3) increased social-engineering leveraging Microsoft Quick Assist/Teams to obtain desktop access, perform reconnaissance, deploy remote access tools, exfiltrate data, and deploy ransomware—while enumerating frequently exploited CVEs, top malware families, observed TTPs (SSH tunneling, living-off-the-land), and recommended emphasis on behavioral detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.