A 2025 Threat Trends Analysis
ID: fc054e95-1e7a-5de0-a1dc-6d2d7311bb4b
STIX ID: report--fc054e95-1e7a-5de0-a1dc-6d2d7311bb4b
Feed Name: LevelBlue SpiderLabs Blog
LevelBlue's 2025 threat overview identifies three dominant trends: Luna Moth’s callback-phishing campaign enabling remote-access and data extortion against professional services; Akira’s exploitation of SonicWall vulnerabilities and SEO-poisoned installers to deploy Bumblebee and follow-on ransomware; and increasing abuse of Microsoft Quick Assist/Teams social-engineering to gain interactive access and deploy ransomware and data theft tools. The report catalogs active exploited CVEs (SonicWall, FortiOS, Ivanti, SAP), top malware families and tools, and MITRE-style TTPs, emphasizing a shift toward living-off-the-land techniques and human-focused attacks that demand behavioral detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
