2025 Unit 42 Global Incident Response Report: Social Engineering Edition
ID: a17966da-68ad-5a0d-a1e6-131c6122a670
STIX ID: report--a17966da-68ad-5a0d-a1e6-131c6122a670
Feed Name: Palo Alto Networks Unit 42
Unit 42 finds social engineering to be the dominant initial access vector (36% of IR cases) in 2024–2025, highlighting two models — high-touch, real-time impersonation (help-desk/MFA bypass) and at-scale ClickFix-style web/browser deception — that enabled rapid credential theft, privileged escalation and data exposure (60% of social-engineering cases). The report profiles financially motivated and state-aligned actors (Muddled Libra, Agent Serpens, DPRK-linked groups), documents common payloads (credential stealers like RedLine and Lampion, silent loaders, RATs), describes AI-assisted scaling and agentic tooling, and recommends identity-centric defenses (ITDR/UEBA, Zero Trust, hardened recovery workflows and network-layer controls).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
