logo

Cybereason TTP Briefing Q4 2025: Diverse Phishing Tactics and RATs on the Rise

ID: 20a533a9-e8ed-5070-add4-a5e12e4caca0

STIX ID: report--20a533a9-e8ed-5070-add4-a5e12e4caca0

Feed Name: Cybereason Blog

Threat Score
75/100

Date Published: 2026-02-05

Date Updated: 2026-04-27

Author: Cybereason Consulting Team

...
...

Cybereason’s TTP Briefing Q4 2025 summarizes frontline IR and SOC intelligence showing rising phishing (52%) and edge device exploitation (18%) as primary intrusion vectors, high MFA adoption but a 96% MFA bypass rate, a surge in SEO-poisoning campaigns that drive RAT downloads (RAT usage for escalation rose from 3% to 60%), increased pre-ransomware network intrusions (7% → 25%), and commonly observed CVEs targeting Fortinet, SonicWall, Oracle and other edge/VPN devices; dwell times remain long (42% ≥31 days), indicating persistent, active threats across industries and company sizes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.