logo

Malware Trends Q4 2025: Inside ANY.RUN’s Latest Threat Landscape Report 

ID: 2d706f78-074e-5bcc-9383-5da7dd38fa35

STIX ID: report--2d706f78-074e-5bcc-9383-5da7dd38fa35

Feed Name: ANY.RUN's Cybersecurity Blog

Threat Score
70/100

Date Published: 2025-12-29

Date Updated: 2026-04-26

Author: ANY.RUN

...
...

ANY.RUN's Q4 2025 Malware Trends report provides an aggregated view of the threat landscape for the last quarter of 2025, highlighting persistent stealer activity (despite a decline), a pronounced surge in RATs and backdoors (notably XWorm +174%), growth in phishing/2FA-bypass kits (Tycoon, EvilProxy, Sneaky2FA), top detected TTPs (e.g., Install Root Certificate T1553.004, Masquerading T1036.* , PowerShell/Command Shell execution), and millions of sandbox analyses with over one billion IOCs collected—underscoring active, large-scale criminal operations and evolving attacker techniques rather than a single exploit or breach.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.