Malware Trends Q4 2025: Inside ANY.RUN’s Latest Threat Landscape Report
ID: 2d706f78-074e-5bcc-9383-5da7dd38fa35
STIX ID: report--2d706f78-074e-5bcc-9383-5da7dd38fa35
Feed Name: ANY.RUN's Cybersecurity Blog
ANY.RUN's Q4 2025 Malware Trends report provides an aggregated view of the threat landscape for the last quarter of 2025, highlighting persistent stealer activity (despite a decline), a pronounced surge in RATs and backdoors (notably XWorm +174%), growth in phishing/2FA-bypass kits (Tycoon, EvilProxy, Sneaky2FA), top detected TTPs (e.g., Install Root Certificate T1553.004, Masquerading T1036.* , PowerShell/Command Shell execution), and millions of sandbox analyses with over one billion IOCs collected—underscoring active, large-scale criminal operations and evolving attacker techniques rather than a single exploit or breach.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
