logo

What’s Trending: Top Cyber Attacker Techniques, December 2025–February 2026

ID: ca684d2d-16de-5aef-878c-608f010b5847

STIX ID: report--ca684d2d-16de-5aef-878c-608f010b5847

Feed Name: ReliaQuest Blog

Threat Score
80/100

Date Published: 2026-04-02

Date Updated: 2026-04-29

...
...

During Dec 1, 2025–Feb 28, 2026 this report highlights a surge in trust-based attacks: BaoLoader-led drive-by compromises and ClickFix social-engineering dominated malware delivery; RMM tools (including trojanized ScreenConnect) were abused for C2; CVE‑2026‑1731 was weaponized rapidly in ransomware campaigns led by Akira and Qilin; and ShinyHunters scaled identity-first intrusions via AiTM phishing and stolen SSO sessions to enable high-impact data extortion. Defenders are urged to prioritize ClickFix-specific user training, RMM allowlists, emergency patching of internet-facing appliances, and centralized SaaS/identity telemetry and session containment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.