Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-stealer-activityransomware-group-operationcybercrime-service-ecosystembotnet-infrastructure

Major Cybercrime and Malware Trends in December 2025

Updated 3mo agoFirst seen Dec 11, 20258 sources

Cybersecurity agencies and researchers reported a surge in sophisticated cybercrime operations and malware campaigns in December 2025. Notable law enforcement actions included the takedown of major cybercriminal forums such as Cracked and Nulled, and the disruption of ransomware networks like Phobos/8Base, as highlighted in SOCRadar's review of top law enforcement operations. Concurrently, threat intelligence sources documented a rise in ransomware attacks, with LockBit 5.0 targeting 25 companies globally, and agencies intensifying pressure on pro-Russian hacktivist groups. The month also saw a significant malware incident in New Zealand, where the national cyber security agency warned 26,000 citizens about infections by Lumma Stealer, a credential-harvesting malware.

Technical research revealed the continued evolution of information-stealing malware, such as Stealc and Phantom Stealer, which leverage new delivery methods including Discord-hosted payloads and fake software updates. The Mirai botnet family demonstrated renewed activity, with new variants like Broadside and Jackskid exploiting IoT vulnerabilities and targeting sectors such as maritime logistics. Reports also underscored the growing threat of browser-based attacks, with critical vulnerabilities being disclosed throughout the year, and the increasing use of social engineering tactics to bypass security controls. These developments reflect a rapidly shifting threat landscape, with attackers adopting advanced techniques and law enforcement responding with coordinated global operations.

Share:
Major Cybercrime and Malware Trends in December 2025
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Dec 11, 20256mo ago

HP report details new social engineering malware delivery tactics

HP's Threat Research Team published a report describing novel social engineering techniques, including fake legal notices, Adobe-themed lures, and Discord-hosted malware used to deliver infostealers and remote access tools. The report also found that 11% of email threats bypassed at least one email gateway scanner.

Dec 10, 20257mo ago

Stealc V2.9.0 documented with expanded theft and evasion features

By December 2025, researchers documented Stealc version 2.9.0, noting enhanced data collection, improved evasion, and broader support for browsers and cryptocurrency wallets. The report also linked the malware to more than 40 command-and-control servers and ongoing underground log trading.

Dec 9, 20257mo ago

New Zealand agency warns 26,000 residents' devices are infected

New Zealand's cyber security agency warned that about 26,000 New Zealanders had devices infected with malicious software. The alert highlighted a large domestic malware infection problem affecting consumer devices.

Nov 1, 20258mo ago

ShadowV2 tests attacks across 28 countries during AWS outage

In November 2025, the ShadowV2 Mirai variant used the AWS outage as cover to test its capabilities across 28 countries. The activity demonstrated how botnet operators were exploiting global events to mask or amplify malicious operations.

Jackskid botnet infects over 40,000 devices per day

As part of the November 2025 Mirai resurgence, the Jackskid botnet was reported infecting more than 40,000 devices daily. The malware also supported high-volume DDoS attacks and additional functions such as crypto-mining and data exfiltration.

November 2025 wave of major cyber incidents hits multiple organizations

During November 2025, a series of significant cyber incidents affected organizations globally, including the Coupang breach, the Balancer theft, Gainsight token abuse, the Eurofiber GLPI incident, and other large-scale breaches and ransomware attacks. Authorities opened investigations in some cases and affected organizations warned users about follow-on phishing and scam risks.

Mirai variants resurge in November 2025

In November 2025, Mirai-derived botnets including Jackskid and ShadowV2 resurged, infecting large numbers of IoT devices and driving major DDoS activity. The campaigns targeted routers, DVRs, industrial controllers, and other exposed systems using zero-days, brute force, and weakly secured firmware.

Jan 1, 20251y ago

Global law enforcement conducts major cybercrime operations in 2025

Throughout 2025, international law enforcement agencies carried out multiple major actions against cybercrime, including takedowns, seizures, sanctions, and indictments targeting forums, ransomware groups, botnets, and fraud networks. These operations included actions against Cracked and Nulled, Phobos/8Base, LummaC2, NoName057(16), BlackSuit, and other criminal infrastructure.

SquareX launches 2025 Year of Browser Bugs research

During 2025, SquareX's Year of Browser Bugs project disclosed a series of major browser security issues across conferences and research publications, exposing architectural weaknesses in modern browsers. Some vendors later introduced patches or guardrails in response to specific findings.

Jan 1, 20233y ago

Stealc malware-as-a-service begins operating

The Stealc infostealer began being offered as a malware-as-a-service operation in early 2023, marking the start of its ongoing criminal use and development.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

110 LINKEDOpen in app
Organizations
62 linked
Microsoft CorporationfbiGovernment TechnologyDiscordEuropolRhadamanthysLummaZserversAustralian GovernmentInterpolWashingtonPrince GroupLockBitNoName057(16)nca_ukAdobeHewlett Packard EnterpriseCyberArmyofRussia_RebornCracked ForumElysium BotnetVikaPhobos/8Base Ransomware NetworkNulled ForumVenomRATBlackSuit ransomwareOperationEndgameForesietAkamai TechnologiesSalesforceNational Health ServicePalo Alto NetworksSOCRadarQualysNetscoutMiljodataSquareXKasperskyAsahi Group HoldingsShadowServer FoundationPajemploiFortinetAkiraOpenaiSynnovisGainsightApplePerplexityEurofiberCoupangCl0p ransomware gangnpm, Inc.MetamaskRussia MarketBalancer LabsURSSAFIndonesianFoodsGLPI NetworkIMYCyberShieldAtlasGoogleUniversity of Pennsylvania
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Major Cybercrime and Malware Trends in December 2025 | Mallory