Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationstate-sponsored-espionagethird-party-vendor-breachendpoint-security-bypass

Major Cyberattack and Malware Trends in 2025

Updated 3mo agoFirst seen Dec 17, 20253 sources

Cybersecurity threats in 2025 were marked by a surge in sophisticated attacks targeting both enterprises and critical infrastructure. Notable incidents included the exploitation of a zero-day vulnerability (CVE-2025-61882) in Oracle E-Business Suite by the Clop ransomware group, leading to data theft and extortion campaigns against multiple organizations. Ransomware activity overall increased, with Akira and Qilin dominating the ransomware-as-a-service market, and new strains like Warlock and HybridPetya introducing advanced evasion and destructive capabilities. The year also saw a significant rise in software supply chain attacks and the emergence of AI-powered malware such as PromptLock, which can generate malicious scripts dynamically.

State-sponsored campaigns remained a persistent threat, exemplified by the BRICKSTORM malware attributed to Chinese actors, which targeted VMware and Windows systems in government and IT sectors. Data breaches, such as the API compromise at 700Credit affecting over 5.6 million individuals, highlighted ongoing risks in third-party integrations and API security. Malware-as-a-service platforms like CloudEyE (GuLoader) surged in prevalence, facilitating the distribution of infostealers and ransomware. The threat landscape was further complicated by the proliferation of EDR killers and the rapid evolution of Android NFC-based threats, underscoring the need for robust detection and response strategies across all platforms.

Share:
Major Cyberattack and Malware Trends in 2025
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

12 events from the most recent confirmed update back to the earliest known activity.

12 EVENTS
Dec 16, 20256mo ago

Authorities arrest suspects after UK retail cyber incidents

Arrests were reported following the UK retail attacks associated with Scattered Spider. The law enforcement action marked a significant response to one of the year's most disruptive criminal cyber campaigns.

UK retail disruptions linked to Scattered Spider

Major disruptions affecting UK retailers were linked to Scattered Spider. The incidents demonstrated the group's ability to cause significant business interruption in consumer-facing industries.

Scattered Spider-linked attacks target airlines

A wave of attacks against airlines was associated with Scattered Spider. The campaign underscored the group's continued focus on high-profile sectors through social engineering and account compromise tactics.

Jaguar Land Rover hit by ransomware and data theft

Jaguar Land Rover was reported to have suffered a significant ransomware and data theft incident. The attack drew attention because of its impact on a major automotive brand and the broader trend of double-extortion operations.

Asahi suffers major ransomware and data-theft incident

Asahi was identified as a victim of a major ransomware and data theft attack in 2025. The incident was notable for combining operational disruption with extortion pressure based on stolen data.

China-aligned groups linked to SharePoint 'ToolShell' attacks

Reporting later attributed part of the SharePoint 'ToolShell' exploitation activity to multiple China-aligned threat groups. This attribution elevated the incident from a broad exploitation wave to one with nation-state implications.

Microsoft SharePoint on-prem 'ToolShell' exploitation emerges

Attackers began exploiting Microsoft SharePoint on-premises vulnerabilities dubbed 'ToolShell,' including CVE-2025-53770 and CVE-2025-53771. The activity affected widely used enterprise systems and became one of the year's most significant vulnerability exploitation stories.

Salesforce customer data thefts tied to third-party integrations

Multiple data theft incidents affecting Salesforce customers were linked to compromised third-party integrations and OAuth tokens. The campaign illustrated how attackers abused trusted cloud connections to reach downstream victims at scale.

Clop allegedly exploits Oracle E-Business Suite zero-day

Clop was reported to have exploited an Oracle E-Business Suite zero-day tracked as CVE-2025-61882. The alleged exploitation led to data theft and extortion activity affecting organizations using the enterprise software.

Coinbase discloses support-agent bribery and customer data theft

Coinbase reported an intrusion in which support agents were bribed, enabling attackers to access and steal customer data. The incident highlighted insider-enabled compromise and social engineering risks in the crypto sector.

Lazarus-linked attackers steal funds in the Bybit heist

A major cryptocurrency theft targeting Bybit was attributed to North Korea's Lazarus Group. The incident stood out for its financial impact and its geopolitical significance as a state-linked cybercrime operation.

PowerSchool pays ransom after student and teacher data theft

PowerSchool was reported to have paid a ransom following a data theft incident involving student and teacher information. The case became one of the notable education-sector cyber incidents of 2025 due to the sensitivity and scale of the exposed data.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

86 LINKEDOpen in app
Affected products
1 linked
Oracle E-Business Suite
Organizations
64 linked
SalesforceCisco SystemsTaniumEye SecurityBeyondtrustJfrogComparitechElasticPowerschoolNutanixZscalerPalo Alto NetworksTenableWestJetQualysIngram MicroGlobalLogicCato NetworksJaguar Land RoverAlexander McQueenCloudflareSalesloftByBitBugcrowdTaskUsHawaiian AirlinesAsahi Group HoldingsBritish Broadcasting CorporationSpyCloudPandoraInfosecurity MagazineHarrodsCoinbaseLouis VuittonGainsightPagerdutyMicrosoft CorporationQantasCyberarkOracleAdidasHitachiCoupangBlackstoneChanelTata Consultancy ServicesRubrikGucciBforeAICertiKNBC 26GoogleMarks & SpencerAllianz LifeDreherPeroniPilsner UrquellCo-opWarlockEsetAkiraQilinNomaniCloudEyE
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.