Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-enabled-threat-activitycybercrime-service-ecosystemidentity-authentication-vulnerabilityransomware-group-operation

Major Cyber Threat Trends and Shifts in 2025

Updated 3mo agoFirst seen Jan 7, 20262 sources

Cybersecurity research throughout 2025 revealed significant changes in the threat landscape, with both SentinelLABS and KrakenLabs reporting a marked evolution in attacker tactics and the professionalization of cybercrime. Threat actors increasingly leveraged artificial intelligence to automate attacks, generate convincing social engineering content, and bypass security controls, making AI a practical tool for both sophisticated and commodity threats. The exploitation of legitimate infrastructure, such as free-tier publishing platforms and commercial AI APIs, became commonplace, while adversaries also began monitoring defender intelligence-sharing platforms to stay ahead of detection. The rise of crimeware-as-a-service (CaaS) further industrialized cybercrime, enabling a broader range of actors to access advanced capabilities and monetize initial access to corporate networks.

Geopolitical tensions and the convergence of organized cybercrime with emerging technologies accelerated the pace and scale of attacks, with threat actors blending ideological motives with financially driven ransomware and extortion campaigns. Traditional carding fraud declined due to regulatory and law enforcement efforts, but attackers shifted focus to abusing trusted third-party platforms and exploiting identity and access management weaknesses. These developments defined the cyber threat environment in 2025 and set the stage for ongoing risks into 2026, as organizations faced increasingly sophisticated and industrialized adversaries.

Share:
Major Cyber Threat Trends and Shifts in 2025
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Jan 1, 20251y ago

SharePoint zero-day CVE-2025-53770 is exploited

SentinelLABS identified exploitation of the SharePoint zero-day CVE-2025-53770 as a notable 2025 incident. The case stood out among a year otherwise marked more by operational scaling than by novel exploitation.

Nobitex cryptocurrency platform is attacked

KrakenLabs cited a 2025 attack on Nobitex as a notable cryptocurrency-related incident. The event reflected the continued targeting of digital-asset platforms amid the convergence of cybercrime and geopolitics.

China's use of private cybersecurity firms for state surveillance is exposed

SentinelLABS said 2025 reporting revealed deep integration between Chinese private cybersecurity firms and state surveillance efforts. The exposure added detail on how commercial entities supported government cyber and monitoring objectives.

Large phishing campaigns leverage thousands of subdomains

SentinelLABS documented 2025 phishing operations that used thousands of subdomains at scale. The campaigns showed how attackers were weaponizing legitimate infrastructure to industrialize social-engineering activity.

Threat actors use LLMs to generate unique malware

During 2025, SentinelLABS observed adversaries using large language models to help create unique malware. The report characterized AI as an operational accelerator that increased speed and variation rather than fundamentally changing tradecraft.

PXA Stealer and Katz Stealer campaigns show advanced automation

SentinelLABS reported that 2025 information-stealer campaigns involving PXA Stealer and Katz Stealer demonstrated increasingly automated operations and monetization. The activity reflected the broader professionalization of cybercrime.

Salesforce breaches occur via social engineering

KrakenLabs identified 2025 data breaches involving Salesforce environments compromised through social-engineering tactics. The incidents underscored growing attacker focus on identity abuse and third-party SaaS access.

Black Basta chat logs are leaked

In 2025, leaked Black Basta chat logs exposed internal communications and operational details of the ransomware group. The leak provided new insight into the group's human dynamics and business practices.

Belsen Group mass-exploits Fortinet FortiGate devices

KrakenLabs highlighted a 2025 campaign in which the Belsen Group conducted large-scale exploitation of Fortinet FortiGate devices. The activity illustrated the continued industrialization of access-focused cybercrime.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Major Cyber Threat Trends and Shifts in 2025 | Mallory