TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Recorded Future Blog

2025 Year in Review: Malicious, Infrastructure

2026-03-19 · Read original ↗

ATT&CK techniques detected

5 predictions
T1588.001Malware
83%
“remcos rat gaining share, and families such as xworm, sectoprat, and gosar entering the top tier, while android dominated mobile activity ( nine of the top ten families ) amid rising use of mercenary spyware. droppers, loaders, and tds remained dynamic but resilient in 2025, with…”
T1588.001Malware
52%
“coverage expanded and competing tools gained traction. tools such as redguard, ligolo, and supershell saw significant growth in use throughout 2025. following law enforcement disruption efforts targeting lummac2, vidar and other infostealers partially filled the gap, reflecting c…”
T1587.001Malware
42%
“remcos rat gaining share, and families such as xworm, sectoprat, and gosar entering the top tier, while android dominated mobile activity ( nine of the top ten families ) amid rising use of mercenary spyware. droppers, loaders, and tds remained dynamic but resilient in 2025, with…”
T1588.002Tool
41%
“2025 year in review : malicious, infrastructure executive summary in 2025, insikt group significantly expanded its tracking of malicious infrastructure, broadeningcoverage across additional malware families and threat categories spanning cybercriminal and apt activity. this expan…”
T1588.001Malware
41%
“, the ecosystem ’ s underlying economic and operational logic is expected to remain intact, allowing established actors to continue operating. at the same time, insikt group anticipates increasingly assertive international law enforcement actions targeting malicious infrastructur…”

Summary

Explore Insikt Group’s 2025 Malicious Infrastructure Report. Gain insights into Cobalt Strike, Vidar infostealers, and AI-driven threats to secure your 2026 strategy.