๐๐๐ฒ ๐๐ข๐ ๐ก๐ฅ๐ข๐ ๐ก๐ญ๐ฌ ๐๐ซ๐จ๐ฆ ๐๐ ๐๐๐๐ ๐๐๐ฅ๐ฐ๐๐ซ๐ ๐๐ซ๐๐ง๐๐ฌ ๐๐๐ฉ๐จ๐ซ๐ญ
Interactive analysis sessions: ANY.RUN users engaged in 1,151,901 public analysis sessions in Q4, a 5.6% increase from Q3. 22.6% of sessions were flagged as malicious, and 6.2% as suspicious, highlighting the rise in cyber threats.
ยท ๐ง๐ผ๐ฝ ๐บ๐ฎ๐น๐๐ฎ๐ฟ๐ฒ ๐๐๐ฝ๐ฒ๐: Stealers led the threat landscape with 25,341 detections. Loaders and RATs remained common, while adware (1,666 detections) emerged in the top ten.
ยท ๐ฅ๐ถ๐๐ถ๐ป๐ด ๐บ๐ฎ๐น๐๐ฎ๐ฟ๐ฒ ๐ณ๐ฎ๐บ๐ถ๐น๐ถ๐ฒ๐: Stealc saw a significant rise of 136.3%, from 2,030 detections in Q3 to 4,790 in Q4. Lumma remained the most detected family with
6,982 detections.
ยท ๐ฃ๐ต๐ถ๐๐ต๐ถ๐ป๐ด ๐ฎ๐ฐ๐๐ถ๐๐ถ๐๐: Phishing-related tasks rose significantly to 82,684, with Storm1747 being the most active group.
ยท ๐๐๐ฎ๐๐ถ๐ผ๐ป ๐๐ฎ๐ฐ๐๐ถ๐ฐ๐: Attackers continued using PowerShell, Windows Command Shell, and various evasion techniques like virtualization and sandbox bypassing.
ยท ๐ง๐ฎ๐ฐ๐๐ถ๐ฐ๐, ๐๐ฒ๐ฐ๐ต๐ป๐ถ๐พ๐๐ฒ๐, ๐ฎ๐ป๐ฑ ๐ฝ๐ฟ๐ผ๐ฐ๐ฒ๐ฑ๐๐ฟ๐ฒ๐ (๐ง๐ง๐ฃ๐): PowerShell and Windows Command Shell remained the top techniques, followed by spearphishing and scheduled tasks, reflecting evolving adversary methods.
For more detailed insights and the full report, visit the ANY.RUN blog.
๐๐จ๐ฐ ๐๐ฑ๐ฉ๐๐ซ๐ญ๐ฌ ๐๐ง๐ ๐๐ซ๐ ๐๐ง๐ข๐ณ๐๐ญ๐ข๐จ๐ง๐ฌ ๐๐๐ง ๐๐ฌ๐ ๐๐ก๐ข๐ฌ ๐๐๐ฉ๐จ๐ซ๐ญ ๐๐จ๐ซ ๐๐๐๐ ๐๐ฒ๐๐๐ซ๐ฌ๐๐๐ฎ๐ซ๐ข๐ญ๐ฒ
This report is an important resource for cybersecurity professionals, businesses, and threat analysts looking to stay ahead of emerging threats in 2025. By analyzing trends in malware activity, phishing campaigns, and evolving attack techniques, organizations can enhance their security strategies and better prepare for the challenges ahead.
๐๐๐จ๐ฎ๐ญ ๐๐๐.๐๐๐
ANY.RUN is an advanced interactive malware analysis platform designed to empower cybersecurity professionals with real-time insights into emerging threats. Offering tools like a dynamic malware sandbox and Threat Intelligence (TI) lookup, ANY.RUN allows users to analyze suspicious files and URLs, identify malware behavior, and track cybercriminal activity.
The ANY.RUN team
ANYRUN FZCO
+1 657-366-5050
email us here
Visit us on social media:
Twitter
LinkedIn