版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
r
ΛrxxQ
}crnn-]cvrt_"I]
vnxvyJOOOCJQQCJJCCJJJn+
}CQCJJCCCJJXv])fft
:';"I)+>i!1C(rcyJYCQCCCQQCzxI.
i,![-nrxt(/t/ftlcttt/rtc{[_<'
cttt/rt({[_<,!+/ff"1tv:icccvxrjfI";+/ji
icccvxrjf;+/ji·:>j/;:i>/i.cncQQOOOOOQJz<>
·+Ifjfjr)jrjt,-tr/n/]jxfnx/rjnvjvzncxI~1QOOOOOOOOOOOQ
j/jjxjjff/[-fjj:…ΛIjt+:jxnvftjvj[+jc1jc11j11cf/tjf.+CQQOQVQQc
<fjj<t-}f")-_{r/t[}t'Yyy_-OQtQJ}+lt!11)
ttjf{fJC[+:::1]!1--}}]}{{}c"(z:1+.'-
11,JXJQJCCz,yn(/f-I,:I;ttIjIC}]][[[[}}[{}][[{}}{1}}1I1
1ZXJYJJXzc!,I,1I}-_[-}{_][]f[}]}-[[[}}}{[[]};]-[]}}}}
VZJJJXJyynxjnyyn'l,rt++<+]-[~__[-[]-[]]]]-][[-+-+__{-+]--[[]-[[[[}
TABLE
OF
CONTENTS
01
02
03
04
05
06
07
02
03
07
37
42
48
49
.YQQn<--!""_jnc
[czcxxxc:<{~lt-f;:<八]xvo
'jxJ.fJJJ-i,<!!1<
{I1<ll-1!;il-i++:
Inrycyyt+}jn1>;+l"">Λ,i+]
.(VJQVOQnxy:CJX/i"}CIC1;<.l".l.i_"Coo(fx[xcooootVYCCOVVCJv]]1t+:-}(;l
Vnxx/cz/t;XQxznvnzyoconnvxo)x>](1):
I,t,CQrxoooyftfJOYCOJxnJooccxnnxQQQCnl-iincJyliQi)QXOXJvozovrxjxrooonJXXVQJxcvnnzJCOCJot+'>
)JC[z"1QYJ<{XXOZJorcorrjfJf/t0oo}(1rxcoQvcICn
{XCC]zt}YIOJ(ZQ1:YIfjQyxyooyxf:IlCC!Zxxxi:Qocrjttoi[Qxcx
c/zojQ-VjJcQJ>VQOCOQnifJJ0ocootoyfx;jjQooxzi1!-r1rcoQJXQ
X.QYCJf(cnoQo:CJVJjxoZQ1{}JOO1CQcfcxvcYJ,:-cccn)fnzooQ:
nz!000~C-oxo]ozoo1oocnJOJr[YQoc,r八":l)Q}xcn.IΛ>)1ccn/IXy·
irco(Coy}cyjQ+llrrc}oxnxΛXox:,八>,ll;<:,nQcrQf-jcoc
:/]QQYQoC)z-onvc;_cfcQnQOQvnxQQ:~"++_i;.'[XZOOQ
nrnQ.OQJ(00ctvz.}zonyccxx0o)!'I
'xjZQoyoCVQ]/n}}C,.Qv;'OCZQvQ1r_:!i
GLOBALTHREATREPORT2025
nx(0OQ,o0rQQQ1n.QQx!]QfxoozQc>!XJfQ:'}l
01INTRODUCTION
elasticsecuritylabs
GLOBALTHREATREPORT20252
Introduction
Theadversary’splaybookhasfundamentallychanged.Theeraofslow,methodicalintrusionhasbeenreplacedbyanewmodelofhigh-velocityattacksthatprioritizespeedandefficiency.Attackersarenowexploitingthetrustedtoolsandworkflowsofthemodernenterprise—cloud
accounts,developerplatforms,andbrowsers—makingtheiractionsharderthanevertodistinguishfromnormalactivity.
Theanswerishiddeninyourdata.Tospottoday’shigh-speedattacks,
youneedanin-depthunderstandingofyourenvironment.Thismeans
usingAI-drivenanalysistoconnectreal-timeeventstohistoricalpatterns,revealingthefullstoryofanattack.Onlywiththisdeep,machine-speedcontextcanyoumakethequick,confidentdecisionsneededtostopa
modernthreat.
Ourteamofresearchers,analysts,andengineersatElasticSecurityLabsbelievesthattheonlywaytosucceedisthroughanopen,community-
basedapproach—weallgetstrongerwhenwesharewhatwelearn.
Thisreportputsthatbeliefintopractice,sharinginsightsfromourglobalvisibilitytohelpyoubuildastronger,moreconfidentdefense.
02EXECUTIVESUMMARY
elasticsecurtyabsGLOBALTHREATREPORT20253
Executivesummary
Theageofpatient,stealthyattacksisgivingwaytoaneweraofhigh-velocity
threats.Ouryear-over-yearanalysisrevealsaclearstrategicshift:Adversaries
areretoolingforspeed,weaponizingAItogeneratenovelthreatsatscale,and
prioritizingimmediateexecutionoverprolongedstealth.Thisaccelerationforcesdefenderstoadapttoanattacklifecyclemeasuredinminutes,notmonths,whererapid,context-richdecisionsdrawnfrombothreal-timeandhistoricaldatahave
becomethekeytoeffectivedefense.
The2025ElasticGlobalThreatReportfromElasticSecurityLabsbreaksdownthisnewlandscape.Basedonouranalysisofglobalthreattelemetry,we’veidentifiedthekey
adversarybehaviorsanddefensiveinnovationsthatmattermost.Here’sapreviewofwhatyou’lllearn:
•AdversaryprioritiesonWindowshaveflippedinthelastyear.Thetactic
categoryofExecutionnowaccountsfor32.05%ofmaliciousbehavior—doublingitspreviousshareof~16%—andsurpassingDefenseEvasionasthetoptactic.Thisdisruptsathree-yeartrendandindicatesastrategicshifttowardimmediatepayloaddeploymentoverinitialstealth.
Whatthismeansforyou–>Attackersarenolongerwaitingtohide;theyarefocusedonrunningmaliciouscodeimmediatelyuponentry.Thismakesruntimememoryprotectionandinitialaccesspreventionmorecriticalthanever.
•Thecloudattacksurfaceishighlyconcentrated.Over60%ofallcloudsecurityeventsboildowntojustthreeadversarygoals:InitialAccess,Persistence,and
CredentialAccess.
Whatthismeansforyou–>Acrossallmajorcloudplatforms,thislaserfocusonidentity-basedattacksisaclearsignalthathardeningauthenticationflowsandmonitoringforanomalousprivilegedaccessarethemosteffectivewaystodefendyourcloudworkloads.
02EXECUTIVESUMMARY
elasticsecurtyabsGLOBALTHREATREPORT20254
•AdversariesareweaponizingAItolowerthebarriertoentryforcybercrime.Wesawa15.5%increaseinGenericthreats,atrendlikelyfueledbyadversariesusinglargelanguagemodels(LLMs)toquicklygeneratesimplebuteffectivemalicious
loadersandtools.
Whatthismeansforyou–>TheriseofAI-generatedthreatsdramatically
increasesthevolumeandvarietyofmalwareyouface.ThismeansrelyinglessonstaticsignaturesandmoreonbehavioralanalyticsandAI-drivendetectiontoautomaticallyidentifyandstopthefloodofnovelthreatsatscale.
•Thetheftofbrowsercredentialshasindustrialized.Ouranalysisofover150,000malwaresamplesrevealedthatmorethan1in8aredesignedtostealbrowser
data.Thisisn’tforisolateduse;thesecredentialsaretherawmaterialfuelingtheaccessbrokereconomy,providingasteadysupplyofkeysforotherattackerstocompromisecorporatecloudaccounts.
Whatthismeansforyou–>Thebrowserisaprimarybattlegroundforyour
organization’smostsensitivedata.Infostealershaveadaptedtobuilt-inbrowserprotections,whichmeanstraditionalidentitycontrolsarenolongerenough.
•Sourcecodeleakscreateuniquelypermanentrisks.Asourinternalinvestigationsshow,asingleaccidentalcommittoGitHub—fromAPIkeystoapassportphoto—becomespartofadistributed,immutablehistorythatisincrediblydifficulttofully
remediate,creatingdurableexposurefromamomentarylapse.
Whatthismeansforyou–>Continuousmonitoringmustextendbeyond
traditionalperimetersandintoyourdeveloperworkflowstosecuretheentiresupplychainecosystem.
Thesetrendsaredeeplyinterconnected.AnadversarycanuseAI-generatedmalwaretostealbrowsercredentials,whicharethenusedtogaininitialaccesstoacloud
account.Onceinside,theyimmediatelyfocusonexecutiontodeployransomwareorstealdata.Thisreportconnectsthedots,showinghowtheseTTPsformthemodernattackchainand,moreimportantly,howtobreakitatmultiplepoints.
Thethreatlandscapeiscomplex,butbyunderstandingmalwareandthreatbehaviorsandleveragingadvanceddefenses,organizationscansignificantlyimprovetheir
resilience.ElasticSecurityprovidesthenecessarycapabilitiesandsharedintelligencetonavigatethesechallengesandbuildamoresecuredigitalfuturethroughcollectiveeffortsandcontinuousadaptation.
02EXECUTIVESUMMARY
elasticsecurtyabsGLOBALTHREATREPORT20255
What’snewinthisreport
Broadervisibilityintocustomerdistribution:Forthefirsttimeinthisreport,Elasticisprovidingthefollowingsummaryofourenterprisecustomerdistributiontohelp
contextualizetrendsandcorrelations.Thisgraphicdepictsthe10mostprevalent
categoriesofenterprise,whichincludesawiderangeofservice-basedbusinesses,
financialservicesproviders,utilities,andpublicsectororganizations.Industrycontextmattersbecausethreatactorsdon’ttargeteveryverticalthesameway,anditis
importanttoseeriskthroughthelensofyour,andadjacent,industrysectors.Tyingthreatstoverticalrealitieshelpsprovideaclearviewofbusinessimpact.
Count
InvestmentManagement4.1%
Software4.5%OtherProfessionalServices6.2%
Telecommunications6.4%
Other15.7%
BusinessServices12.5%
Insurance3.9%
TechnologyConsultingServices
27.3%
Banking9.0%
CivilianAgencies10.4%
Comparisonwithhybridsources:Newthisyear,weprovidesubsectionsthroughout
theTrendsandcorrelationssectionthatdescribeourobservationsfromhybridpublic/privatesources:Eachvendorcollectsuniquetelemetryinthesensethatouruserand
customerpopulationsmaynotoverlapacrossregionsorindustries.Thiscomparisontohybridsourcesservesasatransparentwaytocommunicatethatourvisibilitymaynotequatetothebroaderglobalthreatlandscape.It’sawayofshowingyouthat
weunderstandthelimitsofourimperfectvisibility,whilealsohighlightinggloballyprevalentthreatsyoumighthaveencountered.
InsightintoElasticsecuritymachinelearningandAI:Withthisedition,we’realsoincludinginformationonElasticSecurityMachineLearningandAI,includingmodel
elasticsecuritylabs
GLOBALTHREATREPORT20256
performanceandupdates.Thesetechnologiesplayapivotalroleindefense-in-depth,oftenmitigatingthreatsbeforetheyhaveanopportunitytoimpactenterprises.
VisibilityintoElastic’sinternalthreatdata:AsElasticSecurity’scustomerzero,
Elastic’sinternalinformationsecurityteamprovidesvaluableperspectivesabout
thethreatsweencounterfromtheglobalthreatlandscape.Thecasestudiesthey
contributetothispublicationhighlightthatwehaveskininthegame,andwepracticewhatwepreach.
Sunsetsectionsfrompreviousreports:Finally,thiseditionofElastic’sGlobalThreatReportomitssomesectionsfromprioreditions(suchasforecastsandforecast
rebuttals)andfocusesonkeystatisticsderivedfromthetelemetrydataourusers
andcustomersopttosharewithus.Italsoprovidesinsightsintotheworkwe’redoingbothtogeneratetelemetryandprioritizenewdataorcapabilities.Earlierin2025,we
releasedacompanionreport,
TheStateofDetectionEngineeringatElastic
,whichtellsthisstoryinmuchmoredetail.Let’sseehowwe’rechangingtogether.
03TRENDSANDCORRELATIONS
elasticsecurtyabsGLOBALTHREATREPORT20257
Trendsandcorrelations
Thefollowingsubsectionsdescribethemajortools,tactics,and
procedures(TTPs)employedbythreatsthatwereidentifiedacross
ElastictelemetryfromJune2024toJuly2025.ElastictelemetryincludesdatageneratedbyElasticEndgame,ElasticEndpoint,andtheElastic
Securitysolution.1Insomecases,theElasticSecuritysolutioningesteddatafromthird-partysensorsandothertechnologies.
Malwaresignaturekeystatistics
Inthissection,ElasticSecurityLabsstudiesthedistributionandtrendsofmalware
familiesin2025acrossallourcustomers’platforms,comparingthesefindingswith
lastyear’sresultswhereapplicable.Thisstudyincludesallfileandmemorythreats
identifiedusingourYARArules,whichareasetofstringsorbytesignaturesthat
uniquelyidentifyaspecificthreatorfamily.Inlinewithouropensourcephilosophy,wecontinuetosharetheseruleson
Elastic’sProtectionsartifactsrepository
.
DistributionofmalwarebyoperatingsystemsinElastictelemetry
Windows89.97%
Thissectiongeneralizesthemalwaresignatureeventsobservedacross
Linux9.00%
macOS1.03%
supportedoperatingsystems,whichpresentlyincludesWindows,Linux,andmacOSendpoints.
1TheElasticSecuritysolutiontelemetryisgeneratedbyadiversepopulationofsensorsanddatasourcesthataretoonumeroustodescribeconcisely,includingsensorsnotdevelopedbyElastic.
03TRENDSANDCORRELATIONS
elasticsecurtyabsGLOBALTHREATREPORT20258
Windowssummary
Outofallsignature-relateddetections,89.97%wererecordedonWindows.This
prevalenceislargelyduetothedistributionofWindowsamongcustomerenvironmentsandanemphasisonWindows-basedresearchtocombatnovelandwidespread
malwarethreats.
The23.85%increaseindetectionscomparedtolastyearcanbeattributedtotheincreaseinElasticDefendWindows-basedadoption.
Linuxsummary
Inthisyear’sstudy,Linuxsystemsaccountedfor9%ofobservedsystems,anotable
decreasefromthepreviousyear.However,thisdoesnotsuggestthatLinuxisless
ofatarget.Givenitsprimaryuseinserverandapplicationhosting,intrusionsoften
involveadvancedtechniqueslikeexploitkitsandcustomrootkits,asElasticSecurity
Labsdetailedinits
PUMAKIT
researchearlierthisyear.Suchnoveltechniquesare
challengingtodetectwithYARAsignatures,buttheymaybesuccessfullyidentifiedbyouragentusingbehavioralandmachinelearning–basedmethods.
macOSsummary
macOSrepresentsthesmallestportionofourdataat1.03%,consistentwiththe
previousyear.Whilethispercentageislow,attributedtobothitsloweradoptionamongourcustomersandgenerallylowervolumeofmalwaretargetingtheplatform,itdoes
notimplythatmacOSisinherentlymoresecure.
ElasticSecurity’shighlevelofcoverageonthisplatformallowedus
touncoveran
advancedthreatattack
earlierthisyear,whichweattributetotheDemocraticPeople’sRepublicofKorea(DPRK).
Malwarecategoriesobservedacrossallsupportedoperatingsystems
Eachfileandmemorysignatureweidentifyiscategorizedintodistinctbut
subjectivelydefinedgroups.Thedistributionacrossthesecategoriesisoutlinedinthefollowingtable.
03TRENDSANDCORRELATIONS
elasticsecurtyabsGLOBALTHREATREPORT20259
Trojan64.49%
Generic23.53%
Cryptominer2.77%RemoteAdmin1.91%
Rootkit5.01%Other2.29%
Trojancategory
Inthisyear’sreport,Trojanscomprised64.49%ofallidentifiedmalware.Thesethreatstypicallymasqueradeaslegitimatesoftware,allowingmaliciousactorstoestablisha
footholdoncompromisedsystems,exfiltratesensitivedata,deployadditionalharmfulpayloads,andfurtherpenetratenetworkdefenses.
ElasticSecurityLabsmaintainsvigilanceagainstsuchthreats,documentinga
ClickFix
malwarecampaign
thatwasactivelyemployedtodelivertheseTrojanpayloadsearlierintheyear.
Genericcategory
Genericthreats,encompassingvarioussmalltoolsthatcouldn’tbecategorized
elsewhere,accountfor23.53%ofallthreats;thiscategorysawa15.5%increasefromlastyear.
Thisriseispossiblydrivenbytheeaseofcreatingsuchtools.Largelanguagemodels(LLMs)enableevenless-skilledadversariestoquicklygeneratereliable,simple
loaders.Additionally,aclimateofeconomicuncertaintyoftenspursanincreaseincybercrime,leadingtomorediverseandwidespreadthreatactivity.
Rootkitcategory
Rootkitshaveshownasignificantincrease,reaching5.01%inthisyear’sstudy.
Ourabilitytodetectthemhasgreatlyimproved,particularlyonLinux,wheremany
advancedthreatsleveragekernel-levelfeaturesforstealthandprivilegedfunctionalitytoestablishadeepfootholdoninfectedmachines.Weconductedanin-depthanalysisofaWindowsrootkitanditscapabilitieswerefertoas
ABYSSWORKER
,alsoknownasPOORTRYbyGoogleCloudMandiant,whichwasdetectedinthewildviaourtelemetry.
03TRENDSANDCORRELATIONS
elasticsecuritylabs
GLOBALTHREATREPORT202510
Cryptominercategory
Cryptominerscontinuetoposeathreat,accountingfor2.77%oftheshare.ThemajorityaredeployedtomineMonerocryptocurrency,primarilyutilizing
XMRIG
.
ThisprevalenceislikelyduetoMonero’sprivacyfeatures.Additionally,unauthorizedcryptominingonLinuxhasledtoanincreasedresearchemphasisonthesefamilies.
RemoteMonitoringandManagement(RMM)category
RemoteMonitoringandManagement(RMM)tools,suchas
TeamViewer
or
UltraVNC
,represent1.91%ofobservedinstances.Theselegitimate,free,orpaid“support”toolsareabusedbythreatactorstogainremoteaccesstoavictim’smachineoncethe
victimistrickedintoinstallingthem.
MalwarefamiliesbrokendownbyoperatingsysteminElastictelemetry
Thissectionprovidesthemostprevalentmalwarefamiliesidentifiedoneachoperatingsystem.Thedesignation“malwarefamily”isappliedtorelatedcodefamiliesthatsharesignificantdesignandimplementationsimilarities,butwhichmaybedrasticallydifferentintermsofpackagingoreventranslatedtoanotherdevelopmentlanguage.
Prioreditionsofthisreportcombineddatafromalloperatingsystems,whichinfluencedthereporteddistributionofthesemaliciouscodefamilies.Withthismoredetailedreporting,wehopetobetterrepresentthesedistributions.Foreachoperatingsystem,wehighlightthreatphenomenathatmightotherwisebeoverlookedandwhicharereflectedinendpointbehavioraltrends.
Windows-basedmalwarefamilies
Elastictelemetrycapturedawidevarietyofsignatureeventswithfew,ifany,truly
dominantcodefamilies.However,threegeneralphenomenastandout:theexplosionofinfostealers,reliableoff-the-shelffamilies,andmalwarefromopensources.
elasticsecurtyabsGLOBALTHREATREPORT202511
Windows.Trojan.Bumblebee
6.67%
Windows.Trojan.Asyncrat
8.07%
Windows.Trojan.Njrat
5.33%
Windows.Trojan.Gh0st
5.33%
Windows.Trojan.RedLineStealer
6.67%
Windows.Trojan.Guloader
5.33%
Windows.Trojan.Remcos
9.33%
Windows.Trojan.GhostPulse
12.2%
Windows.Trojan.Lumma
6.67%
Windows.Trojan.Stealc
5.33%
Infostealersandtheprevalenceofaccessbrokernetworks
GhostPulse
representsabout12%ofsignatureeventsandleveragesbuilt-inWindowsscriptinginterfacesandprocessinjectiontodeliverinfostealerssuchas
Lumma
(6.67%)and
Redline
(6.67%).Infostealersplayakeyroleincollectingcredentialsthatarepackagedandsoldbyaccessbrokers,whichcommoditizesinitialaccesswhile
frustratingattributionofinitialaccessattempts.
Off-the-shelfframeworks
RemCos
(9.33%)and
CobaltStrike
(~2%)weretwoofthemost-frequentlyidentifiedoff-the-shelfmalwarefamiliesseentargetingtheWindowsoperatingsystem.These
capabilitiesbenefitfrommaturedevelopmentteamsandhavebeenleveragedbroadlybythreatsofallkindstoachieveavarietyofobjectives.Whilewehaveobservedan
overallreductionofoff-the-shelfimplantsthisyear,weattributethattotherapidpopularityofothercodefamilies.
Opensources
Ayncrat
,
Havoc
,and
njRat
collectivelyrepresentabout13%ofsignatureevents.
Whatseparatesthesecodefamiliesfromthosedevelopedprivatelyisthattheseare
availablepubliclyonGitHub.Theavailabilityofsourcecodelowersthebarriertoentryforsomethreatgroupsandmayinspirefeaturesinclosedmalwaredevelopment
ecosystems.Importantly,thisalsoplaysapowerfulroleinenablingdefenderstoproducecountermeasuresfromthoseverysameopensources.
elasticsecurtyabsGLOBALTHREATREPORT202512
Linux-basedmalwarefamilies
Linuxtelemetryshowsaconsistentthreatlandscapedominatedbycommoditized
malware,cryptocurrencyminers,andlightweightcommand-and-control(C2)
frameworks.Adversariescontinuetorelyonwell-knowncodefamiliessuchasSliver,
Mythic,andMetasploit,oftendeployedafterinitialaccessviaremoteservicesor
public-facingapplications.Theseframeworksaretypicallyuseddirectlyfromtheshell,indicatingahands-onintrusionstyle.
Linux.Trojan.Dropper!
3.09%
Linux.Trojan.XZBackdoor
10.60%
Linux.Trojan.Pornoasset
6.13%
Linux.Trojan.Getshell
4.37%
Linux.Trojan.Gafgyt
6.45%
Multi.Trojan.Mythic
11.99%
Multi.Trojan.Silver
12.43%
Linux.Trojan.Generic
Linux.Trojan.Mettle
3.93%
Linux.Trojan.Metasploit
9.33%
16.77%
Persistentpatterns
Acommonattackmethodologyobservedalongsidesignatureeventdatabegins
withInitialAccess,followedbyrapidestablishmentofPersistence.Scheduledjob
mechanismssuchascronandsystemdweremostcommonlyabused,frequently
triggeringbehavioraldetections.Shellprofilemodification,XDGautostartdesktopentries,andudevruleswerealsoobserved.ElasticSecurityLabsresearcherRubenGroenewoudhasshared
in-depthresearchintoLinuxpersistence
.
Off-the-shelf,onthewire
Ifthecloudis“someoneelse’scomputer”,off-the-shelfcapabilitiesare“someone
else’smalware.”Threatsofmanykindschosematureandwell-builtframeworkslikeSliver(12.43%),Mythic(~12%),andMetasploit(9.39%)becausetheyreducethe
developmentburdenwhilecomplicatingattribution.
elasticsecurtyabsGLOBALTHREATREPORT202513
Cryptocurrencymining
OncepersistenceisestablishedonLinux,adversariescommonlydeploycryptominers,particularlyXMRIGvariants.Thesepayloadsareusuallypartofbroaderscriptsthat
enumeratekernelfeatures,removecompetitorsusingkillcommands,harden
attackerfilesviachattr+i,andattempttoevadedetectionbydisablingsystem
logging,firewallrules,andotherdefenses.Attackersfrequentlyreachouttoexternalservicestodeterminethehost’spublicIPandoftenutilizeBusyBoxforcompact
utilityexecution.Thiscommonattackpatternisalsoobservedintheoverallbehavioraltelemetry.
macOS-basedmalwarefamilies
MacOS.Trojan.Metasploit
MacOS.Cryptominer.Generic
MacOS.Infostealer.MdQueryTCCMacOS.Trojan.Adload
Macos.Infostealer.Wallets
Multi.Trojan.Sliver
MacOS.Cryptominer.Xmrig
Macos.Creddump.KeychainAccessMacOS.Trojan.Thiefquest
MacOS.Trojan.Getshell
Other
25.66%
17.70%
13.27%
10.62%
7.08%
5.31%
4.42%
3.54%
2.65%
2.65%
7.07%
Off-the-shelfmalware
AlthoughthelownumberofmacOSobservationsmakesthestudyofmalware
distributionontheplatforminherentlyskewed,weobservethatthemostwidespreadfamilyisMetasploit,with25.66%oftheshare.
Cryptominers
Genericallyidentifiedcryptominers(17.70%)andthewell-knownXMRigminer
(4.42%)collectivelyrepresentabout22%ofthemalwareweobservedonmacOS.LikeLinux,macOSappearstobeanattractivetargetforcryptocurrencymining.
Infosealers
Infostealersareadominantcategoryonallsupportedoperatingsystems,with
MdQueryTCC(13.27%)andWallets(7.08%)makingupabout20%oftotalmacOS
elasticsecurtyabsGLOBALTHREATREPORT202514
observations.Notably,thisdoesn’tcaptureindirectorscript-based
infostealers—bothofwhichplayedrolesinnoveldiscoveries,whicharebydefinitionminorityevents.
Endpointbehaviorkeystatistics
ElasticSecurityoperatesontheprinciplesofopenness,transparency,andcollaboration.Inlinewiththesevalues,Elasticsharesall
protectionsartifacts
usedinproduction,whichdetailtheendpoint
behaviorallogicdevelopedtoidentifyadversarytradecraftusing
Elastic.Thisreportleveragesglobaltelemetryfromthealertsand
integratedpreventioncapabilitiesderivedfromthisdetectionlogic.TotheextentthattacticsandtechniquesexistinMITREATT&CK
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 2026年教师资格证考试《小学语文》科目真题汇编及答案
- 2026农学相关面试题目大全及答案
- 2026平阴社工面试题及答案大全
- 2026青岛税务面试题及答案
- 2026燃气规划面试题及答案
- 2026生育政策面试题及答案
- 河南catti考试试题及答案
- 廉江市小升初模拟考试试题及答案
- 饭店管理课件
- 湛江市吴川市黄坡镇社区工作者招聘考试题目
- 西藏交通发展集团有限公司招聘笔试真题2025
- 2026江苏连云港市城建控股集团有限公司招聘32人笔试参考题库及答案详解
- 屋面防水施工方案
- 电梯安全性能验收标准
- 2026福建中考语文作文考前专项练习(题目+范文)
- 2026年《中华民族共同体概论》第13讲先锋队与中华民族独立解放(1919-1949)新版课件
- 江西文演集团招聘笔试题库2026
- 快递柜投放运营维护方案
- 年产6500吨电解铜箔生产线技术改造项目环评影响报告
- X-R控制图模板完整版
- GB/T 14345-2008化学纤维长丝捻度试验方法
评论
0/150
提交评论