Phishing remained the most common method of initial access in Q2 2025, according to new incident response data from Cisco Talos IR.
Although it declined from 50% of engagements last quarter to 33% this quarter, phishing continued to represent a significant threat vector -driven largely by the use of compromised internal or trusted partner email accounts to bypass security controls and build trust with targets.
In these cases, malicious messages were often sent from legitimate accounts, with 75% of phishing-related engagements involving compromised email identities.
The primary goal of these campaigns appeared to be credential harvesting, rather than financial fraud or data theft.
In one case, attackers used a compromised partner email to distribute links to a fake Microsoft Office 365 login page that prompted users to complete multi-factor authentication (MFA), likely to steal both credentials and session tokens.
Talos IR analysts noted that this shift suggests cyber-criminals may now prefer brokering stolen credentials – which are easier to monetise and carry less operational risk – over executing direct financial or espionage-based attacks.
In one engagement, the compromise of a single user’s email credentials led to the successful phishing of a dozen more employees through an internal spear phishing campaign disguised as a SharePoint link.
Phishing, Ransomware and Credential Harvesting Dominate Q2 2025 Incident Response Trends
Ransomware and pre-ransomware activity continued to account for 50% of Talos IR engagements, consistent with Q1 2025. During the quarter, Cisco Talos responded to Qilin ransomware for the first time, documenting a set of previously unreported tools, tactics, and procedures (TTPs).
Qilin actors were observed using:
-
A custom encryptor with hardcoded victim credentials,
-
Backblaze-hosted C2 infrastructure,
-
CyberDuck for data exfiltration,
-
And a range of remote access tools including TeamViewer, AnyDesk, Chrome Remote Desktop, and others.
Persistence was maintained through registry AutoRun entries and scheduled tasks, allowing the ransomware to re-execute at reboot or logon. The attack resulted in a full Active Directory domain rebuild and widespread password resets across the environment.
Talos IR also observed signs of increased Qilin activity, including engagements not yet counted in Q2 stats due to ongoing investigation, and a doubling of victim disclosures on the group’s leak site since February 2025. Analysts believe this may reflect either a recruitment of new affiliates or an increase in operational tempo.
Links to Moonstone Sleet, a North Korean state-sponsored group, and RansomHub affiliates were also reported, following RansomHub’s leak site shutdown in April. Qilin actors were observed engaging with former RansomHub members and marketing an updated ransomware variant to attract new partners.
PowerShell 1.0 Used in a Third of Ransomware Engagements
One notable evasion technique observed was the use of PowerShell 1.0, a version of the scripting tool released in 2006 and lacking modern security features such as script block logging, transcription logging, and AMSI (Antimalware Scan Interface).
Threat actors used it in one-third of ransomware and pre-ransomware incidents, likely to bypass detection and gain additional flexibility.
In a Medusa ransomware incident, PowerShell 1.0 was used to exclude the core Windows folder from antivirus scanning. In another case, attackers used it to bypass execution policies and monitor internal file transfers, enabling them to remain stealthy throughout the environment. Talos IR recommends enforcing the use of PowerShell 5.0 or later across all systems to mitigate this risk.
Education Sector Heavily Targeted
In a change from Q1, the education sector became the most targeted industry vertical in Q2.
This aligns with historical patterns, including findings from Talos’ 2024 Year in Review, which recorded high ransomware volumes against educational institutions in the spring months. Education was also the most frequently targeted sector in FY24 Q3 and Q4.
Recommendations for Organisations
Talos IR provided several key recommendations to address recurring security weaknesses observed this quarter:
-
Strengthen MFA Deployment
Over 40% of engagements involved MFA weaknesses, including misconfiguration, lack of enforcement, and bypass techniques. Attackers often abused self-service features to register their own devices. Talos IR advises monitoring for:
-
Use of bypass codes
-
New device registration
-
MFA-exempt account creation
-
Account removal from MFA
-
Improve Logging and Detection
25% of incidents were hampered by poor logging infrastructure, limiting forensic analysis. Organisations are urged to deploy a SIEM for centralised log storage and maintain flow logging and WAF coverage across their networks. This improves response time and visibility into adversary actions. -
Harden Endpoint Detection Tools
A slight increase in EDR tampering was observed this quarter, with attackers disabling protections in 25% of engagements. Talos IR recommends protecting endpoint agents with passwords and customising default configurations to reduce the risk of tampering.
Recommended reading
- AI Ushering in A “Digital Divide” in Cybersecurity, NCSC Warns
- New Report Reveals AI Trust Divide in Cybersecurity
- AI in Cybersecurity: A Risk or an Opportunity?
MITRE ATT&CK Observations
Key ATT&CK techniques included:
-
Credential access via kerberoasting, brute-force, and phishing sites
-
Phishing remained the top initial access method for the second quarter in a row
-
Multiple techniques were observed under credential dumping and adversary-in-the-middle categories
Despite a reduction in phishing’s proportional share of incidents, it remained the dominant access method – now more often focused on harvesting credentials for resale.
Meanwhile, ransomware threats held steady, with Qilin emerging as a rapidly evolving threat employing novel techniques and possibly gaining new affiliates. The use of legacy tools like PowerShell 1.0 reflects a continued emphasis on evasion and stealth, even as attack volumes remain high.





