A new half-year review from Recorded Future shows an expanding and increasingly fragmented threat landscape in the first half of 2025.
The report, titled H1 Malware and Vulnerability Trends, disclosed vulnerabilities rose, threat actors continued to weaponise both new and long-standing malware, and edge and gateway devices remained prime targets for initial access – trends the report says will shape the rest of 2025.
Expanding Attack Surfaces Causing Vulnerability
The report says the total CVE count rose from 20,385 in H1 2024 to 23,667 in H1 2025 – an expanding attack surface that provided more opportunities for exploitation. Web application weaknesses (Cross-Site Scripting, SQL Injection, CSRF and generic injection flaws) remain dominant, underlining that basic application security gaps continue to be valuable to attackers.
Of the actively exploited CVEs, Microsoft led with 28 exploits (twenty targeting Windows), more than triple the next most targeted vendors (Apple, Ivanti, Linux).
The report identifies exploited vulnerabilities across 81 vendors, illustrating a broad targeting strategy that does not rely solely on a handful of large vendors.
Edge security and gateway devices were a conspicuous target class: 17% of actively exploited CVEs affected appliances such as SSL-VPNs and next-gen firewalls from vendors including Ivanti, SonicWall, Fortinet, Palo Alto, Cisco, Citrix, Juniper and Sophos – as well as virtualisation platforms such as VMware.
The report highlights CVE-2025-0282 (Ivanti Connect Secure and Policy Secure) as an example of a vulnerability that permitted unauthenticated remote code execution and credential theft, demonstrating how a single exploited appliance can provide privileged network access and enable lateral movement.
The report’s telemetry found that 111 of the 161 exploited flaws (69%) required no authentication, and 78 (48%) were remotely exploitable. Forty-eight (30%) permitted RCE. The availability of public PoC exploits (42% of exploited CVEs) was noted as a major accelerant for attackers, with exploitation surges often following PoC publication within hours or days.
Where attribution was possible, the report says around 53% of exploitation activity was driven by state-sponsored or suspected state-sponsored actors.
Recorded Future highlights suspected China-linked groups, notably UNC5221, as high-volume exploiters with a preference for Ivanti products (including CVE-2025-4428, CVE-2025-22457 and CVE-2025-0282).
Post-exploit, the report notes that the majority of exploited vulnerabilities (151 of 161) were used to deploy malware; 73 were tied specifically to ransomware. Cobalt Strike beacons and backdoor malware featured prominently among post-compromise payloads – a pattern the report urges defenders to treat as high-priority indicators of compromise.
Malware Trends: Legacy Tools and a pivot to RATs
The report says the malware landscape in H1 2025 combined resurgence and churn. Long-running botnets and families such as Sality and Tofsee reappeared strongly in C2 detections, even as law enforcement disruption took down services such as LummaC2 (which has shown signs of partial recovery via Cloudflare-hosted domains).
The document highlights a tactical shift away from the infostealer dominance seen in H1 2024 toward a greater use of commodity RATs – Remcos, AsyncRAT and XWorm – which provide persistent, interactive access alongside data-theft capabilities.
The report’s triage data placed XMRig, Cobalt Strike, njRAT, DCRat and XWorm among the most-submitted malware families to public sandboxes. Backdoors made up nearly 23% of all post-exploitation activity.
From a TTP perspective, Command-and-Control (TA0011) remained the most frequent tactic, followed by ransomware-related techniques (data encryption for impact), credential abuse and local data theft.
The report also observed rising use of social engineering techniques such as ClickFix for initial access; ClickFix tricks users into running malicious scripts by presenting fake errors or verification prompts and has seen rapid uptake in recent periods.
Mobil Malware: New Strains, Overlays and NFC Fraud
The report says mobile threats expanded materially: at least eleven newly identified mobile strains appeared in H1 2025, and nine existing families continued to operate.
The mobile catalogue included banking trojans, RATs, spyware and infostealers, and the report notes that Android malware frequently abused Accessibility services for overlay attacks, notification interception, keylogging and OCR-based exfiltration.
A notable technical advance was the reported use of virtualization-based overlays by the GodFather trojan, which used frameworks such as Xposed and VirtualApp to run cloned banking apps in a sandboxed environment, evading conventional overlay detection.
The report also flags growing threats to contactless payments. SuperCard X is described as a MaaS platform enabling NFC relay fraud by capturing a tapped card’s signal on a compromised phone and relaying it to an attacker-controlled device — a technique with real-world financial implications, according to the dataset the report analysed.
Distribution methods for mobile malware continued to rely heavily on social engineering (smishing, vishing), fake downloads and brand impersonation, alongside occasional abuse of official app stores and even supply-chain compromises on counterfeit devices.
Ransomware: New Business Models and Evolving TTPs
Ransomware remained dynamic in H1 2025. The return of CL0P, the rebranding and “cartel” stratagems of DragonForce, the demise of BlackBasta and the abrupt disbandment of RansomHub all illustrate a market in flux.
New and flexible affiliate models – including Anubis’s three-mode affiliate model and Qilin’s “Call Lawyer” feature offering affiliates legal-intimidation advice – indicate operators are innovating to attract partners and monetise access.
Operationally, ransomware actors adopted new techniques across the kill chain: social-engineering ClickFix lures for initial access; EDR evasion via “EDR killers” and BYOI (bring-your-own-installer) techniques; and sophisticated loaders and in-memory injection (for example NETXLOADER with JIT hooking) to avoid detection.
Recommended reading
- North Korean Threat Actors Have Infiltrated UK Firms
- OpenAI Reveals Scale of Threat Actors Using AI to Influence Elections
- North Korea Stole $659M in Crypto Last Year, Says US
Attackers also repurposed legitimate dual-use software – AnyDesk, Syteca, GC2, Adaptix, Stowaway and others – to blend in with normal administrative activity and prolong access.
The practical result is a ransomware ecosystem combining bespoke technical advances with increasingly sophisticated commercial models.
Mitigations recommended by the report
The document sets out a range of defensive measures for organisations:
Vulnerability exploitation
-
Maintain inventories of internet-facing hosts and prioritise gateway appliances for monitoring and patching.
-
Adopt agile patch management, prioritising PoC and active exploit vulnerabilities and using interim mitigations where necessary.
-
Harden edge devices, enforce multi-factor authentication on admin interfaces and segregate management networks.
Malware intrusions
-
Use hunting packages and behaviour-based EDR to detect JIT hooking, protected payloads and memory injection.
-
Apply application allowlisting and script controls.
-
Educate employees on social engineering vectors such as ClickFix.
Overall, H1 2025 trends suggest defenders must prepare for a hybrid landscape in which ageing malware resurfaces alongside cutting-edge delivery chains: cross-platform visibility, stronger app and gateway security, and proactive intelligence integration will be critical going into the second half of 2025.





