In H1 2025, ransomware was most frequently used in successful attacks against organizations (49% of attacks), followed by RATs (33%) and spyware (22%). In successful attacks against individuals, the trend toward using spyware (45%) persisted throughout the period, along with continued elevated interest in banking trojans (20%, up 6 percentage points from the previous half-year and up 8 percentage points compared to H1 2024). According to ThreatFabric, campaigns distributing the banking trojan Crocodilus have significantly expanded since March 2025. Initially, it was spotted across Europe, with attackers primarily focusing on Turkey. However, recent data indicates an increase in campaigns targeting other European countries as well as South America. One Poland-focused campaign stood out: the attackers disguised the trojan as official banking apps and e-commerce platforms. To drive distribution, they used Facebook ads offering bonus points for downloading the app.
Cybercriminal toolkits are constantly expanding through the development of new malware. Analysts at Insikt Group identified two new malware families—TerraStealerV2 and TerraLogger—linked to the Golden Chickens group (also known as Venom Spider), recognized for its MaaS offerings used by cybercriminal groups such as FIN6 and Cobalt Group. TerraStealerV2 is aimed at stealing browser-stored credentials, cryptocurrency wallet data, and Chrome extension artifacts. It uses Telegram and legitimate Windows utilities to exfiltrate stolen data. TerraLogger is a standalone keylogger that writes keystrokes to local files. Both malware families are still under active development and currently lack the stealth seen in Golden Chickens' more mature tooling. But given the group's track record, further improvement of these tools is likely.
Malware loaders (or droppers) are another illustration of how rapidly modern malware is evolving. According to our data, these malware types gained particular popularity among cybercriminals in Q2: loader use in attacks on organizations reached its highest level since early 2023, roughly tripling quarter-over-quarter. This aligns with the shift toward more complex cyberattacks: threat actors increasingly deploy loaders for multi-stage malware deployment to complicate detection and analysis. At the early stages of an attack, heavily obfuscated or polymorphic components are used to conceal their true purpose from antivirus programs. The actual payload—such as stealers, remote access trojans, or ransomware—is delivered only at the final stage. One case involved the ModiLoader (DBatLoader), delivered via phishing emails with attachments disguised as official banking documents. The attack's final stage deployed SnakeKeylogger spyware, which captures keystrokes, scrapes clipboard contents, and harvests stored credentials.
In Q2, we are also seeing an increase in the use of legitimate software in successful attacks on organizations (11%, which is 7 percentage points higher than in Q1 2025, and 9 percentage points higher than in Q2 2024). Threat actors are constantly adding new legitimate software to their toolkits. In a recent attack by the Fog ransomware group, Symantec discovered a highly unusual toolkit, which included both legitimate software and obscure open-source utilities. Among them was Syteca—a legitimate program designed for remotely monitoring employee activity, with screen capture and keylogging capabilities. Syteca was covertly delivered via the Stowaway proxy tool and executed through Impacket's SMBExec. The operators also leveraged popular utilities such as PsExec, Process Watchdog, 7-Zip, MegaSync, and FreeFileSync.
In late May 2025, PT ESC reported new attacks by the Rare Wolf group (also known as Rezet), targeting Russia's defense industry. In this campaign, the actors shifted from using ngrok (a publicly available tunneling tool) to establishing a stealthier, more resilient C2 link via a reverse SSH tunnel built with the Tuna utility and the sshd process.