All of our yearly Threat Reports and Nastiest Malware Reports
Recently active
Cyber threats are not just increasing. They are changing shape.The latest OpenText Cybersecurity Threat Report, based on telemetry from tens of millions of endpoints across business and consumer environments, reveals a shift that many organizations are still not fully accounting for.Attackers are moving faster, personalizing more effectively, and increasingly targeting identity over traditional vulnerabilities.Here are the key insights you need to know. 1. Business and Consumer Threats Are Moving in Different DirectionsOne of the clearest signals in this year’s data is that business and consumer environments are no longer moving in parallel. They are diverging.Consumer infection rates surged by over 60% year-over-year, while business environments saw a more modest increase of around 11–12%.At first glance, that might suggest businesses are better protected. They’re not. Attackers are simply being more selective.In consumer environments, scale wins. High-volume campaigns, broad targetin
If 2024 was the year ransomware came roaring back, 2025 was the year it learned your name. Attackers did not just hack networks this year. They hacked people. With artificial intelligence now shaping phishing, voice cloning, and fake job interviews, cybercrime has entered the age of identity warfare.Stream the Webinar on demand HERE The New BattlefieldTraditional defenses are losing ground because the battlefield has moved inside the perimeter. Instead of breaking software, threat actors manipulate users and abuse credentials that look legitimate. Breakout times are now measured in seconds, and every stolen password or phone call can open the door to a full-scale breach.Social engineering, deepfakes, and AI chat tools have turned ordinary interactions into attack vectors. We’re seeing a major spike in credential theft through early 2025, as stolen identities become the preferred gateway for ransomware and data extortion. Once those credentials are compromised, they’re weaponized throug
As cyber threats grow more complex and coordinated, the 2025 OpenText Cybersecurity Threat Report highlights how attackers are evolving and how defenders must respond. This year's analysis draws from our vast telemetry across business and consumer endpoints, email protection, DNS filtering, and web threat intelligence. From ransomware pivots to regional malware surges, here’s what you need to know.Stream the Webinar on-demand! Malware on the March: Business Infections Surge 28%Malware made a strong comeback in 2024, with email-borne threats continuing to dominate the attack vector landscape. While consumer malware infections remained relatively flat, business-targeted malware infections jumped 28% year-over-year. This growth isn’t just in volume, it’s in complexity. We observed a shift toward multi-stage payloads, advanced obfuscation techniques, and regionally tailored campaigns. The surge in business infections reinforces what we’ve seen in ransomware trends: cybercriminals are targ
Steam the Webinar on demand HEREAs we look back on the cybersecurity landscape of 2024, it's clear that the world of digital threats continues to evolve at an alarming pace in parallel with AI. This year has seen ransomware groups adapt and innovate, pushing the boundaries of their malicious capabilities and evasiveness from law enforcement. In our annual "Nastiest Malware" report, now in its sixth year, we've observed a steady increase in both the number and sophistication of malware attacks. The ransomware sector, in particular, has witnessed the emergence of "business models," with ransomware-as-a-service (RaaS) dominating the scene. Elite ransomware authors have concluded that profit sharing and risk mitigation are key contributors to their consistent success and evasion of authorities.The saga of LockBit in 2024 exemplifies the resilience and adaptability of these cybercriminal groups. Despite a major law enforcement operation in February, dubbed "Operation Cronos," which saw the
Be sure to join the Webinar! In today’s evolving threat landscape, cyber defenders are constantly adapting to new adversarial tactics and emerging vulnerabilities. The latest 2024 Threat Hunter Perspective from OpenText™ sheds light on the most pressing threats, nation-state activities, and security recommendations enterprises must consider in the months ahead. Here are the key findings and expert insights to help you stay ahead of the curve. Nation-state collaboration with cybercrime ringsOne of the standout trends identified in the report is the increasing collaboration between nation-state actors and cybercrime rings. Adversaries are more coordinated than ever, launching synchronized attacks aimed at maximizing disruption and confusion.Russia: Cyber operations are ongoing, with particular focus on Ukraine and NATO countries, often leveraging criminal groups like Killnet and Lokibot to amplify attacks. China: Expanding its focus to South China Sea neighbors, China often partners wit
As we navigate through 2024, the cyber threat landscape continues to evolve, bringing new challenges for both businesses and individual consumers. The latest OpenText Threat Report provides insight into these changes, offering vital insights that help us prepare and protect ourselves against emerging threats. Here’s what you need to know: The Resilience of RansomwareRansomware remains a formidable adversary, with groups like LockBit demonstrating an uncanny ability to bounce back even after significant law enforcement actions. Despite a recent crackdown that saw authorities dismantle its infrastructure, LockBit swiftly resumed operations, even taunting law enforcement agencies in the process. This adaptability highlights how resourceful ransomware groups have become, enabling them to evade detection and persistently challenge defenders.For businesses, this means implementing a comprehensive incident response plan that includes secure, immutable backups and regular testing to ensure rap
Stream the Webinar on demand!https://www.brighttalk.com/webcast/18665/593543Check out our Nastiest Malware infographic attached below! We've been doing the Nastiest Malware series for over 5 years now and in that time, we have seen a steady increase in the number and sophistication of malware attacks. Ransomware has been the most prevalent type of malware, with cybercriminals increasingly targeting businesses and organizations. Criminal actors in the Ransomware sector have come up with new “business models” and ransomware-as-a-service (RaaS) is dominating. Elite Ransomware authors appear to have concluded that profit sharing and risk mitigation are top contributors to their consistent success and reliable evasion from authorities. Malware payloads are becoming more sophisticated and difficult to detect, and we expect their tactics to be ever evolving. Reflecting on the past five years of the malware landscape offers invaluable insights into the evolution of cyber threats. In 2019, the
Our latest OpenText Cybersecurity Threat Report is finally here! Cybersecurity professionals were kept on their toes throughout 2022. Russia’s invasion of Ukraine sent shockwaves through organized cybercrime and disrupted ongoing operations by REvil and Conti. Global law enforcement continued to aggressively target threat actors, including the Hive ransomware gang. And discovery of critical vulnerabilities and exposures (CVE) continued at a record pace, with nine CVEs published with scores of 9 or higher. Our report is full of great insights. Some key findings include:The Middle East, Asia, and South America were the regions with the highest percentage of infections. 55.6% of consumer PCs were infected more than once, and 19.9% infected more than 5 times. Facebook was most often impersonated company in phishing attacks. During 2022, 84% of ransomware attacks now include leak sites The year-end average for ransomware payments in 2022 has skyrocketed to over $400,000With Ransomware now t
With 2023 around the corner, we’ve seen yet another eventful year for the threat landscape and malware continues to be center stage in the threats posed towards individuals, businesses, and governments. The infosec industry continues the struggle of the perpetual cat and mouse game tactics that haven’t really stopped since cybercriminals first started decades ago. This absolutely accelerated into overdrive the past 9 years with the mainstream adoption of ransomware payloads and cryptocurrency facilitating payments.If you’ve seen our writeup of Blackhat 2022, the keynote speakers noted that in 25 years of doing hacking conferences, we still don’t have a handle on what’s going on, and the surface area of attack is only growing so we all expect it to get worse.The ransomware double extortion tactic continues to be a match made in heaven for criminals and absolute hell for victims. Every major ransomware campaign has been utilizing a Tor leak site for data exfiltrated with the intention of
Our latest BrightCloud Threat Report is finally here! This year, our findings show us that cybercriminals are improving their efforts to evade detection. 2021 was the year where everything security-related that could go wrong did go wrong. We witnessed unprecedented attacks on the supply chain around the world. Despite American and Russian coordinated efforts to take down Emotet, REvil, and Conti, cybercriminals found avenues to resurrect themselves and carry out their lethal efforts.The normalization of remote and hybrid work continued to shift the way bad actors pursue lucrative avenues for exploitation. We also witnessed cybercriminals strategically releasing their executed attacks during specific times of the year.Our report is full of great insights. Some key findings include:The Middle East, Asia, and Africa were the regions with the highest percentage of infections. 53% of consumer PCs were infected more than once, and 19% infected more than 5 times. Apple was most often imperso
Every year at BlackHat USA we debut the mid-year update to our yearly flagship Threat Report. Our mid-year update provides contextual insights from the 2022 BrightCloud® Threat Report. These updates highlight the most recent trends in malware and phishing within the first six months of 2022.If you haven’t already, check out our 2022 BrightCloud Threat Report The Manufacturing vertical continues to experience the highest above-average infection rate, rising just over 12% since 2021 to 66.5%. The Information and Public Administration verticals also saw spikes in above-average infection rates, 47.4% and 42.7%, respectively. Windows 11 adoption remains stagnant, only rising 4% for businesses and 15% for consumers within the first nine months of the release. Since the adoption of Windows 11 has been slow, these results highlight the importance of incorporating a layered security approach that includes DNS protection which helps reduce infection rates.Protective DNS services are essential co
It's Like 2020 But WorseCheck out the full infographic attached below!Check out our Q&A and maybe even win a prize This year was yet another year with COVID-19 and malware running rampant in the headlines. Be it in person or online, the world is still struggling in the fight against viruses. This year took another ghastly turn when attacking critical infrastructure and supply chains became a new trend. Perhaps because popular botnets were down, or maybe it’s just plain old-fashioned nation-state sponsored attacks.We saw some previous big players exit the scene this year, some vacation to the beach and some off to prison. In any event, 2021 was one where cyberthreats, especially ransomware, dominated the news.Ransomware extortion has evolved from a trend into a new normal. Every major ransomware campaign is running the double extortion method, a scary prospect for small businesses. Not only are they stealing and locking files away, but the bad actors will absolutely leak data in the
The latest Webroot BrightCloud Threat Report is here, and our findings show that cybercriminals are as creative and hardworking as ever. Although 2020 brought countless challenges for businesses and individuals all over the world, it seems to have offered cybercriminals new avenues to scam internet users, steal data, and cause disruption.But the criminals weren’t the only ones hard at work. Cybersecurity analysts have been clocking overtime to identify and neutralize new threat tactics as quickly as they appear. Operating systems and web browsers are making effective improvements to their built-in security. Security awareness training for employees continues to improve security postures. Nations and companies are working together to break down cybercriminal infrastructure. Here are some of the highlights from the reportCriminals targeted COVID-19 topics like it was their job (because it kind of is…) Most of the malicious spam (malspam) emails we’ve seen have used COVID-related phishin
Webroot revealed the results of the 2019 Webroot Threat Report, showcasing that while tried-and-true attack methods are still going strong, new threats emerge daily, and new vectors are being tested by cybercriminals. The report is derived from metrics captured and analyzed by Webroot's advanced, cloud-based machine learning architecture: the Webroot® Platform. Explore the 2019 Webroot Threat Report Notable Findings: 40 percent of malicious URLs were found on good domains. Legitimate websites are frequently compromised to host malicious content. To protect users, cybersecurity solutions need URL-level visibility or, when unavailable, domain-level metrics, that accurately represent the dangers. Home user devices are more than twice as likely to get infected as business devices. Sixty-eight percent of infections are seen on consumer endpoints, versus 32 percent on business endpoints. Phishing attacks increased 36 percent, with the number of phishing sites growing 220 percent over th
Webroot Also Observed a 125% Increase in Malware Targeting Windows 7 The annual Webroot Threat report was recently released, highlighting not only the agility and innovation of cybercriminals who continue to seek out new ways to evade defenses, but also their commitment to long-established attack methods. Most notably, Webroot observed a 640 percent increase in phishing attempts and a 125 percent increase in malware targeting Windows 7. The report is derived from metrics captured and analyzed by Webroot’s advanced, cloud-based machine learning architecture: the Webroot Platform. “In the cybersecurity industry the only certainty is that there is no certainty, and there is no single silver bullet solution,” said Hal Lonas, Senior Vice President and CTO, SMB and Consumer, OpenText. “The findings from this year’s report underline why it’s critical that businesses and users of all sizes, ensure they’re not only protecting their data but also preparing for future attacks by taking simple
Check out the Webroot Threat Report: Mid-Year Update, which explores the ever-evolving cybersecurity landscape.Highlights include:· Windows 7 is becoming even riskier, with infections increasing by 71%.· Hackers are using trusted domains and HTTPS to trick victims.· Phishing continued rapid growth into 2019, and criminals are expanding their phishing targets.· Phishing lures are becoming increasingly personalized as more PII is collected from breaches.Read the full press release and report here!Or check it out by video Hear a security expert explain key threats Ready why context matters for threat intelligence
Check out the Webroot® Threat Report: Mid-Year Update, which explores the ever-evolving cybersecurity landscape. Highlights include: There has been a massive shift from ransomware to cryptomining. Cryptojacking scripts are on the rise. Windows® 10 adoption increases. Ransomware attacks exploit unsecured RDP to find the most valuable targets. Phishing attempts skyrocket and Dropbox is now primary target for phishing attacks. Businesses are realizing the necessity for security awareness training programs.Read the full press release and report here!
If there’s one thing that came through loud and clear in our analysis of malware and other threats in 2017, it’s that, when it comes to cybersecurity, change is the only constant. While analysts, researchers, and security companies worked quickly to identify and block emerging threats, attackers were just as quick in finding new ways to evade defenses. Phishing attacks became more targeted and successful, and most phishing sites were only online for 4-8 hours. Cryptojacking gained traction as an anonymous and relatively easy path to profit, as did ransomware attacks, which made headlines numerous times throughout the year. High-risk IP addresses continue to cycle between benign and malicious to avoid detection, and the top 10,000 IPs most often associated with malicious activity changed status an average of 18 times throughout the year. The 2018 edition of our annual Threat Report shares a glimpse into our discoveries and analysis of threat activity throughout 2017, to equip yo
The Webroot 2017 Annual Threat Report presents analysis, findings, and insights from the Webroot Threat Research team on the state of threats, including the following: » Malware and potentially unwanted applications (PUAs) » IP addresses associated with malicious activity » URL reputations and classifications » Phishing targets, sites, and URLs » Mobile app reputations and the threats mobile apps can contain This report is intended to help you understand the current threat landscape and related trends so you can prepare your organization to better handle threats during the coming year. https:///webroot/attachments/webroot/ent2/1144/1/Webroot_2017_Threat_Report_US.pdf
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.