• 07 3184 7575
  • August 3, 2026
  • 0 Comments

When many people think about cybercrime, they picture ransomware headlines: locked systems, ransom demands, and public disruption.

But the latest Red Report from Picus Security shows a different and more subtle reality.

In 2025, 80% of the most commonly observed attack techniques were designed to remain hidden after initial access. Instead of loudly encrypting data, attackers are focusing on stealth, identity abuse, and long-term access.

The report analysed more than 1.1 million unique files and 15.5 million malicious actions, mapping them to the MITRE ATT&CK framework. The findings reveal a clear shift: attackers are prioritising evasion over disruption.

Ransomware Is No Longer Just About Encryption

One of the most striking findings is a 38% year-on-year decline in the ransomware technique known as “Data Encrypted for Impact.”

Traditionally, ransomware operators locked files to force payment. Now, many are quietly stealing sensitive data first and then using extortion without encryption.

Dr. Süleyman Özarslan, co-founder and VP of Picus Labs, explains the shift:

“As organizations mastered backups and resilience, the traditional business model collapsed. Attackers no longer need to lock your data to monetize it; they just need to steal it.”

This evolution reflects a broader reality: as organisations strengthen recovery strategies, attackers adapt their monetisation methods.

Backups remain critical — but data exfiltration and identity abuse now sit at the centre of modern attack strategies.

Stealth Techniques Are Increasing Rapidly

The report identified a significant rise in techniques designed specifically to evade detection.

Sandbox and Virtualisation Evasion

Malware increasingly checks whether it is running inside a security testing environment. If it detects sandbox conditions, it simply remains inactive to avoid triggering alerts.

Some strains now analyse mouse movement angles, treating unnaturally precise movement as evidence of automation.

Process Injection

For the third consecutive year, process injection was the most prevalent technique, accounting for 30% of tracked activity.

This tactic inserts malicious code into legitimate processes already running on endpoints, allowing attackers to operate under the cover of trusted applications.

Traditional detection tools that rely heavily on known signatures or basic anomaly detection can struggle in these scenarios.

Identity Is Becoming the Primary Attack Surface

The report found that one in four observed attacks involved stealing saved browser passwords.

Rather than repeatedly exploiting vulnerabilities, attackers increasingly log in as legitimate users. Once authenticated, they blend into normal activity — accessing systems, moving laterally, and exfiltrating data without generating obvious red flags.

This aligns with a wider industry shift: identity is now a central target.

Strong perimeter controls offer limited protection if compromised credentials allow attackers to enter through standard authentication pathways.

Abuse of Trusted Services

Another observed trend is routing command-and-control traffic through widely trusted platforms such as Amazon Web Services and OpenAI.

Because these services generate high volumes of legitimate traffic and are often encrypted, malicious activity can blend into normal business network flows.

Security teams may whitelist or deprioritise alerts involving reputable cloud providers, giving attackers more time to operate unnoticed.

Hardware-Level Tactics Are Emerging

The report also highlights the use of physical IP-KVM devices by state-sponsored actors to control systems at the hardware level.

By operating below the operating system layer, these methods can bypass traditional endpoint monitoring tools. While this tactic is more commonly associated with highly resourced actors, it demonstrates how adversaries continue to search for blind spots.

The Bigger Shift: From Disruption to Persistence

The overarching theme of the Red Report is clear: attackers are investing in stealth, persistence, and evasion.

Rather than triggering immediate disruption, they aim to:

  • Blend into legitimate processes
  • Use valid credentials
  • Avoid obvious encryption events
  • Route traffic through trusted infrastructure
  • Extend dwell time inside networks

As Dr. Süleyman Özarslan noted:

“We forced the adversary to evolve… Attackers no longer need to lock your data to monetize it; they just need to steal it.”

This reflects an ongoing arms race. As organisations improve resilience, attackers refine quiet techniques that reduce the likelihood of early detection.

A CSB Perspective

At CSB, we see this shift clearly reflected across industries. The challenge is no longer just blocking attacks at the perimeter — it’s maintaining visibility inside environments after an attacker may already have valid access.

This requires a deliberate shift in defensive focus.

Organisations need:

  • Regular testing of detection controls against common evasion techniques
  • Strong identity governance and credential protection
  • Continuous monitoring, not static assessments
  • Verification of resilience strategies beyond backup alone

As attackers invest more in stealth, the defensive strategy must move toward behaviour monitoring, identity validation, and ongoing security validation exercises.

Cybersecurity is not just about preventing entry — it is about detecting quiet persistence before it turns into material damage.

In today’s environment, visibility is resilience.

Previous Post
Cyber Safe Business Advisory Bulletin -Origin Energy Confirms Customer Data Breach – What Businesses