Cybersecurity experts and industry observers are highlighting a significant escalation in both the sophistication and impact of cyber threats as 2025 draws to a close. Ransomware groups such as Qilin have become increasingly aggressive and lucrative, with their activities dominating the criminal landscape and targeting high-value sectors like manufacturing, as evidenced by the severe financial losses suffered by Jaguar Land Rover following a cyberattack. The convergence of operational technology (OT) and information technology (IT) continues to expose critical infrastructure to heightened risk, prompting new governance and regulatory responses, including updated guidance for secure AI integration and revised cybersecurity performance goals for critical infrastructure.
Meanwhile, threat actors are rapidly evolving their tactics, leveraging new social engineering techniques and exploiting emerging technologies. Mobile phishing attacks using weaponized PDF documents have surged, with campaigns targeting both enterprise and personal users through SMS and MMS, often bypassing traditional security measures. Law enforcement efforts have also made headlines, with the disruption of international scam call centers responsible for defrauding hundreds of victims across Europe. The overall threat environment is marked by increased automation, systemic risk, and the growing use of AI by both attackers and defenders, underscoring the need for organizations to adapt their security strategies to address these accelerating challenges.

TTPs, infrastructure, and targeting history in one profile.
16 events from the most recent confirmed update back to the earliest known activity.
The UK government was reported to be advancing efforts to require or promote nudity-blocking technology on mobile devices. The move was presented as a policy development with security and privacy implications.
Microsoft announced the deprecation of the RC4 cipher in Kerberos, signaling a security hardening step away from legacy cryptography. The change was part of broader efforts to reduce exposure to outdated authentication mechanisms.
A new malware family called SantaStealer was identified as an emerging threat. Its appearance was noted alongside other late-2025 developments in criminal tooling and attack tradecraft.
A social engineering technique dubbed GhostPairing was reported as being used to take over WhatsApp accounts. The method underscored the continued effectiveness of account hijacking through user manipulation rather than software exploitation.
The Russian hacktivist group NoName057(16) was reported to be sustaining DDoS campaigns while frequently rotating its command-and-control infrastructure. The infrastructure churn appeared intended to preserve resilience and complicate disruption.
Researchers reported exposed MCP servers that were leaking sensitive information due to insecure configuration. The finding added to concerns around rapidly deployed AI-related infrastructure lacking basic security controls.
Attackers were observed abusing Google Application Integration as part of phishing activity. The technique illustrated continued misuse of trusted cloud services to improve delivery and credibility of malicious lures.
The React2Shell vulnerability was reported as being used in ransomware intrusions. This showed threat actors moving quickly from vulnerability awareness to operational exploitation.
Authorities across Europe and Asia disrupted multiple cybercrime operations, including phishing SMS factories and smishing activity using IMSI catchers. The actions reflected coordinated enforcement against mobile-enabled fraud infrastructure.
Law enforcement disrupted an international scam operation that used fraudulent call centers in Ukraine. The action was highlighted as one of several cross-border cybercrime crackdowns reported that week.
The analyzed phishing operations used automation, including domain generation techniques, to rapidly create more than 2,100 phishing domains. Attackers also used direct IP addressing and URL shorteners to complicate detection and takedown efforts.
Researchers detailed two PDF-based mobile phishing campaigns: one targeting EZDriveMA users for credential theft and another impersonating PayPal to steal financial information through phishing links and vishing. The campaigns demonstrated sophisticated social engineering and mobile-focused delivery.
Zimperium zLabs reported a significant increase in mobile phishing campaigns using PDF files delivered through SMS and MMS. The campaigns used obfuscation and automation to evade traditional detection and harvest credentials and financial data.
Researchers reported a large-scale AWS cryptomining operation that leveraged compromised IAM credentials to gain and maintain access in cloud environments. The campaign highlighted continued cloud-focused monetization by attackers.
New Fortinet flaws CVE-2025-59718 and CVE-2025-59719 were reported as being actively exploited in the wild. This represented a notable escalation from disclosure to real-world abuse.
A cyberattack on the French Interior Ministry's email servers was confirmed, marking a significant government-sector incident noted in 2025 reporting. The available references do not provide further timing or technical details beyond the confirmation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 44 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
blog.talosintelligence.com
Open sourcethehackernews.com
Open sourcezimperium.com
Open sourcexage.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.