Malware activity in 2025 demonstrated significant evolution, with non-ransomware malware playing a critical role in cyber intrusions across enterprise and industrial environments. Notable malware families such as QakBot, IcedID, Emotet, TrickBot, AsyncRAT, RedLine Stealer, and Lumma Stealer were widely used for initial access, credential theft, persistence, and post-compromise control, often operating undetected for extended periods. These malware strains enabled attackers to harvest sensitive data and maintain long-term footholds, supporting broader attack campaigns and facilitating the distribution of secondary payloads.
Industrial automation systems also faced persistent threats, with Kaspersky reporting that 20.1% of ICS computers encountered blocked malicious objects in Q3 2025, involving over 11,000 different malware families. The biometrics, engineering, and manufacturing sectors were particularly affected, with notable increases in malware activity in East Asia due to the spread of malicious scripts within OT infrastructures. The diversity and sophistication of malware targeting both enterprise IT and industrial OT environments underscore the ongoing challenge of defending against evolving cyber threats.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Throughout 2025, smaller organizations were disproportionately affected by malware due to limited security resources, while macOS-targeted and cross-platform malware also grew notably. Attackers increasingly abused legitimate tools and targeted browser and cloud authentication data to evade detection and maintain post-compromise control.
Across 2025, malware activity was characterized by persistent, low-noise campaigns using families such as QakBot, IcedID, Emotet, TrickBot, and RedLine Stealer for initial access, credential theft, and persistence. Email remained the primary delivery vector, while attackers increasingly monetized stolen access through infostealers and Malware-as-a-Service ecosystems.
In Q3 2025, a large-scale phishing campaign exploiting CVE-2017-11882 contributed to increased detection of malicious documents in South America. Kaspersky also observed rising spyware and ransomware infection rates in industrial environments during the quarter.
In Q3 2025, Kaspersky reported a significant increase in malicious activity in East Asia, driven in part by the spread of malicious scripts affecting engineering organizations and ICS integrators. The report also noted continued targeting of the biometrics sector and broad malware diversity across industrial environments.
During Q3 2025, Kaspersky ICS CERT recorded a slight decrease in the share of industrial control system computers on which malicious objects were blocked, reaching 20.1%, the lowest level noted in the report. Internet access, email clients, and removable media remained the main infection sources in ICS environments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.