Cybercriminals are leveraging artificial intelligence (AI) to revitalise traditional attack methods, enabling mass production of malicious tools and intensifying probes against corporate networks, according to Elastic’s latest Global Threat Report.
Released in October 2025, the analysis draws on over one billion data points from live production environments, revealing a 15.5 per cent rise in generic threats – often AI-generated loaders – and a near-doubling of malicious code execution on Windows to 32.5 per cent.
“Attackers are shifting from stealth to speed, launching waves of opportunistic attacks with minimal effort,” said Devon Kerr, head of Elastic Security Labs and director of Threat Research. This pivot highlights the need for organisations to bolster identity protections and refine detection amid rapid threat evolution.
The report, the fourth in Elastic’s annual series, highlights how AI lowers entry barriers for novice adversaries, fostering a ‘new class’ of actors reliant on off-the-shelf malware and stolen credentials rather than sophisticated evasion. With infostealers now comprising over 25 per cent of detected malware—up from prior years—these tools feed a thriving access broker economy, supplying credentials for broader compromises.
Browsers Emerge as the Primary Battleground
Browsers have become the frontline in credential theft, with more than one in eight malware samples (over 12.5 per cent) targeting browser data, marking it as the most prevalent access sub-technique. Infostealers increasingly exploit Chromium-based browsers to circumvent built-in safeguards, industrialising the theft process. Notable examples include emerging families like BANSHEE, EDDIESTEALER, and ARECHCLIENT2, which harvest data to fuel cloud account breaches via exposed storage services.
Trojanised software accounts for 61 per cent of malware observations, often delivered through the ClickFix technique—a deceptive prompt mimicking legitimate fixes. Over 24 per cent of Windows samples belong to named infostealer families, amplifying risks as stolen credentials bypass perimeter defences.
Execution Tactics Eclipse Evasion Efforts
For the first time in three years, execution tactics have overtaken defence evasion on Windows, surging to 32 per cent of techniques—roughly one-third of all activity—while evasion drops to 23 per cent and initial access holds at 19 per cent. This shift reflects attackers’ preference for ‘cheap footholds’ via scripts, browser exploits, and SaaS compromises, minimising exposure.
GhostPulse loaders dominate signature events at 12 per cent, frequently deploying infostealers such as Lumma and Redline (each at 6.67 per cent). The REF7707 campaign exemplifies this, using FINALDRAFT, PATHLOADER, and GUIDLOADER to evade detection through Microsoft GraphAPI for command-and-control.
AI Democratises Malicious Innovation
AI, particularly large language models (LLMs), empowers adversaries to generate basic yet potent loaders, driving the 15.5 per cent generic threat increase. Off-the-shelf families persist: RemCos at 9.33 per cent and Cobalt Strike at around 2 per cent. As AI adoption grows, it promises to reshape both offensive and defensive landscapes, with Elastic anticipating enhanced automation in threat synthesis.
The methodology incorporates hundreds of millions of telemetry events, benchmarked against open and closed-source baselines for transparency, enabling defenders to contextualise their exposures.
Cloud Identities Face Concentrated Assaults
Cloud environments bear the brunt, with over 60 per cent of security events tied to initial access, persistence, or credential access. Authentication vulnerabilities in Microsoft Entra ID are stark: 54 per cent of anomalous Azure signals stem from audit logs, rising to nearly 90 per cent when including full telemetry. Access brokers exacerbate this by leveraging infostealer hauls for indirect cloud infiltration.
Fortifying Defences
Elastic advocates a defence-in-depth strategy via its XDR platform for unified detection across IT ecosystems. Key advice includes: automating responses with AI-assisted analytics while retaining human oversight; fortifying browser plugins, extensions, and integrations; and prioritising robust identity verification, including enhanced know-your-customer protocols.
As AI blurs lines between elite and amateur threats, organisations must treat identity as a core security pillar to counter this era of accelerated, volume-driven attacks.
Image: Ideogram
Source: Cyber Security Intelligence