Part 1. New Attack Trends to Watch in 2025 and Beyond

14 October 2025

Cybercriminals will continue to rely on tried-and-true tactics that have allowed them to achieve their objectives year after year. As the cybercrime industry evolves in 2025 and beyond, clear attack trends are emerging. Here are several anticipated developments that will keep security teams on high alert.

Evolving attack chain: Attackers are increasingly specializing in specific stages of attacks, such as reconnaissance or initial access, leading to the emergence of the «cybercrime as a service» (CaaS) market:

In recent years, cybercriminals have increasingly spent their “leftover time” on the reconnaissance and weaponization stages of the cybercrime chain. As a result, attackers can execute targeted attacks more quickly and precisely. This focus on pre-attack activity among attackers, combined with the rise of new vulnerabilities, has paved the way for the emergence of the Cybercrime as a Service (CaaS) marketplace, a practice where sophisticated cybercriminals sell tools and expertise on the darknet to help others commit cybercrimes. Many CaaS vendors act as jacks of all trades, offering buyers everything they need to launch an attack, from phishing kits to their payloads. However, it has been predicted and is now confirmed that CaaS teams will embrace specialization, with many teams focusing on providing offerings that focus on just one segment of the attack chain. It is now clear that separate early access brokers and infrastructure providers are emerging, each offering the specific intelligence needed to execute one stage of an attack, and then passing the buyer on to the next expert. This chain of vendor delivery is expected to expand. For example, Intelligence-as-a-Service brokers are likely to emerge as groups hone their expertise in different aspects of an attack and seek to capitalize on specific stages of the cybercrime chain.

Cloud as a Likely Target for Cyberattacks:.

Endpoints such as OT systems remain popular targets for attacks, especially as 5G direct-to-device connectivity expands. The greater number of devices, combined with improved connectivity, offers attackers a broader attack surface, providing new opportunities for compromise. While this target will continue to attract attackers’ attention, defenders should pay close attention to another part of the attack surface over the next few years: their cloud environments. While the cloud is not a new technology, it is increasingly gaining interest from cybercriminals. Cloud applications are increasingly becoming a target for attacks, and this trend is expected to grow in the future. According to the Fortinet 2024 Cloud Security Report, 78% of enterprises are using hybrid or multi-cloud strategies. Given that most organizations rely on multiple cloud providers, it is not surprising that attackers are exploiting more cloud-specific vulnerabilities. And this is leading to high-profile cyber incidents. While basic security measures such as multi-factor authentication can help prevent unauthorized access to data in cloud application environments, these cybersecurity measures are sometimes overlooked as organizations rush to embrace digital evolution.

In addition to implementing security measures to protect cloud environments, this growing adoption of cloud technologies opens up broader opportunities for cybersecurity advocates. One example is the development of frameworks to describe, mitigate, and prevent cloud-centric breaches, such as the analytics developed and made available through MITRE ATT&CK. In addition, initiatives such as the Cloud Security Alliance are developing and delivering best practices and controls tailored for cloud environments, helping organizations combat specific threats through shared security knowledge and standards. Increasing cloud visibility, ensuring least-privileged access, and using continuous monitoring solutions are essential to increasing resilience. The cybersecurity community can also focus on creating and implementing more comprehensive cloud incident response guides and expanding the sharing of threat intelligence specific to cloud vulnerabilities, providing collective defense against cloud-focused attacks. Not surprisingly, attackers are also seeing the cloud as an area for growth. Cloud environments provide another opportunity for cybercriminal groups to carve out a niche. There is now an increase in cybercriminal groups selling cloud-specific information on the darknet, with some attackers becoming primary brokers for this part of the attack chain.

Crime Automation: There is a growing number of automated attack tools available on the darknet, including phishing kits and DDoS services.

The CaaS market has expanded rapidly over the past few years. Today, there are many attack vectors and associated code available in this market, such as phishing kits, RaaS, DDoS-as-a-Service, etc. But attackers are not stopping there. While there is already some reliance on AI to power CaaS offerings, this trend is expected to spread in the future. It is likely that attackers will use automated LLM output to power CaaS offerings and expand the market, for example, to scout social media and automate this information into neatly packaged phishing kits. The introduction of automation will increase the number of CaaS variants available for purchase on the darknet, and is another profitable opportunity for attackers. The expansion of the CaaS market is likely to lead to an overall increase in cyberattacks, as more offerings mean more entry points into cybercrime for both novices and experienced adversaries.

Cybercrime will continue to grow rapidly in 2025, using both traditional methods and emerging technology solutions. Key trends such as specialization in the attack chain (CaaS), the rise of cloud-based attacks, and the automation of criminal activity indicate that attackers are becoming more organized and innovative.

However, the cybersecurity community is also improving its approaches to countering threats. The use of artificial intelligence, international cooperation and continuous training of employees allow organizations to defend themselves more effectively. The key to success is proactivity, information sharing and integration of modern technologies into security systems.

📷
📷
📷
Читати більше новин
EN