KROLL-2025年6月威胁情报(TI)焦点趋势报告(英)-2025_22页_934kb
报告摘要
Threat Intelligence (TI) Spotlight Trends Report - June 2025
Core Content Overview
This report provides a detailed analysis of cybersecurity threats observed by Kroll in June 2025, based on their incident response engagements. It highlights the most common initial access methods, ransomware variants, threat incident types, and industries most impacted by cyber threats. Additionally, it outlines the potential impacts of these threats and includes definitions for threat intelligence sharing protocols.
Main Points
Initial Access Methods
- Phishing was the most common method, with subcategories:
- Phishing: Link (26%)
- Phishing: Non-Technical (22%)
- Phishing: Attachment (17%)
- Valid Accounts (17%)
- External Remote Services (e.g., VPN) and Valid Accounts were also frequently used.
Most Impacted Industries
- Professional, Scientific, and Technical Services (18%)
- Finance and Insurance (14%)
- Health Care and Social Assistance (12%)
- Manufacturing (12%)
- Information (11%)
Top Ransomware Variants
- QILIN (40%)
- AKIRA (20%)
- PLAY (20%)
- MEDUSALOCKER (20%)
Top Threat Incident Types
- Email Compromise (35%)
- Insider Threat (26%)
- Ransomware (12%)
- Unauthorized Access (11%)
- Malware (4%)
Industry-Specific Analysis
Professional, Scientific, and Technical Services
- Top Threat Incident Type: Email Compromise
- Top Initial Access Method: Valid Accounts
- Most Confirmed Impacts:
- Data Encrypted for Impact
- Data Exfiltrated for Impact
- Financial Theft
Finance and Insurance
- Top Threat Incident Type: Email Compromise
- Top Initial Access Method: Valid Accounts
Health Care and Social Assistance
- Top Ransomware Target: QILIN
- Top Initial Access Methods:
- Phishing: Attachment
- External Remote Services (e.g., SonicWall)
Manufacturing
- Top Threat Incident Type: Email Compromise
- Top Initial Access Method: Valid Accounts
Information
- Top Threat Incident Type: Email Compromise
- Top Initial Access Method: Valid Accounts
Incident Impact Analysis
The most common impacts observed in June 2025 were:
- Data Encrypted for Impact
- Data Exfiltrated for Impact
- Financial Theft
Other notable impacts include:
- Data Destruction
- Data Manipulation
- Defacement
- Disk Wipe
- System Shutdown/Reboot
- Inhibit System Recovery
Trending Vulnerabilities
| CVE | Vendor/Software | Advisory |
|---|---|---|
| CVE-2025-32710 | Windows | NVD Link |
| CVE-2025-33053 | Windows | NVD Link |
| CVE-2025-20282 | Cisco | NVD Link |
| CVE-2025-5419 | NVD Link | |
| CVE-2025-47172 | SharePoint | NVD Link |
Threat Incident Type Trends
- Email Compromise remained the most frequent threat type over the past six months.
- Insider Threat and Web Compromise also showed significant trends.
- Ransomware and Malware were less frequent but still relevant.
- Unauthorized Access was a growing concern.
Additional Resources
-
Webinar: Building a Resilient OT Security Program
- Date: Wednesday, September 17 | 11:00 a.m. – 11:45 a.m. ET
- Speakers: Sameer Koranne, Sumit Janmejai, and Marco Ayala
- Focus: OT security strategies in critical sectors like oil and gas, maritime, and chemical industries.
-
Publication: The Invisible Threat: Rethinking OT Security for Clean Energy and National Infrastructure
- Highlights the risks of Chinese-manufactured "kill switches" in power inverters.
- Discusses supply chain vulnerabilities and geopolitical dependencies in OT systems.
-
Webinar Replay: Navigating AI Governance in Retail
- Explores AI governance in the retail sector, focusing on data privacy, secure deployment, and ethical use.
- Includes real-world examples from the retail industry.
Definitions: Traffic Light Protocol (TLP)
| TLP | When to Use | How to Share |
|---|---|---|
| TLP: RED | Information cannot be effectively acted upon by additional parties. | Shared verbally or in person; not shared outside the specific exchange. |
| TLP: AMBER + STRICT | Information requires support to be acted upon but carries risks if shared outside the involved organizations. | Shared only within the organization; additional limits may be specified. |
| TLP: AMBER | Information requires support to be acted upon but carries risks if shared outside the involved organizations and clients. | Shared within the organization and with clients; additional limits may be specified. |
| TLP: GREEN | Information is useful for awareness within the community. | Shared with peers and partners within the sector or community. |
| TLP: CLEAR | Information carries minimal or no risk of misuse. | Shared without restriction, subject to standard copyright rules. |
Contact Information
For more information, please contact:
-
Ed Currie
Associate Managing Director
Phone: 12024491816
Email: edward.currie@kroll.com -
George Glass
Associate Managing Director
Phone: +44 7584999104
Email: george.glass@kroll.com
About Kroll
Kroll is a leading independent provider of financial and risk advisory solutions. The firm offers a wide range of services including M&A advisory, capital raising, and secondary market advisory, with operations in the United States, United Kingdom, and India. Kroll's expertise spans risk, governance, transactions, and valuation, with a focus on delivering advanced solutions and intelligence to help clients achieve competitive advantage.
试读结束,高清完整版pdf/doc/ppt,请点下载