Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Shadow AI’s Real Threat Is Access Control

June 26, 2026

Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

June 26, 2026

The Security Coverage Gap is a Math Problem

June 26, 2026
Facebook X (Twitter) Instagram
Saturday, June 27
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Attacker Breakout Time Falls to 18 Minutes
News

Attacker Breakout Time Falls to 18 Minutes

Team-CWDBy Team-CWDSeptember 23, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Threat actors are accelerating their attacks and adopting innovative new ways to circumvent endpoint detection mechanisms, according to a new report from ReliaQuest.

The threat intelligence vendor claimed in its latest Threat Spotlight report for the period June–August 2025 that average breakout time – the period from initial access to lateral movement – dropped to 18 minutes.

One attack from the Akira came in at just six minutes, way below the lowest breakout time recorded in 2024, of 27 minutes.

The figure keeps falling. In January, ReliaQuest claimed breakout time in 2024 was 22% shorter than the previous year. Once adversaries reach this stage, attacks become harder to detect and contain.

Threat actors are not just getting faster but also smarter, ReliaQuest warned. There’s been a sharp rise in ransomware operations using the SMB file-sharing protocol for remote file encryption – from 20% to 29% of ransomware attacks.

Read more from ReliaQuest: Automation and Vulnerability Exploitation Drive Mass Ransomware Breaches.

“Using compromised credentials, attackers access shared files on a network via a single compromised host, often through unmanaged devices or VPNs,” the report noted.

“By encrypting data remotely, they bypass endpoint protections entirely, operating quietly and efficiently within the network. This highlights a critical flaw in endpoint-focused defenses: Attacks don’t stop at the endpoint, and neither should your defenses.”

USB Malware on the Rise

ReliaQuest also warned that drive-by-compromise remains the most popular tactic for initial access, accounting for 34% of incidents. That’s versus 12% for spear phishing links and, remarkably, 12% for USB malware.

“USB-based malware is thriving because of weak policy enforcement and inconsistent endpoint controls. It’s easy to overlook the dangers of plugging in unvetted USBs and attackers exploit this to infiltrate corporate networks,” the report noted.

It pointed to the Gamarue variant as particularly prevalent in the period.

“Gamarue hides its malicious Dynamic Link Libraries (DLLs) so well that most employees wouldn’t know they’re infected,” ReliaQuest said. “The infection trigger – a malicious LNK file – disguises itself as a legitimate file already present on the USB, making it even harder to spot.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleApple Warns French Users of Fourth Spyware Campaign in 2025, CERT-FR Confirms
Next Article Samsung Fixes Critical Zero-Day CVE-2025-21043 Exploited in Android Attacks
Team-CWD
  • Website

Related Posts

News

Shadow AI’s Real Threat Is Access Control

June 26, 2026
News

Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

June 26, 2026
News

China-Linked Hackers Strike Asian CNI with New Backdoor

June 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Beware of threats lurking in booby-trapped PDF files

October 7, 2025

How it preys on personal data – and how to stay safe

October 23, 2025

Is Poshmark safe? How to buy and sell without getting scammed

February 19, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.