ANY.RUN, a pioneer in cybersecurity innovation, has unveiled its Q1 2025 Malware Trends Report, offering crucial insights into the ever-evolving landscape of cyber threats. Powered by data from 15,000 organizations and 500,000 analysts using the ANY.RUN Interactive Sandbox, this report presents actionable intelligence designed to enhance security measures for businesses across industries.
This detailed report delves into major threat categories, from the rise of notorious malware families and Advanced Persistent Threats (APTs) to the increasing prevalence of phishing kits and the adaptive tactics used by cybercriminals. It provides a deep dive into the shifting Tactics, Techniques, and Procedures (TTPs) that shape modern cyber threats, offering businesses a clear view of emerging risks.
By drawing on the latest findings, the report allows organizations to bypass hours of research and proactively bolster their defenses against complex attacks. The first quarter of 2025 has seen notable shifts in the cybersecurity arena, with stealers remaining a dominant threat while ransomware incidents surged sharply. This dynamic report highlights a surge in cybercriminal activity across several areas, underscoring the growing challenges that security professionals face as cyber threats advance at a rapid pace.
ANY.RUN’s Interactive Sandbox facilitated over 1.4 million analysis sessions during Q1 2025, marking a 23% growth from the previous quarter. The analysis led to the detection of 279,515 malicious files and 80,319 suspicious files, yielding more than 829 million indicators of compromise (IOCs). This sharp uptick in analyzed data points to the increasingly complex threat environment organizations must navigate.
The collected data not only uncovers emerging patterns in cyber threats but also arms security teams with the intelligence they need to adapt and reinforce their defenses against an ever-growing range of sophisticated attacks.
Key Malware Trends & Shifting Threat Landscape
Stealers have remained the most prevalent malware type, with detections jumping from 25,341 to 36,043 in Q1 2025. This trend highlights an ongoing focus on harvesting valuable credentials and sensitive data from infected systems.
Even more concerning is the startling 77% rise in ransomware activity, with detections soaring from 5,853 to 10,385. This sharp increase signals a shift toward more aggressive, monetized cyberattacks that pose significant financial and operational risks for organizations.

Malware Variants and Shifting Threats
In Q1 2025, loader malware exhibited a significant surge, with detections rising by 49%, reaching 15,523 cases. These loaders play a critical role in facilitating initial access for attackers, paving the way for secondary payloads to infiltrate compromised systems. Other key trends observed include:
- Backdoor activity skyrocketing by over 200%, jumping from 679 detections to 2,089.
- Botnets breaking into the top five malware threats, with a total of 5,272 detections.
- Keylogger attacks also saw a notable spike, with detections doubling to 4,499.
When examining malware families in detail, Lumma retained its dominant position, showing a 17.7% increase in detections. However, the most noteworthy shift came from Xworm, which made a significant leap from fifth place to second, with its detection rate more than doubling to 6,599. Additionally, Snake malware surged, climbing from eighth to third place with a 2.3-fold increase in detections.
Two newcomers, DCRat (2,299 detections) and Quasar (1,501 detections), have emerged within the top malware families, indicating a shift in the tactics and preferences of cybercriminals. On the other hand, some previously prominent families have experienced sharp declines in activity. Stealc saw a steep drop, falling from second to ninth place with a 67.5% decrease in detections, while Redline completely vanished from the top rankings.

Malware Families & Evolving Attack Techniques
ANY.RUN’s latest findings reveal a dramatic shift in the tactics, techniques, and procedures (TTPs) utilized by cyber adversaries. The Registry Run Keys/Startup Folder (T1547.001) has risen to prominence, topping the list of most detected techniques with 52,415 instances, marking a substantial jump from 18,394 in Q4 2024.
The Exploit Public-Facing Application (T1190) technique has emerged as a significant new threat, climbing to third place with 37,579 detections, a major leap from its previous absence in the top 200. Additionally, Scheduled Task techniques (T1053.005) saw a remarkable surge, increasing by 109% to 37,470 detections, underscoring the growing sophistication of attackers.
Process Injection (T1055) has gained traction as attackers refine their evasion and persistence strategies, with 20,547 instances detected. This highlights a clear trend toward more complex infiltration techniques designed to avoid detection.
Phishing-related threats also showed concerning growth, rising by 30% from 82,684 detections to 107,793. The STORM-1747 group remained the most prolific, with 16,140 detections, while TA569 climbed to second place with 1,005 instances.
Among phishing kits, Tycoon 2FA saw notable expansion, reaching 21,463 samples, up from 8,785, while EvilProxy secured second place with 4,743 detections. This indicates an ongoing trend of increasingly sophisticated phishing tools, emphasizing their role as a primary method for gaining initial access.
UPX, despite a slight decline, remained the most commonly detected packer, with 8,594 detections, while NETReactor held steady in second place with 4,917. A new contender, PureCrypter, emerged with 1,540 detections, and ASPack nearly doubled its presence, reaching 1,092 detections, highlighting a shift in the methods used to package and obfuscate malicious payloads.

Packers and Evasion Techniques
Packers remain a significant hurdle in cybersecurity, enabling malware to bypass conventional detection systems. These obfuscation tools complicate the identification of malicious payloads, emphasizing the urgent need for advanced behavioral analysis techniques that go beyond traditional signature-based defenses.
The Q1 2025 Malware Trends Report from ANY.RUN reveals an increasingly complex and active cyber threat environment. The sharp rise in ransomware attacks, credential theft, and exploitation tactics highlights the shifting objectives of cybercriminals.
To stay ahead of these growing threats, organizations must adopt robust, multi-layered security frameworks. Regular threat hunting, proactive defense strategies, and continuous security training for all employees are essential for mitigating the risks posed by these advanced, ever-evolving cyber threats.




