New report: 1M malware samples reveal 93% of attacks are preventable

Picus Security has released its annual Red Report 2025, which assesses over 1 million real-world malware samples and 14 million malicious actions. The findings show that 93% of malware attacks can be traced back to just 10 techniques, indicating that many existing security measures are not adequately equipped to detect these prevalent threats.

The report highlights a notable increase in credential-stealing malware, which surged three-fold in 2024, accounting for 25% of all attacks. This type of malware is particularly alarming as it has become the fastest-growing technique recognized by the MITRE ATT&CK framework and is a significant blind spot for organizations' security protocols.

A new form of stealth-first malware called ‘SneakThief’ has emerged, which automates the process of extracting user credentials while remaining undetected. This development has been described as “the perfect heist” for attackers, raising concerns over the ongoing security challenges.

Dr. Suleyman Ozarslan, co-founder and VP of Picus Labs, stated, “Threat actors are leveraging sophisticated extraction methods, including memory scraping and registry harvesting, to acquire credentials that give them access to sensitive systems.” He emphasized the need for organizations to pair password managers with multi-factor authentication and discourage password reuse.

The report indicates that attackers are increasingly favoring complex and prolonged multi-stage attacks, necessitating advancements in malware to achieve success. Picus researchers noted that a typical malware sample can now execute an average of 14 malicious actions, suggesting a shift towards more elaborate cyber threats.

Volkan Ertürk, CTO and co-founder of Picus, said, “Focusing on the top 10 MITRE ATT&CK techniques is the most viable way to stop the kill chain of sophisticated malware strains as early as possible.” The findings suggest that a concerted effort to address these techniques could help organizations prevent up to 90% of malware attacks.

The report also found that adversaries are increasingly employing covert exfiltration tactics, often using encrypted communication methods to mask their activities. In a notable observation, the analysis found no indication that cybercriminals are making widespread use of AI-driven malware, despite discussions on the intersection of AI and cybersecurity.

The complete findings and methodology can be explored in the Picus Red Report 2025, which offers a deeper dive into the analysis of malware threats.