The 2025 Global Threat Report, based on more than 1 billion data points derived from real production environments, finds that generic threats — typically loaders built using AI — jumped 15.5% in the past year, while malicious code execution on Windows nearly doubled to 32.5%.
AI-created malware and easy access to stolen browser credentials are fueling a new class of bad actors who are less reliant on stealth attacks and are leaning into continuous, steady probes for entry into corporate networks.
“Attackers are shifting from stealth to speed, launching waves of opportunistic attacks with minimal effort,” said Devon Kerr, head of Elastic Security Labs and director of Threat Research. “This evolution shows how urgent it is for defenders to harden identity protections and to adapt their detection strategies for this new era of speed attacks.”
Key Findings
Browsers are the new front line
Execution has overtaken evasion
AI lowers the barrier to entry
Cloud identity is under siege
While Elastic Security takes a defense-in-depth approach with Elastic XDR unified threat detection, investigation, and response across the entire IT ecosystem to detect AI-created and other malware, here are additional recommendations for defenders:
Additional Resources
About the Report
The 2025 Elastic Global Threat Report is a distillation of security insights from Elastic Security Labs, Elastic’s dedicated cybersecurity intelligence team. Elastic Security Labs used Elastic technologies to search, sort and refine hundreds of millions of events between June 2024 and July 2025. This includes Elastic telemetry, public and third-party data voluntarily submitted to surface threats to Elastic Security Labs. All information has been sanitized and anonymized where applicable.
About Elastic
Elastic (NYSE: ESTC), the Search AI Company, integrates its deep expertise in search technology with artificial intelligence to help everyone transform all of their data into answers, actions, and outcomes. Elastic's Search AI Platform — the foundation for its search, observability, and security solutions — is used by thousands of companies, including more than 50% of the Fortune 500. Learn more at elastic.co.
Elastic and associated marks are trademarks or registered trademarks of Elasticsearch BV and its subsidiaries. All other company and product names may be trademarks of their respective owners.
View source version on businesswire.com: https://www.businesswire.com/news/home/20251008259174/en/
Hinweis: ARIVA.DE veröffentlicht in dieser Rubrik Analysen, Kolumnen und Nachrichten aus verschiedenen Quellen. Die ARIVA.DE AG ist nicht verantwortlich für Inhalte, die erkennbar von Dritten in den „News“-Bereich dieser Webseite eingestellt worden sind, und macht sich diese nicht zu Eigen. Diese Inhalte sind insbesondere durch eine entsprechende „von“-Kennzeichnung unterhalb der Artikelüberschrift und/oder durch den Link „Um den vollständigen Artikel zu lesen, klicken Sie bitte hier.“ erkennbar; verantwortlich für diese Inhalte ist allein der genannte Dritte.