Julian-Ferdinand Vögele
@julianferdinand
Threat Research @ Recorded Future. Previously @ Security Research Labs. He/Him. 🏳️🌈
Big thanks to @monicakello.bsky.social and the amazing team for organizing @haguetix.bsky.social! Had an absolute blast, so many interesting conversations, and already looking forward to next year!
Had a great time presenting and reconnecting with everyone at @pivotcon.bsky.social. Huge thanks to @pstirparo.bsky.social & @corpen.secman.pl for organizing this event and building this unique community, many of whom I’m lucky to call friends. Looking forward to seeing everyone in 2027.
15/ Russian, North Korean, and Iranian actors increasingly converged on scalable, low-cost tradecraft, combining credential harvesting, abuse of legitimate services, and rapid infrastructure rotation to enable low-visibility espionage against government, defense, and critical sectors globally.
14/ Chinese state-sponsored activity in 2025 continued to be defined by the use of relay networks, including botnets and compromised edge devices, enabling stealthy operations, rapid infrastructure rotation, and targeted exploitation of telco and internet-facing infrastructure worldwide.
12/ Based on this analysis, Virtualine Technologies ranked as the highest-risk network in 2025, followed by CrazyRDP and Stark Industries Solutions (now THE[.]Hosting), both of which faced enforcement actions during the year.
11/ To address network size based biases, in 2025 we focused on TAEs using Recorded Future’s Threat Density model, identifying networks disproportionately linked to malicious activity relative to their size.
10/ The traffic distribution system ecosystem continues to expand, with activity from groups such as GrayCharlie and TAG-124, supported by a large user base that frequently relies on ClickFix in its various forms.
9/ In parallel, we maintained extensive tracking of ransomware groups, continuously analyzing their tooling and infrastructure. This includes deeper visibility into higher-tier infrastructure, as demonstrated in cases such as InterLock ransomware.
8/ We also continued to track mercenary spyware vendors such as Candiru, Intellexa, and others, providing insights into their operational infrastructure, higher-tier networks, and global customer bases.
7/ AsyncRAT continues to lead the RAT landscape, with open-source tools widespread and MaaS close behind. At the same time, new families emerged, including CastleRAT, first identified by Insikt Group in March 2025, with C and Python variants pointing to a deliberately designed framework.
6/ Similar dynamics were observed in the loader and dropper landscape, where new malware families continued to emerge. One example is CastleLoader, attributed to GrayBravo, reinforcing the constant evolution of initial access tooling.
5/ The infostealer ecosystem continues to demonstrate significant volatility. Following law enforcement disruption efforts targeting LummaC2, other families such as Vidar partially filled the gap, highlighting how quickly this segment adapts to disruption.
4/ While Cobalt Strike remains the most prominent OST, its relative share of detected command-and-control infrastructure declined as detection coverage expanded and competing tools gained traction. Tools such as RedGuard, Ligolo, and Supershell saw notable growth throughout 2025.
2/ This year’s report builds on major enhancements, including deeper analysis of infrastructure types, improved detections, expanded use of Recorded Future Network Intelligence, more high-tier infrastructure insights and victimology, and a new focus on so-called Threat Activity Enablers (TAEs).
4/ We identified multiple activity clusters based on factors including TLS certificate patterns, NetSupport RAT license keys and serial numbers, and the use of additional tooling such as the Acunetix scanner.
3/ Infections often progress to additional payloads, including Stealc, SectopRAT, and more recently REMCOS RAT. While the use of infostealers points to credential theft, GrayCharlie may also monetize accesses by providing it to other threat actors.
9/ Historical CastleLoader panel analysis also surfaced links to an online persona, “Sparja”, active on Exploit Forums. While attribution remains cautious, the alias’s distinctiveness and activity patterns suggest potential ties to GrayBravo operations.
8/ TAG-161 also deploys tools tailored for targeting Booking[.]com, and Insikt Group identified several related panels, including ones titled ‘Менеджер Email’, ‘Менеджер Редиректов и рассылок’, and ‘Менеджер Редиректов и Email’.
7/ Another cluster, we track as TAG-161, impersonates Booking[.]com. This group also relies on ClickFix for CastleLoader delivery and deploys advanced payloads, including Matanbuchus.
5/ Notably, TAG-160 leverages access to legitimate freight-matching platforms, including DAT Freight & Analytics and Loadlink Technologies, using these platforms in multiple stages of its operations.
4/ Emails by TAG-160 urge recipients to open a link to view a supposed shipment rate confirmation, telling them to copy and paste the URL into a browser if it doesn’t open automatically.
3/ One cluster, we track as TAG-160, impersonates global logistics firms. Their campaigns use phishing lures and the #ClickFix technique to deliver CastleLoader. They also spoof legitimate logistics emails and abuse freight-matching platforms to reach victims.
2/ Our latest analysis uncovered four distinct activity clusters within GrayBravo’s ecosystem, all leveraging the group’s #CastleLoader malware. Each cluster uses different tactics, techniques, and targets, reinforcing the assessment that GrayBravo runs a #MaaS model.
8/ Among Amnesty’s most concerning revelations: at the time the leaked training videos were recorded, Intellexa retained the capability to remotely access Predator customer systems, including those located on-premises within government facilities.
6/ Two entities in the advertising sector (also linked to the Czech cluster) may be connected to the “Aladdin” ad-based infection vector, originally revealed by Haaretz and previously tied to the Czech cluster via a leaked 2022 invoice.
5/ We also identified additional entities in Kazakhstan (OOO Seven Hills) and the Philippines (ComWorks) involved in importing Intellexa products, highlighting Intellexa’s continued global corporate expansion.
4/ In at least one instance, a delivery very likely went directly to an end user, offering a rare look into how Intellexa tools reach their final destinations. The timing aligns closely with our prior reporting on the Botswana cluster.
3/ By examining corporate records, infrastructure, and export/import data, we identified an entity (PULSE FZCO) tied to the previously reported Czech cluster that highly likely facilitated shipments of Intellexa products to clients.
I'm excited to speak at #VB2025 later this week! I'll be diving into TAG-124, a group whose services are leveraged by a wide range of actors, from cybercriminals to state-sponsored groups. Hit me up if you are in town! www.virusbulletin.com/conference/v...
Really excited to present at #LABScon25 on ChamelGang‘s most recent campaign targeting the Taliban, a collaborative research project with @milenkowski.bsky.social (SentinelLABS) and @azaka.fun (TeamT5)! www.labscon.io/speakers/jul...