Foundation: Methodology and Analytical Basis

The 2025 Threat-Led Defense Report from Tidal Cyberis derived from tens of thousands of documented adversary behaviors collected through its threat intelligence platform. The analysis correlates observed real-world attack activity with the MITRE ATT&CK framework, enabling consistent comparison of adversary behavior across campaigns, industries, and geographic regions.

This behavior-centric methodology reveals repeatable attacker tradecraft rather than isolated incidents, forming the foundation for the three major threat evolutions outlined below.

Evolution 1: Scattered Spider’s Strategic Expansion

From Narrow Targeting to Broad Sector Coverage

Between 2022 and 2025, the threat group commonly referred to as Scattered Spider demonstrated a clear and deliberate expansion strategy. Initially focused on customer support providers and business process outsourcing organizations, the group progressively moved into retail, technology, and financial services environments.

This expansion was not opportunistic. Target selection consistently aligned with organizations that maintain high-value cloud assets, identity infrastructure, and SaaS-centric operational models.

The Shift Toward Cloud-Native Intrusion Paths

As sector targeting broadened, Scattered Spider pivoted toward cloud-first attack techniques. Operations increasingly focused on Software-as-a-Service platforms that store sensitive data and act as identity hubs for enterprise environments. Confirmed compromises and access attempts included Salesforce, Microsoft Teams, Slack, Confluence, and SharePoint.

This shift reflects a strategic emphasis on identity compromise and trust abuse rather than perimeter exploitation.

A Repeatable, Modular Playbook

Researchers documented 225 distinct procedures across 94 separate activity clusters, indicating a highly modular and repeatable operational model. Rather than tailoring entirely new approaches per victim, Scattered Spider consistently executed the following behavioral sequence:

  • Initial Access: Compromise of legitimate SaaS or enterprise credentials instead of direct network exploitation
    Valid Accounts (T1078)
  • Persistence: Modification of cloud identity or configuration settings to retain access despite credential resets
    Account Manipulation (T1098)
  • Environment Mapping: Enumeration of SaaS applications and cloud resources in use
    Cloud Service Discovery (T1526)
  • Data Exfiltration: Theft of information via legitimate cloud APIs and services
    Exfiltration Over Web Services (T1567.002)
  • Sustained Access: Continued entry through SaaS portals and federated identity mechanisms
    External Remote Services (T1133)

Evolution 2: Akira Ransomware’s Refinement Strategy

Optimization Over Innovation

In contrast to Scattered Spider’s expansion, Akira ransomware operations throughout 2025 focused on refining proven techniques rather than introducing novel tradecraft. The report documents 165 observed procedures demonstrating consistent reuse of known commands, combined with subtle changes in execution order and timing to evade detection.

This approach reflects operational maturity and an emphasis on reliability.

A Consistent Operational Sequence

Akira’s activity follows a predictable progression, with each phase enabling the next:

  • Credential Harvesting: Extraction of authentication material to support lateral movement
    Credential Dumping (T1003)
  • Internal Reconnaissance: Enumeration of user accounts and group memberships to identify privilege paths
    Account Discovery (T1087)
    Permission Group Discovery (T1069)
  • Service Identification: Discovery of internal network services that can be exploited or abused
    Network Service Discovery (T1046)
  • Data Exfiltration: Theft of sensitive data prior to encryption to support double-extortion tactics
    Exfiltration Over Command and Control Channel (T1041)
  • Recovery Disruption: Removal of backups and disabling of recovery mechanisms
    Inhibit System Recovery (T1490)

Abuse of Legitimate Administrative Tooling

Akira operators rely heavily on commonly used enterprise administration utilities such as AdFind, Net Group, and SharpHound. These tools blend into normal IT activity, complicating detection efforts and reducing the likelihood of immediate security escalation.

Evolution 3: The Democratization of Zero-Day Exploitation

From State-Exclusive to Broadly Accessible

One of the most significant shifts observed in 2025 is the widespread adoption of zero-day exploitation beyond traditional state-sponsored actors. Techniques once reserved for elite intelligence operations are now routinely leveraged by criminal groups and hybrid actors with both financial and geopolitical motivations.

Evidence of Widespread Use

The report identifies more than 58 threat activities linked to confirmed or suspected zero-day exploitation. Multiple campaigns illustrate the breadth of this transition:

  • State-Aligned Activity: Chinese-affiliated groups conducting large-scale exploitation of previously unknown SharePoint vulnerabilities
  • Infrastructure Targeting: A campaign beginning in December 2024 exploiting Ivanti VPN appliances to compromise secure remote access infrastructure
  • Criminal Monetization: Financially motivated actors using zero-day access to steal cloud-hosted data for extortion and ransomware operations

Common Behavioral Patterns

Despite differences in vulnerabilities, zero-day campaigns consistently exhibit similar behavioral traits:

  • Privilege Escalation: Elevation from limited access to administrative control
    Exploitation for Privilege Escalation (T1068)
  • Infrastructure Compromise: Exploitation of exposed services such as VPNs and web servers
    Exploitation for Remote Services (T1210)
  • Execution Without Interaction: Code execution via vulnerable services without user involvement
    Exploitation for Client Execution (T1203)
  • Rapid Command and Control Establishment: Immediate use of web-based C2 channels to capitalize on short exploitation windows
    Command and Control over Web Services (T1102)

Critical Defense Implications

Compressed Response Windows

The commoditization of zero-day exploits has dramatically reduced defender response timelines. Exploits now transition from discovery to widespread abuse within days, eliminating the buffer once afforded by delayed adoption.

The Failure of Patch-First Models

Traditional security strategies centered on CVE awareness and patch deployment are increasingly ineffective. When exploitation precedes public disclosure, defenders are left exposed until after compromise has already occurred.

The Behavioral Detection Imperative

Effective defense now depends on identifying behavioral indicators that persist regardless of the underlying vulnerability, including:

  • Unusual or anomalous process execution
  • Unauthorized or unexpected privilege elevation
  • Post-compromise discovery activity such as credential harvesting and network enumeration

Threat-Led Defense as a Strategic Requirement

Because adversary behavior remains consistent even as vulnerabilities change, threat-led defense models grounded in MITRE ATT&CK mappings are now essential. By monitoring for the techniques repeatedly used by actors such as Scattered Spider, Akira, and modern zero-day operators, organizations can detect and disrupt intrusions even when the specific exploit remains unknown or unpatched.

Tidal Cyber1  is a U.S.-based cybersecurity company specializing in cyber threat intelligence and “Threat-Led Defense.” Founded in 2022 by veterans of MITRE Corporation, it helps organizations align their defenses with real adversary behavior using the MITRE ATT&CK framework. The company is recognized for operationalizing threat-informed defense through data-driven mapping of attacker tactics, techniques, and procedures (TTPs).