Foundation: Methodology and Analytical Basis
The 2025 Threat-Led Defense Report from Tidal Cyber1 is derived from tens of thousands of documented adversary behaviors collected through its threat intelligence platform. The analysis correlates observed real-world attack activity with the MITRE ATT&CK framework, enabling consistent comparison of adversary behavior across campaigns, industries, and geographic regions.
This behavior-centric methodology reveals repeatable attacker tradecraft rather than isolated incidents, forming the foundation for the three major threat evolutions outlined below.
Evolution 1: Scattered Spider’s Strategic Expansion
From Narrow Targeting to Broad Sector Coverage
Between 2022 and 2025, the threat group commonly referred to as Scattered Spider demonstrated a clear and deliberate expansion strategy. Initially focused on customer support providers and business process outsourcing organizations, the group progressively moved into retail, technology, and financial services environments.
This expansion was not opportunistic. Target selection consistently aligned with organizations that maintain high-value cloud assets, identity infrastructure, and SaaS-centric operational models.
The Shift Toward Cloud-Native Intrusion Paths
As sector targeting broadened, Scattered Spider pivoted toward cloud-first attack techniques. Operations increasingly focused on Software-as-a-Service platforms that store sensitive data and act as identity hubs for enterprise environments. Confirmed compromises and access attempts included Salesforce, Microsoft Teams, Slack, Confluence, and SharePoint.
This shift reflects a strategic emphasis on identity compromise and trust abuse rather than perimeter exploitation.
A Repeatable, Modular Playbook
Researchers documented 225 distinct procedures across 94 separate activity clusters, indicating a highly modular and repeatable operational model. Rather than tailoring entirely new approaches per victim, Scattered Spider consistently executed the following behavioral sequence:
- Initial Access: Compromise of legitimate SaaS or enterprise credentials instead of direct network exploitation
Valid Accounts (T1078) - Persistence: Modification of cloud identity or configuration settings to retain access despite credential resets
Account Manipulation (T1098) - Environment Mapping: Enumeration of SaaS applications and cloud resources in use
Cloud Service Discovery (T1526) - Data Exfiltration: Theft of information via legitimate cloud APIs and services
Exfiltration Over Web Services (T1567.002) - Sustained Access: Continued entry through SaaS portals and federated identity mechanisms
External Remote Services (T1133)
Evolution 2: Akira Ransomware’s Refinement Strategy
Optimization Over Innovation
In contrast to Scattered Spider’s expansion, Akira ransomware operations throughout 2025 focused on refining proven techniques rather than introducing novel tradecraft. The report documents 165 observed procedures demonstrating consistent reuse of known commands, combined with subtle changes in execution order and timing to evade detection.
This approach reflects operational maturity and an emphasis on reliability.
A Consistent Operational Sequence
Akira’s activity follows a predictable progression, with each phase enabling the next:
- Credential Harvesting: Extraction of authentication material to support lateral movement
Credential Dumping (T1003) - Internal Reconnaissance: Enumeration of user accounts and group memberships to identify privilege paths
Account Discovery (T1087)
Permission Group Discovery (T1069) - Service Identification: Discovery of internal network services that can be exploited or abused
Network Service Discovery (T1046) - Data Exfiltration: Theft of sensitive data prior to encryption to support double-extortion tactics
Exfiltration Over Command and Control Channel (T1041) - Recovery Disruption: Removal of backups and disabling of recovery mechanisms
Inhibit System Recovery (T1490)
Abuse of Legitimate Administrative Tooling
Akira operators rely heavily on commonly used enterprise administration utilities such as AdFind, Net Group, and SharpHound. These tools blend into normal IT activity, complicating detection efforts and reducing the likelihood of immediate security escalation.
Evolution 3: The Democratization of Zero-Day Exploitation
From State-Exclusive to Broadly Accessible
One of the most significant shifts observed in 2025 is the widespread adoption of zero-day exploitation beyond traditional state-sponsored actors. Techniques once reserved for elite intelligence operations are now routinely leveraged by criminal groups and hybrid actors with both financial and geopolitical motivations.
Evidence of Widespread Use
The report identifies more than 58 threat activities linked to confirmed or suspected zero-day exploitation. Multiple campaigns illustrate the breadth of this transition:
- State-Aligned Activity: Chinese-affiliated groups conducting large-scale exploitation of previously unknown SharePoint vulnerabilities
- Infrastructure Targeting: A campaign beginning in December 2024 exploiting Ivanti VPN appliances to compromise secure remote access infrastructure
- Criminal Monetization: Financially motivated actors using zero-day access to steal cloud-hosted data for extortion and ransomware operations
Common Behavioral Patterns
Despite differences in vulnerabilities, zero-day campaigns consistently exhibit similar behavioral traits:
- Privilege Escalation: Elevation from limited access to administrative control
Exploitation for Privilege Escalation (T1068) - Infrastructure Compromise: Exploitation of exposed services such as VPNs and web servers
Exploitation for Remote Services (T1210) - Execution Without Interaction: Code execution via vulnerable services without user involvement
Exploitation for Client Execution (T1203) - Rapid Command and Control Establishment: Immediate use of web-based C2 channels to capitalize on short exploitation windows
Command and Control over Web Services (T1102)
Critical Defense Implications
Compressed Response Windows
The commoditization of zero-day exploits has dramatically reduced defender response timelines. Exploits now transition from discovery to widespread abuse within days, eliminating the buffer once afforded by delayed adoption.
The Failure of Patch-First Models
Traditional security strategies centered on CVE awareness and patch deployment are increasingly ineffective. When exploitation precedes public disclosure, defenders are left exposed until after compromise has already occurred.
The Behavioral Detection Imperative
Effective defense now depends on identifying behavioral indicators that persist regardless of the underlying vulnerability, including:
- Unusual or anomalous process execution
- Unauthorized or unexpected privilege elevation
- Post-compromise discovery activity such as credential harvesting and network enumeration
Threat-Led Defense as a Strategic Requirement
Because adversary behavior remains consistent even as vulnerabilities change, threat-led defense models grounded in MITRE ATT&CK mappings are now essential. By monitoring for the techniques repeatedly used by actors such as Scattered Spider, Akira, and modern zero-day operators, organizations can detect and disrupt intrusions even when the specific exploit remains unknown or unpatched.
Tidal Cyber1 is a U.S.-based cybersecurity company specializing in cyber threat intelligence and “Threat-Led Defense.” Founded in 2022 by veterans of MITRE Corporation, it helps organizations align their defenses with real adversary behavior using the MITRE ATT&CK framework. The company is recognized for operationalizing threat-informed defense through data-driven mapping of attacker tactics, techniques, and procedures (TTPs).