Picus

21 STATS2 REPORTS

All Statistics

Maori, a ransomware strain, had a prevention effectiveness rate of 41%.

PicusBlue Report 2025·Aug 11, 2025
RansomwareMaori

Attacks using valid credentials were successful 98% of the time.

PicusBlue Report 2025·Aug 11, 2025
Valid credentials

Logging coverage held steady at 54%.

PicusBlue Report 2025·Aug 11, 2025
Logging

Infostealer malware has tripled in prevalence.

PicusBlue Report 2025·Aug 11, 2025
Infostealer

BlackByte, a ransomware strain, had a prevention effectiveness rate of just 26%.

PicusBlue Report 2025·Aug 11, 2025
RansomwareBlackByte

BabLock, another ransomware strain, had a prevention effectiveness rate of 34%.

PicusBlue Report 2025·Aug 11, 2025
RansomwareBabLock

Discovery techniques like System Network Configuration Discovery and Process Discovery scored below 12% in prevention effectiveness.

PicusBlue Report 2025·Aug 11, 2025
Discovery techniques

Overall prevention effectiveness declined from 69% in 2024 to 62% in 2025.

PicusBlue Report 2025·Aug 11, 2025
Prevention

Only 14% of attacks generated alerts.

PicusBlue Report 2025·Aug 11, 2025
Cyber attacksAlerts

Data exfiltration attempts were only stopped 3% of the time in 2025. This is down from 9% in 2024, representing a 3x decrease.

PicusBlue Report 2025·Aug 11, 2025
Data exfiltration

In 46% of tested environments, at least one password hash was successfully cracked. This is an increase from 25% in 2024.

PicusBlue Report 2025·Aug 11, 2025
Password

On average, malware now executes 14 malicious actions.

PicusRed Report 2025·Feb 1, 2025

There has been a 3X increase in malware specifically targeting credential stores like password managers and browser-stored login data.

PicusRed Report 2025·Feb 1, 2025

Process Injection (T1055) has a prevalence rate of 31%.

PicusRed Report 2025·Feb 1, 2025

On average, malware now executes 14 malicious actions.

PicusRed Report 2025·Feb 1, 2025

25% of the malware examined showed behaviours related to T1555 (Credentials from Password Stores).

PicusRed Report 2025·Feb 1, 2025

Process Injection (T1055) has a prevalence rate of 31%.

PicusRed Report 2025·Feb 1, 2025

There has been a 3X increase in malware specifically targeting credential stores like password managers and browser-stored login data.

PicusRed Report 2025·Feb 1, 2025

93% of all malicious actions observed could be mapped to just 10 MITRE ATT&CK techniques.

PicusRed Report 2025·Feb 1, 2025

93% of all malicious actions observed could be mapped to just 10 MITRE ATT&CK techniques.

PicusRed Report 2025·Feb 1, 2025

25% of the malware examined showed behaviours related to T1555 (Credentials from Password Stores).

PicusRed Report 2025·Feb 1, 2025