Report by Bridewell
Cyber Threat Intelligence Report 2026
Key Findings
China hosted 42.3% of all tracked Cobalt Strike infrastructure, the US hosted 18.9%, and Hong Kong hosted 15.8%.
Across 2025, 7,918 victim postings were observed on ransomware group data-leak sites (DLS) across 129 distinct threat actors sourced from ransomware.
China remained the second largest adversary infrastructure hosting location at 13.55%, down from 17.57% the previous year.
Cobalt Strike accounted for 38.4% of all OST output (3,944 of 10,272 tracked OST instances), maintaining its position as the primary adversary framework.
Germany increased to 8.74%, becoming the third largest adversary infrastructure hosting location and overtaking both Hong Kong (7.22%) and the Netherlands (6.51%).
WhiteSnake Stealer was the most widely observed infostealer family, accounting for 31.6% of all tracked output, followed by RedLine at 23.9%, Rhadamanthys at 17.1%, and StealC at 6.9%.
The most prevalent malware families observed in 2025 are Cobalt Strike, Sliver, Metasploit, Burp, PlugX, SuperShell C2, Havoc, Panda C2, Brute Ratel, and ShadowPad.
In 2025, 27.89% of all adversary infrastructure tracked was hosted in the US, an increase from 23.63% in 2024.