Report by Bridewell

Cyber Threat Intelligence Report 2026

8 FINDINGSPublished May 18, 2026
View Original Report →

Key Findings

China hosted 42.3% of all tracked Cobalt Strike infrastructure, the US hosted 18.9%, and Hong Kong hosted 15.8%.

Cobalt StrikeChinaUSHong Kong

Across 2025, 7,918 victim postings were observed on ransomware group data-leak sites (DLS) across 129 distinct threat actors sourced from ransomware.

RansomwareData Leak SiteDLS

China remained the second largest adversary infrastructure hosting location at 13.55%, down from 17.57% the previous year.

Adversary InfrastructureChina

Cobalt Strike accounted for 38.4% of all OST output (3,944 of 10,272 tracked OST instances), maintaining its position as the primary adversary framework.

Cobalt StrikeOST

Germany increased to 8.74%, becoming the third largest adversary infrastructure hosting location and overtaking both Hong Kong (7.22%) and the Netherlands (6.51%).

Adversary InfrastructureGermanyHong KongThe Netherlands

WhiteSnake Stealer was the most widely observed infostealer family, accounting for 31.6% of all tracked output, followed by RedLine at 23.9%, Rhadamanthys at 17.1%, and StealC at 6.9%.

Infostealer

The most prevalent malware families observed in 2025 are Cobalt Strike, Sliver, Metasploit, Burp, PlugX, SuperShell C2, Havoc, Panda C2, Brute Ratel, and ShadowPad.

Malware Cobalt StrikeSliverMetasploitBurp

In 2025, 27.89% of all adversary infrastructure tracked was hosted in the US, an increase from 23.63% in 2024.

Adversary InfrastructureUS