Huntress 2025 Cyber Threat Report: Key Trends and Industry Impact (Part 1 of 2)
Cyber Threats: Sophisticated Attacks Become the New Normal
Part 1 of the Huntress 2025 Cyber Threat Report: the 2024 threat mix, who got hit hardest, and how fast attackers moved.
The Huntress 2025 report shows attackers in 2024 relied most on infostealers and malicious scripts - and ran the same techniques against businesses of every size.
The headline is not a single new threat; it is standardization. Methods once reserved for large enterprises are now deployed against small and midsize businesses too, because attackers have industrialized their playbook. Part 1 covers what that playbook looked like: the mix of threats, the industries hit hardest, how quickly ransomware landed, and the tools that made it all run.
The 2024 Threat Mix
Data theft and scripting led the year.
Infostealers (24%) and malicious scripts (22%) topped 2024, with malware, remote access trojans, and ransomware filling out the rest.
The full breakdown: infostealers 24%, malicious scripts 22%, general malware 17%, remote access trojans 13%, and ransomware 9.5%. Ransomware may be a smaller slice, but it is the loudest - and, as the numbers below show, it lands fast.
Who Got Hit Hardest
Every sector, its own flavor of attack.
Education, healthcare, and technology absorbed the most attacks - each facing a slightly different mix of scripts, infostealers, and tool abuse.
- Education (21%). Malicious scripts led, especially PowerShell, VBScript, and WMI abuse, with heavy reliance on remote-management tools.
- Healthcare (17%). The highest rate of malicious script executions, often tied to infostealers like Gootloader and PowerShell obfuscation.
- Technology (12%). Attackers abused remote-management tools and ran credential theft with Mimikatz, lazagne, and infostealers Meduza and Strela.
- Government (11%). Infostealers led, with SOCGholish, AsyncRAT, and increased Cobalt Strike and Bloodhound use.
- Manufacturing (9%). Heavy remote access trojan use - and 23% of malware disguised itself as Adobe components.
Ransomware Speed and Attacker Tools
The window to respond is measured in hours, not days.
Attackers averaged about 17 hours from break-in to ransomware - and took roughly 18 malicious actions along the way, often using trusted remote tools.
Some groups moved far faster: Akira deployed ransomware within six hours of initial access. Others were methodical, favoring data theft and extortion over speed. Either way, the tooling was consistent, and much of it hid inside software your team already trusts.
- Remote access trojans - 75% of remote access methods, the dominant way in.
- RMM tool abuse - 17.3% of remote access, with ConnectWise ScreenConnect making up 74.5% of that abuse.
- Cobalt Strike - 31.7% of detected hacking tools, still the top offensive framework.
- Mimikatz - 17.6% of hacking-tool usage, for harvesting credentials.
- ~18 actions before encryption. Reconnaissance, privilege escalation, and data theft precede the payload - each a chance to catch it.
Catch Attacks Before Ransomware Fires
CinchOps runs 24/7 monitoring and rapid response to spot the reconnaissance and tool abuse that precede ransomware - as part of everyday cybersecurity and managed IT.
Explore CinchOps cybersecurity →How CinchOps Helps Secure Your Business
CinchOps is a Katy, Texas managed IT services provider serving businesses across the Houston metro, built to catch exactly the tactics this report describes.
- 24/7 threat monitoring and response. Real-time detection across network and endpoints, with rapid incident response.
- Industry-specific protection. Security tuned to the attack patterns your sector actually faces.
- Ransomware defense and recovery. Protection against remote access trojans and malicious scripts, plus tested backups.
- RMM and tool-abuse monitoring. Watching the trusted remote-management tools attackers hijack for access.
- Assessments and training. Regular posture reviews, awareness training, and incident-response testing.
Do not let your size make you a soft target. Contact CinchOps to defend against the 2024 playbook.
The number that should stop a business owner is 17 hours - and six for the fastest groups. That is your entire window from break-in to encryption. You do not beat that with a nightly log review; you beat it with monitoring that never sleeps.
Frequently Asked Questions
What were the most common cyber threats in 2024?
According to the Huntress 2025 Cyber Threat Report, infostealers led at 24% of incidents, followed by malicious scripts (22%), general malware (17%), remote access trojans (13%), and ransomware (9.5%). Attackers increasingly ran the same techniques against businesses of every size.
How fast is ransomware deployed after a breach?
The report found an average time-to-ransom of about 17 hours in 2024. Some groups moved far faster - Akira deployed ransomware within six hours of gaining access - while others took longer, favoring data theft and extortion. Attackers averaged roughly 18 malicious actions before encrypting.
Which industries were hit hardest in 2024?
By share of attacks, education (21%) led, followed by healthcare (17%), technology (12%), government (11%), and manufacturing (9%). Each sector faced a slightly different mix - for example, healthcare saw the most malicious script executions, while manufacturing saw heavy remote-access-trojan use.
What tools do attackers use most?
Remote access trojans were the dominant remote-access method at 75%. Attackers also abused legitimate remote-management tools (ConnectWise ScreenConnect made up 74.5% of that abuse), and used offensive frameworks like Cobalt Strike (31.7% of hacking tools) and Mimikatz (17.6%) for credential theft.
Why are small businesses at risk from enterprise-grade attacks?
Attackers have standardized their methods, so techniques once aimed at large enterprises are now automated and pointed at organizations of every size. Being small no longer means being overlooked - the same playbook runs against everyone, which makes strong detection and response essential.