Industry executives and experts share their predictions for 2025. Read them in this 17th annual VMblog.com series exclusive.
By Pascal
Geenens, Director of Threat Intelligence, Radware
As we look ahead to 2025, the cybersecurity landscape is
poised for change influenced by a variety of factors. Among these are three predictions
shaped by trends we witnessed this year, including lower entry barriers to
cybercrime, shrinking exploitation windows, and the migration of threat actors
to new platforms.
Offline AI
models will lower the entry barrier for cybercriminals
The
accessibility of offline AI models is enabling bad actors to learn and advance
their skill sets faster than before. Downloadable, pre-trained GPT models have
significantly lowered the entry barrier to cybercrime. Cloud-based AI models
like ChatGPT have built-in guardrails to restrict malicious use. However,
offline models can be customized, leveraging Retrieval Augmented Generation
(RAG), and their ethical constraints removed completely. Cybercriminals can use
these AI models to automate tasks that were once labor-intensive, such as
creating highly personalized phishing messages, generating convincing deepfake
content, developing complex malware, and discovering and exploiting
vulnerabilities.
In 2025, we can expect to see an increase in the
overall sophistication of cyber attacks as more threat actors adopt offline
models. We can also expect an increase in automated attack campaigns as threat
actors start to adopt agentic AI frameworks. Underground GPT services like
FraudGPT, which are optimized for malicious purposes, combined with offline
agentic frameworks, such as the Bee Agent Framework, will enable cybercriminals
to ramp up the frequency of their attack campaigns and execute them faster than
ever before.
Shrinking
exploitation windows will increase the pressure on already short-staffed
security teams
AI models
not only are making attacks more accessible but also can significantly reduce
the time between vulnerability disclosure and exploitation-up to within minutes
of disclosure and before defenders have the chance to assess and respond. In
the past, threat actors often required hours or even days to analyze a newly
disclosed vulnerability, develop a working exploit, and deploy it effectively.
However, with the help of Agentic AI bad actors will be able to automate the
process of identifying and exploiting newly disclosed vulnerabilities almost
instantaneously. In 2025, compressing exploitation windows will be a major
challenge for cybersecurity teams because they will need to address
vulnerabilities in real-time. Eventually, traditional patching cycles will
become insufficient, forcing companies to adopt more adaptive, AI-driven
defenses that can respond automatically to potential threats and anomalies.
Threat actors will
migrate to new platforms
As platforms evolve and users gravitate from one
platform to another, threat actors will move with them, reshaping the landscape
of threat intelligence sources. Intel sources align with the platforms where
threat actors spend most of their time-from underground forums and marketplaces
to social networks. For example, as more users move away from X to Mastodon and
to Bluesky, activist threat actors will move where they find the most
followers.
The trust in underground markets has been negatively
impacted by more frequent exit scams. As a result, in the last few years, we
have seen a good amount of threat actors gravitate towards Telegram. Threat
actors can leverage Telegram to provide services through Telegram bots,
transact encrypted currencies, and gather attention and followers by posting on
public channels.
Telegram’s openness to users and its interesting
privacy policy, in which platform owners were not disclosing information to or
cooperating with law enforcement, have made it the platform of choice for bad
actors of all kinds. The recent arrest of Pavel Durov, CEO of Telegram, by the
French authorities will, however, have an impact on the popularity of the
platform for illegal use and crimes. As a result of the arrest, the terms of
service of Telegram have recently been updated to include the sharing of IP
addresses and phone numbers with law enforcement when accounts are involved in
criminal activities. Moreover, several countries in Europe started banning
Palestinian hacktivist channels because they “violate local laws,” making their
channels and content inaccessible from within most countries in the EU.
These recent policy changes in and around Telegram
will result in crime groups and malicious actors migrating to other platforms
in 2025. Where they will go is still unclear, but as authorities and nations
clamp down on the content and activities the platform used to allow, users will
flee. As migration happens, threat intel sources will have to be updated to
follow the bad guys.
In 2025, staying ahead of these threats will require vigilance
and a proactive approach to managing an increasingly complex and quickly
evolving cyber landscape.
##
ABOUT THE
AUTHOR
Pascal Geenens is the director of threat intelligence
for Radware and leads the company’s
global threat intelligence program. With more than 25 years of experience in
information security and technology, Pascal has developed strong expertise in
tracking cyber adversary groups. Throughout his career, Pascal has discovered
several malware families, including BrickerBot, malware designed to destroy
unsecured IoT devices. Pascal’s unique perspective and insights have been
featured in many publications and inspired audiences across the globe. Pascal
contributed several chapters to the CRC Press book ?Botnets – Architectures,
Countermeasures, and Challenges.’
Before joining Radware, Pascal worked as a consulting
engineer for Juniper Networks and as an engineer at IBM. Pascal holds a Master
of Science degree in electrical engineering, communication, and information
technology from the Free University of Brussels.






