Opens in a new tab
vmblog logo 2024 wht (updated)

Blackpoint Cyber 2025 Predictions: Why Cheap and Simple Cyber Attacks Will Be Even More Dangerous in 2025

Share: 

David Marshall | Published: November 21, 2024

vmblog-predictions-2025 

Industry executives and experts share their predictions for 2025.  Read them in this 17th annual VMblog.com series exclusive.

By Aaron Shaha, Chief Threat Research and Intelligence at Blackpoint Cyber

As we look ahead to 2025, we’re all thinking about maximizing resources and delivering better business outcomes. For many of us, that means leaning into AI and automation. While I don’t expect AI to become sentient anytime soon, I see it as a powerful force multiplier for cybersecurity, particularly for automating mundane, repeatable tasks. Unfortunately, the same capabilities that benefit us are also readily exploitable by our adversaries.

Cybercriminals are thriving by applying a simple principle that General George S. Patton articulated: “A good solution applied with vigor now is better than a perfect solution applied ten minutes later.” And they’re doing exactly that. Increasingly, identity attacks like credential stuffing become a preferred tactic. Why? Because it’s effective. Threat actors opt for these “good enough” tactics-relying on breached passwords-rather than spending time and money on a “perfect solution” involving elaborate zero-day exploits.

One rising trend is the widespread use of infostealers. These lightweight, easy-to-deploy tools-often delivered through malvertisements-are frequently overlooked by defenders, making them even more dangerous. Infostealers can quickly collect vast amounts of data, which can then be combined and analyzed using AI to identify promising attack vectors.

Let’s explore how AI can leverage these infostealers into actionable exploitation by cybercriminals.  Imagine an adversary using AI to take all that data gathered by infostealers and put it to work-testing and validating accounts, even at scale. This combination of automation and bulk testing makes AI such a powerful force multiplier for attackers. It also helps explain the increasing rate of identity-based attacks we’re seeing.

As we continue to post more information on our personal and corporate social media accounts, we naturally give adversaries more data on which to train an AI. They can then trick us into clicking an attachment or following a malicious link. Threat actors have access to many of the same tools as we do. As a result, they can use either existing “cloud” AIs or stand-alone AIs to ingest and learn from data posted on websites, videos, and social media to generate realistic and more convincing spear phishing payloads. Those “I’m the CEO, send gift cards” SMS messages are still out there-and, sadly, still effective. Now imagine receiving a phone call that sounds exactly like your CEO, thanks to AI-generated voice cloning.

This approach allows attackers to leverage a cheap, disposable toolkit while maximizing effectiveness. Their ability to weaponize our own data against us is an emerging trend worth watching. We need to be prepared for how this will impact cybersecurity operations, particularly around identity protection.

We’re also seeing a fusion of traditional hacking techniques with these identity-based attacks to access systems like Office 365. Once in, attackers might exploit the Graph API for persistence and data exfiltration-sometimes through basic methods like setting up mailbox forwarding rules, other times with sophisticated maneuvers that are much harder to detect. And while technologies like passkeys and hardware-based authentication can help mitigate these attacks, widespread adoption is still a challenge due to implementation complexity and cost.

With AI amplifying the capabilities of our adversaries, 2025 promises to be a year where even “simple” attacks can lead to significant consequences. The challenge for us, as defenders, is to stay ahead of these emerging threats and build resilience against attacks that leverage both the latest technology and tried-and-true tactics. It’s a dynamic and ever-changing landscape-and one we must be ready to navigate.

##

ABOUT THE AUTHOR

Aaron Shaha, Chief of Threat Research and Intelligence

Aaron Shaha

Strategic Information Security Executive and subject matter expert with a record of pioneering cyber security trends by developing novel security tools and techniques that align with corporate objectives. Known for building and leading strong teams that provide technology enabled business solutions for start-ups, industry leaders (Deloitte and its Fortune clients) and government agencies (NSA). Skilled at developing information security strategies and standards, leading threat detection and incident response teams to mitigate risk, and communicating effectively across all levels of an organization.