Skip to content

79 Percent of 2025 Cyberattacks Exploit Legitimate Systems Instead of Malware

Bottom line: Attackers increasingly bypass detection systems through abuse of legitimate systems and AI-powered malware generation rather than deploying traditional malware.

2025 marks a paradigm shift in cyberattacks: 79 percent of successful attacks forgo malware and instead abuse legitimate operating system tools and stolen credentials. This tactic circumvents traditional detection systems virtually undetected.

These techniques are called Living-off-the-Land (LOTL) and Living-off-the-Services (LOTS). In LOTL, attackers hijack legitimate system tools such as PowerShell, WMI, or scripting engines that come standard in Windows, Linux, and macOS installations. Using stolen login credentials, they operate as normal users and trigger no alarms – their activities appear as regular user actions.

With LOTS, cybercriminals take it a step further and use cloud services as infrastructure: they store metadata and credentials in Google Sheets, Firebase, or Supabase and transmit command-and-control instructions via Slack or Discord. This tactic is particularly effective because communication flows through legitimate services and blends into regular network traffic.

Artificial intelligence significantly amplifies this trend. LLMs enable hacker organizations to generate functional malware at scale – not through sophisticated coding tools, but by leveraging SDKs, documentation, and code examples fed into the model. CrystallShell is a current example: this backdoor written in the Crystal programming language operates cross-platform (Windows, Linux, macOS) and uses hardcoded Discord channel IDs for communication.

The situation intensifies for CISOs due to growing IT complexity: cloud services, hybrid infrastructures, mobile workplaces, and digital supply chains continuously expand the attack surface. At the same time, automated and AI-powered attack methods identify vulnerabilities and misconfigurations significantly faster than before.

A structural countermeasure is preventive security platforms that interrupt attack chains before they cause damage. The classic reactive approach (detection after successful intrusion) is no longer sufficient – the focus must shift to prevention.


Source: www.it-daily.net · Published 14 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: