CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Acceleration of initial access handoff to secondary threat groups observed in 2025 incidents

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Analysis of 2025 incident data shows a dramatic reduction in the median time between initial system compromise and handoff to secondary threat groups, shrinking from hours to just 22 seconds. This shift reflects increased operational integration between initial access brokers and follow-on intrusion groups, with automation likely facilitating direct delivery of payloads. The trend underscores a maturing cybercrime ecosystem where access commodification and specialization accelerate attack timelines. The median dwell time for intrusions increased to 14 days in 2025, despite long-term declines over the past decade, driven in part by advanced evasion techniques attributed to North Korean cyberespionage actors and IT workers.

Timeline

  1. 23.03.2026 17:00 1 articles · 4h ago

    Initial access handoff time to secondary threat groups drops to 22 seconds in 2025 incidents

    Analysis of 2025 incident response data shows the median time between initial access and handoff to secondary threat groups has decreased from hours to 22 seconds, reflecting automation and closer operational ties between initial access brokers and follow-on intrusion groups. The report attributes this acceleration to direct payload delivery workflows replacing traditional cybercrime forum-based access sales.

    Show sources

Information Snippets