Skip to main content
All articles

Threat Intelligence November 24, 2025 · 3 min read

Microsoft Digital Defense Report 2025: Top Three Takeaways

Microsoft's Digital Defense Report 2025 examines global cybersecurity threats from July 2024 through June 2025, drawing on an enormous dataset: over 100 trillion security signals monitored daily, 4.5 million malware files blocked daily, and 38 million identity threats detected daily on average. Ascent pulled three findings security teams should have on their radar.

1. The Rise of ClickFix: A New Era of Social Engineering

Microsoft reports a rapid surge in the use of ClickFix beginning in November 2024. Both cybercriminals and nation-state actors use this social engineering technique to deploy infostealers, Remote Access Trojans, and other malware.

The FileFix Variant

Ascent's threat intelligence team predicted new ClickFix variants would emerge, and on June 23, 2025 security researcher mr.d0x published “FileFix – A ClickFix Alternative,” documenting a dangerous new variant with technical analysis, proof-of-concept code, and a video demonstration.

How ClickFix and FileFix Attacks Work

Both techniques exploit User Execution (MITRE ATT&CK T1204) through social engineering that gets a victim to run malicious PowerShell commands (T1059.001):

  • ClickFix: directs the user to paste a command into the Run dialog (Win + R)
  • FileFix: directs the user to paste a command into File Explorer (Ctrl + L or Alt + D)

How to Defend Against It

The most effective defense is comprehensive security awareness training — what Ascent calls “Patching the Human Firewall,” the subject of a three-volume blog series. Threat actors aren't dropping this technique; expect more variants.

2. Email Bombing: The Gateway to Sophisticated Social Engineering

Microsoft's report shows email bombing (MITRE ATT&CK T1667) evolving from a nuisance into a sophisticated precursor attack: “Email bombing is now often used as a precursor to vishing or Teams-based impersonation, where the attacker contacts the target posing as IT support.” Attackers use the resulting confusion to set up unauthorized access.

Real-World Case: Storm-1811

Ascent's combined Security Operations Center and Cyber Threat Intelligence team successfully blocked a 2025 attack from Storm-1811 (also tracked as CURLY SPIDER and STAC5777). The group has barely changed its playbook since 2023, because it still works — largely because many users assume Microsoft Teams is immune to impersonation.

Essential Defense Strategies

Storm-1811 activity is expected to continue through 2026. Recommended measures:

  • Lock down Microsoft Teams — restrict external access and communication, require strict verification for IT support contacts, and monitor for suspicious Teams activity.
  • Deploy email bomb detection — alert on mass subscription patterns, chain those alerts to subsequent contact attempts, and have a rapid response protocol ready.
  • Train users — teach recognition of Teams-based impersonation, and make clear that legitimate IT never requests remote access through an unsolicited message.
  • Have an incident response protocol — when an email bomb is detected, contact affected users immediately and ask directly whether anyone called or messaged them on Teams about it, and isolate any system where remote access tools were installed.

3. Exploiting Vulnerabilities: The Persistent Threat of Unpatched Systems

Per Microsoft's report, “vulnerability exploitation remains one of the most reliable, scalable, and silent methods of initial access for threat actors.” Ransomware groups including Cl0p, Warlock, and Akira actively exploit unpatched systems in enterprise software, third-party IT management tools, and critical infrastructure.

Most successful attacks aren't zero-days — they exploit vulnerabilities that were publicly disclosed and patchable for months or years, because organizations accepted the risk, missed the disclosure, or had a patch management process break down.

Microsoft's Core Recommendation: Patch Fast, Patch Early

That discipline is harder to sustain than it sounds — it requires consistency in patch cycles, enough capacity to keep pace, a plan for remediation debt from missed cycles, and testing that balances speed against stability.

How Ascent Solves the Vulnerability Intelligence Gap

Vulnerability overload is real. Ascent combines Cyber Threat Intelligence and Threat & Vulnerability Management to surface which vulnerabilities actually matter, why, and how attackers are exploiting them right now — tracking everything from proof-of-concept exploit drops to weaponized code circulating on the dark web. That gives organizations early warning and a way to prioritize fixes by real risk instead of CVSS score alone.

Want to talk this through with an expert?

Bring your current environment and we'll map it to what's above.

Speak with an Expert