The Evolving Landscape of RATs and Trojans in Cybersecurity
In the ever-changing world of cybersecurity, Remote Access Trojans (RATs) and other Trojan families remain critical topics of discussion within underground forums. These malicious software tools are often the first stage of infection for cybercriminals, facilitating unauthorized access to victim devices and networks. Recent analyses of dark web activities reveal persistent levels of RAT usage alongside notable trends in malware proliferation, illustrating how these tools continue to shape the cyber threat landscape.
RAT Activity Trends
Figure 1 provides a visual representation of RATs and Trojan activity over the past year, as observed across dark web forums and marketplaces. It charts trends based on mentions, listings, and infection telemetry. This ongoing activity signals a robust market for RATs, complemented by the continuing evolution of their functionality by threat developers.

Contrastingly, general malware activity—including various types of malicious software—exhibits a consistent level of presence with intermittent surges coinciding with the release of new stealer kits and ransomware variants. Figure 2 illustrates this trend, showcasing the dynamic nature of malware threats currently available in underground markets.

Emerging Malware Trends in 2025
The first half of 2025 has witnessed the emergence and evolution of various malware families, reflecting both rapid technological advancement and the influence of geopolitical tensions. Noteworthy threats include:
-
Sponsor Backdoor: This malware exploits vulnerabilities in Microsoft Exchange (CVE-2021-26855) to maintain persistent access to systems and facilitate data exfiltration.
-
BUGHATCH Malware: Targeting organizations across the Americas, BUGHATCH exploits Veeam Backup & Replication flaws to deploy additional malicious payloads.
-
Destructive Malware Families: Tools like WhisperGate, FoxBlade, DesertBlade, and CaddyWiper have been decidedly destructive, disrupting critical infrastructure and underscoring the intersection of crime and state-sponsored cyber operations.
-
ChaosBot: This new malware, developed in Rust, utilizes popular communication platforms like Discord for command and control, showcasing an alarming trend of blending malicious activities with legitimate online activities.
Sector-Specific Malware Targeting
Understanding which sectors are the most targeted helps organizations prioritize their cybersecurity efforts. Here’s a closer look at the sectors most at risk in 2025:
1. Technology
The technology sector remains a prime target for cybercriminals, driven by the interconnectivity of its ecosystem. Many attacks infiltrate trusted vendor relationships, managed service providers, and software supply chains. In 2025 alone, nearly 47% of breaches involved technology products and services. Recent dips in dark web discussions and infection telemetry may suggest a temporary shift in focus or improvements in defenses, rather than a reduced risk.

2. Government and Administration
Government entities continue to face myriad threats from both state-linked and financially motivated attackers. Data theft, espionage, and disruption campaigns target various branches, reflecting the significant value of governmental data. Notably, public sector networks are seeing consistent pressure, with attackers exploiting vulnerabilities in remote access infrastructure.

3. Finance
Financial institutions present a lucrative target for attackers due to the sensitive transactional data they handle. An alarming 47% year-over-year increase in attacks against the finance sector during 2024 has been primarily driven by ransomware and credential theft campaigns. As institutions enhance their detection and response capabilities, cybercriminals are evolving their techniques to maintain pressure.

4. Education
Educational institutions are also feeling the brunt of cyber threats, with increasing levels of ransomware and data theft. The challenge stems from decentralized IT environments and legacy systems, making these organizations vulnerable targets. Underground marketplaces frequently advertise access to university networks, indicating that these institutions are becoming playgrounds for opportunistic cybercriminals.

5. Healthcare
The healthcare sector is among the most targeted due to the sensitive nature of its data. In 2024, 93% of U.S. healthcare organizations reported cyber incidents, with 60% suffering ransomware attacks. The average breach cost in this sector was approximately $10.3 million, highlighting significant financial risks associated with cyber breaches in healthcare.

Future Directions in Cybercrime
As 2025 unfolds, the underground cybercrime economy continues to flourish, with service-based models like Malware as a Service (MaaS) and Ransomware as a Service (RaaS) streamlining the entry of novice actors into sophisticated cyber operations. The healthcare and technology sectors persist as primary targets, while finance and education also grapple with ongoing threats.
Increasingly, threat actors are exploiting legitimate infrastructures—such as cloud services and collaboration tools like Discord—to execute their schemes, complicating traditional detection and attribution methods. As we move further into 2025, vigilance around third-party risk management, patch hygiene, and identity security will be crucial for organizations seeking to mitigate the emerging threats from this increasingly professional underground market.

