Intelligence Insights: Dec 2025 banner image
News
BCON COLLECTIVE

Intelligence Insights: Dec 2025

1 December 2025

Gavin Knapp, Principal Threat Intelligence Lead | Joshua Penny, Senior Threat Intelligence Analyst | Bridewell CSIRT


The Bridewell Threat-Led Approach

Bridewell’s managed security services are built upon a proactive, threat-led defence strategy. Moving beyond reactive monitoring, we actively track adversary infrastructure and tradecraft. By seamlessly integrating Cyber Threat Intelligence (CTI), Incident Response (IR), and Managed Detection and Response (MDR), we ensure our clients remain ahead of the evolving threat landscape.

In a landscape defined by rapid adaptation, knowing what is attacking you is just as critical as knowing how. This month’s Threat Insights leverages data from Bridewell’s global MDR and Incident Response engagements to expose the top malicious infrastructure of December 2025. We go beyond the headlines to provide actionable detection guidance on the month's threat insights, equipping your team with the foresight to stay one step ahead.

Top 5 Malicious Infrastructure Threat Tracked

Threat NameCategoryDec. Volume Monthly Trend
Xtreme-RATRemote Access Trojan3,139▼ Decreasing
Cerberus-AndroidMobile Banking Trojan966▲ Rising
Brute RatelC2 Framework911▼ Decreasing
BurpVulnerability Scanner677▲ Rising
MetasploitExploitation Framework623▲ Rising

New Threat Cluster Infrastructure Sightings

Threat NameTypeDetectionsStatus
GoPhishPhishing Framework215NEW ENTRY
VidarInfo Stealer81NEW ENTRY
Castle RATRemote Access Tool23NEW ENTRY
Empire DownloaderPowerShell Stager16NEW ENTRY
RedGuard C2C2 Obfuscator14NEW ENTRY

Threat Detection Insights - December

Castle-RAT Distribution

CastleRAT is a lightweight remote access trojan (RAT) that was observed as a payload in campaigns leveraging CastleLoader malware. Originally this payload was discovered and coined PyNightshade which was seen being delivered via campaigns leveraging ClickFix for initial access to victims.

Our research into the threat has produced the following security outcomes to proactively improve your defence against this threat.

Community Detection Opportunities

Detection Opportunity (KQL) 1
//CastleLoader and CastleRAT - Commandline Detections
// TAG150
// Detects the execution of 'schtasks.exe' being used to create a new task where the task payload involves Rundll32.exe.
DeviceProcessEvents
  | where FileName =~ "schtasks.exe"
  // Check for the creation flag
  | where ProcessCommandLine has_any ("/create", "-create")
  // Check for the malicious payload trigger
  | where ProcessCommandLine has "rundll32"
  | project TimeGenerated, DeviceName, AccountName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, FolderPath, SHA256
Detection Opportunity (KQL) 2
//CastleLoader and CastleRAT - Commandline Detections
// TAG150
// New Botnet Emerges from the Shadows: NightshadeC2 | eSentire
DeviceProcessEvents
| where InitiatingProcessCommandLine has_all ("-Force","Add-MpPreference","-ExclusionProcess","C:","Users")

Bridewell CSIRT Detection Rules & Analytics

The following detection content was generated through our managed threat intelligence, threat hunting, and detection and response (MDR) services. The content automatically protects our customers from known and emerging threats.

Detection Rule NameCategory
HTTP-CastleRAT-Unknown-Pivot-000003Infrastructure Hunting
HTTP-CastleRAT-000002Infrastructure Hunting
HASH-CastleRAT-000001Infrastructure Hunting
HTTP-CastleRAT-0000033Infrastructure Hunting
HTTP-CastleLoader-000001Infrastructure Hunting
KQL_MDE_DeviceProcessEvents_CastleLoader_DefenderExclusionTTP Analytic
KQL_MDE_DeviceNetworkEvents_CastleRAT_C2BeaconingTTP Analytic
KQL_MDE_DeviceProcessEvents_ClickFix_RunDialogPowerShellTTP Analytic
KQL_MDE_DeviceProcessEvents_ClickFix_ClipboardExecutionTTP Analytic
KQL_MDE_DeviceProcessEvents_CastleLoader_UACBypass_WindirEnvTTP Analytic
KQL_MDE_DeviceProcessEvents_CastleLoader_Rundll32_Ordinal61TTP Analytic
KQL_MDE_DeviceEvents_CastleLoader_CleanupAndPayloadDropTTP Analytic
KQL_MDE_DeviceProcessEvents_CastleLoader_RegistryCleanup_WindirTTP Analytic
KQL_MDE_DeviceFileEvents_CastleLoader_PowerShellPayloadDropTTP Analytic
KQL_MDE_DeviceProcessEvents_CertUtil_URLCache_DownloadTTP Analytic
KQL_SEN_SecurityEvent_ScheduledTask_Rundll32_TriggerTTP Analytic
KQL_MDE_DeviceEvents_ScheduledTask_Rundll32_Registration_ParsedTTP Analytic
KQL_MDE_DeviceFileEvents_ExecutablesInSuspiciousPathsTTP Analytic

Stop Reacting. Start Hunting.

Bridewell’s threat-led MDR service combines world-class analysts with proprietary intelligence to protect your critical infrastructure and assets 24/7.

bridewell-logo

Bridewell CSIRT

Cyber Security Incident Response Team

Real-world incident response insights from our cyber security experts.