- Picus Security says the number of attacks against password guides Skyrocket in 2024
- Malware grows more sophisticated
- Users need to implement MFA with password administrators, research suggests
Cyber criminals are increasingly targeting passwords in an attempt to break into various important digital accounts.
Picus Security detailed his findings in the recently released Red Report 2025, based on an in-depth analysis of more than one million malware variants collected last year, where he found a quarter of all malware (25%) targeted credentials in password stores. This, the researchers claim, represent a triple increase compared to the previous year.
“For the first time ever, stealing the credentials of password stores in the top 10 techniques listed in the Mitre Att & CK framework,” they said. “The report reveals that these Top 10 techniques accounted for 93% of all malicious actions in 2024.”
Multifactor approval
The attackers use all kinds of sophisticated extraction methods in their attacks, Picus Security co-founder and VP of Picus Labs, Dr. Suleyman Ozarslan, including memory crapping, harvest database harvest and compromising local and cloud -based password stores.
To tackle the threat added Ozarslan, it is crucial people who use password managers along with multifactor approval (MFA). Furthermore, they should never reuse a password, especially for their password administrator.
The attacks grow not only in volume but also in sophistication. Picus said it has seen threat players prioritizing “complex, long-lasting, multi-step attacks” that require a new generation of malware. This malware, infosteals included, comes with increased stealth, persistence and even automation. The researchers compared this rising sophistication with “The Perfect Heist” as most malware tests come with “more than a dozen malicious actions designed to help attackers avoiding defense, increasing permissions and exfiltrate data.”
A password administrator is a tool that is safely storing, generating and autofill’s passwords and apps. It helps users create and manage strong, unique passwords without having to remember them all. It is considered one of the most important columns with good cyber security hygiene.