Google Cloud’s Mandiant division released its annual M-Trends report on March 24, drawing on more than 500,000 hours of incident response engagements conducted during 2025. The headline finding reshapes how security operations teams should think about detection windows: the median time between an attacker gaining initial access and handing that access to a secondary threat group has collapsed from more than eight hours in 2022 to just 22 seconds in 2025.

That statistic is not an outlier pulled from a single engagement. It represents the industrialization of the initial access broker market, where the handoff between a compromise operator and a ransomware affiliate now happens faster than most SIEM correlation rules can fire. For defenders, the practical consequence is stark: by the time a Tier-1 analyst opens the first alert, the entity operating inside the network may already be a different group with different tooling and different objectives than the one that breached the perimeter.

Exploitation Still Dominates, but Vishing Surges

Exploitation of internet-facing systems held its position as the leading initial infection vector for the sixth consecutive year, appearing in 32 percent of cases where Mandiant identified the entry point. The second-place vector, however, marks a significant shift. Voice phishing climbed to 11 percent of engagements, displacing email phishing (which dropped to six percent) as adversaries discovered that a well-crafted phone call to a help desk bypasses every email security control an organization has deployed.

Advertisement

CyberTech Your brand belongs here. Reach the decision-makers who read CyberTech every day. Premium placements across the site and newsletter. Advertise with us

The rise of vishing aligns with the operational model of groups like UNC3944, which Mandiant tracks as a primary practitioner of help desk social engineering. These actors call IT support teams, impersonate employees, and convince staff to reset MFA or issue temporary credentials. The tactic circumvents technical controls entirely because the attack surface is human process, not software.

Prior Compromise Fuels Ransomware Acceleration

The report identifies “prior compromise” as the initial vector in 30 percent of ransomware engagements, up from 15 percent the previous year. This doubling confirms what the 22-second handoff figure implies at an operational level: ransomware operators are purchasing pre-staged access at scale rather than conducting their own reconnaissance and exploitation. The access broker ecosystem has matured into a reliable supply chain where credentials, sessions, and footholds are commodities traded on closed marketplaces with service-level expectations.

Recovery Denial Replaces Simple Encryption

Mandiant observed a tactical evolution in extortion campaigns away from straightforward file encryption toward what the report terms “Recovery Denial.” Modern operators systematically destroy an organization’s ability to restore operations by targeting Active Directory Certificate Services, deleting backup objects from cloud storage, and compromising hypervisor management planes. The shift means that even organizations with tested backup strategies face extended outages if those backups depend on infrastructure the attacker has already mapped and undermined.

AI Enters Live Operations

The report documents two malware families, PROMPTFLUX and PROMPTSTEAL, that actively query large language models during execution to generate evasion logic or modify payloads on the fly. A third tool, QUIETVAULT, specifically scans compromised developer machines for local AI command-line utilities and their cached authentication tokens. While 2025 was not the year where breaches were directly caused by AI, Mandiant’s findings confirm that adversaries have moved from experimenting with generative models to integrating them into production toolchains.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

Dwell Time Rises for Espionage, Falls for Ransomware

Global median dwell time rose to 14 days from 11 the previous year, but that aggregate masks a divergence. Cyber espionage and nation-state intrusions, particularly those linked to North Korean IT worker schemes, carried a median dwell time of 122 days. Financially motivated intrusions, by contrast, moved faster than ever, reflecting the compressed handoff timelines and automated tooling that define the current ransomware ecosystem.

What This Means for Security Leadership

Three operational shifts follow from the report’s data. First, playbooks built around sequential triage stages cannot accommodate a 22-second adversary handoff. Detection engineering must assume that the initial alert and the escalation to a different threat actor happen simultaneously, not sequentially. Second, backup infrastructure requires the same hardening and monitoring as production systems. Recovery Denial works because backup systems are often treated as out-of-band infrastructure with lighter access controls. Third, voice channel authentication deserves the same investment that organizations have spent on email security over the past decade. A help desk that will reset MFA based on a phone call is functionally equivalent to an unpatched internet-facing appliance.

The complete M-Trends 2026 report is available as a free download from Google Cloud Security.

Source: Google Cloud Threat Intelligence Blog.