Are ransomware and encryption still the defining signals of modern cyberattacks, or has the industry become too focused on the noise, missing a more dangerous shift happening quietly around them? According to the new Red Report 2026 from Picus Labs, which analyzed over 1.1 million malicious files and mapped 15.5 million hostile actions observed in 2025, attackers are no longer focused on disruption.
See also: Warlock Ransomware breached SmarterTools

Instead, their goal is now long-term, invisible access. To be clear, ransomware isn't going anywhere, and hackers continue to innovate.
But the data shows a clear strategic shift away from noisy, disruptive attacks toward techniques designed to evade detection, remain within environments, and silently exploit identity and trusted infrastructure. Instead of invading and burning systems, today’s attackers increasingly behave like Digital Parasites. They live inside the host, feeding on credentials and services, and remain invisible for as long as possible.
Public attention often turns to dramatic disruptions and visible impact. This year’s Red Report data tells a quieter story, one that reveals where defenders are truly losing sight. For the past decade, ransomware served as the clearest signal of cyberthreat. When your systems were locked down and your operations were frozen, the breach was unmistakable.
This signal is now losing its relevance. Year over year, Data Encrypted for Impact (T1486) has declined by 38%, from 21.00% in 2024 to 12.94% in 2025. This decline does not indicate a decrease in attacker capability. Rather, it reflects a deliberate shift in strategy. Rather than locking up data to force payment, malicious actors are turning to data extortion as their primary profit model.
See also: BridgePay: Ransomware attack behind outage

By bypassing encryption, attackers keep systems operational while:
- Silently extract sensitive data
- They collect credentials and badges
- They remain embedded in environments for extended periods
- They apply pressure later through blackmail instead of interruption
The consequence is clear: impact is no longer defined by locked systems, but by how long attackers can maintain access to a host's systems without being detected.
As attackers turn to prolonged, silent persistence, identity becomes the most reliable path to control.
The Red Report 2026 shows that Credentials from Password Stores (T1555) appear in nearly one in four attacks (23.49%), making credential theft one of the most prevalent behaviors observed in the last year. Rather than relying on noisy credential dumping or complex exploit chains, attackers are increasingly extracting stored credentials directly from browsers, keychains, and password managers.
Once they have valid credentials, privilege escalation and lateral movement are usually just a few native management tools away. More and more modern malware campaigns behave like digital parasites. There are no alarms, no crashes, and no obvious indicators. Just an eerie silence. This same logic now shapes the art of attackers more broadly.
See also: DragonForce ransomware targets critical business infrastructure

80% of Top ATT&CK Techniques Now Prefer Silent Action Despite the breadth of the MITRE ATT&CK®, real-world malware activity continues to be concentrated around a small set of techniques that increasingly prioritize evasion and persistence.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
