CrowdStrike, an endpoint security vendor, publishes an annual Global Threat Report built from its own telemetry and incident response work. The 2026 edition calls 2025 the "year of the evasive adversary," and most of its named campaigns target large enterprises, governments, and critical infrastructure, not a 20-person Perth business. But underneath the nation-state material sits a pattern that applies at any size: attacks are getting faster, and less of them look like "malware" while they're happening.
The Number That Matters Most: 29 Minutes
"Breakout time", how long it takes an attacker to move from their initial foothold to higher-value systems, dropped to an average of 29 minutes in 2025, a 65% increase in speed on the year before. The fastest recorded breakout was 27 seconds.
The report includes a case study worth sitting with. An adversary the report calls CHATTY SPIDER called a U.S. law firm employee, posed as IT support, and talked them into granting remote access via Microsoft Quick Assist. Within four minutes, the attacker attempted to move data out using a file transfer tool. That attempt was blocked by a firewall rule, so the attacker simply switched to Google Drive instead, all within about an hour of the first phone call.
The practical takeaway isn't about that specific group, it's that a response measured in hours or days, checking logs the next business morning, isn't fast enough anymore. That's what continuous, automated monitoring is actually for, and it's the gap a tested incident response plan is meant to close.
82% of Attacks Don't Use "Malware" at All
CrowdStrike found 82% of the detections in its 2025 telemetry were malware-free, up from 51% in 2020. Attackers increasingly rely on valid credentials, trusted remote-access tools, and built-in administrative functions rather than a malicious file that antivirus software can flag. In the law firm example above, the tools involved, Quick Assist, WinSCP, Google Drive, are all legitimate software most businesses already trust.
This is precisely why signature-based antivirus alone increasingly misses real intrusions. Detecting behaviour that looks unusual, not just files that look malicious, is the job of endpoint detection and response, and it's a meaningfully different capability from the antivirus most small businesses already have installed.
Vishing Is Specifically Targeting Law Firms and Help Desks
CHATTY SPIDER's law firm targeting wasn't incidental, the report describes it as the adversary's primary focus throughout 2025. Separately, the report's most active ransomware operator, SCATTERED SPIDER, relies almost entirely on calling help desks and talking staff into resetting a password or multi-factor authentication on someone else's account.
Both patterns match what we've seen in the other 2026 breach reports: voice-based social engineering is now the hardest attack type for staff to filter and among the costliest when it succeeds, a theme we also covered in Verizon's 2026 breach report. For a law firm or accounting practice specifically, that means the habits we've written about before, verifying unusual requests through a second, known channel, and protecting trust account transactions against exactly this kind of impersonation, matter more than most other controls combined. It's also worth checking that whoever handles password or MFA resets for your business, whether that's an internal admin or an outsourced IT provider, has a verification step a phone call alone can't talk them past.
A Simpler Trick Worth Flagging to Staff: Fake "Verify You're Human" Pages
Not every technique in the report requires nation-state resources. CrowdStrike recorded a 563% increase in fake CAPTCHA pages used to trick people into downloading and running malware, replacing the fake browser update pop-ups that were common the year before. These pages imitate the routine "prove you're not a robot" check most staff click through without thinking, which is exactly why it works. It's a good, concrete example to add to staff phishing training: not every threat arrives as a suspicious email attachment anymore.
What This Means for a Perth Business
One detail worth a brief mention for local context: the report notes a China-nexus group compromised VPN appliances at organisations across several countries including Australia during 2025, as part of a broader pattern of targeting network edge devices for long-term access. That specific campaign is aimed at large, strategically valuable targets, not typical SMBs, but it's a reminder that unpatched edge devices like VPNs and firewalls are attractive to attackers precisely because they're often the least monitored part of a network.
- Assume a response has to happen in minutes, not the next business day. A 29-minute average breakout time means manual, occasional monitoring is no longer a real defence.
- Don't rely on antivirus alone. Most detections last year involved no malicious file at all, only stolen credentials and everyday tools used the wrong way.
- Train staff, and IT support, on vishing specifically. A phone call impersonating IT support is now a proven way in, particularly against professional services firms.
- Patch internet-facing devices first. VPNs, firewalls, and other edge devices remain a preferred entry point precisely because they're easy to forget about.
Frequently Asked Questions
What does "malware-free" mean, and why is it concerning?
It means an attacker got in and moved around using legitimate tools and stolen credentials, rather than a malicious file a security scanner could flag. CrowdStrike's 2026 report found 82% of detections were malware-free, up from 51% in 2020. Traditional antivirus, which mostly looks for known-bad files, misses this kind of activity, which is why endpoint detection and response (EDR) that watches for unusual behaviour matters more than ever.
What is vishing, and why are law firms specifically being targeted?
Vishing is phishing done over the phone, an attacker calls pretending to be IT support, a help desk, or another trusted party to talk someone into an action like installing remote access software or resetting a password. CrowdStrike's report documents an adversary that primarily targeted law firms this way throughout 2025, likely because law firms hold sensitive client and trust account information and often have smaller in-house IT teams to double-check unusual requests.
What is "breakout time" and why does it matter for a small business?
Breakout time is how long it takes an attacker to move from their initial foothold to accessing more valuable systems. CrowdStrike's report found the average dropped to 29 minutes in 2025, with the fastest recorded breakout at 27 seconds. It matters because it shows manual, next-business-day security monitoring is no longer fast enough, a response needs to happen in minutes, which generally requires an automated or 24/7 managed service rather than someone checking logs occasionally.
Should a small Perth business be worried about the state-sponsored hackers mentioned in this report?
Not directly. Most of the named campaigns in CrowdStrike's report target large enterprises, government agencies, and critical infrastructure. What does apply regardless of size is the underlying pattern: faster attacks, less use of detectable malware, and social engineering aimed at help desks and staff, all of which affect a small business the same way they affect a large one.
We help Perth law firms and professional services businesses build the verification habits and monitoring that catch attacks measured in minutes, not days.
Cybersecurity Services →Not sure how fast your business would actually notice a breach?
Call 0433 087 091 for a free, no-obligation conversation about your current monitoring and response setup.
Book a Free ConsultationFor related reading, see Verizon's 2026 Data Breach Report, IBM's 2026 Breach Cost Report, and EDR vs Antivirus for Perth Businesses.
Source: CrowdStrike 2026 Global Threat Report. Statistics, adversary names, and case details referenced in this article belong to CrowdStrike; for the full report, refer to it directly at crowdstrike.com/global-threat-report. This article is general information only, not a formal security assessment of your business.