Η Check Point Software Technologies Ltd., a cloud-delivered artificial intelligence cybersecurity company, has released its June 2025 Global Threat Index, highlighting the rise of new and evolving threats.
Η Check Point Research revealed that AsyncRAT, a remote access Trojan (RAT), which climbed into the top 3 of the top malware threats this month, exploits Discord invite links to distribute malicious payloads. Meanwhile, FakeUpdates remains the most prevalent malware, continuing to impact organizations around the world.
Furthermore, the team qilin ransomware remains a significant player in the cybercrime scene, with targeted attacks on big companies, especially in the areas of health care and of education.
As cybercriminals become increasingly sophisticated, organizations must stay ahead of evolving threats with multi-layered security solutions. The Global Threat Index June 2025 emphasizes the need to take preventive measures to protect against the most advanced attacks of the year.
Ο By flight finkelstein, Director of Threat Intelligence at Check Point Software, commented:
"The campaign AsyncRAT and the continued dominance of FakeUpdates show the evolving complexity of cyberattacks. With the advent of dominant groups ransomware, like the qilin, we are seeing more targeted and sophisticated approaches to data theft and encryption. Organizations must be proactive in their defense, implementing real-time threat information and integrated security strategies”.
Key findings
- The AsyncRAT continues to hold a high position in the threat ranks in June 2025, exploiting trusted platforms like Discord for payload delivery and data leakage. It allows attackers to remotely access and control infected systems.
- FakeUpdates, still the most widespread malware worldwide, is associated with the Evil Corp hacker group and spreads via drive-by downloads. It delivers various secondary payloads after infection.
- The qilin, a team ransomware-as-a-service, continues to target high-value industries such as healthcare and education, using phishing emails to infiltrate networks and encrypt sensitive data.
Top Malware Families
- FakeUpdates – FakeUpdates remains the most prevalent malware, affecting 4% of organizations worldwide. This downloader malware is used to install fake updates, allowing attackers to deploy secondary payloads on compromised systems.
- Androxgh0st – Androxgh0st, a Python-based malware, scans for exposed .env files to steal sensitive credentials from applications running on the Laravel PHP framework. It uses a botnet for cloud exploitation and cryptocurrency mining.
- AsyncRAT – AsyncRAT, a remote access Trojan (RAT), has gained rapidly increasing visibility. It is used to steal data and compromise the system, allowing attackers to execute commands such as downloading additional programs, killing processes, and taking screenshots.
Top Ransomware Groups
- Qilin – Qilin (also known as Agenda) remains the leading ransomware group, responsible for 17% of attacks in June 2025. This ransomware-as-a-service group specializes in targeting large enterprises, particularly in the healthcare and education sectors.
- SafePay – SafePay continues to be a significant ransomware threat, using a dual-extortion model to encrypt victims’ files while also stealing sensitive data. This ransomware group has been active against both large organizations and small businesses.
- Akira – Akira ransomware exploits vulnerabilities in VPN endpoints, encrypting data with a distinctive “.akira” extension. It primarily targets businesses with weak or outdated security measures.
Top Mobile Malware
- Anubis – The Anubis is the most widespread mobile malware, known for its ability to bypass multi-factor authentication (MFA) and steal banking credentials. It is often distributed through malicious apps available on the Google Play Store.
- AhMyth – The AhMyth, a remote access Trojan (RAT) for Android, masquerades as legitimate applications and provides attackers with access to extract banking credentials, MFA codes, and perform keylogging and screen recording.
- Necro – The Necro is a malicious downloader that can execute harmful commands on Android devices, including downloading malware and advertisements, as well as redirecting web traffic through compromised devices, turning them into part of a botnet.
Top-Attacked Industries
- Education – The education sector remains the most targeted globally, as educational institutions are vulnerable to attacks due to their large number of users and critical infrastructure.
- Government – Government organizations continue to be prime targets due to their sensitive data and public sector responsibilities.
- Telecommunications – The telecommunications sector faces ongoing threats as cybercriminals target its vast volume of sensitive data and communications infrastructure.
The June 2025 Global Threat Index highlights the rise of multi-stage malware campaigns and the increasing sophistication of ransomware groups like Qilin.
As FakeUpdates continues to be the most prevalent malware, additional threats such as AsyncRAT and Qilin ransomware require urgent attention.
Organizations in the education, government, and telecommunications sectors remain the most vulnerable. It is clear that as cybercriminals evolve their tactics, organizations must adopt comprehensive, proactive security measures to protect against these advanced threats.
For the full June 2025 Global Threat Index and additional information, visit Blog of Check Point.
Although the press releases will range from very select to rare, I said I'd pass...because sometimes the editors hide.

