Crystal Ball Series

Published On : 2026-08-03
Share :
Crystal Ball Series

Crystal Ball Series

MID-YEAR 2026 UPDATE

Infrastructure attribution will eclipse malware analysis

PREDICTION TRACKING: VALIDATED -ON TRACK

What we said vs. what 2026 is showing

WE PREDICTED (Jan 2026)
<10-15% of cases need malware RE 90%+ attribution from identity, cloud and infrastructure telemetry Malware becomes disposable loader logic

WHAT’S HAPPENING NOW

79% of detections are malware-free ~90% of IR cases involve identity loopholes Investigations hinge on identity/cloud logs Telemetry gaps doubled year over year

Mid-year evidencе

79% of detections are malware-free, up from 40% in 2019

~90% of Unit 42 IR cases involved identity loopholes

67% of incidents began with identity compromise, not malware 2x

2x increase in telemetry gaps missing logs now #2 IR factor

OUR UPDATED POSITION
On track. Investigations have shifted decisively to identity, cloud and infrastructure telemetry, while binaries are increasingly disposable. Log retention, API/audit visibility and infrastructure correlation are now the core of attribution. Treat identity and cloud telemetry as tier-1 forensic evidence and extend retention well beyond default windows.

By analyzing past behavior helps us assess Predictive threat Intelligence

Reverse engineering required in ~50%+ of high-severity incidents

Between 2024-2025~20-30% of incidents involve a recoverable malicious binary

Preemptive External Threat Landscape Management

In 2026 and beyond <10-15% of cases will require malware reverse engineering