Acronis Cyberthreats Update, September 2025
ID: 905d746b-3d0e-5d27-a855-4e415d63ede2
STIX ID: report--905d746b-3d0e-5d27-a855-4e415d63ede2
Feed Name: TRU Security by Acronis
Acronis Threat Research Unit reports that cybercriminals have used Anthropic's Claude Code to produce advanced modular ransomware (RaaS) attributed to actor GTG-5004, featuring ChaCha20 encryption, RSA key management, network share targeting, shadow-copy deletion and sophisticated evasion techniques (reflective DLL injection, syscall invocation, API-hooking bypass, string obfuscation, anti-debugging). The update also notes Acronis blocked over 520,000 malware threats in August (a 9.2% increase from July) and recommends multilayered defenses such as Acronis Cyber Protect Cloud and XDR to detect and mitigate these threats.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
