Dragos Industrial Ransomware Analysis for the Fourth Quarter of 2025
ID: 0f563cf5-ddfc-5bd3-8cbb-8a54231b2d24
STIX ID: report--0f563cf5-ddfc-5bd3-8cbb-8a54231b2d24
Feed Name: Dragos Blog
Q4 2025 saw a material rise in ransomware and data-extortion activity against industrial organizations, with Dragos identifying 1,211 incidents concentrated among mature RaaS operations (Qilin, Akira, CL0P, Everest). Adversaries focused on enterprise IT systems that support OT (ERP, file-sharing, VPNs, identity services), leveraging compromised credentials, exposed remote access, and IAB-provided access to rapidly exfiltrate data and apply extortion pressure; impact was global and heavily skewed toward manufacturing and other low-tolerance-for-downtime sectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
