logo

Dragos Industrial Ransomware Analysis: Q4 2024

ID: 5d367130-1b74-5f92-b38e-888c0cbbc057

STIX ID: report--5d367130-1b74-5f92-b38e-888c0cbbc057

Feed Name: Dragos Blog

Threat Score
85/100

Date Published: 2025-02-11

Date Updated: 2026-04-27

...
...

Dragos' Q4 2024 ransomware landscape describes an increasingly fragmented and dynamic ransomware ecosystem targeting industrial organizations, where RaaS operators and newly rebranded groups leverage exploited vulnerabilities (Veeam, Cleo, VPNs, firewalls, backup solutions), living-off-the-land techniques, cloud-based exfiltration, and RMM tools to cause operational disruptions. The report documents high-impact incidents (e.g., RECOPE, Stoli Group, Pittsburgh Regional Transit), sectoral concentration in manufacturing and transportation, regional distributions (North America dominant), and recommends mitigations such as MFA, offline backups, hardened remote access, personnel training, and threat intelligence sharing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.