logo

Dragos Industrial Ransomware Analysis: Q1 2025

ID: 87b9e852-d78a-59cd-adeb-58bca188c9b4

STIX ID: report--87b9e852-d78a-59cd-adeb-58bca188c9b4

Feed Name: Dragos Blog

Threat Score
88/100

Date Published: 2025-05-21

Date Updated: 2026-04-27

...
...

Q1 2025 Dragos ransomware landscape: Dragos observed 708 ransomware incidents impacting industrial sectors worldwide, driven by a surge in exploit-driven campaigns (notably Cl0p exploiting Cleo MFT), emergence of new groups (FunkSec, Lynx, DragonForce), and advanced TTPs including AI-enhanced phishing, encryption-less extortion, credential theft, EDR evasion, and active exploitation of zero-day and file-transfer vulnerabilities (CLFS, Cleo, CrushFTP), resulting in substantial operational and supply-chain impacts to manufacturing, transportation, and critical infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.