Akira, Cl0p Top List of 5 Most Active Ransomware-as-a-Service Groups
ID: a0c45be2-bf7c-53f3-a062-872a2c1230bd
STIX ID: report--a0c45be2-bf7c-53f3-a062-872a2c1230bd
Feed Name: Dark Reading
### Executive summary Flashpoint's mid‑2025 ransomware recap reports a 179% increase in ransomware incidents compared to H1 2024, driven by the RaaS model that enables lower-skilled affiliates. The report identifies top RaaS groups (Cl0p, Akira, Qilin, RansomHub), notes exploitation of unpatched and zero-day vulnerabilities in managed file transfer and remote monitoring tools, describes living‑off‑the‑land post‑compromise techniques, and highlights early, limited use of AI by some groups for phishing and tooling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
