logo

Ransomware: Tactical Evolution Fuels Extortion Epidemic

ID: 960579e5-b33f-51c8-bd7a-09475c9ee803

STIX ID: report--960579e5-b33f-51c8-bd7a-09475c9ee803

Feed Name: security.com

Threat Score
88/100

Date Published: 2026-01-14

Date Updated: 2026-04-29

Author: Threat Hunter Team

...
...

The Symantec Threat Hunter Team reports record-high extortion activity in 2025 driven by a rise in encryptionless data-theft extortion (notably campaigns by Snakefly/Cl0p and ShinyHunters) alongside sustained ransomware operations; a critical Oracle E-Business Suite zero-day (CVE-2025-61882) was actively exploited, LockBit and RansomHub collapsed leading to growth of Akira, Qilin, Safepay and DragonForce, and attackers increasingly rely on living-off-the-land and dual‑use remote-access tools for lateral movement and exfiltration — mitigation guidance is provided via the Symantec Protection Bulletin.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.