Extortion and Ransomware Trends January-March 2025
ID: 94779b5f-5219-53f6-a38b-9347b1a74248
STIX ID: report--94779b5f-5219-53f6-a38b-9347b1a74248
Feed Name: Palo Alto Networks Unit 42
Unit 42 provides a high-level analysis of ransomware and extortion trends observed in early 2025, reporting hundreds of leak-site disclosures and notable shifts in attacker behavior: threat actors exaggerating or fabricating compromises, collaboration between North Korean state-sponsored groups and ransomware actors, adoption of tools that disable endpoint security (EDR killers), expanded targeting of cloud/Linux/ESXi/macOS environments, and insider-facilitated extortion. The report includes leak-site activity by family, monthly and country/industry breakdowns, and recommended defensive measures and Palo Alto Networks protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
