logo

Last Year in Ransomware: Threat Trends and Outlook for 2025

ID: 58a6b079-4928-5654-8aec-3fa008ed99cb

STIX ID: report--58a6b079-4928-5654-8aec-3fa008ed99cb

Feed Name: Halcyon Blog

Threat Score
78/100

Date Published: 2025-04-15

Date Updated: 2026-04-28

...
...

The report reviews ransomware trends heading into 2025, profiling active and emerging groups (Akira, RansomHub, Cl0p and others), describing shifts toward decentralised and encryption-less extortion, the growing use of AI for crafting attacks, and frequent exploitation of unpatched VPNs and web applications (notably several CVEs). It emphasizes living-off-the-land techniques, credential theft (e.g., Mimikatz), SIM swapping, and RaaS offerings that lower attacker skill barriers, and recommends capability-based defenses: faster patching, behavior-based detection, strong access controls, and updated security awareness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.