logo

Halcyon Threat Insights 016: May 2025 Ransomware Report

ID: 86a12b73-94ad-59c2-a220-de9d6e648409

STIX ID: report--86a12b73-94ad-59c2-a220-de9d6e648409

Feed Name: Halcyon Blog

Threat Score
78/100

Date Published: 2026-03-02

Date Updated: 2026-04-28

...
...

Halcyon RISE's April 2025 intelligence summarizes widespread ransomware-related activity: targeted verticals (hospitals, manufacturing, finance), numerous hacktools and trojans detected as ransomware precursors (e.g., XMRig, JuicyPotato, NirSoft tools, Dnoper), multiple ransomware families and payloads blocked (Medusa/IMPS, BianLian, Lynx, Rhysida, RansomHub/Splinter), and a spotlight on Fog ransomware tactics including credential-based access, disabling backups/defenses, and double-extortion behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.