logo

Last Year in Ransomware: Major Developments, Targeted Industries, Linux Variants

ID: fb1a98dc-8b55-574e-8e0e-9edff76ff312

STIX ID: report--fb1a98dc-8b55-574e-8e0e-9edff76ff312

Feed Name: Halcyon Blog

Threat Score
78/100

Date Published: 2025-03-25

Date Updated: 2026-04-28

...
...

The report reviews 2024 ransomware developments: major law-enforcement disruptions of BlackCat/ALPHV and LockBit (Operation Cronos) provided decryption keys and operational intelligence, but a new RaaS group, RansomHub, rapidly filled the void and became highly active; concurrently Linux-targeted ransomware variants (ESXi-focused strains, Mallox Linux, Helldown) expanded the attack surface. It highlights industry impacts (notably healthcare, manufacturing, construction), attack methods (phishing, vuln exploitation, credential theft, network mapping), published IoCs and advisories, and emphasizes that while takedowns demonstrated international cooperation success, persistent and evolving threats require continued vigilance and cross-sector defensive improvements.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.