logo

Ransomware 2025: Infostealers on the March

ID: 69d84a5e-59f5-58e2-be74-d17e7474240f

STIX ID: report--69d84a5e-59f5-58e2-be74-d17e7474240f

Feed Name: ReversingLabs Blog

Threat Score
70/100

Date Published: 2025-09-09

Date Updated: 2026-04-29

Author: Ashlee Benge

...
...

ReversingLabs' H1 2025 Ransomware Feed analysis finds malware remains endemic: infostealers (including macOS-targeting strains) are surging while RAT detections decline and late-stage ransomware binaries grow; attackers are favoring direct deployment (more early-stage droppers/downloaders, fewer middle-stage trojans). Common techniques include discovery, obfuscation, DLL sideloading, sandbox evasion and process injection; the feed observed ~100k samples in six months with >98% unsigned, leading to the recommendation that enforcing application signing and early-stage detection can block the majority of campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.