Ransomware 2025: Infostealers on the March
ID: 69d84a5e-59f5-58e2-be74-d17e7474240f
STIX ID: report--69d84a5e-59f5-58e2-be74-d17e7474240f
Feed Name: ReversingLabs Blog
ReversingLabs' H1 2025 Ransomware Feed analysis finds malware remains endemic: infostealers (including macOS-targeting strains) are surging while RAT detections decline and late-stage ransomware binaries grow; attackers are favoring direct deployment (more early-stage droppers/downloaders, fewer middle-stage trojans). Common techniques include discovery, obfuscation, DLL sideloading, sandbox evasion and process injection; the feed observed ~100k samples in six months with >98% unsigned, leading to the recommendation that enforcing application signing and early-stage detection can block the majority of campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
