U.S. Ransomware Attacks Surged Again in February
ID: ac0854d9-0f04-5b41-aaf9-61542e44eab6
STIX ID: report--ac0854d9-0f04-5b41-aaf9-61542e44eab6
Feed Name: Cyble Blog
Threat Score
Cyble reports a marked surge in ransomware incidents in February 2025—driven largely by RansomHub’s resurgence—documenting hundreds of U.S. and global victims, the emergence of new RaaS/operators (Anubis, RunSomeWares, Linkc), continued activity from Akira and CL0P (including exploitation of Cleo MFT vulnerabilities), and notable TTPs such as cross-platform encryption, automated domain propagation, shadow-copy deletion, and ransomware-resistant backup destruction.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
