logo

Ransomware Under Pressure: Tactics, Techniques, and Procedures in a Shifting Threat Landscape

ID: 35eb5fd5-4938-5ef9-b2f2-5d591bef3c35

STIX ID: report--35eb5fd5-4938-5ef9-b2f2-5d591bef3c35

Feed Name: Threat Intelligence

Threat Score
78/100

Date Published: 2026-03-16

Date Updated: 2026-04-27

Author: Google Threat Intelligence Group

...
...

This report summarizes the 2025 ransomware landscape observed by Mandiant/GTIG, highlighting that exploitation of VPNs and firewalls was a common initial access vector, 77% of analyzed intrusions involved suspected data theft, targeting of virtualization infrastructure rose to ~43% of incidents, and REDBIKE and emergent RaaS brands (Qilin, Akira) were prominent; it also notes declining profitability for ransomware operators and recommends protection and containment strategies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.