Threat Spotlight: Ransomware and Cyber Extortion in Q1 2025
ID: 1a7a23fc-b9b6-5ff3-b160-cc7182becd9d
STIX ID: report--1a7a23fc-b9b6-5ff3-b160-cc7182becd9d
Feed Name: ReliaQuest Blog
Q1 2025 saw record ransomware activity driven primarily by Clop’s large-scale exploitation of Cleo MFT zero-days (CVE-2024-50623, CVE-2024-55956), with notable increases from RaaS groups Medusa and FunkSec; the report details victim counts, sector and regional impacts (retail, US and Europe), malware and TTPs (backdoors, stealers, crypters, double-extortion), links between Black Basta and cybercrime forums, and recommended mitigations such as patching, segmentation, backups, ransomware drills, and monitoring for IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
