logo

Ransomware and Cyber Extortion in Q2 2025

ID: e7f072f5-1b37-593d-b539-f8bf064ab79a

STIX ID: report--e7f072f5-1b37-593d-b539-f8bf064ab79a

Feed Name: ReliaQuest Blog

Threat Score
78/100

Date Published: 2025-07-03

Date Updated: 2026-04-29

...
...

Q2 2025 ransomware landscape: Emerging RaaS actors Qilin and Akira surged by leveraging mass exploitation of critical CVEs (e.g., FortiOS/FortiProxy, SonicWall, Cleo) and automation to rapidly compromise organizations and post victims to data-leak sites; the report details victimology (US-heavy, rising German targeting), exploited CVEs, attacker tactics (credential theft, RMM and SSH misuse, automated discovery), operational trends (affiliate models, site defacements), and prescribes actionable defenses including asset discovery, prioritized patching, MFA, RMM minimization, and network segmentation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.