In mid-2025, ransomware incidents surged significantly, with the Qilin group leading the charge as one of the most aggressive and active threat actors. Intelligence gathered from Dark Web and Deep Web activity revealed that Qilin surpassed competing groups by strategically focusing on high-impact industries such as public administration, medical services, industrial production, and energy infrastructure. Their campaign has been strengthened by absorbing former RansomHub affiliates, resulting in highly sophisticated attacks. Key targets of the attack ranged from an autonomous region in Spain and a major healthcare provider in the United States to multinational companies operating across the UK, Japan, Singapore, and the U.S. The ASEC report indicates Qilin’s attacks now go beyond financial extortion, aiming for strategic disruption across industries. Alongside Qilin’s dominance, newer groups like Team XXX, Warlock, Global, W.A., and Kawa4096 are reshaping the Ransomware-as-a-Service (RaaS) landscape by acquiring tools and talent from defunct operations. Established ransomware groups Akira and Lynx have concentrated their efforts on industries reliant on global supply chains. Akira launched attacks against companies in Japan, the United States, and Germany, while Lynx set its sights on petrochemical and communications sectors in both the U.S. and Thailand. Geopolitical motives have entered the fray, most notably with APTiran’s attack on Israeli infrastructure, signaling a dangerous blend of political agendas with cybercrime. Groups such as Gunra, RHYSIDA, Anubis, and Arkana widened their reach to government agencies, nonprofits, and major entertainment brands, increasing both ransom leverage and reputational damage.
The OnionDrop loader campaign is a sophisticated malware operation that uses DLL sideloading to distribute multiple infostealers at scale. Attackers deliver a ZIP archive containin...
Cybersecurity researchers have uncovered new Windows-based variants of the SprySOCKS backdoor, a malware family previously associated with the China-linked threat actor Earth Lusca...
A cybercrime group tracked as UNC3753, which is also referred to by several aliases including Luna Moth, Chatty Spider, and Silent Ransom Group, has been carrying out targeted exto...