Truesec Threat Intelligence Report 2025

Truesec Threat Intelligence Report 2025
Truesec’s 2025 Threat Intelligence Report shows that cybersecurity investments are helping some large Nordic enterprises reduce ransomware impact, while attackers shift toward smaller organizations, identity-based intrusions, data theft, and AI-assisted social engineering. The report also highlights major law-enforcement disruptions of criminal infrastructure, escalating geopolitical cyber sabotage, and the growing use of ransomware-as-a-service by groups such as BlackCat, LockBit, RansomHub, and Cicada3301. #BlackCat #LockBit #RansomHub #Cicada3301 #Truesec #XZ #Tietoevry #OperationCronos #OperationEndgame #OperationSynergiaII

Keypoints

  • Annual threat intelligence reports typically begin with an executive message, followed by an overview of the organization, then thematic sections covering threat trends, intrusion methods, extortion, espionage, sabotage, emerging technologies, supply chain risk, and practical guidance or outlook for the year ahead.
  • This report follows that structure closely, combining leadership context, Truesec’s background, incident-response data, sector analysis, malware and actor research, law-enforcement developments, and forward-looking assessments for 2025.
  • A major finding is that 2024 showed positive effects from increased cybersecurity investment in the Nordics, especially among large enterprises, but intrusion attempts remained at roughly the same level as the previous year, indicating that threats are not declining.
  • More than 40% of ransomware incidents started with exploitation of vulnerabilities in internet-facing security products such as VPNs and firewalls, while the majority of the rest began with identity-based attacks such as stolen credentials, brute force, and information-stealing malware.
  • The report states that over 90% of Truesec’s ransomware incident engagements in 2024 could likely have been prevented through blocking password guessing, enforcing MFA, and maintaining active vulnerability management.
  • Cybercriminals are increasingly opportunistic: as larger enterprises harden defenses, attackers are shifting toward smaller organizations that have weaker security, less monitoring, and fewer resources.
  • Business Email Compromise remains a major fraud vector and usually begins with phishing, credential theft, or token theft, allowing attackers to quickly hijack mailboxes and send fraudulent payment instructions.
  • Cyber extortion is broader than ransomware alone and increasingly includes data leak threats and DDoS-based pressure, with attackers choosing victims based on how much they depend on availability, confidentiality, or customer trust.
  • The report highlights a clear move from noisy ransomware toward “silent” intrusions in enterprise environments, where the goal is increasingly data theft, espionage, or supply-chain compromise rather than immediate disruption.
  • Law enforcement and private-sector cooperation had a major impact in 2024 through operations such as Operation Cronos, Operation Dark Hunt, Operation Nova, Operation Synergia II, and Operation Endgame, which dismantled infrastructure tied to LockBit, IcedID, Smokeloader, Pikabot, Bumblebee, HIVE, Dharma, and others.
  • Operation Cronos alone took down 34 servers and froze more than 200 cryptocurrency accounts linked to LockBit, while Operation Synergia II dismantled over 22,000 malicious IPs and servers and led to 41 arrests.
  • The report notes that criminal ecosystems are resilient: even after major takedowns of BlackCat and LockBit infrastructure, new ransomware-as-a-service groups such as RansomHub and Cicada3301 emerged.
  • Cicada3301 is analyzed as a Rust-based ransomware-as-a-service operation targeting Windows and Linux/ESXi systems, with strong similarities to ALPHV/BlackCat in code, encryption behavior, and operational patterns.
  • The report identifies valid-credential abuse, likely brute-forced against a Net-Support Manager appliance, and possible links to the Brutus botnet and password-guessing campaigns against VPN solutions.
  • Small and medium-sized businesses are a major concern because they make up about 99% of Nordic companies and contribute around 51.4% of Swedish GDP value added, yet often lack advanced security, dedicated staff, patch discipline, and backup maturity.
  • Recommended SMB defenses include outsourcing where necessary, keeping systems updated, enforcing strong authentication everywhere, securing offline backups, and considering cyber insurance, which has become more accessible and reportedly dropped about 30% in price over the last 12 months.
  • The AI section stresses that generative AI is amplifying attacks by making phishing, malware development, and reverse engineering easier, while deepfake voice and video are emerging as high-impact tools for CEO/CFO fraud that can exceed €10 million per incident.
  • The report also warns that AI expands the attack surface through insecure AI deployments, exposed data, and framework vulnerabilities such as CVE-2023-48022 affecting the Ray AI framework.
  • Supply-chain risk is shown as a major systemic issue, with the XZ backdoor and the Tietoevry ransomware incident demonstrating how one compromise can cascade into disruption for governments, healthcare, municipalities, retailers, and public services.
  • On the policy and compliance side, the report argues that cybersecurity and privacy must go beyond documentation and regulatory checklists, warning that Goodhart’s Law can make organizations focus on compliance metrics rather than real protection.
  • The geopolitical outlook for 2025 expects continued cyber sabotage, hybrid warfare, and increased pressure from Russia, China, Iran, and North Korea, alongside more use of cybercrime to finance state-linked activities and influence operations.
  • Key recurring themes across the report are the need for MFA, patching, logging, visibility, backups, incident reporting, supply-chain assurance, and public-private collaboration to stay ahead of fast-changing, financially motivated, and geopolitically driven threats.
Source: Awesome Annual Security Reports - The reports in this collection are limited to content which does not require a paid subscription, membership, or service contract. (https://github.com/jacobdjwilson/awesome-annual-security-reports/)

Download Report from Github