Extortion and Ransomware Trends January-March 2025

Extortion and Ransomware Trends January-March 2025

This report from Unit 42 outlines evolving trends in ransomware and extortion, revealing that 86% of incidents cause business disruption. Key observations include the collaboration between nation-state actors and ransomware groups, the use of tools to disable security measures, and a rise in insider threats. The report highlights the importance of proactive measures against these threats. Affected: Organizations, Cybersecurity Sector, Various Industries

Keypoints :

  • 86% of ransomware incidents result in business disruptions.
  • Threat actors often exaggerate their claims to manipulate victims.
  • Nation-state actors are increasingly collaborating with ransomware groups.
  • Ransomware attacks target a broader range of systems, including cloud environments.
  • Insider threats are leveraging their positions for extortion.
  • Palo Alto Networks provides tools to enhance ransomware protection for its customers.
  • Proactive assessments can help organizations mitigate ransomware threats.

MITRE Techniques :

  • Initial Access (T1078) – Actors exploit misconfigurations and weak credentials to gain unauthorized access to systems.
  • Defense Evasion (T1027) – Ransomware actors utilize EDR killers to disable security sensors and operate undetected.
  • Impact (T1486) – Ransomware actors encrypt data as part of their extortion tactics to force ransom payments.
  • Insider Threat (T1086) – North Korean actors use fake identities to infiltrate organizations and leverage inside information for extortion.

Indicator of Compromise :

  • No IoCs Found

Full Story: https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/