This report from Unit 42 outlines evolving trends in ransomware and extortion, revealing that 86% of incidents cause business disruption. Key observations include the collaboration between nation-state actors and ransomware groups, the use of tools to disable security measures, and a rise in insider threats. The report highlights the importance of proactive measures against these threats. Affected: Organizations, Cybersecurity Sector, Various Industries
Keypoints :
- 86% of ransomware incidents result in business disruptions.
- Threat actors often exaggerate their claims to manipulate victims.
- Nation-state actors are increasingly collaborating with ransomware groups.
- Ransomware attacks target a broader range of systems, including cloud environments.
- Insider threats are leveraging their positions for extortion.
- Palo Alto Networks provides tools to enhance ransomware protection for its customers.
- Proactive assessments can help organizations mitigate ransomware threats.
MITRE Techniques :
- Initial Access (T1078) – Actors exploit misconfigurations and weak credentials to gain unauthorized access to systems.
- Defense Evasion (T1027) – Ransomware actors utilize EDR killers to disable security sensors and operate undetected.
- Impact (T1486) – Ransomware actors encrypt data as part of their extortion tactics to force ransom payments.
- Insider Threat (T1086) – North Korean actors use fake identities to infiltrate organizations and leverage inside information for extortion.
Indicator of Compromise :
- No IoCs Found
Full Story: https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/