Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationai-enabled-threat-activityhacktivist-operationstate-sponsored-espionage

AI-Driven Ransomware and Extortion Surge in Europe

Updated 3mo agoFirst seen Nov 7, 20252 sources

European organizations are experiencing a significant increase in ransomware and extortion attacks, with threat actors leveraging artificial intelligence to accelerate and enhance their operations. According to CrowdStrike’s 2025 European Threat Landscape Report, Europe now accounts for nearly 22% of global ransomware and extortion victims, making it the second most targeted region after North America. AI is enabling adversaries to breach networks and deploy ransomware more quickly, with groups like SCATTERED SPIDER reducing their attack cycle to approximately 24 hours. The most targeted countries include the United Kingdom, Germany, France, Italy, and Spain, and affected sectors span manufacturing, professional services, technology, and retail. Attackers are also employing advanced social engineering tactics, such as fake CAPTCHA lures, to compromise victims.

The report also highlights a rise in hacktivism and nation-state cyber operations, particularly from Russian and North Korean actors, amid ongoing geopolitical tensions. Russian threat actors have shifted focus toward Ukraine and related regions since the 2022 invasion, while North Korea is reportedly supporting Russian operations and targeting Ukraine. The European threat landscape is described as increasingly complex, with eCrime, espionage, and disruptive attacks posing significant risks to both public and private sector organizations. Security teams are urged to adapt to the evolving threat environment, where AI-driven automation and deception are reshaping the speed and scale of cyberattacks.

Share:
AI-Driven Ransomware and Extortion Surge in Europe
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Nov 7, 20258mo ago

CrowdStrike details intensified nation-state cyber activity in Europe

The report identified heightened operations by Russia-, China-, Iran-, and North Korea-linked actors in Europe, including groups tied to the Ukraine conflict and named clusters such as Pulsar Kitten, Haywire Kitten, Vertigo Panda, Vixen Panda, and Velvet Chollima.

Report warns AI is accelerating ransomware operations in Europe

CrowdStrike said AI is helping cybercriminals speed up intrusions, ransomware deployment, and social engineering, citing tactics such as fake CAPTCHA lures and activity associated with groups like SCATTERED SPIDER.

Nov 6, 20258mo ago

CrowdStrike publishes its 2025 European Threat Landscape Report

CrowdStrike released its 2025 European Threat Landscape Report, describing a rise in extortion and ransomware across Europe, increased nation-state activity, and elevated risk in countries such as the U.K., Germany, Italy, France, and Spain.

Jan 1, 20242y ago

Europe records more than 2,100 ransomware and extortion victims

From January 2024 onward, Europe accounted for nearly 22% of global ransomware and extortion victims, with more than 2,100 incidents affecting sectors including manufacturing, professional services, technology, and retail.

Feb 24, 20224y ago

Russia's 2022 invasion of Ukraine reshapes Russian cyber targeting

Since Russia's 2022 invasion of Ukraine, Russian threat actors shifted more of their cyber focus toward Ukraine and conflict-related targets, according to CrowdStrike's later assessment of the European threat landscape.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

18 LINKEDOpen in app
Organizations
10 linked
CrowdStrikeVixen PandaHaywire KittenScattered SpiderVelvet ChollimaPulsar KittenVertigo PandaNorth Korean adversariesDPRKRussia
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.