Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationcybercrime-service-ecosystemransomware-tooling-evolutioncritical-infrastructure-threat

Ransomware Threat Landscape and Ecosystem Evolution in 2025

Updated 3mo agoFirst seen Dec 24, 202511 sources

Ransomware in 2025 has evolved into a highly organized and profit-driven cybercrime ecosystem, with threat actors leveraging Ransomware-as-a-Service (RaaS), initial access brokers, and advanced extortion strategies. Attack volumes have reached record highs, with over 4,700 confirmed incidents through September and a notable increase in targeting of critical infrastructure, healthcare, and manufacturing sectors. The landscape is now fragmented among more than 85 active groups, and while victim disclosures have increased, ransom payments have dropped significantly as organizations improve their resilience and recovery capabilities. Attackers are increasingly using supply-chain compromises, zero-day exploits, and living-off-the-land techniques, making ransomware a persistent and adaptive threat.

The underground infrastructure supporting ransomware operations has also matured, with dark web forums like RAMP serving as central hubs for collaboration, recruitment, and intelligence sharing among major ransomware groups such as LockBit, DragonForce, and Medusa. These forums facilitate the rapid dissemination of new ransomware variants and operational tactics, contributing to the ecosystem's agility. Meanwhile, specific ransomware families like HardBit 4.0 continue to innovate, employing sophisticated techniques such as brute-forcing RDP/SMB services and using legacy malware like Neshta as droppers to evade detection and maintain persistence, underscoring the technical advancement and adaptability of modern ransomware campaigns.

Share:
Ransomware Threat Landscape and Ecosystem Evolution in 2025
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Jan 8, 20266mo ago

Emsisoft reports ransomware victim claims surpassed 8,000 in 2025

An Emsisoft report published in January 2026 said claimed ransomware victims worldwide rose by more than 50% versus 2023, exceeding 8,000 cases in 2025. Despite takedowns such as BlackSuit, the report found that smaller, unstable groups and social-engineering-driven intrusions kept overall ransomware activity growing.

Jan 6, 20266mo ago

Top-10 ransomware review confirms 2025 decentralization trend

A January 2026 review of the top ransomware groups of 2025 concluded that traditional RaaS brands had lost influence as affiliates rotated between groups and shared infrastructure more freely. The report said attackers were using quieter, longer-dwell operations that enabled more precise data theft and extortion.

Jan 1, 20266mo ago

Briefing documents rise of exfiltration-only ransomware extortion

At the start of 2026, researchers reported a growing shift from encryption-based ransomware to pure data exfiltration and extortion. Attackers were said to abuse legitimate cloud services and administrative tools to steal data quietly, often leaving little forensic evidence and increasing regulatory and reputational pressure on victims.

Dec 29, 20256mo ago

Researchers warn ransomware entry points expanded beyond the perimeter

A briefing published at the end of 2025 described attackers increasingly gaining access through cloud misconfigurations, supply-chain weaknesses, social engineering on platforms like Microsoft Teams, and abuse of legitimate IT tools. It also highlighted evasion methods such as safe mode encryption, telemetry suppression, and BYOVD to bypass defenses.

Dec 25, 20256mo ago

Analysis finds 2025 ransomware shifted to fewer, higher-value targets

A late-2025 industry briefing reported that ransomware operators were increasingly pursuing fewer but more lucrative victims, using business-like RaaS models, data theft, supply-chain pressure, and layered extortion. The shift was associated with lower payment rates but larger overall payouts and greater impact per incident.

Dec 23, 20256mo ago

RAMP forum identified as a key hub for ransomware collaboration

Researchers highlighted RAMP (Russian Anonymous Marketplace) as a major dark web forum used by ransomware operators, affiliates, and brokers for recruitment, trading, and coordination. The forum was noted as an early source of signals on campaigns involving groups such as DragonForce, Qilin, Medusa, Eldorado, GLOBAL Group, and LockBit.

HardBit 4.0 ransomware emerges with new evasion and access tactics

By late 2025, HardBit released version 4.0, adding a multi-stage deployment chain, use of the Neshta file-infecting virus as a dropper, Windows Defender disabling, and passphrase-gated execution to hinder analysis. The group continued to rely on brute-force access to exposed RDP and SMB services, followed by credential harvesting, lateral movement, and persistence via registry changes and hidden files.

Dec 31, 20241y ago

Dominant ransomware groups disrupted, fragmenting the ecosystem

Following disruptions of major ransomware groups in 2024, the 2025 ecosystem became more fragmented and decentralized. Affiliates increasingly operated independently, reused tools across brands, and made attribution and disruption harder for defenders.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

49 LINKEDOpen in app
Malware
2 linked
Affected products
8 linked
RclonePowershellAzureBitbucketWindows DefenderTeamsFortigateScreenconnect
Organizations
10 linked
EmsisoftMorphisecInternational Business MachinesSecureworksFortinetGartnerSOCRadarPicus SecurityMicrosoft CorporationSonicwall
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.