Deep Dive Ransomware Analysis: 2025's Evolving Threat Landscape

Share

The 2025 Ransomware Landscape: Record Claims, Fragmented Gangs, and What It Mean

Article Type: Deep-dive analysis Target Audience: Security professionals, continuity planners, homelab and personal infrastructure operators Estimated Word Count: ~3,500 words Estimated Runtime: 12–15 min read Publish Channel: blog.malwlab.se Date: 2026-07-10

Introduction

The number 7,419 does not look dramatic at first glance. It is not a headline that makes you drop your coffee. But it represents a 32% increase over the previous year's record — the biggest single-year jump in documented ransomware victim claims since the modern ransomware economy took shape. And behind that figure sits a story about an industry in transition: gangs fracturing and re-forming, ransomware evolving beyond encryption into pure data extortion, manufacturing bearing the brunt of attacks that threaten physical operations, and a U.S. government starting to treat inadequate cybersecurity not just as a business failure but as civil fraud.

This article examines the 2025 ransomware landscape through data from Comparitech, Bitsight, Dragos, Halcyon, the Canadian Centre for Cyber Security, the UK NCSC, CISA, Barracuda, Fortinet, BlackFog, and Vectra AI. It translates enterprise-scale trends into actionable takeaways for operators of homelab and personal infrastructure — because the same attack patterns that hit a state government or a Fortune 500 manufacturer follow the same playbooks, and the defenses that work at scale apply in principle at the smaller end of the spectrum.

The Scale of the Threat — and Why the Numbers Disagree

Three different organizations counted ransomware victims in 2025 and produced three different numbers:

The variation — spanning over a thousand incidents — is not a data error. It reflects methodological differences that matter for anyone trying to understand what is actually happening. Comparitech manually verifies victim claims and distinguishes confirmed attacks (acknowledged by the target organization) from unconfirmed ones. Bitsight uses automated extraction from dark web leak sites and deduplicates claims. ransomware.live records every listing, confirmed or not, verified or fabricated.

The result is that no single number tells the whole story. The true attack volume is likely significantly higher than any of these figures. BlackFog estimates that approximately 86% of ransomware attacks went entirely undisclosed in 2025. If that estimate holds, the actual incident count may exceed 50,000 — making ransomware one of the most prevalent cyber threats of the year by a wide margin.

Three structural drivers explain the 32% surge:

1. The RansomHub collapse. In early April 2025, after dominating the ransomware market since mid-2024 at roughly 75 victims per month and maintaining ~230 active leak-site listings, RansomHub went dark on April 1, 2025 (with SOC in a Box confirming total site silence). Over 280 of its affiliates redistributed across Qilin — which surged 71.4% in activity from March to April as those affiliates came online and Group-IB's analysis identified Qilin as the primary destination for former RansomHub affiliates — Akira, Play, and emerging groups — fragmenting the market but not the threat. More hands were on the keyboard, not fewer.

2. CVE-2025-61882 in Oracle E-Business Suite. On October 4, 2025, Oracle released an out-of-cycle security advisory for CVE-2025-61882 — a critical pre-authentication remote code execution vulnerability in Oracle E-Business Suite's Concurrent Processing product (specifically the BI Publisher Integration component). The exploit chains server-side request forgery (SSRF), CRLF injection, authentication bypass, and unsafe XSLT processing to achieve unauthenticated code execution. Cl0p exploited this CVE in targeted extortion campaigns against organizations running affected versions of Oracle EBS (12.2.3 through 12.2.14).

3. Proliferation of new groups. Seventy-three new ransomware groups emerged in 2025 alone. The Top 10's share of total victims declined from 71% in Q1 to 56% in Q3 — market fragmentation, yes, but fragmentation means more attackers operating with less internal coordination and more incentive to shoot first and ask questions later.

The Evolving Threat Landscape: Gangs, Fragmentation, and the RaaS Economy

The Top Players

Comparitech's full-year 2025 rankings for the most prolific ransomware groups:

Qilin leads by a meaningful margin. Akira follows, benefiting from the RansomHub affiliate exodus. Clop's position is sustained by its zero-day campaigns. Play maintains volume through its established RaaS infrastructure.

* Qilin figures are approximate: Barracuda reports 700 confirmed attacks in 2025 (92 TB stolen, 28 TB from confirmed incidents); Comparitech tallied up to ~1,034 victim claims total for the year; Group-IB verified a cumulative data theft of ~116 TB across Qilin's operational history. The discrepancy between attack counts reflects different counting methodologies (confirmed by the group vs. all claimed victims).

What Changed

- RansomHub went dark on April 1, 2025 after dominating the market since mid-2024. Over its final months it averaged roughly 75 victims per month and maintained a data-leak site with ~230 active listings before going silent. Many of its former affiliates redistributed to Qilin — which surged 71.4% in activity from March to April as those affiliates came online, with Group-IB's analysis identifying Qilin as the primary destination for displaced RansomHub affiliates — though some also joined Akira, Play, or the emerging groups that proliferated later in the year. - LockBit returned as LockBit5 in September 2025, following Operation Cronos disruption in February 2024. It did not recapture its former market share. - The Gentlemen emerged in September 2025 offering a 90/10 affiliate revenue split — the most affiliate-favorable terms in the market. This is both a business development and a competitive signal: if a new group can attract affiliates with generous terms, it is betting on high volume and is willing to invest in recruitment. - Worldleaks appeared as a rebrand of Hunters International, operating as a data-theft-only platform — no encryption, just exfiltration and publication. - Market fragmentation accelerated. The Top 10's share of all victim claims dropped from 71% in Q1 to 56% in Q3. More groups, more tools, more competition for victims.

The RaaS Ecosystem, as Described in Public Reporting

Multiple threat intelligence reports published during 2025 describe a layered ransomware-as-a-service economy. Synthesizing across sources — Barracuda's reporting on IAB infrastructure, ReliaQuest's analysis of affiliate payment models, and Halcyon Research's observations on ISP-hosted command-and-control channels — the ecosystem breaks down into recognizable tiers:

1. Initial Access Brokers (IABs) specialize in network penetration and sell access to affiliates. They do not deploy ransomware; they open doors. Barracuda documented IAB operations as early as Q1 2025, noting their role as a distinct tier from the actual ransomware operators.

2. RaaS Platform Providers maintain the malware infrastructure, negotiate with victims, manage customer support, and take a cut of profits. This was the layer most visibly disrupted by RansomHub's collapse — over 280 affiliates redistributed across competing platforms.

3. RaaS Affiliates execute attacks using the platform's toolkit. They are the largest group in the ecosystem numerically but carry the highest operational risk.

4. Infrastructure Providers (ISP/C2P). Reported by Halcyon Research, ReliaQuest, and Barracuda as a previously opaque layer of the supply chain — legitimate hosting providers that lease infrastructure to threat actors for command-and-control operations and data exfiltration channels. This is our own synthesis of across-source reporting rather than a formal taxonomy from any single researcher.

Revenue splits typically run 70/30 or 80/20 (affiliate to platform). The Gentlemen's 90/10 split is the outlier, representing a competitive strategy to attract affiliates away from established platforms.

The Speed of Attack

Halcyon's data reveals how quickly ransomware operations have accelerated:

- Dwell times collapsed from days to hours. Attackers spend less time sitting in compromised networks and more time moving laterally with purpose. - 69% of attacks were deliberately staged during nights or weekends, reducing the chance of detection by daytime security staff. - 78% of incidents involved Remote Monitoring and Management (RMM) tool abuse, allowing attackers to blend indistinguishably from legitimate administrative traffic. - 69% of paying organizations were attacked again — the recidivism rate. Payment does not buy immunity; it signals willingness to pay.

Manufacturing: The #1 Target and the IT/OT Convergence Risk

Manufacturing was the dominant ransomware target sector in 2025, confirmed independently by every major tracking organization:

There is no discrepancy here. These figures measure different populations:

- The 56% YoY increase refers specifically to the manufacturing sector's growth in total ransomware attacks (from 937 to 1,466). - The 68% figure from Dragos refers to industrial (OT/ICS) incidents where manufacturing was the impacted sector — a narrower, infrastructure-specific lens. - The 28% share from Bitsight represents manufacturing's portion of all leak-site claims.

All converge on the same finding: manufacturing is the most targeted sector, and the gap between it and the second-ranked sector is widening.

Why Manufacturing?

Three factors combine to make manufacturing uniquely vulnerable:

1. Critical role in supply chains. Production line halts create immediate economic pressure on targets to resolve incidents quickly. There is less time to evaluate options, less patience for "wait and see." 2. High-value IP. Manufacturing environments contain proprietary designs, process parameters, and intellectual property that are directly monetizable on the dark web. 3. IT/OT convergence vulnerabilities. As manufacturing environments digitize — connecting OT devices to IT networks for monitoring and optimization — the attack surface expands. Industrial control systems were not designed with cybersecurity as a primary concern. Fortinet's 2025 OT Report found that 48% of impacted organizations experienced operational outages affecting productivity, and 46% faced outages risking physical safety.

The ransom demand differential is telling: the average ransom demand across all sectors declined 26% to approximately $1.04 million (down from $1.4M in 2024, per Comparitech), but manufacturing-specific demands clustered higher — nearly $1.2 million on average in 2025 versus $523,000 in 2024, more than doubling year-over-year according to Comparitech's own sector breakdown. Attackers price their demands to the victim's ability to pay and the urgency of the situation; manufacturers' critical role in supply chains creates both high willingness-to-pay and acute recovery pressure.

The Anatomy of Double Extortion — and Beyond

The ransomware model of 2025 is defined by a single shift: exfiltration before encryption.

Source: Vectra AI, Sophos State of Ransomware 2025, Verizon DBIR 2025

Double extortion — exfiltrate data, then encrypt, then threaten to publish both — has become the default model. By 2025, 96% of incidents involved data theft prior to encryption. The traditional defense of "restore from backups" no longer works, because the attackers have already taken the data.

But the story does not stop there. 22% of incidents in 2025 involved data exfiltration without any encryption at all. Attackers are increasingly skipping the encryption step entirely — stealing data and threatening publication without the operational disruption that encryption causes. This shifts the calculus for defenders: you can be attacked and extorted even if your backup integrity is perfect, even if your encryption detection systems fire, even if you can restore every system in hours. The threat is the data, not the lock.

Multi-Extortion

The Canadian Centre for Cyber Security identified a further evolution: multi-extortion, where attackers deploy multiple pressure vectors simultaneously:

- Financial pressure (ransom demand) - Data publication threat - DDoS attacks against the victim's customers or partners - Legal and regulatory pressure (exploiting notification obligations) - Supply-chain leverage (pressuring the victim's clients to demand compliance)

This is not theoretical. Multi-extortion increases the victim's cost of resistance across every dimension — financial, operational, legal, reputational, and commercial.

Geographic Patterns and Case Studies

The Numbers

The U.S. accounted for 51.4% of global claims. Germany saw the steepest increase among major economies at +62%. The UK was the only major country to see a decrease (−5%). South Korea had the steepest percentage increase: +540%, from 10 to 64 attacks — a small absolute number but indicative of emerging threat in a region with significant manufacturing exposure.

Case Study A: Nevada State Government (August 2025)

The Nevada ransomware attack is one of the most thoroughly documented government incidents of 2025. An After-Action Report from the Governor's Technology Office, analyzed by Barracuda, provides a rare window into a real ransomware incident from initial compromise through recovery.

Timeline:

- May 14, 2025: A state employee downloads a malware-laced sysadmin tool from a spoofed website, accessed through SEO poisoning of Google Ads. The threat resembles the Nitrogen loader family. - June 26, 2025: Symantec detected and removed the source file, but persistence mechanisms (backdoor) remained active on the network. - August 2025: Attackers return, exfiltrate files from 60+ state agencies, delete all backup volumes, and deploy ransomware simultaneously across virtual machines. - Attack discovered: Approximately 1:52 AM Pacific Time. A ransom note with recovery instructions was left on compromised systems. - Recovery: 28 days total (below the national average of 27.8 days for government entities). Critical services restored within one week. Payroll obligations met on time. - Cost: $1.5 million in total recovery expenses, covered by $7 million in cyber insurance. - Data exposure: 26,408 files accessed; 3,241 potentially exposed. The Governor's office statement suggested some data may have been exfiltrated but did not confirm. - Attribution: Not publicly identified. TTPs resemble Nitrogen loader.

The lesson: Nevada's rapid recovery was not accidental. Prior investments in incident response planning, cyber insurance, multi-agency simulations, and federal partnerships (DHS/FBI) created the infrastructure that enabled a sub-average recovery timeline. The state did not pay ransom. It restored from backups it had not yet lost — because the attackers had only deleted the backups present at the time of their second wave, and some had been replicated to air-gapped or delayed-sync storage.

Case Study B: DOJ Civil Cyber-Fraud Initiative

The U.S. Department of Justice's Civil Cyber-Fraud Initiative, launched in October 2021, entered a phase of massive acceleration in 2025. Using the False Claims Act (FCA), the DOJ pursued government contractors and grant recipients for cybersecurity deficiencies — not criminal charges against attackers, but civil liability against victims who failed to maintain adequate security on government systems.

Notable 2025 settlements:

Total False Claims Act settlements in FY2025 reached $6.8 billion — the largest single-year total on record.

The relevance to ransomware defenders is structural: inadequate cybersecurity posture on government systems is now a pathway to civil fraud liability. This changes the incentive equation for organizations handling government contracts, grants, or subcontracts. The threat is no longer just the attacker — it is the regulator, the auditor, and the civil court.

Case Study C: Dollar Tree and INC Ransom

In July 2025, INC Ransom claimed to have infiltrated Dollar Tree's systems, stealing over 1.2 terabytes of sensitive data and threatening publication. Dollar Tree's response was unusual: the company publicly denied that its systems were impacted by ransomware, stating that the data likely originated from a defunct discount chain acquisition, not current operations.

This is a rare case of a major company directly disputing a ransomware group's claim on the record. It illustrates the fundamental verification challenge: INC Ransom may have acquired legacy data from a former acquisition and retroactively attributed it to the current corporate entity, or Dollar Tree may be downplaying a genuine breach to avoid regulatory scrutiny and reputational damage.

Comparitech recorded that only 1,173 of the 7,419 victim claims in 2025 were confirmed by the target organization — approximately 16%. The other 6,246 unconfirmed claims include a mix of paid-but-non-disclosed incidents, fabricated claims, and genuine breaches the target chose not to acknowledge. The Dollar Tree case sits in that ambiguous middle ground.

What This Means for Homelab and Personal Infrastructure Operators

The trends described above originate in enterprise and government environments. But the attack playbooks — the tools, techniques, and operational patterns — are democratized. Ransomware groups publish guides, share tools on forums, and recruit affiliates with minimal technical backgrounds. The same RMM abuse, phishing campaigns, and backup-deletion tactics that hit Nevada state government are available to anyone with basic internet literacy.

Here is what the 2025 landscape means for operators of home labs, homelab infrastructure, and personal network environments:

1. Backups Are Necessary But Not Sufficient

The double-extortion model means that restoring from backups addresses only half the threat. If your data has been exfiltrated, backup restoration leaves the encryption problem solved but the data exposure problem intact.

Actionable implication: Treat backup integrity as table stakes. The differentiator is data loss prevention — knowing what is on your systems and whether it has been accessed. This means: - Monitoring for unusual data access patterns (large downloads, bulk copies, unusual file access times) - Segmenting sensitive data from network-accessible storage - Using versioned backups with offline or air-gapped copies (not just network-attached storage that the attacker can reach)

2. RMM Tools Are a Known Attack Vector

78% of ransomware incidents in 2025 involved RMM tool abuse, per Halcyon. If you manage multiple systems — and homelab operators typically do — you likely use some form of remote management tool. These are indistinguishable from legitimate traffic and provide attackers with exactly the access they need.

Actionable implication: If you use RMM or remote access tools in your homelab or home network: - Enforce multi-factor authentication on every RMM account - Restrict RMM access to specific source IPs - Log and monitor all RMM sessions - Consider whether you actually need persistent remote access to every device

3. The Recidivism Rate Is a Warning

69% of paying organizations were attacked again. Payment signals to the attacker that you are a willing customer. For homelab operators, the risk is lower (attackers are not targeting home labs at enterprise scale), but the principle holds: if you pay a ransom or negotiate with an attacker, you are on their list.

Actionable implication: Have a recovery plan that does not involve payment. Test it regularly. The Nevada government's ability to recover in 28 days was a function of preparedness, not luck.

4. Night and Weekend Attacks Are the Norm

69% of attacks in 2025 were deliberately staged during nights or weekends. This is not an accident of attacker preference — it is a strategic choice. Security teams are smaller, response times are longer, and detection is delayed.

Actionable implication: Automated monitoring and alerting are non-negotiable for anyone running production or semi-production infrastructure. If you are not getting alerts when something unusual happens at 2 AM, you will not know until the ransom note appears.

5. Supply-Chain Risk Extends to Your Toolchain

The RaaS ecosystem includes Initial Access Brokers, platform providers, affiliates, and C2P infrastructure providers. Your software supply chain — the tools, libraries, and services you rely on — has a similar layered structure. A compromised dependency, a malicious package update, a spoofed download mirror — these are the personal-infrastructure equivalents of supply-chain attacks.

Actionable implication: - Verify checksums and signatures on downloaded software - Use package managers with verified repositories, not direct downloads from forums - Treat compromised credentials in any service you use as a cascading risk — if a service you rely on is breached, assume your access may be compromised

6. Insurance and Incident Response Apply at Every Scale

Nevada's $7 million cyber insurance policy covered a $1.5 million recovery. You do not need enterprise insurance to benefit from the principle: having a plan, having contacts, having a documented recovery procedure — these reduce recovery time regardless of scale.

Actionable implication: Write down your incident response plan. Identify what you would do if every system on your network was encrypted tomorrow. Know where your backups are, how to restore from them, and what data is most critical to recover first. Practice it.

Comparative Threat Outlook: Canada vs. US and UK

Canada's ransomware experience in 2025 (+31% YoY) sits between the U.S. (+33%) and the U.K. (−5%) — a pattern that reflects structural differences in threat exposure, regulatory environment, and defensive posture.

The Canadian Centre for Cyber Security's 2025–2027 Threat Outlook is particularly notable for identifying multi-extortion as a growing vector. Canadian organizations face not just the traditional ransom-and-publish model but coordinated pressure campaigns that include regulatory notification obligations under PIPEDA (Personal Information Protection and Electronic Documents Act), which can amplify the financial and reputational damage of a breach.

The UK's decline (−5%) may reflect the NCSC's Annual Review 2025 findings around improved defensive practices, but it may also reflect reporting patterns — the UK's data collection methodology may undercount certain categories of incident. The UK NCSC's own Annual Review noted improvements in detection capabilities and response coordination, which could indicate genuine progress.

For Canadian homelab and infrastructure operators, the takeaway is that regulatory exposure adds another dimension to the ransomware equation. PIPEDA notification requirements mean that a breach is not just an operational incident — it is a compliance event with public disclosure obligations. This is structurally similar to the U.S. DOJ Civil Cyber-Fraud Initiative, though the mechanisms differ.

Outlook: What to Watch in 2026

Several trends are likely to shape the ransomware landscape in 2026:

1. Continued market fragmentation. With 73 new groups in 2025 and declining Top-10 concentration, the market will remain competitive. Competition drives innovation in attack methodology — and increases the total number of actors with something to prove.

2. AI-assisted campaigns. The first AI-assisted autonomous ransomware campaigns were detected in 2025. Expect more sophisticated phishing, automated vulnerability exploitation, and potentially autonomous lateral movement in 2026.

3. Encryption-less extortion growth. The 22% of attacks in 2025 that involved data theft without encryption suggest a shift toward pure extortion models. Attackers who can steal data without disrupting operations reduce the victim's ability to categorize the incident and may increase the pool of viable targets (organizations with strong backup and recovery but weaker data loss prevention).

4. Regulatory enforcement expansion. The DOJ's Civil Cyber-Fraud Initiative in the U.S., PIPEDA enforcement in Canada, and similar frameworks globally are creating a new dimension of accountability. Cybersecurity failures will increasingly have legal and financial consequences beyond the attacker's ransom demand.

5. OT/ICS targeting. Dragos and Fortinet both confirm manufacturing as the primary target for industrial ransomware. As industrial digitization accelerates, the convergence of IT and OT security becomes not just an enterprise concern but a risk for anyone operating connected industrial or maker-space infrastructure.

Conclusion

The 2025 ransomware landscape is defined by three converging trends: scale, complexity, and accountability. The number of attacks is growing. The attack models are diversifying — from simple encryption to multi-vector extortion, from enterprise-targeted campaigns to democratized toolkits. And the consequences of failure are expanding beyond the attacker's ransom note to include civil liability, regulatory notification, and supply-chain contagion.

For homelab and personal infrastructure operators, the message is not that you are a target — though you can be, particularly if you host services that are internet-facing or handle sensitive data. The message is that the same defensive principles that apply at enterprise scale apply at home: verified backups with offline copies, continuous monitoring, network segmentation, verified software supply chains, and documented incident response procedures.

The attackers are not getting more skilled. They are getting more numerous, more patient, and more integrated into the infrastructure of the internet itself. The defense is not harder — it is just more systematic.

Sources

1. Comparitech, "Worldwide Ransomware Roundup: 2025 End-of-Year Report" (January 13, 2026) 2. Bitsight, "State of the Underground 2025" (June 2026) 3. Canadian Centre for Cyber Security, "Ransomware Threat Outlook 2025–2027" (December 2025) 4. UK NCSC, "Annual Review 2025" (October 2025) 5. CISA, "StopRansomware: Akira Ransomware" Advisory (November 2025) 6. Barracuda, "Nevada Ransomware Attack Offers Lessons in Statewide Cyber Resilience" (December 11, 2025) 7. Barracuda, "Nitrogen Ransomware: From Staged Loader to Full-Scale Extortion" (November 7, 2025) 8. Dragos, "Industrial Ransomware Analysis: Q1 2025" 9. Halcyon Research, "2025 Ransomware Evolution Report" 10. SOC in a Box, "The Global Ransomware Landscape in 2025" 11. Fortinet, "2025 State of Operational Technology and Cybersecurity Report" 12. BlackFog, "The State of Ransomware: July 2025" 13. Vectra AI, Double-Extortion Ransomware Research (2025) 14. Sophos, "State of Ransomware 2025" 15. Verizon, "Data Breach Investigations Report (DBIR) 2025" 16. Fluet Law, "DOJ Cyber-Fraud Settlements Surge 233% in 2025"

Uncertainties and Limitations

- True attack volume: Estimated at 50,000+ by BlackFog based on an 86% undisclosed rate, but no reliable method exists to quantify the actual total. All published figures capture only a fraction of real incidents. - Nevada attack attribution: Not publicly identified. TTPs resemble the Nitrogen loader family, but this is an inference, not confirmation. - Dollar Tree/INC Ransom claim validity: Unclear whether INC Ransom genuinely breached Dollar Tree's current operations or is retroactively attributing legacy data from a defunct acquisition. Both scenarios are plausible. - OT vs IT boundary: No standard taxonomy exists for distinguishing "OT ransomware attacks" from traditional IT attacks that affect manufacturing environments. Dragos and Fortinet track industrial-specific incidents, but cross-reference with general-sector data is imperfect. - Payment rate data: Comparitech recorded only 6 payment confirmations and 122 non-payment confirmations in 2025. The actual payment rate may be higher, as many paid organizations do not publicly confirm.

Topics: