惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

雷峰网
雷峰网
博客园 - 聂微东
酷 壳 – CoolShell
酷 壳 – CoolShell
宝玉的分享
宝玉的分享
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
罗磊的独立博客
Hugging Face - Blog
Hugging Face - Blog
T
Tailwind CSS Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
博客园_首页
博客园 - 三生石上(FineUI控件)
博客园 - 叶小钗
Apple Machine Learning Research
Apple Machine Learning Research
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
量子位
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
人人都是产品经理
人人都是产品经理
美团技术团队
小众软件
小众软件
Jina AI
Jina AI
S
SegmentFault 最新的问题
博客园 - Franky
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com

The Register - Security: CSO

Anthropic's Mythos has The Kettle crew curious, skeptical 'People's Panel' to check if UK wants controversial Digital ID will cost £630K Top npm package backdoored to drop dirty RAT on dev machines Lightning-fast exploits mean patch fast, says Cisco Talos Lightning-fast exploits mean patch fast, says Cisco Talos Smooth criminals talking their way into cloud environments, Google says Cybercrime up 245% since the start of the Iran war Scattered Lapsus$ Hunters seeks women to defraud helpdesks Every day in every way, passwords are getting worse CISA quietly updated ransomware flags on 59 flaws last year Deepfake job seeker applied to work for an AI security firm Deepfake job seeker applied to work for an AI security firm AI-powered cyberattack kits are 'just a matter of time' AI-powered cyberattack kits are 'just a matter of time' FortiGate SSO bug still exploitable despite December patch FortiGate SSO bug still exploitable despite December patch Judge tosses CrowdStrike shareholder suit over 2024 outage DRAM shortage may drive firewall prices higher: analysts Around 1,000 systems compromised in ransomware attack on Romanian water agency 1,000 systems pwned in Romanian Waters ransomware attack Half of exposed React servers remain unpatched amid attacks CISA warns spyware crews are breaking into Signal and WhatsApp accounts FCC guts Salt Typhoon telco rules despite espionage risk CISA orders feds to patch Oracle Identity Manager zero-day SEC drops SolarWinds lawsuit that painted a target on CISOs everywhere SEC bails on SolarWinds lawsuit Palo Alto kit sees massive surge in malicious activity amid mystery traffic flood Palo Alto kit sees massive surge in malicious activity Countries use cyber targeting to plan strikes: Amazon CSO Overconfidence is the new zero-day as teams stumble through cyber simulations
Ransomware attacks kept climbing in 2025 as gangs refused...
2026-01-08 · via The Register - Security: CSO

If 2025 was meant to be the year ransomware started dying, nobody appears to have told the attackers.

In its 2025 State of Ransomware in the US report, security firm Emsisoft says ransomware attacks continued to climb last year, with more victims appearing on extortion sites and more groups operating than ever before. The figures climbed even as police and prosecutors notched up a string of wins against ransomware groups, such as the global takedown of BlackSuit in August.

Trackers keeping an eye on ransomware leak sites logged more than 8,000 claimed victims worldwide in 2025, a rise of more than 50 percent compared to 2023. The counts come from outfits watching dark web shaming pages such as Ransomware.live and RansomLook.io, so they only include cases where crooks decided to post receipts. Plenty of victims, Emsisoft says, will have paid up, recovered, or kept quiet without ever appearing on a leak site.

Emsisoft's numbers also suggest there are more gangs in the game than there were a couple of years ago, with the count of active ransomware crews climbing from a few dozen in 2023 to well into three figures by the end of 2025. Instead of a handful of mega-brands dominating, the scene now looks messier, with lots of smaller outfits popping up, disappearing, and reappearing under new names as affiliates drift between operations.

That could explain why all the splashy takedowns haven't translated into fewer ransomware attacks. While pulling the plug on a gang's infrastructure might kill one brand, it rarely kills the people behind it, who tend to resurface quickly under a new name or latch onto the next crew looking for experienced hands.

Even so, the same handful of ransomware brands kept turning up again and again on leak sites last year, with names like Qilin, Akira, Cl0p, and Play racking up large victim counts. Emsisoft warns against treating those tallies like a proper leaderboard, though, since some gangs are far louder than others when it comes to naming and shaming victims.

The report also points to a change in how many ransomware break-ins actually start. Bugs and exposed services still play a role, but gangs are leaning harder on old-fashioned tricks such as phishing, stolen logins, and social engineering to get a foot in the door, with crews that include Scattered Lapsus$ Hunters favoring approaches that go straight around perimeter defenses rather than through them.

Emsisoft threat intelligence analyst Luke Connolly says the churn, along with this change in tactics, is what keeps ransomware ticking over: affiliates move on, names disappear, and the same attacks keep happening under different banners.

"As long as affiliates remain plentiful and social engineering remains effective, victim counts are likely to continue rising," he said. ®