惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

N
News | PayPal Newsroom
I
InfoQ
小众软件
小众软件
T
The Blog of Author Tim Ferriss
WordPress大学
WordPress大学
V
V2EX
G
Google Developers Blog
罗磊的独立博客
量子位
酷 壳 – CoolShell
酷 壳 – CoolShell
N
Netflix TechBlog - Medium
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
P
Proofpoint News Feed
M
MIT News - Artificial intelligence
IT之家
IT之家
J
Java Code Geeks
L
LangChain Blog
D
DataBreaches.Net
F
Fortinet All Blogs
B
Blog
博客园 - 叶小钗
人人都是产品经理
人人都是产品经理
aimingoo的专栏
aimingoo的专栏
Google DeepMind News
Google DeepMind News
Engineering at Meta
Engineering at Meta
P
Privacy & Cybersecurity Law Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
K
Kaspersky official blog
博客园 - 【当耐特】
T
Tenable Blog
AWS News Blog
AWS News Blog
V
Visual Studio Blog
T
Tor Project blog
阮一峰的网络日志
阮一峰的网络日志
H
Heimdal Security Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
S
Secure Thoughts
Security Archives - TechRepublic
Security Archives - TechRepublic
I
Intezer
Attack and Defense Labs
Attack and Defense Labs
Webroot Blog
Webroot Blog
Latest news
Latest news
TaoSecurity Blog
TaoSecurity Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Know Your Adversary
Know Your Adversary
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
T
Threatpost
SecWiki News
SecWiki News
S
Security Affairs
H
Help Net Security

Threat Intelligence – ThreatDown by Malwarebytes

The AI era of cybercrime has arrived: The 2026 Cybercrime in the age of AI report | ThreatDown Prinz Eugen ransomware: a deep dive into a new Go-based encryptor - ThreatDown by Malwarebytes CastleRAT attack first to abuse Deno JavaScript runtime to evade enterprise security Machine-scale cybercrime: The 2026 State of Malware report How to prevent a rootkit attack AI-orchestrated cyberattacks Inside EDR-Freeze: How ThreatDown stops the attack before it spreads EDR vs MDR vs XDR – What’s the Difference? KMSpico explained: No, KMS is not “kill Microsoft” When you shouldn’t trust a trusted root certificate - ThreatDown by Malwarebytes Ransomware in April 2025—RansomHub is gone
Ransomware in March 2025
Mark Stockley · 2025-04-30 · via Threat Intelligence – ThreatDown by Malwarebytes
Ransomware review

March 2025 saw a huge number of ransomware attacks, and the Pennsylvania State Education Association quietly notify over 500,000 current and former teachers that hackers infiltrated its networks last year.

On March 17, 2025, the Pennsylvania State Education Association quietly notified over 500,000 current and former teachers that hackers from the Rhysida gang had infiltrated its networks in July 2024 and stolen personal data including Social Security numbers, driver’s-license details, and health-insurance records.​

Less than a week earlier, the Moscow-linked Qilin ransomware group took credit for breaching Ukraine’s Ministry of Foreign Affairs, boasting on its dark web leak site that it had stolen private correspondence, official decrees and personal staff data​.

The Ministry of Foreign Affairs of Ukraine is listed as a victim on the Qilin dark web site.

In mid-March, the newly emerged Hellcat gang attacked Swiss telecoms specialist Ascom, which confirmed in a March 16 press release that its “technical ticketing system” was breached.

March was also notable for what did not happen—there were no new attacks attributed to the Cl0p ransomware gang. The gang’s sporadic and unpredictable approach means that it is often inactive for several months, before it erupts into life with an automated, zero-day attack. After a few months of breathless activity, the group now seems to have entered one of its dormant phases.

With Cl0p quiet, the list of the top ten most active groups resumed a more typical order. Despite the recent noise and fury from Cl0p, RansomHub remains the most consistently active group.

Known ransomware attacks by group, March 2025

The USA was the biggest target for ransomware gangs in March, as it normally is, but the month saw the USA’s usual share of attacks cut by a surge in ransomware activity in countries outside the top 10.

Technology and manufacturing were the most frequently attacked industries in March.

Known ransomware attacks by industry, March 2025

How to avoid ransomware

  • Block common forms of entry. Create a plan for patching vulnerabilities in internet-facing systems quickly; and disable or harden remote access like RDP and VPNs.
  • Prevent intrusions. Stop threats early before they can even infiltrate or infect your endpoints. Use endpoint security software that can prevent exploits and malware used to deliver ransomware.
  • Detect intrusions. Make it harder for intruders to operate inside your organization by segmenting networks and assigning access rights prudently. Use EDR or MDR to detect unusual activity before an attack occurs.
  • Stop malicious encryption. Deploy Endpoint Detection and Response software like ThreatDown EDR that uses multiple different detection techniques to identify ransomware, and ransomware rollback to restore damaged system files.
  • Create offsite, offline backups. Keep backups offsite and offline, beyond the reach of attackers. Test them regularly to make sure you can restore essential business functions swiftly.
  • Don’t get attacked twice. Once you’ve isolated the outbreak and stopped the first attack, you must remove every trace of the attackers, their malware, their tools, and their methods of entry, to avoid being attacked again.

To learn more about ransomware and how to defend against the Living Off the Land tactics used by ransomware gangs, download the 2025 State of Malware report.