INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Lazarus Group Exploits Zero-Day in Microsoft Office
| 2025-12-23 13:00 CRITICAL LOW RANSOMWARE & EXTORTION DATA BREACH
Executive Summary
AI-generated
In 2025, a significant number of ransomware attacks occurred globally, with the US being the primary target country for victims, accounting for almost half of the total listed victims at approximately 3328. The Russian-linked ransomware group Clop was particularly active in the first quarter of 2025 before slowing down during the summer months until October, when a small peak of activity occurred. Ransomware groups targeted various industries, including manufacturing (930 victims), technology (893 victims), and healthcare (529 victims). Meanwhile, less organized collectives such as Scattered Spider, Lapsus$, and ShinyHunters gained notoriety in 2025, while traditional ransomware syndicates continued to be active throughout the year.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ra•••••.live
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Scattered SpiderScattered Spider
QilinQilin
Target & Sectors
DACH
DACH
NORTH_AMERICA
NORTH_AMERICA
manufacturingmanufacturing
Incident Timeline
2025/12/23
Ransomware groups claimed 7902 victims in the United States, accounting for almost half of total ransomware group-listed victims worldwide.
Click on any entity below to view its context and source!
victims
10 sectorial categories
US Ransomware Victims Made Half of 2025’s Total
In 2025, ransomware groups targeted a wide range of industries, with Ransomware.live reporting victims for at least 10 sectorial categories.
financial
973 Ransomware.live
Qilin, the group that
claimed the cyber-attack on brewing giant Asahi
in September, was
the most prolific ransomware group
, with 1001 victims listed on its data leak site according to Ransomware.live and 973 according to competitor RansomLook.
victims
358 listed victims
The second most targeted country, Canada, represented a far lower number with 358 listed victims over the past year.
victims
930 manufacturing sector
The highest number of victims came from the manufacturing sector (930), followed by technology (893) and healthcare (529).
threat_actor
Scattered Spider
Additionally, less organized collectives such as Scattered Spider, Lapsus$ and ShinyHunters grabbed many of the headlines in 2025.
victims
5336 victims
This is significantly higher than the 6129 victims listed in 2024 and the 5336 victims listed in 2023.
Tactical Metrics
Metrics
victims
10
Sectorial Categories
Click for context!
US Ransomware Victims Made Half of 2025’s Total
In 2025, ransomware groups targeted a wide range of industries, with Ransomware.live reporting victims for at least 10 sectorial categories.
Metrics
victims
358
Listed Victims
The second most targeted country, Canada, represented a far lower number with 358 listed victims over the past year.
Metrics
victims
930
Manufacturing Sector
The highest number of victims came from the manufacturing sector (930), followed by technology (893) and healthcare (529).
Metrics
financial
973
Ransomware.Live
Qilin, the group that
claimed the cyber-attack on brewing giant Asahi
in September, was
the most prolific ransomware group
, with 1001 victims listed on its data leak site according to Ransomware.live and 973 according to competitor RansomLook.
Metrics
victims
5,336
Victims
This is significantly higher than the 6129 victims listed in 2024 and the 5336 victims listed in 2023.
Intelligence Sources
Infosecurity-Magazine
2025-12-23
Top Ransomware Trends of 2025
Infosecurity-Magazine
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T06:22
Comprehensive Tactical Telemetry
Highly Correlated Entities
6x
timeline
Temporal Reference
the first quarter of 2025
date
5x
organisation
Identified Entity
Asahi
entity
4x
target region
Target Country
United States
country
3x
industry
Targeted Sector
Manufacturing
sector
2x
source region
Origin Country
Russian Federation
country
2x
tactic
Cyber Operation Type
Ransomware
tactic
2x
general metric
Uk
251
uk
Contextual Telemetry
Context Block
12 METRICS
victims
Sectorial Categories
10
sectorial categories
victims
Listed Victims
358
listed victims
general metric
Germany
318
germany
victims
Manufacturing Sector
930
manufacturing sector
general metric
Technology
893
technology
general metric
Healthcare
529
healthcare
general metric
Groups
306
groups
malware
Malware Payload
Qilin
tool
financial
Ransomware.Live
973
ransomware.live
general metric
Top
10
top
threat actor
APT Group
Scattered Spider
actor
victims
Victims
5,336
victims
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.