470 Ransomware Attacks in 2025: Qilin Leads, Followed by Silent and Crypto24

470 Ransomware Attacks in 2025: Qilin Leads, Followed by Silent and Crypto24

In April 2025, the global ransomware scene experienced a notable shift, with 470 victims reported worldwide — a 29% drop from March’s figures. However, this decrease in numbers doesn’t signal a lull in activity. Instead, it highlights a trend where cybercriminals are refining their tactics and becoming more discerning in their targets, rather than reducing their efforts.

The manufacturing sector took the brunt of these attacks, followed by the information technology sector, while the United States continued to be the top target for these cyber offenses.

Amid this changing environment, the Qilin group has emerged as a dominant force, showing an impressive 71.4% surge in activity from the previous month, solidifying its position at the forefront of ransomware operations.

Top 5 Ransomware Groups of 2025 (Source – Cyfirma)

Qilin has made a striking leap in the ransomware arena, with 72 confirmed victims, marking a significant rise in both its capabilities and infrastructure expansion. This rapid growth points to an alarming trend of increasing sophistication within the group.

Other well-established ransomware operators are also showing notable increases in activity. Play saw a sharp 75.9% surge in operations, while DragonForce experienced a more moderate yet still significant 25% rise, reflecting the evolving and unpredictable nature of the ransomware landscape.

In addition, April 2025 saw the rise of several new ransomware factions, with Silent and Crypto24 making their mark through unique and innovative tactics. These groups quickly gained traction, establishing themselves in the threat landscape.

The appearance of these newcomers aligns with the surprising shutdown of RansomHub, hinting at a shift in resources and talent across the ransomware ecosystem, potentially leading to a restructuring of attack strategies.

Data Leak Platforms (Source – Cyfirma)

In late April 2025, the Silent ransomware group introduced its leak site, marking a departure from conventional ransomware strategies. While most operators concentrate on encryption, Silent places greater emphasis on stealing sensitive corporate data, which it then sells either on dark web marketplaces or to competitors.

With four confirmed victims so far, the group employs a method that reduces detection by encrypting only minimal data. This discreet approach enables them to leverage stolen information more effectively while maintaining a low profile.

In contrast, Crypto24 has adopted a more aggressive stance, claiming responsibility for eight attacks since its emergence. It seems to be capitalizing on the void left by RansomHub’s closure, possibly attracting former affiliates searching for new avenues for their operations.

FOG Ransomware’s Advanced Attack Sequence

FOG ransomware exemplifies the growing sophistication of today’s cyber threats, featuring a multi-step infection process that starts with phishing emails containing a ZIP file named “Pay Adjustment.zip.” This file holds a malicious LNK file that triggers a PowerShell script (“stage1.ps1”) designed to download several harmful components, including:

  • A tool to wipe data (“cwiper.exe”)
  • A privilege escalation exploit (“ktool.exe”)
  • A script for harvesting system and geolocation data (“lootsubmit.ps1”)

The malware’s infection sequence utilizes “ktool.exe” to exploit a vulnerability in the iQVW64.sys driver, escalating privileges on the victim’s system. FOG also incorporates scripts to gather system details and geolocation information.

Before launching encryption, FOG checks for virtualized environments, a strategy designed to bypass common sandbox detection methods. Once active, the ransomware encrypts files with a “.flocked” extension and drops a ransom note (“readme.txt”) that includes politically motivated messages. In a rare move, FOG also instructs victims to spread the malware further, utilizing social engineering to expand its reach—an approach that distinguishes it from more conventional ransomware groups.

As ransomware groups continue to refine their tactics, organizations must stay alert and bolster their defenses to protect against these increasingly sophisticated threats that remain rampant in 2025.

More Articles & Posts