CYFIRMA Research

CYFIRMA Research- Tracking Ransomware: May 2025

CYFIRMA

Stay ahead of evolving ransomware threats with CYFIRMA’s May 2025 Ransomware Report.

May witnessed a 15.95% spike in ransomware attacks compared to April, with 545 incidents logged globally. New actors like SafePay and SilentRansomGroup rapidly gained ground, while established groups like Qilin deployed advanced loaders like NETXLOADER and SmokeLoader. Attackers leveraged tools such as Kickidler for stealthy credential theft and embedded ransomware in JPEG files to evade detection. Vulnerabilities in SAP NetWeaver were exploited by multiple groups, deploying payloads like PipeMagic. Meanwhile, emerging groups like IMN Crew and J Group began naming victims on their leak sites.

As attackers shift to evasive techniques and exploit enterprise software, our report provides timely insights to defend critical systems.

Link to the Research report: https://www.cyfirma.com/research/tracking-ransomware-may-2025/

#CyberSecurity #RansomwareReport #ThreatIntelligence #DigitalDefense #ETLM #ThreatLandscape #StaySecure #CYFIRMA #CyberResilience #Qilin #Play #Manufacturing #IT #SafePay #Qilin #JGroup #IMNCrew

https://www.cyfirma.com/