Fabio Assolini | Lead Security Researcher | Kaspersky GReAT | mail me |
We have released a new report outlining ransomware trends that shaped 2025. The report also provides insights into how the ransomware threat landscape may evolve.
According to our Security Network, Latin America recorded the highest share of organisations affected by ransomware attacks at 8.13%. The Asia-Pacific region followed at 7.89%, while Africa stood at 7.62%. In addition, the Middle East recorded 7.27%, the Commonwealth of Independent States (CIS) reached 5.91%, and Europe reported 3.82%.
The report also highlights the rise of “encryption-less” extortion attacks. Furthermore, ransomware groups now use post-quantum cryptography and continue distributing compromised data sets and credentials through Telegram channels. These developments show how ransomware threats continue evolving globally.
Evolving attack methods
Although the overall share of organisations attacked by ransomware declined slightly in 2025 compared to 2024, users still face significant risks. Attackers continue industrialising their operations and automating intrusion methods. In addition, many groups now prioritise stealing and leaking sensitive data instead of only encrypting systems. Consequently, ransomware threats now extend far beyond traditional file-encryption attacks.
One major trend in 2025 involves the continued rise of endpoint detection and response (EDR) “killers”. These tools specifically disable endpoint security solutions before malware execution. Consequently, EDR killers have become a standard feature in attacks. This shift reflects increasingly deliberate and methodical intrusions linked to modern ransomware threats.
Researchers also observed ransomware families adopting post-quantum cryptography standards. We had predicted this development previously. The shift signals growing concern around encryption methods that may resist future quantum-computing decryption attempts.
The role of Initial Access Brokers (IABs) also continues growing. These cybercriminal intermediaries sell pre-compromised corporate access through underground forums and messaging platforms. In addition, attackers increasingly target RDWeb portals, which allow remote control of devices.
Underground cybercrime networks
Ransomware groups continue industrialising attacks through “Access-as-a-Service” operations. As a result, the barrier to launching ransomware attacks continues declining. This trend further intensifies global ransomware threats.
Meanwhile, Telegram channels and dark web forums continue serving as platforms for distributing and selling compromised data sets and access credentials. Many of these credentials originate from ransomware attacks. Authorities seized a major underground forum, RAMP, in January 2026.
The platform allowed threat actors to advertise ransomware services and publish service-related updates. Authorities also seized another underground forum, LeakBase, in March 2026. LeakBase mainly distributed exfiltrated and compromised data. However, despite ongoing law-enforcement efforts against dark web platforms and ransomware leak sites, similar portals may still emerge over time.
Active groups
Among the most active ransomware groups in 2025, we identified Qilin as the dominant ransomware-as-a-service (RaaS) operator after RansomHub ceased operations. Clop ranked second, while Akira placed third.
Although several major ransomware groups stopped operating in 2025, new actors continue emerging. Looking ahead, Gentlemen has become one of the most important new ransomware actors.
The group’s rapid growth, structured operations, and increasing focus on data-centric extortion drive its influence. Furthermore, the group may include attackers previously associated with other major ransomware operations. Gentlemen also reflects a broader shift within the ransomware ecosystem.
Many groups now prefer scalable, business-like extortion models over chaotic, high-noise campaigns. These operations focus mainly on stealing sensitive data and leveraging reputational and regulatory pressure instead of relying solely on disruptive file encryption.
These developments demonstrate how ransomware threats continue to change in sophistication and scale.
Strengthening cyber resilience
Ransomware has evolved into a highly organised ecosystem focused on monetising stolen data, disabling defences and scaling attacks with business-like efficiency. Threat actors are quickly adapting, weaponising legitimate tools, exploiting remote-access infrastructure and even adopting post-quantum cryptography years earlier than many expected.
The purpose of Anti-Ransomware Day is to raise global awareness about the threats posed by ransomware and to promote best practices for prevention and response. We urge all users to stay secure, establish layered defences, invest in backups and improve cyberliteracy levels to counter attacks.
We encourage organisations to follow these best practices to protect against ransomware:
- Enable ransomware protection across all endpoints. The free Anti-Ransomware Tool for Business shields computers and servers from ransomware and other malware. It also prevents exploits and remains compatible with existing security solutions.
- Always keep software updated across all devices. Regular updates help prevent attackers from exploiting vulnerabilities and infiltrating networks.
- Focus defence strategies on detecting lateral movement and data exfiltration to the Internet. In addition, monitor outgoing traffic closely to detect cybercriminal connections within networks. Organisations should also establish offline backups that intruders cannot tamper with. Furthermore, companies must ensure quick access to backups during emergencies.
- Companies outside the industrial sector should install anti-APT and EDR solutions. These tools support advanced threat discovery, detection, investigation and timely incident remediation. Organisations should also provide SOC teams with access to the latest threat intelligence. Regular professional training further strengthens cybersecurity readiness against ransomware threats.




























