Ransomware attacks surged globally in the third quarter of 2025, with a 36% year-over-year increase in publicly disclosed incidents, according to BlackFog’s analysis. The number of attacks reached 270 in Q3 2025, compared to 198 in the same period of 2024, marking a 335% increase since Q3 2020. This escalation affected organizations in 93 countries, spanning critical sectors such as airlines, automotive manufacturers, and government entities. The Qilin ransomware group emerged as the most active threat actor during this period, being responsible for 20 incidents, including high-profile attacks like those on the Asahi Group. Notably, 54 ransomware groups were attributed to attacks in this quarter, with 18 new groups emerging, highlighting the fragmentation and volatility in the ransomware ecosystem. Among the newcomers, the Devman group made a significant impact, conducting 19 attacks across Asia, Africa, Europe, and Latin America, and was linked to a $91 million ransom demand. Law enforcement actions in 2024 and 2025, particularly against major operators like LockBit, contributed to the proliferation of new ransomware schemes, with 37 new groups appearing in the first half of 2025 and additional groups surfacing in July and August. Despite these disruptions, the overall volume of ransomware attacks remained high, with the number of victims posted to leak sites in July and August 2025 exceeding those from the same months in 2024. The attacks were more evenly distributed across multiple groups compared to previous years, indicating a shift in the operational landscape. The ransomware threat was not limited to large organizations; small businesses also suffered significant impacts, often lacking the resources to recover, as highlighted by personal accounts of business owners losing substantial revenue and savings. The persistence of legacy vulnerabilities and the absence of multi-factor authentication continued to facilitate successful attacks. Ransomware operators increasingly leveraged data exfiltration and extortion tactics, with a substantial portion of attacks involving the theft and public release of sensitive data. The emergence of new Ransomware-as-a-Service (RaaS) platforms, such as Devman’s, further democratized access to ransomware tools, enabling affiliates to launch attacks with greater ease. The continued evolution of ransomware tactics, the rise of new groups, and the resilience of established actors underscore the ongoing challenge for organizations in defending against these threats. The global ransomware battlefield in Q3 2025 was marked by increased attack frequency, greater diversity of threat actors, and escalating financial and operational impacts on victims.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Fortinet and Ivanti released patch advisories highlighted in security reporting on major enterprise and edge-device risks. The advisories were part of a broader October 2025 patch cycle focused on actively targeted infrastructure technologies.
CISA added two Windows zero-day vulnerabilities being exploited in the wild, along with an IGEL OS Secure Boot bypass, to its must-patch catalog. The move signaled active exploitation and increased urgency for defenders to remediate affected systems.
Microsoft revoked more than 200 certificates associated with Vanilla Tempest, also known as VICE SPIDER, after they were used to distribute Oyster malware through fake Microsoft Teams installers. The action was part of a response to ongoing abuse of signed binaries and installer trust.
Trend Micro reported on Operation Zero Disco, in which attackers exploited Cisco SNMP vulnerability CVE-2025-20352 to implant rootkits on Cisco switches. The activity enabled stealthy persistence, control, and lateral movement in affected environments.
Google threat intelligence linked the EtherHiding activity, which stored malware payloads on Ethereum and BNB Smart Chain, to North Korean threat actor UNC5342. The campaign reportedly used fake recruiter lures to deliver JADESNOW followed by INVISIBLEFERRET.
F5 disclosed that it had suffered a breach in August 2025, with the announcement delayed until it received permission from the U.S. Department of Justice. Reporting said attackers stole BIG-IP source code, customer data, and information on unreleased vulnerabilities.
BlackFog published its Q3 2025 ransomware findings, stating that ransomware attacks increased 36% compared with the same quarter a year earlier. The report marked a broader assessment of ransomware activity and trends during the quarter.
In late September 2025, the ransomware operator known as Devman shifted from working as an affiliate for groups including Qilin, DragonForce, and Conti to launching his own RaaS operation. He consolidated prior leak-site activity into new infrastructure and began recruiting affiliates under strict entry requirements.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
vulnu.com
Open sourcenews.sophos.com
Open sourceblackfog.com
Open sourcedetectionengineering.net
Open sourceblackfog.com
Open sourceanalyst1.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.