Threat actors have increasingly exploited public-facing applications, particularly on-premises Microsoft SharePoint servers, to gain initial access to organizations, with a significant rise in attacks attributed to the ToolShell attack chain. Cisco Talos Incident Response reported that over 60 percent of their recent engagements involved this vector, a sharp increase from the previous quarter, and noted a shift in ransomware activity, with new variants such as Warlock, Babuk, and Kraken observed alongside established families like Qilin and LockBit. The use of open-source DFIR tools like Velociraptor for persistence was also documented, marking a novel tactic in ransomware operations, and some attacks were linked to the China-based group Storm-2603.
Ransomware continues to pose a persistent threat, particularly to public sector organizations, with Trustwave reporting nearly 200 government entities worldwide victimized in 2025 alone. Babuk and Qilin have been identified as the most active ransomware groups targeting the public sector, causing significant operational downtime, service outages, and financial losses. The evolving tactics of ransomware actors and the increasing exploitation of vulnerabilities in public-facing applications underscore the need for robust segmentation and rapid incident response measures across both public and private sectors.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Trustwave reported that ransomware attacks against public sector organizations were still occurring as of its October 2025 publication, indicating an ongoing campaign trend affecting government-related entities. The reference does not provide a specific incident date beyond the publication timeframe.
Cisco Talos reported that ToolShell-related intrusions were the dominant incident response trend in the third quarter of 2025, underscoring the importance of network segmentation and rapid response. This reflects activity occurring during the Q3 2025 period rather than a single isolated incident.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
blog.talosintelligence.com
Open sourcetrustwave.com
Open sourceblog.talosintelligence.com
Open sourceblog.talosintelligence.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.