Ransomware attacks are increasingly shifting from traditional on-premises systems to cloud environments, with attackers exploiting misconfigured cloud storage, such as Amazon S3 buckets, and leveraging stolen credentials to compromise business-critical data. Trend Micro research highlights five S3 ransomware variants and details how attackers use native cloud features to delete, overwrite, or exfiltrate data, often evading traditional security tools. Meanwhile, a study of Australian individuals and SME owners reveals that ransomware victims frequently receive multiple ransom demands, with SMEs more likely to pay and experience repeat attacks, often affecting both work-issued and personal devices used for business. The human element remains a significant vulnerability, and the spread of ransomware within organizations underscores the need for both technological and behavioral defenses.
The evolving ransomware landscape also includes sophisticated attack paths, such as lateral movement using compromised credentials, targeting backup servers, and exfiltrating sensitive files before deploying ransomware, as seen in recent incidents involving the Lynx ransomware. These developments highlight the necessity for organizations to implement robust cloud security measures, improve detection and response capabilities, and educate users about the risks of paying ransoms. The convergence of cloud-focused ransomware tactics and the persistent targeting of individuals and small businesses demonstrates the broadening scope and impact of ransomware threats in the current cybersecurity environment.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
Trend Micro published research describing how ransomware actors increasingly target AWS cloud-native assets such as S3 buckets, snapshots, databases, container registries, and backup systems. The report emphasized that compromising or deleting these resources can block recovery and increase pressure on victims to pay.
The DFIR Report publicly documented the nine-day March 2025 intrusion, detailing the attack path, persistence, exfiltration, infrastructure, and ransomware deployment. The publication provided technical insight into the Lynx ransomware operation.
On the final day of the roughly nine-day intrusion, the actor accessed backup servers, deleted Veeam backup jobs, and deployed Lynx ransomware across multiple backup and file servers via RDP. The report assessed the time from initial access to ransomware as about 178 hours.
During the intrusion, the actor changed RDP source infrastructure between two IP addresses attributed to Railnet LLC, described in the report as a front for the Russia-based bulletproof hosting provider Virtualine. The same client hostname was maintained across the infrastructure change.
Midway through the intrusion, the actor gathered sensitive data from multiple network shares, compressed it with 7-Zip, and exfiltrated it using the temporary file-sharing service temp.sh. This established a data-theft phase before ransomware deployment.
During the intrusion, the attacker relied heavily on SoftPerfect Network Scanner for network discovery and lateral movement. They later downloaded NetExec to conduct SMB password spraying and enumeration over port 445.
Within minutes of initial access, the actor used a separate compromised domain administrator account to RDP into a domain controller. They created multiple look-alike Active Directory accounts, added them to privileged groups, and set passwords to never expire for persistence.
In early March 2025, an attacker accessed an internet-exposed host through RDP using pre-compromised valid credentials. The report found no evidence of brute force or credential stuffing during the initial compromise.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
trendmicro.com
Open sourceaic.gov.au
Open sourcethedfirreport.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.