Multiple cybersecurity reports highlight a surge in both ransomware and infostealer malware activity targeting organizations worldwide in late 2025. Notably, Qilin ransomware targeted a South Korean semiconductor back-end firm and a private equity firm, while data from a South Korean online ticketing platform was sold on dark web forums. The French interior ministry also faced a data breach, with claims surfacing on BreachForums and a suspect subsequently arrested. These incidents underscore the persistent threat posed by ransomware groups, with attacks affecting critical infrastructure sectors such as manufacturing, healthcare, and finance. The November 2025 threat trend report details the prevalence of major ransomware groups like Clop, Akira, and Qilin, and provides statistics on affected industries and regions.
In parallel, infostealer malware campaigns have intensified, with Phantom Stealer version 3.5 emerging as a sophisticated threat capable of extracting sensitive data such as passwords, browser cookies, and cryptocurrency wallet information. This malware often masquerades as legitimate software installers, employing advanced evasion and process injection techniques to avoid detection. The November 2025 Infostealer Trend Report notes that infostealers like ACRStealer, LummaC2, and Rhadamanthys are frequently distributed via cracked software and SEO poisoning. Additionally, phishing campaigns using purchase order-themed PDFs are being used to harvest business credentials and system information, which are then exfiltrated to attackers via Telegram for further exploitation or sale.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
Researchers described Phantom Stealer v3.5 as an active infostealer distributed through fake Adobe installers and other deceptive lures. The malware uses obfuscated scripts, process injection, anti-analysis techniques, and exfiltration over channels including SMTP, FTP, Telegram, and Discord to steal credentials, cookies, payment data, and wallet information.
A claim alleging a data breach involving the French interior ministry was posted on BreachForums. ASEC also noted that a suspect connected to the incident was arrested.
Data allegedly taken from a South Korean online ticketing and reservation platform was advertised for sale on DarkForums, indicating a breach affecting the service. ASEC included the sale in its roundup of notable December 2025 dark web incidents.
ASEC reported that the Qilin ransomware group targeted a South Korean semiconductor back-end company and a South Korean private equity firm in December 2025. The incidents were part of broader ransomware and dark web activity tracked during the month.
Analysis of the phishing kit’s heavily obfuscated JavaScript revealed that it harvested credentials and victim telemetry such as browser, OS, language, cookies, screen size, and location. The stolen data was exfiltrated via POST requests to an attacker-controlled Telegram bot and forwarded to a hardcoded Telegram chat.
Multiple phishing PDFs, including one titled “NEW Purchase Order # 52177236.pdf,” were observed linking to the same ionoscloud.com subdomain, indicating a credential-harvesting campaign reusing shared infrastructure across lures. The phishing pages pre-filled victims’ email addresses and targeted business email credentials.
AhnLab’s November 2025 infostealer report found ACRStealer, LummaC2, Rhadamanthys, and AURA Stealer to be the most prevalent families, with DLL sideloading used in 77.3% of samples. The report also noted SEO poisoning, abuse of legitimate sites and forums, and mass distribution of a new loader variant.
AhnLab’s November 2025 ransomware trend report documented continued growth in attacks worldwide, especially against manufacturing, healthcare, and finance. The report highlighted activity from both established and newly emerged ransomware groups based on AhnLab and leak-site data.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
asec.ahnlab.com
Open sourcecybersecuritynews.com
Open sourcemalwarebytes.com
Open sourceasec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.