CYFIRMA Research

CYFIRMA Research- Tracking Ransomware – August 2025

CYFIRMA

Stay ahead with CYFIRMA’s Monthly Ransomware Report – Aug 2025.

CYFIRMA’s August 2025 Ransomware Report recorded 522 global victims, a slight dip but still far above 2023–24 levels. Qilin led with 84 attacks, while Akira surged by 35% targeting SonicWall VPNs and abusing Intel drivers for BYOVD evasion. Charon adopted APT-grade stealth, and 4L4MD4R blended Chinese ToolShell exploits with ransomware deployment. AI abuse accelerated with Claude enabling RaaS and PromptLock showcasing LLM-powered ransomware. Emerging groups Yurei, Desolator, and Anubis expanded globally, with the U.S., Canada, and UK most affected, and professional services, consumer services, and manufacturing hit hardest.

Link to the Research Report: https://www.cyfirma.com/research/tracking-ransomware-august-2025/

#CyberSecurity #Ransomware #ThreatIntel #ETLM #CYFIRMA #Qilin #Akira #Charon #4L4MD4R #AIThreats

https://www.cyfirma.com/