Kaspersky's 2025 Ransomware Report Reveals AI-Driven Threats and Regional Vulnerabilities

2 Sources

Share

Kaspersky's latest report highlights the evolving ransomware landscape, including the rise of AI-powered attacks, regional vulnerabilities, and emerging trends in cybercrime tactics.

News article

Global Ransomware Landscape

Kaspersky's 2025 Ransomware Report, released ahead of International Anti-Ransomware Day on May 12, provides crucial insights into the evolving cyberthreat landscape. The report reveals that the share of users affected by ransomware attacks globally increased by 0.1% from 2023 to 2024

1

. While this percentage may seem small, it reflects the targeted nature of ransomware attacks, which often focus on high-value targets rather than mass distribution.

Regional Vulnerabilities

The Middle East, Asia-Pacific (APAC), and African regions lead in the share of users attacked by ransomware, followed by Latin America, the Commonwealth of Independent States (CIS), and Europe

2

. This distribution is attributed to varying levels of digital transformation, cybersecurity maturity, and economic factors across regions.

In APAC, rapid digital transformation and expanding attack surfaces have made enterprises prime targets, particularly in countries with growing economies and new data privacy laws

2

. Africa, despite lower overall digitization, is seeing an increase in ransomware attacks, especially in South Africa and Nigeria, targeting manufacturing, financial, and government sectors

2

.

Emerging Threats and Trends

AI-Powered Ransomware

The report highlights the increasing use of AI tools in ransomware development. A notable example is FunkSec, a ransomware group that emerged in late 2024 and quickly gained notoriety

1

. FunkSec's operations showcase:

  • Use of AI-generated code with flawless comments, likely produced by Large Language Models (LLMs)
  • Double extortion tactics combining data encryption and exfiltration
  • Targeting of government, technology, finance, and education sectors in Europe and Asia
  • A high-volume, low-cost approach with unusually low ransom demands

Ransomware-as-a-Service (RaaS) Model

The RaaS model continues to dominate the ransomware landscape, lowering the technical barrier for cybercriminals

1

. In 2024, platforms like RansomHub thrived by offering malware, technical support, and affiliate programs, enabling less-skilled actors to execute sophisticated attacks

1

.

Future Projections

Looking ahead to 2025, Kaspersky anticipates several developments in ransomware tactics:

  1. Exploitation of unconventional vulnerabilities, such as using webcams to bypass endpoint detection systems

    2

  2. Increased targeting of IoT devices and smart appliances

    2

  3. Refined tactics focusing on stealthy reconnaissance and lateral movement within networks

    2

  4. Proliferation of LLMs tailored for cybercrime, further lowering the technical barrier for creating malicious code and phishing campaigns

    2

Regional Cybersecurity Landscape

The CIS region sees a smaller share of ransomware attacks, but faces threats from hacktivist groups like Head Mare and Twelve, which often use ransomware such as LockBit 3.0

1

. Manufacturing, government, and retail sectors are the most targeted in this region

1

.

Europe, while consistently targeted, benefits from robust cybersecurity frameworks and regulations that deter some attackers

1

. Sectors such as manufacturing, agriculture, and education are often targeted, but mature incident response and awareness limit the scale of attacks

1

.

As ransomware threats continue to evolve, the report underscores the importance of global awareness and the implementation of best practices for prevention and response across all regions and sectors.

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo