HomeSecurityRansomware: Shift to silent attacks and long-term access

Ransomware: Shift to silent attacks and long-term access

Ransomware groups are shifting tactics to more stealthy infiltration as the threat of public exposure of sensitive corporate data becomes the primary extortion mechanism. Picus Security ’s annual red-teaming report shows that attackers are moving away from noisy disruptions and toward quiet, long-term access . Additionally, they are shifting from “predatory” smash-and-grab tactics to “parasitic” stealth.

Ransomware

The most common attack techniques used by ransomware groups are designed to remain hidden once attackers gain initial access. For example, ransomware operations are increasingly using defense evasion and persistence techniques.

Attackers are also increasingly directing command-and-control (C2) traffic through trusted enterprise services like OpenAI and AWS, making malicious activity look more like regular business traffic. Picus’ findings come from attack simulations combined with analysis of 1.1 million malicious files and 15.5 million adversary actions mapped to the MITRE ATT&CK framework.

See also: Ransomware attacks are on the rise, ransom payments are falling

Picus' findings about attackers' preference for quiet and persistent action over noisy disruption are consistent with research findings from Securin, which reports that attackers link vulnerabilities to their attacks on corporate systems.

“Ransomware groups no longer treat vulnerabilities as isolated entry points,” says Aviral Verma, a threat analyst at Securin. “They combine them into deliberate exploit chains, selecting weaknesses not just for their severity, but for how effectively they can impact trust, persistence, and operational control across entire platforms.” Artificial intelligence is now widely accessible to attackers, but it acts primarily as a force multiplier rather than a driving force in ransomware attacks.

Ransomware: Double threat – double blackmail

Ransomware gangs typically prefer a double blackmail tactic, which involves the threat of leaking stolen information along with the disruption caused by encryption – locking down systems after intruding into corporate networks. Picus reports a 38% decline in encryption over the past 12 months as more cybercriminals turn to silently extracting data for blackmail.

Ransomware: Shift to silent attacks and long-term access

Picus’ suggestion that the volume of ransomware attacks is decreasing is disputed by other experts. Tony Anscombe, chief security officer at Eset, offers a contrasting perspective. “In Eset’s recent H2 2025 Threat Report, detection data shows a 13% increase between H1 and H2, with a parallel 40% increase in publicly reported victims via ecrime.ch,” Anscombe tells CSO.

See also: Predator: Intellexa founder sentenced to prison for wiretapping

Nick Hyatt, senior threat intelligence consultant at cybersecurity services firm GuidePoint Security, says that data from over 7,000 victims was published last year, a number that likely excludes “victims who paid ransom and never had their details published by the attacker.”

Additionally, the number of active ransomware groups reached an all-time high last year, according to GuidePoint.

“Attackers simplified their attack capabilities, using a mix of established techniques, vulnerability exploitation, and new attacks to hit their targets,” Hyatt says.

The most “significant” ransomware groups

Experts interviewed by the CSO identified Qilin, Cl0p, and Akira as the most active ransomware groups, but there were many other threats as well.

“Akira stands out as the No. 1 ransomware group today from Huntress’ 2025 data,” says Dray Agha, senior director of security operations at Huntress. “Their craft is evolving rapidly specifically to defeat existing security solutions, and we see them aggressively targeting the hypervisor level to completely bypass traditional endpoint protections.”

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Collin Hogue-Spears from Black Duck Software says ransomware operators have stopped operating like organized crime and have started operating like a business platform.

Ransomware: Shift to silent attacks and long-term access

“Qilin reported over 1,000 victims in 2025, a seven-fold increase from the previous year,” according to Hogue-Spears. “LockBit 5.0 regained operational capability after its collapse.” Meanwhile, the Scattered Spider/Lapsus$/ShinyHunters (SLSH) collective has brought so-called extortion-as-a-service, an approach that makes it easier for less-skilled cybercriminals to make illicit money. SLSH has created a “structural shift” in the cybercrime ecosystem.

See also: Steaelite RAT: Data theft and ransomware in one tool

“Seventy-three new teams have popped up in six months because they no longer have to build their own tools,” says Hogue-Spears. “They rent them.”

New threat techniques require a security rethink

Vasileios Mourtzinos, a member of Quorum Cyber, says more groups are moving away from encryption towards extortion-based models that prioritize data theft and prolonged, silent access.

“This approach, popularized by actors like Cl0pthrough large-scale vulnerability exploitation, is now being copied by other hackers, along with increased abuse of valid accounts and legitimate management tools . In some cases, attempts have been observed to recruit or encourage insiders to facilitate access,” says Mourtzinos.

The evolving “art” of ransomware groups should prompt a rethink of defense strategies. “For CISOs, the priority should be to strengthen identity checks, closely monitor trusted third-party applications and integrations, and ensure that detection strategies focus on persistence and data extraction activity,” advises Mourtzinos.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS