Ransomware's Fragmentation Reaches a Breaking Point While LockBit Returns
These articles are AI-generated summaries. Please check the original sources for full details.
Ransomware’s Fragmentation Reaches a Breaking Point While LockBit Returns
In Q3 2025, Check Point Research recorded 85 active ransomware groups, the highest ever observed, alongside LockBit 5.0’s return, signaling a shift in cybercrime dynamics. 1,590 victims were disclosed across 85 leak sites, reflecting sustained activity despite law enforcement pressure.
Why This Matters
The ransomware landscape has transitioned from centralized RaaS models to a fragmented ecosystem of short-lived, independent operations. This decentralization erodes the predictability that security teams relied on, as smaller actors avoid infrastructure reuse and reputation-based intelligence becomes unreliable. Enforcement actions against major groups like RansomHub only displace affiliates, who regroup under new brands, sustaining attack volume. Payment rates have dropped to 25–40% as victims lose trust in unverified decryption promises.
Key Insights
- “85 active ransomware groups in Q3 2025, Check Point Research”
- “Decentralized operations over RaaS hierarchies, as seen in the collapse of RansomHub and 8Base”
- “LockBit 5.0’s return with updated Windows/Linux/ESXi variants and unique negotiation portals”
Practical Applications
- Use Case: “Healthcare sector targeted at 8% with Play group avoiding it to reduce scrutiny”
- Pitfall: “Assuming payment guarantees from small, unverified groups leads to lower recovery rates and increased financial risk”
References:
Continue reading
Next article
Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference Frameworks
Related Content
Osiris Ransomware Leverages POORTRY Driver in Novel BYOVD Attack
The newly discovered Osiris ransomware strain utilized a custom POORTRY driver in a Bring Your Own Vulnerable Driver (BYOVD) attack, resulting in data theft and security tool disabling in November 2025.
CISA's Hidden Ransomware Updates to KEV Catalog
A third of the 'flipped' CVEs affect edge devices, leading to increased ransomware risk with 59 vulnerabilities updated in 2025.
U.S. Prosecutors Indict Cybersecurity Insiders for BlackCat Ransomware Attacks
Federal prosecutors in the U.S. have indicted three cybersecurity professionals for orchestrating BlackCat ransomware attacks on five companies between May and November 2023, highlighting the risks of insider threats in the cybersecurity sector.