Ransomware Activity Driven by VPN Exploitation, Takedowns
Statistical Overview
Victim Totals
- This month: 542
- This quarter: 1320
- Year to date: 3946
- Last 24h: 22
Quarterly Breakdown Q1: 2631 | Q2: 1320 | Q3: 0 | Q4: 0
Ransomware activity continues at a consistent pace, with the observed 22 new victims in the last 24 hours contributing to the ongoing quarterly totals. This period reflects a diverse targeting approach across various sectors and geographies.
Introduction
The past 24 hours saw 22 new ransomware victims, indicating persistent activity across the threat environment. The most active groups included Payload (4 victims), APT73 (3 victims), CoinbaseCartel (3 victims), and The_Gentelman (3 victims). Affected sectors ranged from Transportation & Logistics and Healthcare to Technology/Software and Manufacturing, with many incidents in the United States.
Ransomware Summary Table
| # | Group | Victims (24h) | Sample Victims | Geos | Sectors |
|---|---|---|---|---|---|
| 1 | Payload | 4 | A-sonic logistic solutions, G theodor freese, Internal medicine and pediatrics of cullman (+1) | Germany, Singapore | Transportation & Logistics, Healthcare |
| 2 | APT73 | 3 | Alkaloid.com.mk, Narit.or.th, Ungererandcompany.com | United States, Thailand | Pharmaceuticals & Biotech, Manufacturing |
| 3 | CoinbaseCartel | 3 | Openmind networks, Panasonic aero, Pragmatic solutions | United States, Gibraltar | Telecommunications, Technology / Software |
| 4 | The Gentelman | 3 | Grupo pasquel, Mbm corp, Ymca of columbia | United States, Ecuador | Retail & Ecommerce, Manufacturing |
| 5 | CMD | 2 | Goodstone Group, Ira & Larry Goldberg Coins & Collectibles | United States | Professional Services |
| 6 | Nova (RALord) | 2 | Neubox, Softseba | Bangladesh, Mexico | Technology / Software |
| 7 | Qilin | 2 | Hamer childs, Porter w yett | United States, United Kingdom | Legal, Construction & Engineering |
| 8 | 3AM | 1 | Consultic.be | Belgium | Technology / Software |
| 9 | Brain Cipher | 1 | Sheppadviser.com.au | Australia | Media & Entertainment |
| 10 | LockBit | 1 | shottermill-jun.surrey.sch.uk | United Kingdom | Education |
Payload emerged as the most prolific ransomware group in this period, predominantly impacting transportation and healthcare entities. Other notable activity includes APT73 targeting manufacturing and pharmaceuticals, CoinbaseCartel breaching telecommunications and technology firms, and The_Gentelman affecting retail and manufacturing across the Americas. Several groups, including Qilin and LockBit, continued to target diverse geographies and industries.
Victim Distribution
By Country
- United States: 8
- United Kingdom: 2
- Singapore: 2
- Thailand: 1
- Australia: 1
- North Macedonia: 1
- Mexico: 1
- Ireland: 1
- Gibraltar: 1
- Germany: 1
By Industry
- Astronomical Research: 1
- Office Equipment Manufacturing: 1
- Numismatics and Collectibles: 1
- Nonprofit Organization: 1
- Healthcare: 1
- Executive Coaching and Leadership Development: 1
- Construction: 1
- Chemical Manufacturing: 1
- Aviation and Aerospace Component Manufacturing: 1
- Law Firms & Legal Services: 1
The United States remains a primary target, with the highest number of victims, while industrial and technology sectors show broad exposure. This suggests a continued opportunistic targeting approach combined with a focus on economically vital infrastructure.
Ransomware News
Topline - Law enforcement significantly disrupted ransomware infrastructure while threat actors continued exploiting VPN vulnerabilities and targeting supply chain entities and financial institutions.
Campaigns & Operations - In a coordinated multinational effort, Europol executed "Operation Saffron," seizing the "First VPN" service and arresting its administrator, which was widely used by ransomware gangs for anonymity. Concurrently, ransomware attacks impacted Hongsu Technology, a TSMC CoWoS equipment factory in Taiwan, and Nostrum Co., Ltd. in Japan, which provides learning support services. ShinyHunters claimed a data breach against 7-Eleven, exfiltrating franchisee data. CoinbaseCartel and TeamPCP asserted data-leak claims against an Open-Source Visualization Platform and a major developer platform respectively. Reports also described ongoing threats to the Korean financial sector, involving a three-stage malware workflow. Various industrial organizations also faced APT and financial attacks from groups like Head Mare, LockBit 5.0, and DynoWiper/LazyWiper. For more information on recent threat activity, see our analysis of latest ransomware threat activity.
Vulnerabilities & TTPs - Threat actors continue to exploit poorly patched SonicWall SSL VPN appliances, specifically using CVE-2024-12802 for MFA bypass and credential brute-forcing. Beyond VPNs, initial access commonly involved phishing delivering backdoor-downloader-droppers and infostealers, as observed in the Korean financial sector. The threat environment also includes discussions on securing AI model pipelines from ransomware, which targets vulnerabilities in weights, training pipelines, and orchestration layers.
Analyst Note - The period shows a dual focus: disrupting established cybercrime infrastructure and confronting persistent exploitation of network perimeter vulnerabilities and expanding threats to emerging technologies.
Technical Takeaways
- Europol's takedown of "First VPN" demonstrates an increased focus on disrupting core cybercrime infrastructure.
- Persistent exploitation of VPN vulnerabilities, specifically SonicWall SSL VPN CVE-2024-12802, shows the need for complete patching and multi-factor authentication.
- Ransomware activity includes targeting of supply chain entities, such as the attack on Hongsu Technology, a TSMC CoWoS equipment supplier.
- Financial and industrial sectors face diverse attack chains, incorporating multi-stage malware, infostealers, and a variety of ransomware strains (e.g., Everest, Qilin, LockBit 5.0).
- Emerging threats to AI infrastructure show vulnerabilities within model pipelines, training data, GPU clusters, and other components, which points to a future ransomware vector.