Ransomware attacks evolve with bolder tactics, Palo Alto Networks warns

Palo Alto Networks logo featuring a combination of orange and black colors.

Palo Alto Networks has released its Unit 42 Extortion and Ransomware Trends report covering January to March 2025. The findings reveal a significant shift in how cybercriminals operate, with threat actors now using more aggressive extortion tactics, collaborating with state-sponsored groups, and adopting methods that go beyond traditional encryption.

Across the Asia-Pacific and Japan region, more organizations are taking cybersecurity seriously, often detecting breaches early in the attack cycle. This has resulted in a higher number of incident response cases being contained at the initial network access stage. However, despite these improvements, ransomware and extortion campaigns remain highly effective.

Unit 42 researchers found that as organizations strengthen their defenses, cybercriminals are adapting with even more persistent and manipulative strategies designed to increase pressure and secure larger payouts. These tactics include false claims of data breaches, insider threats, and tools that disable security software.

“We are witnessing a shift in ransomware operations both globally and within Asia-Pacific and Japan,” said Philippa Cogswell, Vice President and Managing Partner of Unit 42 in the region. “Attackers are moving away from traditional encryption methods and are now using deception, social engineering, and direct attacks on security controls. It’s crucial for businesses to move past reactive strategies and invest in full-spectrum visibility and rapid incident response capabilities.”

In the Philippines, ransomware remains a pressing concern for both government institutions and private enterprises. Recent incidents have disrupted online services and locked down sensitive data, often halting operations entirely until ransoms are paid or systems are recovered.

Given the scale and frequency of these attacks, the need for a unified and proactive cybersecurity approach is more urgent than ever. The country’s National Cybersecurity Plan 2023–2028 has made ransomware readiness a top priority, emphasizing the protection of critical infrastructure and building up response capabilities. Still, experts say additional investments are needed in real-time threat detection, AI-powered tools, and cross-sector collaboration.

The Unit 42 report highlights several important trends:

  • False extortion claims are rising: Cybercriminals are increasingly sending fake ransom demands, including physical notes to executives’ homes and fabricated evidence of breaches.
  • Manufacturing remains the most targeted industry, followed by wholesale and retail, and professional and legal services.
  • Top targeted countries include the United States, Canada, United Kingdom, and Germany, based on victim organization headquarters.
  • Cloud and endpoint environments are under pressure: Attackers are using tools known as “EDR killers” to disable endpoint detection and response systems, while ramping up their focus on cloud infrastructure.
  • AI-generated identity fraud is creating new insider threats: North Korean actors are reportedly posing as remote IT contractors using AI-generated identities, stealing proprietary code and threatening to leak it unless paid.
  • RansomHub has emerged as the dominant ransomware variant during the first quarter of 2025. Initially spotted in mid-2024, it has quickly become one of the most widely deployed ransomware strains.

As cyber threats continue to evolve, the report underscores the importance of adopting a defense-in-depth strategy that includes prevention, detection, response, and recovery.

For more information and to access the full report, visit: https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/

Leave a Reply

Discover more from

Subscribe now to keep reading and get access to the full archive.

Continue reading