February 2025 has set a grim record as the worst month in ransomware history, recording a 126% year-over-year increase in claimed victims.
According to the latest Bitdefender Threat Debrief, ransomware groups claimed 962 victims in February 2025, up from 425 in February 2024, with cyber criminals increasingly exploiting newly discovered vulnerabilities in edge network devices.
The Clop (Cl0p) ransomware-as-a-service (RaaS) group was responsible for a significant portion of these attacks, claiming 335 victims – an 300% increase from the previous month.
This surge is attributed to the group’s exploitation of two critical vulnerabilities in Cleo file transfer software, CVE-2024-50623 and CVE-2024-55956, both rated 9.8 out of 10 in severity.
These vulnerabilities, disclosed in late 2024, allowed attackers to remotely execute commands on vulnerable systems. The delay between vulnerability disclosure and the actual ransomware attacks underscores the time-intensive manual hacking phase that follows initial access.
How Ransomware Groups Are Adapting
Ransomware groups are shifting their focus from targeting specific industries to exploiting high-risk vulnerabilities that meet specific criteria: high Common Vulnerability Scoring System (CVSS) scores, the ability to allow remote code execution (RCE), and affecting internet-accessible software.
Once a vulnerability is disclosed, threat actors rapidly deploy automated scanners to identify and exploit vulnerable systems within 24 hours. The subsequent manual hacking phase, which involves lateral movement and living-off-the-land techniques, often takes weeks or months before ransomware is deployed or data is stolen.
Recommended reading
- Arctic Wolf Threat Report: Ransomware As A Service On the Rise
- Deepfake Fraud Explodes 2,000% In Three Years
- NHS Staff Don’t Think They’re Cyber Ready, BT Finds
To combat these evolving threats, Bitdefender recommends several key defenses:
- Smart Patching: Prioritise patching for actively exploited vulnerabilities and stay informed about known exploits through resources like the CISA KEV catalog.
- Threat Hunting: Proactively search networks for hidden threats and backdoors before attackers can escalate their operations.
- EDR/XDR with SOC/MDR: Utilise advanced detection systems and expert analysis to identify and stop lateral movement within networks.
Notable Ransomware Developments
- Black Basta Chatbot: Following the leak of over one million Black Basta chats, a cybersecurity firm developed BlackBastaGPT, a chatbot that helps researchers analyse the group’s operations. Insights revealed include the group’s profits, use of deepfakes, and references to over 60 CVEs.
- Ghost Ransomware Advisory: CISA issued a joint advisory on Ghost (Cring) ransomware, a China-based group exploiting vulnerabilities like CVE-2021-34473. The group uses tools such as PowerShell scripts and Cobalt Strike, and organisations are urged to implement network segmentation, scheduled backups, and phishing-resistant MFA.
- RA World Tools Linked to Chinese Threat Actors: RA World attacks, which use DLL sideloading techniques, have been traced back to Chinese threat actors like Mustard Panda, highlighting the blending of APT and RaaS operations.
- Akira’s Webcam Exploit: The Akira ransomware group bypassed defenses by compromising a victim’s webcam, exploiting its Linux OS compatibility and lack of monitoring to deploy ransomware over SMB.
- FunkSec’s Wolfer Tool: The rapidly growing FunkSec group released Wolfer, an infostealer that interacts with a Telegram bot to extract system information, network connections, and Wi-Fi passwords.
- Cactus Linked to Black Basta: Researchers identified similarities between Cactus and Black Basta, including the use of social engineering tactics and the BC Module for persistence and reconnaissance.
- Emerging Groups: New ransomware groups like Anubis and Run Some Wares have emerged, employing double extortion tactics and maintaining their own data leak sites.





