Site navigation

Nation-State Attacks Surging Across Europe, Warns CrowdStrike

Tom Quinn

,

nation state cyber attack
Violence-as-a-Service is emerging as a potent new threat in Europe, with attackers bridging cyber and physical operations resulting in sabotage, arson, and targeted violence offline.

Europe has become the world’s second-largest ransomware target, trailing only North America, amid rising aggression from “Big Four” nation-state actors, a new CrowdStrike report has warned.

The cybersec firm’s 2025 European Threat Landscape Report reveals that European organisations made up nearly a quarter (22%) of global ransomware and extortion victims last year, as state-backed actors from Russia, China, North Korea, and Iran ramped up cross-industry attacks.

Since January 1, 2024, over 2,100 European victims have appeared on extortion leak sites, most from the UK, Germany, France, Italy, and Spain, with 92% of cases involving file encryption and data theft.

CrowdStrike identifies China as one of the most aggressive state actors in data theft, though less focused on ransomware and more intent on infiltrating cloud infrastructure and software supply chains to steal intellectual property. 

Persistent campaigns tied to Chinese groups have targeted healthcare and biotech sectors, with Vixen Panda emerging as the leading threat to European government and defence networks.

Iran has also reportedly expanded its cyber operations in Europe, with threat groups linked to the Islamic Revolutionary Guard Corps (IRGC) ramping up their phishing, hack-and-leak, and DDoS campaigns against the UK, Germany, and the Netherlands. 

In one notable example of Iran’s growing influence, the Haywire Kitten group (malicious despite its cute name) claimed responsibility for a DDoS attack against a Dutch news outlet, while multiple other Iran-nexus actors masqueraded as hacktivists to obscure state-sponsored espionage efforts.

Meanwhile, more established threat groups linked to Russia have continued to target Ukraine, conducting credential phishing, intelligence collection, and destructive operations targeting government, military, energy, telecom, and utilities, while North Korean groups have expanded their targeting of European defence, diplomatic, and financial institutions, combining espionage with cryptocurrency theft to advance strategic interests. 

It’s no coincidence these hostile groups are targeting Europe’s largest economies, home to high-value sectors like manufacturing, professional services, technology, industrials, and engineering, which remain prime targets for the likes of DPRK hackers, who are increasingly concerned with revenue generation to supplement the state’s coffers.

“The cyber battlefield in Europe is more crowded and complex than ever,” said Adam Meyers, head of Counter Adversary Operations at CrowdStrike. 

“We’re seeing a dangerous convergence of criminal innovation and geopolitical ambition, with ransomware crews using enterprise-grade tools and state-backed actors exploiting global crises to disrupt, persist, and conduct espionage.


Recommended reading


Meanwhile, CrowdStrike also observed a jump in threat actor capabilities, with high-profile groups like SCATTERED SPIDER increasing their ransomware deployment speed by 48%, meaning the average attack now takes just twenty-four hours.

This efficiency is supplemented by the evolution of the cyber underground, with English and Russian-language forums becoming central to Europe’s criminal ecosystem, with dark web markets allowing the exchange of stolen data, malware, and criminal services, while platforms like Telegram, Tox, and Jabber facilitate collaboration, recruitment, and monetisation. 

More terrifying than any of that, however, is that these groups are no longer restricting themselves to cyber savagery, with Violence-as-a-Service emerging as a fast-growing threat across Europe.

CrowdStrike observed threat actors using Telegram-based networks to coordinate physical attacks, kidnappings, and extortion tied to cryptocurrency theft, saying that groups connected to “The Com” ecosystem are bridging cyber and physical operations, offering payments for sabotage, arson, and targeted violence.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data