Executive Summary
In Q2 2025, the global ransomware threat landscape saw a significant surge with the discovery of 1,702 new ransomware variants and nearly 86,000 users targeted. High-profile law enforcement actions included indictments and extraditions involving Black Kingdom, Nefilim, Ryuk, DoppelPaymer, and RobbinHood operators. Major campaigns leveraged vulnerabilities in SAP NetWeaver, Fortinet devices, and Microsoft Windows (CLFS driver), with actors like Qilin and DragonForce demonstrating adeptness in exploiting zero-days and supply chain weaknesses. Double extortion and rapid lateral movement were widely observed, affecting critical sectors worldwide, including healthcare, government, and managed service providers.
This incident underscores the advancement of ransomware attack tactics, the spread of sophisticated variants, and the persistence of threat actors despite law enforcement measures. The continued exploitation of newly discovered vulnerabilities and focus on high-revenue targets highlight the urgent need for enhanced prevention, detection, and incident response across organizations of all sizes.
Why This Matters Now
The escalation of ransomware tactics in Q2 2025, including rapid exploitation of critical vulnerabilities and resurgence of double extortion, demonstrates that organizations remain highly vulnerable. The urgent need to address lateral movement, east-west security, and multi-cloud visibility is critical as attackers shift to opportunistic, high-impact campaigns that evade traditional defenses.
Attack Path Analysis
Attackers exploited internet-facing vulnerabilities in enterprise software and firmware (e.g., SAP NetWeaver, FortiGate, SimpleHelp) to gain unauthorized access. They escalated privileges locally—often through kernel or service exploits—to gain broader control. Next, they moved laterally across internal cloud/hybrid environments, leveraging remote admin tools and exploiting weak east-west traffic controls. They established encrypted command and control channels to stealthily manage assets. Sensitive data was exfiltrated—sometimes using encrypted outbound channels—before deploying ransomware that encrypted data, destroyed backups, and demanded ransom.
Kill Chain Progression
Initial Compromise
Description
Adversaries exploited unpatched vulnerabilities in public-facing systems (SAP NetWeaver CVE-2025-31324, FortiGate CVE-2024-21762/55591, remote admin tools) for initial cloud or hybrid network access.
Related CVEs
CVE-2024-57727
CVSS 9.8SimpleHelp remote support software v5.5.7 and earlier is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests.
Affected Products:
SimpleHelp SimpleHelp – <= 5.5.7
Exploit Status:
exploited in the wildCVE-2024-57728
CVSS 8.8SimpleHelp remote support software v5.5.7 and earlier allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file, which can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.
Affected Products:
SimpleHelp SimpleHelp – <= 5.5.7
Exploit Status:
exploited in the wildCVE-2024-57726
CVSS 7.2SimpleHelp remote support software v5.5.7 and earlier has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions, which can be used to escalate privileges to the server admin role.
Affected Products:
SimpleHelp SimpleHelp – <= 5.5.7
Exploit Status:
exploited in the wildCVE-2025-31324
CVSS 9.1SAP NetWeaver software contains a vulnerability that allows attackers to upload malicious files without authentication, potentially leading to complete system compromise.
Affected Products:
SAP NetWeaver – All versions prior to patch
Exploit Status:
exploited in the wildCVE-2024-21762
CVSS 9.8FortiGate software contains a vulnerability that allows attackers to bypass authentication and execute malicious code remotely.
Affected Products:
Fortinet FortiGate – All versions prior to patch
Exploit Status:
exploited in the wildCVE-2024-55591
CVSS 9.8FortiGate software contains a vulnerability that allows attackers to bypass authentication and execute malicious code remotely.
Affected Products:
Fortinet FortiGate – All versions prior to patch
Exploit Status:
exploited in the wildCVE-2025-29824
CVSS 7.8Windows Common Log File System (CLFS) driver contains a zero-day vulnerability that allows an attacker to elevate privileges on a compromised system.
Affected Products:
Microsoft Windows – All versions prior to patch
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Phishing: Spearphishing Attachment
Valid Accounts
Create Account
Command and Scripting Interpreter
Exploitation for Privilege Escalation
Data Encrypted for Impact
Service Stop
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS v4.0 – Security of Public-Facing Applications
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Article 9
CISA Zero Trust Maturity Model (ZTMM) v2.0 – Continuous Validation of User Access
Control ID: Identity - Access Management
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
PCI DSS v4.0 – Audit Log Management
Control ID: 10.4.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Health Care / Life Sciences
Ransomware groups exploiting SAP NetWeaver and Fortinet vulnerabilities threaten healthcare data encryption, demanding HIPAA compliance for encrypted traffic and zero trust segmentation.
Financial Services
Banking sector faces elevated ransomware risks from Qilin and RansomExx groups exploiting Windows CLFS vulnerabilities, requiring PCI-compliant east-west traffic security and egress filtering.
Government Administration
Government agencies targeted by RobbinHood ransomware through SimpleHelp remote administration tools, necessitating NIST 800-53 compliant threat detection and multicloud visibility controls.
Information Technology/IT
IT infrastructure vulnerable to mass SAP NetWeaver exploitation and IoT botnet attacks from China/India, requiring zero trust segmentation and inline IPS protection.
Sources
- IT threat evolution in Q2 2025. Non-mobile statisticshttps://securelist.com/malware-report-q2-2025-pc-iot-statistics/117421/Verified
- CISA and Partners Release Update to BianLian Ransomware Cybersecurity Advisoryhttps://www.cisa.gov/news-events/alerts/2024/11/20/cisa-and-partners-release-update-bianlian-ransomware-cybersecurity-advisoryVerified
- NVD - CVE-2024-57727https://nvd.nist.gov/vuln/detail/CVE-2024-57727Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying robust Zero Trust segmentation, east-west traffic controls, inline intrusion prevention, and strong egress enforcement would have significantly limited attacker movement, data exfiltration, and the ultimate ransomware impact at every stage of the kill chain.
Control: Cloud Firewall (ACF)
Mitigation: Blocks direct access to vulnerable public services through enforced perimeter security.
Control: Threat Detection & Anomaly Response
Mitigation: Detection and rapid alerting on abnormal privilege activity or exploitation.
Control: Zero Trust Segmentation
Mitigation: Prevents unauthorized east-west traffic and limits blast radius.
Control: Inline IPS (Suricata)
Mitigation: Identifies and blocks C2 traffic patterns and known malicious signatures.
Control: Egress Security & Policy Enforcement
Mitigation: Stops unauthorized exfiltration using FQDN, application, and data movement controls.
Centralized visibility enables rapid response and containment to limit overall damage.
Impact at a Glance
Affected Business Functions
- Remote Support Services
- Network Security
- Data Management
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive configuration files, user credentials, and other critical data due to unauthorized access and exploitation of vulnerabilities.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce dynamic Zero Trust segmentation to restrict workload-to-workload and inter-region traffic, minimizing lateral movement opportunities.
- • Deploy cloud-native firewalls and inline IPS for real-time inspection and automated enforcement of anomalous, malicious, or C2 traffic—east-west and outbound.
- • Strengthen continuous threat detection and anomaly response to quickly identify privilege escalation and unusual access, enabling faster containment.
- • Implement granular egress controls and FQDN/application filtering to prevent unauthorized data exfiltration and detect double extortion tactics.
- • Centralize visibility and policy management across multicloud and hybrid environments to enable rapid incident response, scope identification, and damage limitation.



