2025 Ransomware trend toward built-in Windows tooling and lower ransom payment rates
Trend
Summary
Hide ▲
Show ▼
Ransomware operators are increasingly leaning on built-in Windows tooling while ransom payment rates continue to decline across 2025, weakening extortion returns for enterprise victims. The same incident set shows more data theft and more targeting of virtualization infrastructure, which raises disruption and double-extortion risk. Attackers are also exploiting VPNs and firewalls for initial access while relying less on tools like Cobalt Strike Beacon. The shift points to a more stealth-oriented operating model that is harder to detect and disrupt.
Related Happenings
Google hit by network compromise
Incident
H score42
First: 14.07.2026 09:19
Last: 14.07.2026 09:19
Sources 1
About this happening:
Google confirmed a June 2025 compromise of one corporate Salesforce instance, and attackers took largely public business contact data before access was cut off. Th...
Google hit by network compromise
IncidentAbout this happening: Google confirmed a June 2025 compromise of one corporate Salesforce instance, and attackers took largely public business contact data before access was cut off. Th...
INC ransomware group’s RaaS expansion and victim growth in 2026
Threat Actor Meta
H score45
First: 18.06.2026 17:12
Last: 18.06.2026 17:12
Sources 1
About this happening:
INC has grown from a RaaS startup into one of 2026’s most prolific ransomware groups, with 830+ victims since August 2023. The expansion followed affiliate migrati...
INC ransomware group’s RaaS expansion and victim growth in 2026
Threat Actor MetaAbout this happening: INC has grown from a RaaS startup into one of 2026’s most prolific ransomware groups, with 830+ victims since August 2023. The expansion followed affiliate migrati...
ScarCruft sqgame[.]net supply-chain espionage campaign
Campaign
H score8
First: 05.05.2026 12:07
Last: 05.05.2026 12:07
Sources 1
About this happening:
ScarCruft's late-2024 supply-chain campaign against sqgame[.]net expanded a niche gaming platform compromise into a multi-platform espionage channel. The operation...
ScarCruft sqgame[.]net supply-chain espionage campaign
CampaignAbout this happening: ScarCruft's late-2024 supply-chain campaign against sqgame[.]net expanded a niche gaming platform compromise into a multi-platform espionage channel. The operation...
Instructure hit by cyberattack
Incident
H score78
First: 04.05.2026 01:16
Last: 04.05.2026 01:16
Sources 1
About this happening:
Instructure disclosed a cybersecurity incident that exposed user information and prompted an investigation with outside experts and law enforcement. The event matters beca...
Instructure hit by cyberattack
IncidentAbout this happening: Instructure disclosed a cybersecurity incident that exposed user information and prompted an investigation with outside experts and law enforcement. The event matters beca...
Latest development: 14.05.2026 23:19
The House Committee on Homeland Security and the US Senate Committee on Health, Education, Labor, and Pensions sought briefings from Instructure over the Canvas compromise, pressing the edtech vendor on whether it paid a ransom, what data was affected, how it handled the recent attacks, and whether the incident was linked to a prior Salesforce compromise.
Vect 2.0 ransomware wiper-flaw activity
Malware Activity
H score31
First: 29.04.2026 18:23
Last: 29.04.2026 18:23
Sources 1
About this happening:
The Vect 2.0 ransomware variant now permanently destroys large files instead of encrypting them, which can leave defenders without a recoverable copy. The flaw affects ver...
Vect 2.0 ransomware wiper-flaw activity
Malware ActivityAbout this happening: The Vect 2.0 ransomware variant now permanently destroys large files instead of encrypting them, which can leave defenders without a recoverable copy. The flaw affects ver...
Timeline
-
17.03.2026 23:41 2 articles · 4mo ago
GTIG reports ransomware shift toward native Windows tools
Initial DisclosureGoogle Threat Intelligence Group published 2025 ransomware research showing threat actors leaning more on built-in Windows capabilities and less on external tooling such as Cobalt Strike Beacon and Mimikatz, while ransom payment rates continue to fall for affected organizations. The findings say suspected data theft appeared in about 77% of attacks, 43% of intrusions targeted virtualization infrastructure, vulnerabilities were used for initial access in one-third of cases, and data leak sites increasingly name victims that do not pay. Google also observed PowerShell used to query Active Directory objects, along with internal Windows utilities such as ipconfig, netstat, ping, and nltest, as part of this evasion-through-normalcy approach.
Show sources
- Less Lucrative Ransomware Market Makes Attackers Alter Methods — www.darkreading.com — 17.03.2026 23:41
- Less Lucrative Ransomware Market Makes Attackers Alter Methods — www.darkreading.com — 17.03.2026 23:41