Palo Alto Networks’ Unit 42 Extortion and Ransomware Trends Report reveals aggressive new tactics and escalation of threat actor collaboration

Palo Alto Networks’ Unit 42 Extortion and Ransomware Trends Report reveals aggressive new tactics and escalation of threat actor collaboration

Despite progress, ransomware and extortion campaigns continue to succeed at significant rates

Palo Alto Networks recently released the Unit 42 Extortion and Ransomware Trends January-March 2025 report, which revealed that threat actors are evolving their tactics, collaborating with state-backed groups and using extortion scams to extract payments.

Organisations across the Asia-Pacific and Japan (JAPAC) region are putting their security posture first, and many are now detecting intrusions early in the attack lifecycle, before attackers can execute their objectives.

This has led to an increase in incident response cases that are contained at the network access stage. Despite progress, ransomware and extortion campaigns continue to succeed at significant rates.

Analysing Palo Alto Networks’ Unit 42 incident response cases, Unit 42 researchers found that in response, threat actors are intensifying their tactics, using more aggressive methods to pressure victims and secure higher, more consistent payouts.

“We’re seeing a clear shift in how ransomware and extortion actors operate globally and across the Asia-Pacific and Japan region. Attackers are shifting from traditional encryption tactics to more aggressive and manipulative methods including false claims, insider access, and tools that disable security controls,” said Philippa Cogswell, Vice President and Managing Partner, Unit 42, Asia-Pacific & Japan, Palo Alto Networks. “These new and evolving tactics show just how critical it is for organisations to move beyond reactive defences and invest in security strategies that provide full visibility and rapid response across their environments.”

Singapore has seen an increase in malicious cyberactivity, particularly in the form of ransomware. Given the rise of AI, attackers are becoming more sophisticated, uncovering new methods to access victims’ data – many of which go unreported.

With local organisations implementing only 70% of essential cybersecurity measures, and just one in three fully adopting at least three of the five categories under Cyber Essentials, Singapore’s national cybersecurity standard, organisations need to adopt more comprehensive and vigilant cybersecurity practices in Singapore. “Ransomware threats in Singapore are evolving rapidly, with attackers now using increasingly aggressive and deceptive tactics to extort victims. Although organisations have improved in early detection and incident response, attackers continue to view Singapore as a viable and attractive target,” said Steven Scheurmann, Regional Vice President for ASEAN, Palo Alto Networks.

“To stay ahead of these sophisticated threats, organisations must employ a defense-in-depth strategy and be prepared to encounter additional forms of pressure from these ransomware actors.”

Key findings of the report include:

Attackers are lying to get paid: Unit 42 observed a growing number of cases of extortion scams using fake data and even physical ransom notes sent to executives’ homes.

Manufacturing remains the top ransomware target, continuing a trend that has persisted for several years. The second most impacted industry is wholesale & retail, followed by professional & legal services.

Ransomware activity by location headquarters: The most targeted regions for attackers are the United States, Canada, UK and Germany.

Cloud and endpoint security are under siege: Attackers are increasingly using “EDR killers” to disable endpoint security sensors and targeting cloud systems more aggressively than ever before.

AI-generated insider threat extortion is on the rise: North Korean operatives using AI-generated identities to post as remote IT workers have extorted companies by stealing proprietary code and threatening public leaks.

RansomHub emerges as top ransomware variant: RansomHub became the most prolific ransomware observed during the reporting period. This marks a sharp rise from mid-2024, when it was first identified as an emerging threat to watch.

Browse our latest issue

Intelligent CISO

View Magazine Archive