International Cyber Expo International Cyber Expo
  • About Us
Saturday, 25 July, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Bridewell report indicates rise in lone wolf ransomware actors

by Guru Writer
June 25, 2025
in Featured
Bridewell report indicates rise in lone wolf ransomware actors
Share on FacebookShare on Twitter
Bridewell, a UK-based cybersecurity services company, has released its latest CTI Annual Report – a comprehensive deep dive into ransomware trends. It highlighted a significant shift in attack strategies, payment dynamics and threat actor behaviours, revealing that data theft and extortion have overtaken traditional encryption-only ransomware as the most successful approach for attackers.
While encryption-based attacks tend to result in larger individual ransom payments, often due to the urgency of restoring critical services, data theft and extortion cases are more likely to result in a payment, with attackers leveraging the fear of regulatory penalties and reputational damage to pressure victims into compliance.
At the same time, ransomware payments overall have continued to decline year-on-year. Bridewell attributes this to stricter regulations, greater law enforcement coordination and increasing sanctions on cybercriminal entities. Organisations considering payment must now conduct rigorous due diligence to avoid inadvertently transacting with sanctioned groups or Ransomware-as-a-Service (RaaS) operations.
Other key findings include:
Vulnerability exploitation on the rise
Bridewell has observed that groups such as Clop and Termite have become highly proficient in exploiting internet-facing systems and edge devices, including Fortinet, Ivanti and others. Exploiting unpatched vulnerabilities remains a primary attack vector, allowing threat actors to compromise many victims at scale and drive larger financial outcomes.
Fragmentation and lone wolves
The ransomware ecosystem is becoming increasingly fragmented. Bridewell threat intelligence links this to both infighting within groups and persistent law enforcement takedowns, which have led to the splintering of major groups such as Conti and AlphV/BlackCat. This has resulted in a broader and more diverse pool of active ransomware actors, making the threat landscape more volatile and difficult to defend against.
Compounding this issue is the rise of lone-wolf actors, or individual affiliates or cybercriminals operating independently. These actors often rely on leaked RaaS source code or publicly available tools to mount ransomware operations without the need for an established group. This trend is partly driven by a lack of trust in larger operations due to the risk of exit scams, where affiliates are denied their share of ransom proceeds.
Tactical shifts in tooling and techniques
Bridewell continues to observe ransomware actors targeting VMware ESXi environments, aiming to cripple core virtualised infrastructure quickly. Groups like VanHelsing and DragonForce are actively pursuing this tactic in ongoing campaigns.
Meanwhile, adversaries are developing or acquiring capabilities to evade Endpoint Detection and Response (EDR) systems, often through the abuse of vulnerable drivers or native software features. The use of Living-Off-the-Land Binaries (LOLBINs) and Remote Monitoring and Management (RMM) tools has become widespread, allowing attackers to avoid detection and maintain persistent access without deploying traditional malware.
Despite efforts to disrupt its use, Cobalt Strike remains the most widely used offensive security tool by ransomware operators, closely followed by others such as Metasploit, Sliver, Brute Ratel, and more recently Pyramid C2, a Python-based command and control (C2) framework.
Shift to data theft-only operations
Bridewell has also observed the continued evolution of data-theft-only ransomware operations, which bypass encryption altogether. This approach is particularly effective in today’s increasingly regulated privacy landscape, where organisations fear substantial fines and long-term brand damage. Attackers are now refining their extortion tactics to exploit this pressure more effectively.
Remote access and patch management still a weak link
Bridewell’s insights, aligned with Q1 2025 data from Coveware, show that remote access solutions (VPNs, RMMs) and unpatched software vulnerabilities remain leading intrusion vectors. Although phishing incidents appear to be decreasing, it is likely that phishing is now being used indirectly, by access brokers selling credentials to ransomware affiliates.
“We’re seeing a clear shift in ransomware tactics. Encryption-only attacks are proving less effective, while data theft and extortion are leading to more successful payment outcomes. At the same time, organisations are increasingly hesitant to pay ransoms due to growing regulatory pressure and the risk of violating sanctions,” said Gavin Knapp, Cyber Threat Intelligence Principal Lead at Bridewell. “Our goal with this report is to provide actionable insights that help organisations strengthen their defences and build greater resilience against cyber attacks. Staying ahead of persistent and evolving threat actors is no easy task, but understanding and mitigating the risks posed by adversarial infrastructure must remain a core component of any robust cybersecurity strategy.”
ShareTweet
Previous Post

Keeper Security Achieves SOC 3 Compliance

Next Post

Defining Cyber Resilience: Industry Leaders Meet in London as AI Threats Accelerate

Recent News

65% of Organisations Still Detect Unauthorised Shadow AI Despite Visibility Optimism

KnowBe4’s Unveils Custom AI Video Builder

July 24, 2026
Examining the Unintended Consequences of the Online Safety Act

Examining the Unintended Consequences of the Online Safety Act

July 24, 2026
Research Shows Quantum Security Deployment Remains Stuck Despite Enterprise Planning

Research Shows Quantum Security Deployment Remains Stuck Despite Enterprise Planning

July 23, 2026
FakeAgent Campaign: Malicious Claude Artifact Used to Distribute SectopRAT to 29 Organisations

FakeAgent Campaign: Malicious Claude Artifact Used to Distribute SectopRAT to 29 Organisations

July 23, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol