Report
Mid-Year Threat Landscape 2025: Ransomware, DDoS, APTs, and Emerging Cyber Risks
This report analyzes cybersecurity activity observed by Inetum’s LiveSOC during the first half of 2025. The team managed 77,093 alerts and 25,171 confirmed incidents, including 21,241 alerts and 10,500 incidents rated critical or high severity. Malware detection, privilege escalation in Azure AD, indicators of compromise, failed authentication, and phishing were among the leading alerts. Ransomware rose sharply, with 2,406 attacks recorded across Inetum’s 19 operating countries; Cl0p, Qilin, Akira, Play, and RansomHub were the most active groups. The report also covers APT29 and APT41, escalating DDoS activity, vulnerability exploitation, MITRE ATT&CK techniques, and 2,077 shared indicators of compromise. Geopolitical conflicts continued to influence cyber operations, while AI expanded bot
