US Threat Landscape Report on ransomware, malware, stealer logs, and more

This week, researchers at SOCRadar released their 2025 USA Threat Landscape Report. This report, based on data collected between April 2024 through March 2025, analyzes several aspects of the current US threat landscape including ransomware threats, stealer logs statistics, phishing breaches, and DDoS stats. 

Key findings include: 

  • Information services, finance, and public administration sectors are the most targeted industries, both in phishing and dark web threats.
  • Selling and sharing stolen data dominate dark web forums, representing over 93% of activities, signaling an active criminal marketplace.
  • Data and unauthorized access are the top commodities, with 57.46% of dark web posts related to stolen databases.
  • RansomHub, PLAY Ransomware, and Akira are leading ransomware groups targeting the US, but a diverse set of other actors make up the majority.
  • Phishing attacks heavily target the Crypto/NFT, information services, and public sector, leveraging fake pages that increasingly use HTTPS (76.4%) to appear legitimate.
  • Stealer logs show massive credential exposure, with over 630,000 email/password pairs leaked, alongside credit card data and victim IP addresses.
  • Popular domains compromised include Reddit, Bing, Instagram, Facebook, and Amazon, highlighting the targeting of mainstream platforms.

For full details, the report can be read here: https://socradar.io/wp-content/uploads/2025/05/USA-Threat-Landscape-Report-2025.pdf

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading