A Look Back at the Top 10 Ransomware of 2025

Several ransomware groups initially highlighted in our March 2025 analysis of emerging ransomware families went on to dominate the actual 2025 threat landscape. Six groups we previously examined—Qilin, Akira, Play, INC Ransom, Lynx, and RansomHub—ultimately appeared in Picus Security’s top 10 ransomware list1.

To revisit their infrastructure footprints, we analyzed 267 network IoCs extracted from public threat reports covering 10 major ransomware operations. Using the WhoisXML API MCP Server and our homegrown threat investigation tools, we uncovered the following findings:

  • One domain identified as an IoC bulk-registered with eight look-alikes
  • Three domains classified as IoCs likely registered with malicious intent
  • 2,626 unique potential victim IP addresses communicated with 40 distinct IP addresses tagged as IoCs
  • 8,491 email-connected domains, 36 of which were deemed malicious
  • Nine additional IP addresses, eight of which were dubbed malicious
  • 713 IP-connected domains, 75 of which were named malicious
  • 324 string-connected domains, two of which were categorized as malicious

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

  • [1] https://www.picussecurity.com/resource/blog/top-10-ransomware-groups-of-2025
Try our WhoisXML API for free
Get started