Experiencing a Cyber Incident? Our DFIR team is on standby 24/7.

Ransomware Operations in 2025: Tracking the Evolution of Threat Actors

Jump to section

Jump to section

Threat Brief – Unit 31 | Ransomware Intelligence Report

Ransomware: A Business Crisis, Not Just a Cyber Risk

Ransomware attacks continue to escalate in frequency and impact, targeting businesses of all sizes across Greece and beyond. In 2024 alone, Greek organisations in shipping, retail, education, and media suffered breaches involving both operational shutdown and sensitive data leaks.

This edition of the Threat Brief, prepared by Unit 31, distils intelligence on three leading ransomware groups: LockBit, Akira, and Play. These actors are responsible for a significant share of global attacks and are actively targeting Greek companies today.

What makes these threats especially dangerous is the combination of data theft with system encryption, known as double extortion. Even organisations with strong backups are now facing public data leaks and reputational fallout.

This report outlines:

  • How each ransomware group operates
  • What to expect during an incident
  • Business-level consequences of a successful breach
  • Executive mitigation actions

Ransomware is no longer a distant risk. It is a present operational threat. Preparedness is no longer optional.

The Current Landscape

Ransomware continues to dominate the threat landscape in 2025. While the underlying extortion model remains familiar, the scale, stealth, and speed of recent operations have shifted significantly.

  • Attackers now operate with professional infrastructure and dedicated affiliate networks.
  • Data exfiltration, publication threats, and even direct contact with executives are now standard tactics.

In Greece, ransomware activity has sharply increased. Attacks have impacted universities, retail groups, shipping firms, and more. Victims have faced:

  • Prolonged downtime
  • Public exposure of stolen data
  • High-stakes ransom negotiations
  • Operational disruption during peak business cycles

The techniques may differ across threat actors, but the playbook is increasingly precise.

This edition of the Threat Brief breaks down the strategies and operations of three of the most active ransomware groups right now: LockBit, Akira, and Play.

Threat Actor Profile: LockBit

Overview

LockBit remains the most prolific ransomware group in the global threat landscape. Operating under a Ransomware-as-a-Service (RaaS) model, the group supplies malware and infrastructure to affiliates in exchange for a percentage of the ransom.

Since 2019, LockBit has evolved through multiple iterations (LockBit 2.0, 3.0, Green) and has been responsible for thousands of attacks worldwide.

Key Characteristics

  • RaaS infrastructure: Enables wide distribution through affiliates.
  • Double extortion: Combines data encryption with exfiltration.
  • StealBit tool: Used for rapid automated data theft.
  • Target range: Public sector, healthcare, critical infrastructure, education, and finance.

Activity Snapshot

  • Linked to over 1,700 confirmed incidents globally (2020–2023).
  • Estimated to have extorted over 90 million USD from US organisations alone.
  • Identified in multiple high-impact attacks in Greece, including a media company and a national IT services provider.

Tactics

  • Exploits known vulnerabilities and misconfigured systems.
  • Frequently uses purchased credentials from Initial Access Brokers.
  • Often deploys malware quickly after exfiltration, aiming for maximum business disruption.

Resilience

Despite law enforcement takedowns of infrastructure in early 2024, LockBit re-emerged within weeks. Its decentralised affiliate model makes it difficult to fully dismantle.

Why It Matters

LockBit’s scale, adaptability, and commercial structure make it one of the most dangerous threats to Greek and international organisations. Even mid-sized enterprises are viable targets.

LockBit 3.0 leak site showing recently exposed victim data.

Threat Actor Profile: Akira

Overview

Akira is a rapidly growing ransomware group that has gained traction since its emergence in early 2023. Despite its relatively recent arrival, the group has demonstrated advanced tactics and a high level of operational maturity.

Akira is believed to run a hybrid model, offering a RaaS platform while also executing attacks directly.

Key Characteristics

  • Double extortion: Encrypts systems and threatens to leak public data.
  • Branding: Operates a stylised leak site with cyberpunk visuals.
  • Cross-platform: Initially targeted Windows, but expanded to Linux/VMware.
  • Sophistication: Believed to use retooled methods from earlier campaigns.

Activity Snapshot

  • Credited with over 250 attacks globally in its first year.
  • Generated an estimated 42 million USD in ransom payments.
  • Targeted a growing number of Greek firms, including maritime and manufacturing companies.

Tactics

  • Uses phishing and compromised credentials for initial access.
  • Maintains stealth during intrusion using admin tools and scripts.
  • Prioritises rapid data theft followed by widespread encryption.

Regional Focus

Akira expanded into the Greek threat landscape during late 2024. At least two local organisations were publicly listed on its leak site. The group’s aggressive tactics and increasing visibility signal an expanding footprint across Europe.

Why It Matters

Akira exemplifies how new actors can scale quickly using proven playbooks. For executive leaders, it reinforces the need to monitor not just known groups but also fast-emerging threats capable of significant disruption.

Screenshot of Akira ransomware leak site with terminal-style ransom note and available commands.

Threat Actor Profile: Play

Overview

Play, also known as PlayCrypt, is a ransomware group that has operated under the radar yet caused widespread damage since mid-2022. Unlike larger affiliate-driven operations like LockBit, Play is believed to be a more closed and tightly coordinated group.

Its campaigns are marked by precision, stealth, and technical depth.

Key Characteristics

  • Intermittent encryption: Encrypts only parts of files to evade detection.
  • Minimalist ransom notes: Provide no payment amount; victims must initiate contact.
  • Aggressive extortion: Known to call victims directly to escalate pressure.

Activity Snapshot

  • Linked to over 900 ransomware incidents globally by mid-2025.
  • Victims span North and South America, Europe, and critical infrastructure sectors.
  • In Greece, Play was responsible for a 2024 ransomware attack against Eurobulk Ltd., highlighting its maritime focus.

Tactics

  • Leverages known software vulnerabilities, especially in VPNs and remote access tools.
  • Uses intermittent encryption to accelerate impact and avoid triggering alarms.
  • Steals data before encryption and publishes it via a Tor-based leak site.

Regional Focus

Play has been active in targeting European organisations across manufacturing, shipping, and services. Its presence in the Greek threat landscape, particularly within maritime, signals a sustained interest in vulnerable logistics infrastructure.

Why It Matters

Play’s tactics combine stealth with pressure. The group’s ability to remain active across multiple industries while avoiding immediate detection highlights the need for improved early warning systems and layered defences.

Play ransomware leak site listing breached companies and publication dates.

How a Ransomware Attack Unfolds

From entry to extortion: understanding the attacker’s playbook

Ransomware groups follow a structured, repeatable process to maximise impact and pressure. Each stage is designed to delay detection, cripple operations, and corner leadership into paying. The lifecycle below outlines how most attacks evolve.

1. Initial Intrusion

Attackers need a foothold. This first step is about quietly breaching the perimeter. They exploit common weaknesses such as:

  • Unpatched internet-facing services (e.g., VPNs, RDP)
  • Phishing emails with malicious attachments or links
  • Unpatched internet-facing services (e.g., VPNs, RDP)
  • Leaked credentials bought from initial access brokers

Access is often sold, not stolen. Many attackers skip the intrusion phase entirely by purchasing pre-compromised access from third-party criminals.

2. Establishing a Foothold

Once inside, attackers move carefully. They aim to stay undetected for as long as possible. They often:

  • Deploy legitimate administrative tools to blend in
  • Install remote access trojans or backdoors
  • Escalate privileges and move laterally across systems
  • Conduct reconnaissance to locate high-value assets

This phase can last from days to weeks. The goal is to prepare the environment for mass disruption.

3. Data Exfiltration

Before encryption begins, data is silently stolen.

Why? It creates leverage. If the ransom is not paid, the stolen data can be exposed or sold. This double-extortion method has become standard. Key targets include:

  • Financial records
  • Customer and employee data
  • Strategic documents and intellectual property
  • Legal or regulatory files

According to multiple industry sources, over 90% of ransomware attacks now involve data exfiltration before encryption is triggered.

4. Encryption and Outage

Now the visible damage begins. Files and systems are locked, and business operations grind to a halt. This step typically involves:

  • Encryption of endpoints, servers, and databases
  • Disabling of security tools or backups
  • Halting of operations such as email, ERP, CRM, or cloud storage

Even unaffected systems are often taken offline as a precaution. The attackers want to create urgency, confusion, and business paralysis.

5. Ransom Demand

With systems locked and data stolen, the extortion begins. Victims are usually greeted with a ransom note that includes:

  • A link to initiate contact (typically via Tor)
  • Payment instructions in cryptocurrency
  • A warning: failure to pay will result in public data leaks

Some attackers go further. They call executives, email customers, or leak sample data to increase pressure.

6. Extortion and Negotiation

Once contact is made, negotiations begin. This is a business transaction for the criminals. Common tactics include:

  • Setting high initial prices, then “offering discounts”
  • Providing a test decryption file as proof
  • Offering deletion of stolen data as part of the deal

There is no honour among thieves. Law enforcement investigations into groups like LockBit have shown that attackers often keep stolen data, even after victims pay.

Some groups re-exploit the same victim months later using the same stolen files.

7. Recovery or Remediation

Whether the ransom is paid or not, the road to recovery is long. Key challenges include:

  • Full infrastructure from trusted backups
  • Legal and regulatory reporting
  • Communication with clients, partners, and staff

Paying the ransom does not guarantee quick recovery. Decryption tools are often flawed or incomplete. Many organisations still face days or weeks of downtime.

  1. Critical disruption: Booking systems, vessel tracking, port logistics, ERP platforms, and finance tools become inaccessible.
  2. Real-world cases: A Greek hospital reverted to handwritten procedures following an attack. A major logistics company lost days of revenue after a ransomware incident froze customs processing.
  3. Crisis escalation: Even networks untouched by the malware are often taken offline proactively, intensifying disruption.

Downtime is not just an IT issue. It affects revenue, customers, and supply chains. Most firms are unprepared for a prolonged shutdown. And every hour of inaction compounds the impact.

Flowchart showing the 7 key stages of a ransomware attack, from breach to recovery.

Why Ransomware Is a Boardroom Issue

Ransomware is no longer a technical nuisance. It is a strategic threat with the power to disrupt operations, expose sensitive data, trigger regulatory scrutiny, and erode brand trust. For maritime executives, it directly threatens continuity, compliance, and commercial resilience.

1. Operational Paralysis

The most immediate impact is downtime. When core systems are encrypted, business stops.

  • Critical disruption: Booking systems, vessel tracking, port logistics, ERP platforms, and finance tools become inaccessible.
  • Real-world cases: A Greek hospital reverted to handwritten procedures following an attack. A major logistics company lost days of revenue after a ransomware incident froze customs processing.
  • Crisis escalation: Even networks untouched by the malware are often taken offline proactively, intensifying disruption.

Downtime is not just an IT issue. It affects revenue, customers, and supply chains. Most firms are unprepared for a prolonged shutdown. And every hour of inaction compounds the impact.

2. Data Breach Exposure

Nearly all modern ransomware attacks involve data exfiltration before encryption. This makes every incident a potential breach.

  • Leaked data: Client records, contracts, financials, maritime logs, procurement files, even personal IDs.
  • Double extortion: Threat actors demand payment to avoid public leaks, with data often dumped on dark web forums if ignored.
  • Reputational impact: Customers, investors, and strategic partners lose trust when sensitive information is exposed.

In one university attack in Greece, hundreds of gigabytes of research, financial, and student data were leaked. That breach had long-lasting effects on institutional credibility.

3. Legal, Regulatory & Compliance Risks

For organisations subject to GDPR, NIS2, IMO 2021, and other frameworks, ransomware triggers mandatory response actions.

  • Mandatory breach reporting under GDPR and national cyber legislation.
  • Risk of regulatory audits, especially if outdated systems or poor controls contributed to the breach.
  • Legal exposure: Affected clients or employees may seek legal remedies if personal data is leaked.

Failing to respond swiftly and transparently can increase penalties. Legal teams must often coordinate with IT and communications in high-pressure environments. For the board, this is a governance challenge.

4. Financial Impact

The financial fallout from ransomware extends far beyond ransom payments.

  • Recovery costs: Incident response teams, forensic analysts, legal counsel, PR firms, and security consultants.
  • Loss of revenue: Business interruption during downtime, especially if operations are customer-facing.
  • Insurance gaps: Some cyber insurance providers have begun limiting ransomware coverage or increasing premiums after incidents.
  • Market confidence: Listed companies often see a share price impact. M&A deals may be delayed or reconsidered post-breach.

According to the IBM Cost of a Data Breach Report 2024, the average breach in transportation now costs USD 4.45 million.

5. Reputational Harm

Cyberattacks are high-visibility events. Even when handled quietly, they often become public.

  • Brand perception declines: Customers lose trust, stakeholders ask hard questions.
  • Media scrutiny increases: Leaked data, failed backups, or ransom payments draw attention.
  • Leadership accountability: Boards demand answers. In some cases, C-level executives step down post-incident.

In the maritime sector, where operational trust is paramount, a cyber incident can damage commercial relationships and competitive positioning for years.

Final Word: From Reaction to Readiness

Ransomware is not slowing down. It is evolving, professionalising, and targeting sectors like maritime with growing precision.

The organisations that weather these attacks best are those that prepare in advance. Not with generic policies, but with realistic drills, tested backups, strong access controls, and board-level ownership of cyber risk.

The difference between a disruption and a disaster often comes down to one factor: how well-prepared you were before the breach.

If your organisation has not yet mapped its ransomware exposure or tested how it would respond, now is the time to act.

Next Step: Simulate Before It’s Real

ThreatScene’s cyber resilience team runs real-world simulations for maritime operators, logistics firms, and critical infrastructure providers across Europe. These are not generic tabletop exercises: they are mapped to your operational environment and risk profile.

Book a consultation with our team to evaluate your ransomware readiness and pressure-test your defences.

Stay ready. Stay resilient. Stay operational.

Curated with purpose, delivered with precision — UNIT 31 | ThreatScene.

Untitled design

Sources:

https://www.cisecurity.org/insights/blog/ransomware-the-data-exfiltration-and-double-extortion-trends

https://medium.com/@s.lontzetidis/greeces-2024-cyber-threat-landscape-trends-and-predictions-4015a1f0fbbc

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a#:~:text=continues%20to%20be%20prolific%20in,This

https://securitydelta.nl/news/overview/law-enforcement-disrupt-lockbit-world-s-biggest-ransomware-operation#:~:text=LockBit%20is%20widely%20recognised%20as,level%20by%20Europol%20and%20Eurojust

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a#:~:text=In%202022%2C%20LockBit%20was%20the,the%20operation%2C%20LockBit%20ransomware%20attacks

https://therecord.media/akira-ransomware-group-publishes-unprecedented-leak-data

https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-109a#:~:text=April%202023%2C%20following%20an%20initial,USD%29%20in%20ransomware%20proceeds

https://www.checkpoint.com/cyber-hub/threat-prevention/ransomware/play-ransomware-group-detection-and-protection/#:~:text=Play%20ransomware%2C%20also%20known%20as,company%20data%20and%20threaten%20businesses

If you like this article valuable, you can share it with your network

Recent Posts

ThreatScene - The Threat Brief - OT moves at the speed of Geopolitics

OT Now Moves at the Speed of Geopolitics

OT risk is no longer moving on engineering timelines. This article explains how geopolitical tension can turn internet-exposed industrial systems into active targets within hours, and why critical infrastructure operators must strengthen visibility, access control and recovery before the next crisis.

Read More »