Actions on objectives are steps or activities taken to achieve a defined objective or goal. In a cybersecurity context, these measurable and actionable steps are part of a larger plan directly linked to threat actor objectives.
According to X-Force incident response data, the deployment of malware was the most observed action on objectives, making up 41% of cases. Of all the malware cases, 18% included the deployment of ransomware, while another 18% deployed webshells. Infostealers and backdoors both made up 10% of malware cases.
The next most observed action on objective was the use of legitimate tools for malicious purposes, accounting for 28% of cases. This finding reflects utilization of hands-on-keyboard post-exploitation efforts and the deployment of utilities that allow for follow-up activities such as lateral movement and privilege escalation.
The X-Force team’s review of dark-web activity indicated that Qilin, Clop, KillSecurity, IncRansom and Play were among the most active ransomware families over the past year. In 2025, Qilin was associated with the largest share of discussed ransomware events, followed by Clop. A ransomware event on the dark web refers to an instance in which a threat actor claims to have impacted an organization.
The 2025 ransomware ecosystem has become highly fragmented and decentralized. We identified 109 active ransomware or extortion groups, with rapid turnover and an increasingly small portion of victims attributed to the top 10 groups. This fragmentation reflects a lower barrier to entry: actors frequently reuse leaked tooling, follow established playbooks or shift between group identities, enabling many small operators to conduct opportunistic, low-volume attacks. Victim counts on ransomware leak sites increased approximately 12% year over year.
Tactically, data extortion has become central, with groups exfiltrating sensitive information and threatening leaks alongside file encryption. Supply-chain intrusions are also rising, with compromised vendors driving widespread downstream impact. Small and midsized organizations are increasingly targeted due to weaker defenses and higher likelihood of operational disruption. Although law-enforcement takedowns disrupt major operations, they have not reduced overall activity. Smaller groups quickly fill the gaps, and several actors have reconsolidated into larger conglomerates—indicating a temporary shift from competition to cooperation within the ransomware ecosystem.
The X-Force team continued to observe significant activity across both established and emerging infostealer families in 2025. Well-known stealers such as Lumma, RisePro, Vidar, Stealc and Rhadamanthys remained widespread, while newer families like Acreed expanded their presence in underground markets.
Although we observed an overall decrease in the number of infostealer events, this decline appears to be driven primarily by changes within Russian Market—a key forum for selling and distributing stolen credentials. Since November 2024, Russian Market-related activity dropped from 20,000–50,000 daily posts to roughly 9,000. This reduction reflects changes to the market’s own operations rather than a true decline in infostealer activity. Since February 2024, there have been intermittent spikes reaching 30,000 posts per day, but gaps in collection persist.
We observed several notable shifts in infostealer market share in 2025:
Strengthen security and compliance with IBM IAM services, streamlining identity across hybrid cloud environments.
Optimize your security program with IBM’s global, vendor-independent threat response services.
Build a secure identity foundation with IBM Verify to simplify access, improve authentication, and scale with confidence.