X-Force Threat Intelligence Index 2026

Actions on objective

Actions on objectives are steps or activities taken to achieve a defined objective or goal. In a cybersecurity context, these measurable and actionable steps are part of a larger plan directly linked to threat actor objectives.

According to X-Force incident response data, the deployment of malware was the most observed action on objectives, making up 41% of cases. Of all the malware cases, 18% included the deployment of ransomware, while another 18% deployed webshells. Infostealers and backdoors both made up 10% of malware cases.

The next most observed action on objective was the use of legitimate tools for malicious purposes, accounting for 28% of cases. This finding reflects utilization of hands-on-keyboard post-exploitation efforts and the deployment of utilities that allow for follow-up activities such as lateral movement and privilege escalation.

Chart showing top actions on objectives observed in 2025 vs. 2024
Top actions on objectives observed in 2025 compared to 2024. Source: IBM X-Force.

Ransomware landscape

The X-Force team’s review of dark-web activity indicated that Qilin, Clop, KillSecurity, IncRansom and Play were among the most active ransomware families over the past year. In 2025, Qilin was associated with the largest share of discussed ransomware events, followed by Clop. A ransomware event on the dark web refers to an instance in which a threat actor claims to have impacted an organization.

The 2025 ransomware ecosystem has become highly fragmented and decentralized. We identified 109 active ransomware or extortion groups, with rapid turnover and an increasingly small portion of victims attributed to the top 10 groups. This fragmentation reflects a lower barrier to entry: actors frequently reuse leaked tooling, follow established playbooks or shift between group identities, enabling many small operators to conduct opportunistic, low-volume attacks. Victim counts on ransomware leak sites increased approximately 12% year over year.

Tactically, data extortion has become central, with groups exfiltrating sensitive information and threatening leaks alongside file encryption. Supply-chain intrusions are also rising, with compromised vendors driving widespread downstream impact. Small and midsized organizations are increasingly targeted due to weaker defenses and higher likelihood of operational disruption. Although law-enforcement takedowns disrupt major operations, they have not reduced overall activity. Smaller groups quickly fill the gaps, and several actors have reconsolidated into larger conglomerates—indicating a temporary shift from competition to cooperation within the ransomware ecosystem.

Pie chart showing the percentage of ransomware events attributed to top ransomware groups in 2025
A ransomware event on the dark web is defined as a claim made by a threat actor group that an organization has been impacted by ransomware. Source: IBM X-Force.

Infostealer landscape

The X-Force team continued to observe significant activity across both established and emerging infostealer families in 2025. Well-known stealers such as Lumma, RisePro, Vidar, Stealc and Rhadamanthys remained widespread, while newer families like Acreed expanded their presence in underground markets.

Although we observed an overall decrease in the number of infostealer events, this decline appears to be driven primarily by changes within Russian Market—a key forum for selling and distributing stolen credentials. Since November 2024, Russian Market-related activity dropped from 20,000–50,000 daily posts to roughly 9,000. This reduction reflects changes to the market’s own operations rather than a true decline in infostealer activity. Since February 2024, there have been intermittent spikes reaching 30,000 posts per day, but gaps in collection persist.

We observed several notable shifts in infostealer market share in 2025:

  • Lumma continued to dominate the ecosystem, maintaining roughly 50% of all observed activity.

  • Acreed and Rhadamanthys experienced significant growth, rising to approximately 16% and 11% of the market, respectively.

  • In contrast, Stealc’s share declined compared to 2024. This drop is likely tied to the timing of Acreed’s rapid expansion—Acreed gained visibility across major Telegram “malware-as-a-service” and traffer recruitment channels just as Stealc’s distribution networks were weakening.

  • Instability within Russian Market favored stealers with diversified log-resale channels. Families like Acreed, which integrated directly with smaller credential marketplaces and private Telegram resale groups, were better positioned to capture market share amid these disruptions.
Pie chart showing the top Infostealers based on credentials for sale
Top 5 infostealers seen on dark web forums based on credentials for sale. Source: IBM X-Force.
3d sphere and cube shapes surrounded by locks
Related solutions
Identity and access management (IAM) services

Strengthen security and compliance with IBM IAM services, streamlining identity across hybrid cloud environments.

Explore IAM services
Threat detection and response services

Optimize your security program with IBM’s global, vendor-independent threat response services.

Explore threat detection services
IBM Verify

Build a secure identity foundation with IBM Verify to simplify access, improve authentication, and scale with confidence.

Explore IBM Verify
Take the next step

Book a personalized discovery briefing to explore how IBM X-Force® can help you reduce cyber risk, validate your defenses and build lasting cyber resilience with offensive and defensive expertise.

  1. Schedule a discovery session with X-Force
  2. Explore IBM X-Force