
Panel | What’s New in the World of Ransomware in 2025
Source: YouTube · SANS Digital Forensics and Incident Response · published Jun 26, 2025 · 44:20
Despite a notable shift toward cloud targeting, the 2025 ransomware landscape largely relies on the same repetitive tactics, techniques, and procedures (TTPs) seen in previous years 0:02.
Key Takeaways:
• Ransomware has not drastically evolved at its core, though attackers are increasingly focusing their efforts on cloud environments 0:12-0:26.
• For experienced incident response consultants, handling ransomware cases feels repetitive and predictable, often described as a "slow pitch softball" despite the client experiencing their worst day 0:29-0:52.
• The underlying tools and TTPs used by threat actors remain largely stagnant, requiring responders to rarely update their understanding of the attacker's toolkits 0:54-1:00.
Ultimately, while the targets may be shifting to the cloud, the fundamental mechanics of ransomware attacks remain highly consistent, allowing seasoned professionals to respond effectively.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
This is our panel entitled what's new in the world of ransomware in 2025. The idea for the panel is is this ransomware by and large has not really like majorly evolved. And what I mean by that is yes there's all kinds of gen small updates um and things of that nature. We just had a major update right now. Oh, they're going for your cloud and they're really going for your cloud. But as an incident response consultant, which I did for 5 years myself before moving to threat hunting, when you deal with ransomware cases, it's it feels like the same thing over and over and over and over. It becomes like a slow pitch softball. It's the worst day that client has ever had. And they're like, everything's on fire. But to you, you start reviewing, you start seeing the TTPs, you start seeing what servi…