The Threat Landscape Now
Six things that changed about ransomware.
Each trend below comes from Halcyon's latest research — with a plain-English “what this means for you.”
Under 1 hour
Attacks now finish before you notice
Fast-moving groups like Akira can break in, spread, and encrypt an entire network in less than sixty minutes — far faster than a person can react.
What this means for you: you can't catch it mid-attack by hand. Automated detection and 24/7 monitoring are essential.
Halcyon: Akira SMBs first
Small businesses are the main target
Halcyon's 2025 research shows attackers deliberately shifting toward small and mid-sized companies — and into industries like automotive, retail, and healthcare.
What this means for you: “we're too small to be a target” is the most dangerous assumption you can make.
Halcyon: 2025 Evolution Report Backups first
Your backups get destroyed first
Newer variants hunt down and delete backups — even on Linux and virtual machines — before they start encrypting, so you have nothing to restore from.
What this means for you: backups must be offline or “immutable” (un-deletable) and tested regularly.
Halcyon: Pay2Key Linux Security off
They turn off your security tools
Groups like Play disable endpoint protection and even seize control of network firewalls before encrypting — blinding your defenses at the worst moment.
What this means for you: a single antivirus isn't enough. Layered defense and outside monitoring catch what one tool misses.
Halcyon: Play One click
A fake popup is the new front door
The “ClickFix” technique tricks employees with a fake error message that asks them to copy-and-paste a “fix” — which actually installs the malware themselves.
What this means for you: your people are the entry point. Security-awareness training is a frontline defense, not a checkbox.
Halcyon: ClickFix AI-assisted
AI is making attackers faster
Halcyon finds AI isn't inventing new super-weapons — but it is lowering the skill barrier and speeding up the work, so more attackers can move more quickly.
What this means for you: the fundamentals still defend you — but the window to get them right keeps shrinking.
Halcyon: AI & Ransomware