Global Incident Response Report 2025

We see five major emerging trends reshaping the threat landscape. First, threat actors are augmenting traditional ransomware and extortion with attacks designed to intentionally disrupt operations. In 2024, 86% of incidents that Unit 42 responded to involved business...

Hypervisor Hangover: Persistence Mechanisms on ESXi

As FIN groups continue to execute fast-impact ransomware campaigns and nation-state APTs favor long-term infrastructure control, hypervisors have become the new high ground. This talk explores a set of stealthy, reliable persistence techniques targeting VMware ESXi,...

LockBit: A Threat Profile

Aliases   ABCD ransomware   LockBit 2.0    LockBit Black (3.0)   LockBit Green   LockBit 5.0 Get Threat Intel and Security Updates Delivered to Your Inbox.   Profiling   Threat Actor Type: Ransomware-as-a-Service (RaaS) with global affiliate network.  ...

The 99% Solution: MFA for Hypervisor Security

Hypervisor attacks are accelerating, and the cost is catastrophic. Recent ESXi ransomware attacks have cost organizations hundreds of millions in recovery. In some cases, a single ESXi breach has led to costs exceeding $400 million.   Ransomware targeting virtualized...