, Singapore
541 views
Photo by Tima Miroshnichenko via Pexels

Ransomware groups surge as July attacks hit Singapore

ThreatBook 2025 report shows tech and finance hit hardest in mid-year breach wave.

Singapore faced a sharp rise in ransomware attacks in 2025, according to the 2025 Singapore Threat Intelligence Report by global cybersecurity firm ThreatBook with attacks peaking in July, affecting technology, finance, manufacturing, and government sectors.

The surge coincided with the release of multiple global software vulnerabilities, which attackers exploited to time their campaigns.

ThreatBook identifies Qilin, DireWolf, Lynx, DevMan, and Akira as the most active ransomware groups.

Qilin targets large enterprises using Office macros and Cobalt Strike to gain access, stealing sensitive data and moving laterally with credential-stealing tools and PowerShell scripts.

DireWolf focuses on manufacturing and industrial systems, combining encryption with public data leaks.

Lynx attacks high-value businesses across multiple sectors, relying on phishing, malware downloads, and social engineering to steal data before encryption.

DevMan targets energy and industrial firms, encrypting files offline and deleting backups, whilst Akira operates across manufacturing, healthcare, blockchain, and transport, exploiting VPN vulnerabilities and phishing campaigns, using segmented encryption and multi-mode data theft.

All five groups employ double extortion tactics, encrypting systems whilst exfiltrating data to dark web leak sites.

Common entry points include phishing emails, malware-laden documents, and exposed remote access tools such as RDP or VPN.

Lateral movement often relies on legitimate administrative tools like SMB, PsExec, AnyDesk, and RustDesk.

Join Singapore Business Review community

Follow the link for more news on

Join Singapore Business Review community
A NOTE FROM SINGAPORE BUSINESS REVIEW

You're the reader we write for. You're also the person our partners want to reach.

If that sentence describes you — a founder, a C-suite, someone whose attention companies pay good money for — then you already understand why SBR works. We've spent twenty years earning the trust of readers exactly like you. Which is exactly what makes this an interesting place for your company to show up, too.

The ways it can show up are broader than most people assume — thought leadership articles, sponsored content, industry summits across Southeast Asia, regional awards programmes, podcasts, and media placements in print and digital. The right fit depends on what you're trying to do, which is why we'd rather start with a conversation than send a rate card.

If your company has something this audience should know about, we'd like to hear what you're working on.

No rate cards until we understand the brief. It's a better use of everyone's time.