Executive Summary
The January 2025 threat report from Revealer.US covers activity observed across underground markets, leak sites, stealer log ecosystems, and exploit chatter during the reporting window. Ransomware extortion volume jumped. Lumma and RedLine still dominate the infostealer ecosystem. 420 million newly exposed credentials became searchable through Revealer.US. Zero-days clustered around enterprise networking appliances and collaboration platforms. Initial access brokers raised prices as demand outpaced supply.
Patch the two critical CVEs disclosed this month first. Then check whether any of your accounts showed up in the new breach corpuses, and write detections for the TTP shifts in the Emerging Techniques section. This report is the monthly snapshot. A data breach lookup and stealer-log search are how you query the underlying data on demand.
Ransomware Activity
Ransomware leak site postings climbed 18 percent month over month, with 312 unique victim disclosures observed across tracked groups. Manufacturing, healthcare, and professional services were the most targeted verticals, together accounting for 58 percent of postings.
Top Active Groups
- LockBit 3.0: 47 claimed victims this month. Despite ongoing law enforcement pressure from Operation Cronos, the affiliate network continues to post victims. Notable disclosures included a mid-market European logistics provider and a US regional hospital system.
- RansomHub: 41 victims. RansomHub has absorbed affiliates from defunct operations and now rivals LockBit in raw volume. Average ransom demands trend higher, with several reported figures in the 8 million USD range.
- Play: 28 victims, continuing its consistent mid-pack performance with a preference for manufacturing and construction targets.
- Akira: 24 victims, with a notable focus on VPN appliance exploitation for initial access.
- Qilin: 22 victims. Qilin has matured operationally and introduced a cross-platform Rust variant targeting ESXi.
- BlackSuit: 17 victims, including a high profile services firm whose data was auctioned after negotiations failed.
Notable Incidents
One particularly disruptive incident involved a North American food distributor whose operational systems were encrypted during peak shipping windows, cascading into downstream grocery chains. Another involved a healthcare network where patient scheduling and imaging were offline for nine days. Both are reminders that ransomware remains primarily a business continuity threat, not just a data confidentiality threat.
Infostealer Campaigns
The infostealer ecosystem is no longer amateur hour. Three families dominate the log volume reaching underground marketplaces and Telegram channels. Fresh logs from those families are the same material a stealer-log lookup is built to search.
Lumma Stealer
Lumma surpassed RedLine this month as the single largest contributor of fresh stealer logs, accounting for approximately 38 percent of new logs observed. Distribution vectors include fake CAPTCHA lures ("verify you are human by pressing Win+R"), cracked software bundles, and YouTube comment spam linking to fake installers. Lumma operators introduced a new panel version this month with improved evasion against common EDR vendors.
RedLine
RedLine accounted for roughly 29 percent of new logs. Despite the November 2024 international takedown operation against RedLine infrastructure, rebranded and forked variants continue to operate. The marketplace has fragmented rather than collapsed, a pattern we saw previously with Raccoon Stealer.
Vidar and StealC
Vidar contributed 14 percent of logs, with StealC at 11 percent. Both are increasingly sold bundled with loaders and crypto drainers in MaaS subscription packages priced at 150 to 300 USD per month.
Distribution Trends
- SEO poisoning for software keywords (AnyDesk, Notion, Figma, OBS) remains the top delivery mechanism.
- Malvertising via Google Ads continues despite platform enforcement, with operators rapidly rotating accounts.
- ClickFix and fake CAPTCHA lures expanded beyond consumer targets into corporate help desk impersonation.
Credential Exposures
420 million new credential records became searchable through Revealer.US during the reporting window. This includes fresh stealer log entries, newly surfaced breach data, and continuous additions from paste sites and leak channels.
Highlights:
- New breach corpuses: Two previously undisclosed data sets surfaced on forums, together containing 87 million email/password pairs tied to ecommerce and SaaS platforms.
- Stealer log additions: 290 million credential pairs extracted from infostealer logs, representing activity across an estimated 2.1 million infected devices.
- Combo list compilations: 43 million records from recompiled combo lists, useful for correlation but lower signal than fresh logs.
For organizations checking their domains, January's exposure deltas were concentrated in finance, gaming, and education sectors. Security teams should expect credential stuffing follow-on activity over the next 30 to 60 days targeting accounts that appeared in this month's exposure data. An email lookup against those corpuses is the fastest way to see whether a specific mailbox showed up.
Zero-Day and CVE Highlights
Two critical vulnerabilities dominated the patching conversation this month.
CVE-2024-57892
An unauthenticated remote code execution flaw in a widely deployed enterprise VPN appliance. Exploitation was observed in the wild within 48 hours of disclosure, with both Akira and a suspected Scattered Spider subcluster chaining the vulnerability for initial access. Patch immediately; if patching is delayed, restrict management interface exposure and hunt for indicators of prior compromise.
CVE-2024-58104
A deserialization flaw in a popular collaboration and file sharing platform allowing authenticated attackers to escalate to SYSTEM. Public proof-of-concept code was released within 72 hours. Cl0p was observed testing the vulnerability against exposed instances, consistent with their historical preference for file transfer and collaboration platform zero-days (MOVEit, GoAnywhere, Accellion).
Additional CVEs to Watch
- CVE-2024-56721: Privilege escalation in a major Linux container runtime.
- CVE-2024-55319: Authentication bypass in a network attached storage vendor, actively exploited by an unattributed ransomware affiliate.
- CVE-2024-54402: Browser sandbox escape reported to a major vendor and patched out of band.
Emerging TTPs
Detection engineering teams should treat these tradecraft shifts as current, not theoretical.
- T1566.002 (Spearphishing Link) via Microsoft Teams: APT29 and multiple criminal clusters expanded Teams based social engineering, impersonating IT support to coax users into running remote assistance sessions.
- T1078.004 (Valid Accounts - Cloud Accounts): Scattered Spider continues to refine its SIM swap to SSO pipeline, with observed pivots through help desk social engineering into Okta and Azure AD.
- T1485 (Data Destruction): Several ransomware affiliates are now deploying wipers alongside encryptors when negotiations fail, eliminating the possibility of silent recovery.
- T1027.013 (Encrypted/Encoded File) via WebAssembly: A small but rising share of loaders embed payloads inside WASM modules to bypass static detection.
- T1556.006 (MFA Request Generation): MFA fatigue attacks remain common, but we are also seeing token theft via adversary in the middle kits paired with real time session replay.
Recommendations for Security Teams
- Patch CVE-2024-57892 and CVE-2024-58104 as priority zero; both have in-the-wild exploitation.
- Query your credential exposure monitoring for any new hits tied to executive, privileged, or service accounts that surfaced this month.
- Review Teams and collaboration platform external access policies. If external federation is on by default, consider restricting it.
- Update help desk verification procedures to defeat SIM swap and social engineering pivots into SSO.
- Ensure EDR is detecting Lumma and StealC loader patterns; new panel versions have altered some telemetry signatures.
- Review IOCs published by CISA and commercial feeds this month for the ransomware groups listed above; block known infrastructure at the perimeter.
- Run a tabletop exercise covering a VPN appliance compromise into ransomware scenario; it remains the most likely path to a major incident in the coming quarter.
Conclusion
January 2025 did not produce one headline catastrophe. It produced escalation in every category we track: ransomware volume, stealer-log volume, credential volume, and in-the-wild exploitation of newly disclosed CVEs. If your monitoring cadence is still monthly, it is already slower than the attackers. Reports like this one are a rear-view mirror. They do not replace checking the feeds that matter to your organization the day a new corpus lands.
To search credential exposure, stealer logs, and breach data tied to your domains, see pricing or start with a free account.
Want to check the exposures in this report against your own domains? Run a data breach lookup or search stealer logs in Revealer.US.