Alexander Lawall, IU International University of Applied Sciences, Germany
Petra Beenken, IU International University of Applied Sciences, Germany
Alexandra Blia, Rapid7, Czech Republic
The current ransomware ecosystem is analyzed, focusing on the Tactics, Techniques, and Procedures (TTPs) adopted by ransomware groups. The last two years are considered and compared. The purpose of the research is to enhance the understanding of ransomware operations and to improve defense strategies. The paper investigates the research questions: (1) How has the ransomware ecosystem evolved over the past two years? and (2) What is the impact of these changes on the TTPs adopted by ransomware groups? Using Open Source Intelligence and Dark Web Intelligence, the methodology follows a three-step approach: (1) Identifying active ransomware groups, (2) Profiling threat actors and mapping their TTPs to the MITRE ATT&CK framework, and (3) Prioritizing mitigation strategies based on a heatmap analysis. The research outcomes reveal a shift in top ransomware techniques with an increasing focus on data exfiltration, vulnerability exploitation, and cloud-based exfiltration. This contributes to empirical insights and data-driven mitigation recommendations, supporting cybersecurity professionals, policymakers, and researchers in strengthening resilience against ransomware attacks.