North America Intelligence Insights Report, April 2025
← Research Hub

North America Intelligence Insights Report, April 2025

Uncover the latest cyber threats targeting North America with Group-IB’s monthly threat insights—tailored for security leaders who need to stay ahead.

Inside, you’ll find detailed information on:

Phishing-as-a-Service evolvesPhishing-as-a-Service evolves

Threat actors exploit compromised corporate email systems to send fake crypto wallet recovery phrases and steal digital assets.

Deepfake deception on the riseDeepfake deception on the rise

AI-generated voice and video deepfakes used in tax-season phishing scams across the U.S., impersonating IRS agents, tax professionals, and even victims’ family members

RansomHub dominatesRansomHub dominates

77 North American organizations disclosed by the most active ransomware group this period.

Cactus surges post-Black BastaCactus surges post-Black Basta

After Black Basta’s suspected exit scam, Cactus ransomware group sees a spike in activity, disclosing 33 companies in February alone.

Shared TTPs and shifting alliancesShared TTPs and shifting alliances

BackConnect malware, social engineering, and leaked infrastructure signal overlap and migration between Black Basta and Cactus operators.