RadioCSIRT - Edition Française · Marc Frédéric GOMEZ

Ép.594 - RadioCSIRT Épisode Spécial Panorama de la Cybermenace 2025 du jeudi 12 mars 2026

·24 min·2 clips
Marc-Frédéric Gomez breaks down the NSSI's 2025 cyber threat panorama, revealing a 51% surge in data exfiltration incidents.
1. RadioCSIRT, a French cybersecurity podcast, dedicates this episode to a chapter-by-chapter walkthrough of the ANSSI Cyber Threat Panorama 2025, reference CertFR-2026-CTI-002, published March 11. 2. Host Marc-Frédéric Gomez presents as a practitioner who attended the CertFR presentation day for this report, giving him direct access to context beyond the public document. 3. The episode's thesis is that the 2025 threat landscape is stable in volume but structurally more opaque, harder to attribute, and technically better adapted to evade traditional defenses. 4. ANSSI treated 3,586 security events in 2025, an 18% drop from 2024 attributed to the exceptional volume spike during the Paris Olympic and Paralympic Games. 5. Confirmed incidents reached 1,366 — effectively flat versus 1,361 in 2024 — but represent a four-year upward trend from 831 in 2022. 6. Four sectors concentrated 76% of all incidents: education and research (34%), ministries and local authorities (24%), healthcare (10%), and telecommunications (9%). 7. Data exfiltration incidents rose 51% to 196 cases in 2025 from 130 in 2024, representing the most significant quantitative shift in the report. 8. Killin ransomware was the most active franchise with 700+ claimed victims including 185 in October 2025 alone; Operation Endgame conducted two additional dismantlement actions targeting Luma Stealer and Radamantis. 9. Clop group exploited CVE-2025-6182 in Oracle e-Business Suite in August 2025 to exfiltrate data from hundreds of companies globally, with ANSSI confirming 80 legitimate claims among all received. 10. North Korean MOA Slit deployed Killin ransomware in a limited number of attacks; Chinese-linked operators used NellaO'Locker and EraWorld ransomware alongside PlugX and ShadowPad espionage tools — a new documented convergence. 11. In espionage, Callisto — attributed by multiple sources to Russia's FSB — targeted members of the French NGO Reporters Without Borders in March 2025 via phishing emails. 12. A new threat actor, Landry Bayer, was created in 2025 by Dutch agencies AIVD and MIVD; it has been active since 2024 targeting EU governmental, military, and media entities. 13. TURLA, attributed to the 16th Centre of Russia's FSB and active since 2004, was documented in July 2025 exploiting Russia's SORM legal interception system to insert into communications between diplomatic personnel and local phone operators, deploying the APOLLOCHAN malware chain. 14. Salt Typhoon compromised the US Army's federal network between March and December 2024, potentially accessing personal data, military credentials, and regional architecture diagrams; ANSSI observed its victimology expanding in France. 15. The most significant sabotage event was a series of coordinated destructive attacks — not DDoS — against Polish electrical infrastructure attributed to Russia-linked actors, the first destructive attack on EU member state infrastructure. 16. In August 2025, Norway's PST formally attributed to Russian attackers the remote takeover of a dam in the western part of the country. 17. On attacker capabilities, AnyDesk was the most documented RMM tool in ANSSI incidents, deployed by INC Ransom affiliates in a hospital attack in October 2025; APT28 used cloud storage services including Filen.io for payload staging in Operation FantomNet Voxel. 18. The 'ClickFix' technique — tricking victims into executing malicious commands via fake CAPTCHAs or error prompts — progressed sharply from autumn 2024, used by APT28, Callisto, and cybercriminal groups to distribute RATs and infostealers. 19. On access vectors, 29% of exploited vulnerabilities in 2025 were exploited on the day of publication or before, compressing the defender reaction window; more than 6,200 French assets remain affected by vulnerabilities from 2023-2024 as of end-2025. 20. Cybersecurity professionals working in threat intelligence, SOC operations, or compliance under NIS2 and GDPR will extract the most value from this episode.
Listen to the show on